← Regulatory & Technology Tracker
NIS2 — cybersecurity duties for essential and important entities
NIS2 widens the scope far beyond classic critical infrastructure and puts management bodies personally on the hook for cybersecurity measures. In Poland the amended National Cybersecurity System Act implements the directive on a fixed calendar: entry in the KSC register by 3 October 2026, implemented duties (ISMS, incident reporting, responsible persons, S46 connection) by 3 April 2027, first mandatory cybersecurity audit by 3 April 2028.
Now: confirm classification (essential/important) and prepare the register entry for September. Next: plan backwards from the 2028 audit — it will ask for a year of operating evidence. Monitor: sector-specific guidance from national authorities.
Official source → · Last verified: 2026-08-01