Skip to content
Governance, Risk and Compliance

KSC compliance and NIS2 implementation

The amendment to the Polish KSC Act transposing NIS2 significantly expands the catalogue of entities covered by regulation in Poland — essential services operators, digital service providers, and their supply chain. Fines reach €10 million or 2% of global turnover, with personal liability of management. We guide you from entity classification, through gap analysis and control implementation, to incident reporting to CSIRT and ongoing compliance maintenance.

Sales Representative
Grzegorz Gnych

Grzegorz Gnych

Sales Representative

What is KSC and NIS2 compliance?

KSC (Krajowy System Cyberbezpieczeństwa — Polish National Cybersecurity System) and NIS2 compliance is the process in which an organization classifies itself as an essential or important entity, audits gaps against the Polish KSC Act and the EU NIS2 Directive, implements required controls (ISMS, supply chain risk management, incident response, business continuity, cryptography, MFA), and builds an incident reporting process to CSIRT within the required deadlines (24h / 72h / 1 month). nFlo runs the full cycle: from entity classification and gap analysis, through implementation and documentation, to compliance maintenance and support during regulator inspections.

200+ clients
Experience in compliance
24/7 SOC
24/7 SOC for incident reporting
Audit + implementation + maintenance
Full compliance cycle

Fines up to €10 million and personal liability of management — KSC is not just paperwork

€10 million or 2% of global turnover — maximum NIS2 fine for essential entities

Three pillars of KSC and NIS2 compliance

Gap analysis

Entity classification and assessment of current state against the KSC Act and NIS2 Directive

Control implementation

ISMS, supply chain risk management, incident response, BCM, cryptography, MFA — documentation and technical controls

Maintenance and reporting

Ongoing oversight, incident reporting to CSIRT NASK within 24h / 72h / 1 month deadlines

What is KSC and NIS2 — in 60 seconds

KSC (Krajowy System Cyberbezpieczeństwa — Polish National Cybersecurity System) is the Polish act that builds the national information security management system and transposes the European Union directive NIS2 (Network and Information Security Directive 2) into Polish law. The amendment transposing NIS2 significantly expands the catalogue of entities covered by regulation — from a narrow group of essential services operators to the entire ecosystem of critical sectors and their supply chain.

AttributeValue
EU actNIS2 Directive (2022/2555)
PL actKSC Act (amended for NIS2)
Scope18 critical sectors + ICT supply chain
Maximum fine€10 million or 2% of global turnover
Incident reporting deadline24h (early warning) / 72h (notification) / 1 month (final)
Competent authority in PLCSIRT NASK, CSIRT GOV, sector-specific CSIRTs

nFlo guides companies in Poland through the full cycle of KSC and NIS2 compliance — from entity classification, through gap analysis and control implementation, to ongoing compliance maintenance and incident reporting to CSIRT.

Essential services operator missed the reporting deadline — fine plus inspection

A mid-sized digital infrastructure provider had no formal incident classification procedure. After a ransomware attack, the IT team spent the first 18 hours trying to restore services and only after 30 hours formally reported the incident to CSIRT — breaching the 24h early warning threshold. The regulator initiated a review proceeding, during which it turned out that current ISMS documentation and ICT supplier records were also missing. The outcome: an administrative fine, an order to implement missing controls within 6 months, and a personal proceeding against the management board member responsible for cybersecurity.

Without KSC and NIS2 preparation:

  • You risk fines up to €10 million or 2% of annual turnover
  • You don’t know if you are subject to regulation (extended catalogue of 18 sectors)
  • You lose contracts — recipients in the supply chain require proof of compliance
  • The management board bears personal liability, including a possible ban on holding management positions
  • The regulator may order suspension of service delivery

Who is covered by the 2024 amendment — entity matrix

The amendment to the KSC Act transposing NIS2 introduces three categories of covered entities. Classification determines the scope of obligations, reporting deadlines and the level of potential fines.

