Penalties for non-compliance with UKSC/NIS2 will not apply until April 2028 – sounds like good news, but it is not. The two-year period without sanctions can easily be confused with the impression that there is still plenty of time. And this is the worst reason to delay implementation of the amendment to the Act (KSC 2.0).
Because punishment is not the first thing that will happen. First comes the incident: interrupted business continuity, customers who cannot be served, and contracts that go to better-prepared competitors.
Therefore, the real deadline to think about when implementing UKSC/NIS2 is not written in the Act. It is determined by the first incident, customer pressure and personal responsibility of the management board – and these do not wait until 2028. During the webinar on KSC implementation, we broke down this trap into prime factors – if you want to gain access to recordings and materials, fill out the form on this page.
Where did the two-year penalty-free period come from?
The Act provides for a transitional period during which administrative fines for non-compliance are not imposed. It covers the first two years of the regulations being in force, i.e. until April 2028. This also applies to a situation in which the entity does not report to the KSC List on time (by October 3, 2026).
For the first two years after the entry into force of the act, i.e. until April 2028, no penalties will be imposed at all. There is a clear exclusion in our act – it will not be possible to impose a financial penalty for someone who does not report to the list of KSC entities by October 3.
However, it is worth separating two things: no penalty from no obligation. The provisions apply from the date the Act enters into force – only the possibility of their financial enforcement in the first period is excluded. The deadlines for the implementation itself (full implementation of the ISMS and connection to the S46 system by April 3, 2027) run regardless of this exclusion.
Postponing the topic until 2028 is actually abandoning it
The main effect of delay is that theorganization does not start workat all. Failure to register is usually a symptom of a broader problem – uncertainty about one’s status, which blocks subsequent steps. Marcin Serafin pointed this out:
If someone does not report, it is probably not because they already know everything, but just forgot to do it – but probably because they have put it off and are still not entirely sure whether they are subject to it, to what extent they are subject to it, and consequently they cannot actually start work related to the implementation. And this is actually the whole point.
The entire process of preparing the organization is postponed – from qualifications, through systems inventory, to response procedures. It is worth remembering that compliance is not the default state: as noted in the interview, most organizations still need to be adapted to NIS2 and KSC, and being “automatically” compliant is the exception, not the rule.
The risk of punishment increases with the risk of the incident
Administrative punishment rarely occurs in isolation from the event. In practice, it is the result of an incident – loss of data or interruption of business continuity – and not the formal misconduct itself.The less prepared the organization, the greater the probability that such an event will occur, and the more serious its consequences.
At the webinar about KSC, an important caveat was made: high-profile, publicly disclosed ransomware attacks are only the tip of the iceberg. Below it are organizations that suffered measurable losses, numbering in millions, as a result of incidents, although they never made headlines. From this perspective, the date 2028 is irrelevant for risk assessment – events are not guided by the legislator’s calendar.
There is also a personal dimension. The amendment makes the management responsible for cybersecurity, and delegating tasks to the IT department does not remove this responsibility – it also changes the position of the person responsible for security, as we wrote about in more detail in the article “How does UKSC/NIS2 affect the role of CISO?”.
Why are penalties not the main tool for enforcing compliance with UKSC?
Sanctions are not a mechanism on which the legislator bases the effectiveness of regulations. If the goal was to enforce compliance through the threat of penalties, the design of the regulations would be different.
The legislator does not think that penalties will force someone to implement or not implement – because if that were the case, automatic scanning of everyone would be implemented, not administrative proceedings and so on. However, the legislator thinks that if we deal with issues, we will think about how to adapt, we will analyze the risks associated with us and therefore we will adapt and it will be a process, not a one-off project that will end.
The purpose of regulation is to encourage organizations to manage risk on an ongoing basis. Cybersecurity treated as a permanent process, and not a one-off project closed with an entry in the list, actually reduces the likelihood of an incident. It is this change in approach, and not formal compliance itself, that is the effect that UKSC is about.
The market enforces requirements faster than the legislator
Compliance with UKSC/NIS2 is increasingly verified not by authorities, but by contractors. This was pointed out by Jerzy Muszyński, legal advisor:
The pressure associated with KSC is not due to deadlines and penalties, but rather because – in my opinion – these requirements are starting to flow through the supply chain, contracts, customer audits, requests for proposals and management accountability. Because, in fact, for the first time in such a broader context, we can talk about the company’s management board being an active entity participating in the current management of cybersecurity within the company’s structures.
This is confirmed by experience with GDPR. Over the eight years that the regulations have been in force, approximately one hundred financial penalties have been imposed in Poland, and yet the level of security has clearly increased – it was not caused by sanctions, but by market requirements.
With UKSC, the mechanism is the same: the entity covered by the act must manage the security of the entire supply chain, so it transfers the requirements to its suppliers by contract. An organization that does not meet the standard will not receive a fine from the state, but may lose its contract – and this happens well before 2028.
How to use the time to implement UKSC requirements?
It is worth treating the time until the sanctions enter into force as a space for calm, documented implementation, carried out without last-minute pressure. First, four actions make sense:
→ self-identification with the evidence left – determining whether and as what entity the organization is subject to the regulations,
→ inventory of critical systems and verification of backup copies of data on which business continuity depends,
→ developing and testing an incident response procedure,
→ implementation plan within a 30/60/90-day horizon, ready to be presented to the management board.

