arrow_circle_right Critical Infrastructure
Compliance with the KSC Act to withstand scrutiny
The amended National Cybersecurity System Act has been in effect in Poland since 3 April this year. We apply the engineering discipline of defence programmes to critical infrastructure, systems that meet the requirements and can prove it in the register, incident report or audit.
Compliance timeline 2026–2028
The Act establishes the relevant deadlines, each of which requires supporting evidence. Since July 2026, the CER Directive has applied in parallel. Although it does not cover all entities within scope, where it does apply, its obligations are cumulative and sit alongside those under the KSC Act.
-
Act enters into force: self-identification of entities begins.
-
Current status: self-identification process underway.
-
Registration deadline: essential and important entities must register in the S46 system.
-
Implementation deadline: ISMS and Chapter 3 obligations must be in place.
-
Audit deadline: First security audit required for essential entities, repeated every 3 years thereafter.
Stronger enforcement & greater personal responsibility
€10m or 2% of global turnover
The maximum administrative fine for an essential entity – up to €7m or 1.4% of turnover.
300% of monthly pay – a personal fine on the head of the entity
The Act allocates responsibility for cybersecurity to the head of the entity, rather than to the IT department. If no board member is designated, all of them are liable. Delegation does not remove responsibility. Training is mandatory. For public entities, penalties are capped at 100%.
36% of security specialists don’t know if they fall under NIS2
Self-identification is the first obligation, and where most organisations trip up.
The KSC Act sets the mandate, CER builds the capability
Everyone falls under the KSC Act through self-identification. A CER designation is an administrative decision that imposes obligations, not the other way around.
The KSC Act
(implements NIS2)
- Information security management system (ISMS)
- Incident reporting: early warning within 24 h, notification within 72 h
- Risk analysis and technical-organisational measures
- Security audit every 3 years
The Crisis Management Act amendment
(implements CER)
- Physical and organisational resilience, continuity of the essential service
- Register of critical suppliers and their assessment at least once a year
- Contingency plans for replacing a supplier
- Reporting of significant incidents, critical infrastructure protection report
Compliance by design – from self-identification to audit
We build practical systems that are designed to meet the Act’s requirements and automatically generate the evidence needed to demonstrate compliance as your organisation operates, drawing on the same evidence-driven delivery approach we use across defence programmes.
Self-identification and gap assessment
We will confirm your status as either essential, important or out of scope, and then map your systems against Chapter 3 and the CER obligations.
Impact: a prioritised gap report and a roadmap to 3 April 2027.
ISMS architecture and reporting
We build the technical backbone, including monitoring, incident handling within the 24/72-hour window, access control and business continuity.
Impact: a working management system.
Audit readiness
We organised the evidence in a way that an auditor would recognise, in preparation for the 2028 audit and the annual supplier check.
Impact: one evidence base serving KSC and CER from a single source.
The technology behind the compliance
The Act sets out our obligations, which we then transform into practical, technology-enabled systems with a proven track record.
Incident detection & reporting in one flow
Monitoring is integrated directly into your incident process, so the 24/72-hour clock starts from data that has already been collected.
Compliance evidence platform
Logs, registers, test results and documentation, gathered automatically as systems run, into one structure an auditor recognises.
OT and asset visibility
An inventory of systems, devices and network flows that matches operational reality — the foundation every risk analysis in the Act rests on.
Supplier assessment workflow
A critical supplier register with the annual CER assessment built into procurement.
Qualified for defence. Ready for your critical supplier register
Acting in line with norms, certificates & standards
See our certifications:
- ISO/IEC 27001
- AQAP 2110 / 2210 / 2310 (NATO)
- AS/EN 9100
- TISAX
- Cyber Essentials
- ISO 9001
- WSK – strategic goods trade control
- Polish Ministry of Interior licence
- NATO NCAGE registration
- JOSCAR
Sectors covered by the essential and important entity regime
Energy
Water & wastewater
Transport
Telecommunications
Healthcare
Find out how to prepare critical infrastructure for what’s next
Registration by 3 October. A working system by 3 April 2027. Start by identifying the gaps!
The assessment process begins with an initial conversation about your sector, essential services and current systems. We will review your current position, pinpoint the key gaps and outline the next steps.
Complete the form, and we will get back to you within one working day.