← Regulatory & Technology Tracker

EU Applicable (EU) 2022/2555 PL: KSC register deadline 2026-10-03

NIS2 — cybersecurity duties for essential and important entities

NIS2 widens the scope far beyond classic critical infrastructure and puts management bodies personally on the hook for cybersecurity measures. In Poland the amended National Cybersecurity System Act implements the directive on a fixed calendar: entry in the KSC register by 3 October 2026, implemented duties (ISMS, incident reporting, responsible persons, S46 connection) by 3 April 2027, first mandatory cybersecurity audit by 3 April 2028.

Now: confirm classification (essential/important) and prepare the register entry for September. Next: plan backwards from the 2028 audit — it will ask for a year of operating evidence. Monitor: sector-specific guidance from national authorities.

Official source → · Last verified: 2026-08-01

This material is provided for general information and does not constitute legal, investment, tax, audit or other regulated professional advice. Its application depends on the facts, jurisdiction and current law. Verify the current status of the cited sources and obtain appropriate advice before acting.