arrow_circle_right Critical Infrastructure

Compliance with the KSC Act to withstand scrutiny

The amended National Cybersecurity System Act has been in effect in Poland since 3 April this year. We apply the engineering discipline of defence programmes to critical infrastructure, systems that meet the requirements and can prove it in the register, incident report or audit.

Man presenting cybersecurity data to team, explaining code and network monitoring workflow. Compliance with the KSC Act to withstand scrutiny. Critical Infrastructure

arrow_circle_right Certificates

Compliance timeline 2026–2028

The Act establishes the relevant deadlines, each of which requires supporting evidence. Since July 2026, the CER Directive has applied in parallel. Although it does not cover all entities within scope, where it does apply, its obligations are cumulative and sit alongside those under the KSC Act.

  • Act enters into force: self-identification of entities begins.

  • Current status: self-identification process underway.

  • Registration deadline: essential and important entities must register in the S46 system.

  • Implementation deadline: ISMS and Chapter 3 obligations must be in place.

  • Audit deadline: First security audit required for essential entities, repeated every 3 years thereafter.

Stronger enforcement & greater personal responsibility

€10m or 2% of global turnover

The maximum administrative fine for an essential entity – up to €7m or 1.4% of turnover.

300% of monthly pay – a personal fine on the head of the entity

The Act allocates responsibility for cybersecurity to the head of the entity, rather than to the IT department. If no board member is designated, all of them are liable. Delegation does not remove responsibility. Training is mandatory. For public entities, penalties are capped at 100%.

36% of security specialists don’t know if they fall under NIS2

Self-identification is the first obligation, and where most organisations trip up.

The KSC Act sets the mandate, CER builds the capability

Everyone falls under the KSC Act through self-identification. A CER designation is an administrative decision that imposes obligations, not the other way around.

The KSC Act

(implements NIS2)

  • Information security management system (ISMS)
  • Incident reporting: early warning within 24 h, notification within 72 h
  • Risk analysis and technical-organisational measures
  • Security audit every 3 years

The Crisis Management Act amendment

(implements CER)

  • Physical and organisational resilience, continuity of the essential service
  • Register of critical suppliers and their assessment at least once a year
  • Contingency plans for replacing a supplier
  • Reporting of significant incidents, critical infrastructure protection report

Compliance by design – from self-identification to audit

We build practical systems that are designed to meet the Act’s requirements and automatically generate the evidence needed to demonstrate compliance as your organisation operates, drawing on the same evidence-driven delivery approach we use across defence programmes.

assessment

Self-identification and gap assessment

We will confirm your status as either essential, important or out of scope, and then map your systems against Chapter 3 and the CER obligations.

Impact: a prioritised gap report and a roadmap to 3 April 2027.

api

ISMS architecture and reporting

We build the technical backbone, including monitoring, incident handling within the 24/72-hour window, access control and business continuity.

Impact: a working management system.

fact_check

Audit readiness

We organised the evidence in a way that an auditor would recognise, in preparation for the 2028 audit and the annual supplier check.

Impact: one evidence base serving KSC and CER from a single source.

The technology behind the compliance

The Act sets out our obligations, which we then transform into practical, technology-enabled systems with a proven track record.

Incident detection & reporting in one flow

Monitoring is integrated directly into your incident process, so the 24/72-hour clock starts from data that has already been collected.

Compliance evidence platform

Logs, registers, test results and documentation, gathered automatically as systems run, into one structure an auditor recognises.

OT and asset visibility

An inventory of systems, devices and network flows that matches operational reality — the foundation every risk analysis in the Act rests on.

Supplier assessment workflow

A critical supplier register with the annual CER assessment built into procurement.

Qualified for defence. Ready for your critical supplier register

Acting in line with norms, certificates & standards

See our certifications:

Sectors covered by the essential and important entity regime

Energy

Water & wastewater

Transport

Telecommunications

Healthcare

Find out how to prepare critical infrastructure for what’s next

arrow_circle_right

Registration by 3 October. A working system by 3 April 2027. Start by identifying the gaps!

The assessment process begins with an initial conversation about your sector, essential services and current systems. We will review your current position, pinpoint the key gaps and outline the next steps.

Complete the form, and we will get back to you within one working day.

 

Łukasz Wójcik

Lukasz Wojcik

Director of Industry 4.0 – Automation & Connectivity

+48 664 029 647