Skip to content
Knowledge Base

Amendment to the NSC Act (NIS2) 2026 — Calendar of Deadlines and Obligations Step by Step

The amendment to the NSC Act implementing NIS2 entered into force on 3 April 2026 and launched a strict schedule. The first deadline — registration in the list — falls on 3 October 2026. We explain the entire calendar of deadlines and the order of actions, so that you do not miss any obligation.

On 3 April 2026, the amendment to the National Cybersecurity System Act (NSC), which implements the EU NIS2 Directive into Polish law, entered into force. For thousands of companies and institutions this means one thing: the clock is already ticking. From the day of entry into force, the statutory deadlines began to run, and the first of them — the obligation to submit an application for registration in the list of essential and important entities — falls on 3 October 2026.

The problem is that many organizations still do not know whether they are subject to the new regulations at all, what exactly they have to do, and in what order. In this guide we organize the full calendar of deadlines and obligations, based on the official schedule of the Ministry of Digital Affairs.

What exactly does the amendment to the NSC Act change from 3 April 2026?

The amendment extends the national cybersecurity system to new sectors of the economy and introduces two categories of entities covered by the regulation: essential entities and important entities. It imposes on organizations operating in strategic sectors of the economy the obligation to apply appropriate technical and organizational measures that enhance the security of IT systems.

A key change of a managerial nature: the new regulations introduce liability of the heads of entities for the performance of cybersecurity tasks. Cybersecurity ceases to be solely a problem for the IT department — it becomes an obligation of the management board.

What is the full calendar of NSC/NIS2 deadlines?

We have gathered the most important dates arising from the statutory schedule in a single table:

DeadlineWhat happens
3 April 2026Entry into force of the amendment — all statutory deadlines begin to run
3 October 2026Final deadline for submitting the application for registration in the list of essential and important entities (6 months)
3 April 2027Deadline for implementing the full obligations by entities meeting the criteria on the day the act enters into force
3 April 2028Deadline for the first mandatory cybersecurity audit for essential entities; from this date penalties for the majority of obligations may be imposed

Each of these deadlines triggers a different set of tasks — which is why it is not enough to remember only the registration deadline.

What needs to be done by 3 October 2026?

By 3 October 2026, essential and important entities have time to submit the application for registration in the list. This is the first important deadline arising from the act. In practice it means six months for two things:

  1. Verifying whether a given entity is subject to the new regulations — that is, carrying out self-identification based on the sector of operation and the size of the organization.
  2. Completing the registration formalities — preparing and submitting the application for registration in the list.

Beware of a common interpretation error: submitting the application for registration is not the same as full implementation of security obligations. Registration is only the first, formal step.

How does an essential entity differ from an important entity?

This distinction determines the scope of obligations and the intensity of supervision. In a great simplification:

  • Essential entity — a large organization in a sector of the highest criticality (including energy, transport, banking, healthcare, digital infrastructure); subject to proactive supervision and the highest requirements.
  • Important entity — an organization in the remaining sectors covered by the act; subject to reactive supervision (after an incident occurs).

We have described the exact sectoral criteria and size thresholds in the article on who the national cybersecurity system applies to.

How can I check whether my company is subject to the new regulations?

The Polish model is based on self-identification — the organization itself is to assess whether it meets the statutory criteria. It is worth carrying out the verification in three steps:

  1. Sector — whether you operate in one of the sectors listed in the act (e.g. digital infrastructure, manufacturing, water management, healthcare, postal services).
  2. Size — whether you exceed the employment or turnover thresholds set for medium-sized and larger entities.
  3. Role in the supply chain — whether you provide services critical to other entities covered by the regulation.

If the answer to these questions is affirmative, you most likely fall under the act and are obliged to register in the list by 3 October 2026.

What obligations must be implemented by 3 April 2027?

By 3 April 2027, essential and important entities that meet the statutory criteria on the day the amendment enters into force must implement the full obligations arising from the new regulations. These include, among others:

  • implementation of an information security management system (ISMS) and security policies,
  • risk management, including supply chain risk,
  • procedures for incident handling and reporting,
  • mechanisms ensuring business continuity (BCP/DR),
  • training and building a culture of cyber hygiene within the organization.

To plan these activities rationally, start with a diagnosis — we describe it in detail in the guide to the KSC/NIS2 readiness audit for CISOs.

When will penalties start to apply and what is the liability of the management board?

The legislator has provided for a transitional period. For the majority of obligations, administrative financial penalties will only be able to be imposed after two years have elapsed from the entry into force of the act, that is, after 3 April 2028. This is intentional — this period is meant to give entities time to prepare thoroughly, rather than to act under the pressure of an immediate sanction.

This is not, however, a reason to delay. Implementing a mature security system takes months, and the responsibility for carrying out the tasks rests directly on the management of the entity. A management board that ignores the schedule exposes the organization not only to future penalties, but above all to a real risk of an incident.

What does incident reporting look like in the new system?

One of the pillars of NIS2 is the efficient reporting of serious incidents. The reporting model is multi-stage — from an early warning within the first hours, through the proper notification, to the final report. Operational readiness to meet these deadlines requires continuous security monitoring. We describe how to build such a capability in the article on continuous SOC monitoring and incident reporting.

Where to start preparations right now?

Even though full penalties will come into effect later, the window for calm preparation is narrow. The recommended order of actions:

  1. Self-identification — establish whether and as what type of entity (essential/important) you are subject to the act.
  2. Readiness audit (gap analysis) — measure the distance between the current state and the requirements of the act.
  3. Roadmap — prioritize the gaps according to risk and cost, with a budget and schedule.
  4. Registration in the list — complete the formalities before 3 October 2026.
  5. Implementation — carry out the roadmap so as to close the obligations before 3 April 2027.
  • Essential entity — the highest category of supervision in NIS2
  • Important entity — the remaining sectors covered by the act
  • NIS2 — the EU directive implemented through the NSC amendment
  • DORA — a parallel regulation for the financial sector

Check out our services

Do you need support in implementing KSC/NIS2 requirements? Check out:

The KSC/NIS2 amendment is not a one-off project, but a lasting change in the way security is managed. The earlier you start, the less pressure there will be at the subsequent deadlines in the schedule.

Share:

Talk to an expert

Have questions about this topic? Get in touch with our specialist.

Sales Representative
Przemysław Widomski

Przemysław Widomski

Sales Representative

Response within 24 hours
Free consultation
Individual approach

Providing your phone number will speed up contact.

Want to Reduce IT Risk and Costs?

Book a free consultation - we respond within 24h

Response in 24h Free quote No obligations

Or download free guide:

Download NIS2 Checklist