Essential entities

Medium and large enterprises in sectors of the highest critical significance:

  • Energy — production, transmission and distribution of electricity, gas, oil, heat
  • Transport — air, rail, water, road (infrastructure operators and transport service providers)
  • Banking — credit institutions
  • Financial market infrastructure — trading venue operators, CCPs
  • Healthcare — hospitals, diagnostic laboratories, manufacturers of medicines and medical devices
  • Drinking water and waste water
  • Digital infrastructure — IXPs, DNS, TLDs, cloud providers, data centres, CDNs, trust service providers, electronic communications
  • ICT service management (B2B) — MSP and MSSP providers

Important entities

Medium and large enterprises in the remaining sectors covered by the directive:

  • Postal and courier services
  • Waste management
  • Production, processing and distribution of food
  • Manufacturing (including medical devices, computers, electronic equipment, machinery, vehicles)
  • Processing of chemicals
  • E-commerce, online search engines and social platforms
  • Scientific research

Supply chain of essential services operators

Indirectly covered are all ICT suppliers providing services to essential or important entities. Recipients have an obligation to run a SCRM (Supply Chain Risk Management) process and to require, by contract, defined controls from suppliers: incident reporting, right to audit, MFA, cryptography, vulnerability management and business continuity.

Quantitative thresholds

  • Medium enterprise — 50–249 employees OR turnover up to €50 million / balance sheet total up to €43 million
  • Large enterprise — over 250 employees OR turnover above €50 million

Regardless of size, fully covered are, among others, qualified trust service providers, DNS, TLD and IXP providers, and public administration to the extent defined in the KSC Act.

Your obligations in 5 areas

The NIS2 Directive and the KSC Act require risk management controls in five key areas. Each is reviewed during the audit process and during regulator inspections.

1. ISMS — Information Security Management System

A board-approved security policy, an asset inventory, defined roles and responsibilities, information classification procedures, access management (MFA, least privilege), cryptography (data at rest and in transit), backup and restore policy, vulnerability management, security patching, monitoring and event logging. Best built on a recognised standard — ISO/IEC 27001, NIST CSF or CIS Controls.

2. SCRM — Supply Chain Risk Management

An inventory of all ICT suppliers, classification of criticality, supply chain risk assessment (including cloud and open source providers), contractual clauses requiring incident reporting and right to audit, security assessment of new suppliers before contract signature. A requirement of NIS2 Article 21(2)(d).

3. Incident Response

An incident response plan (IR plan), runbooks for the most common scenarios (ransomware, phishing, BEC, DDoS, Active Directory compromise), tabletop exercises at least once a year, an IR team with clearly assigned roles, and an incident reporting procedure to CSIRT within the required deadlines. Minimum: a 24/7 SOC or an Incident Response retainer with a guaranteed response time.

4. BCM — Business Continuity Management

Business continuity plan (BCP) and disaster recovery plan (DRP), Recovery Time Objective and Recovery Point Objective for critical functions, regular recovery testing, network segmentation, offline (immutable) backups resistant to ransomware, geographic redundancy for essential entities. BCP tests at least once a year, with documented results.

5. Incident reporting

An incident classification procedure (when does an event become a “significant incident”), an early warning template, a communication channel with CSIRT NASK / CSIRT GOV / sector-specific CSIRT, internal escalation to the management board, an incident log, and a mechanism for periodic review of control effectiveness. Three thresholds: 24h (early warning), 72h (notification), 1 month (final report).

Our implementation process (6 steps)

Step 1 — Entity classification

We check whether the organization is an essential entity, an important entity, or part of the supply chain of an essential services operator. We analyse activity, sector, size (employees, turnover, balance sheet total), products and services provided to entities covered by regulation. Outcome: a documented classification with legal justification that can be presented to the regulator.

Step 2 — Gap analysis

We compare the current state of controls with the requirements of the KSC Act, the NIS2 Directive and relevant sector-specific standards. We analyse documents (policies, procedures, registers), technical configurations (firewall, EDR, IAM, backup, SIEM) and organizational processes (incident response, BCM, SCRM). Outcome: a gap report with risk assessment and prioritization.

Step 3 — Implementation plan (roadmap)

We build a prioritized roadmap with timeline, budget, task owners and milestones. We highlight quick wins (configuration changes, policies) and long-term projects (SIEM, segmentation, IAM, cryptography). The roadmap distinguishes mandatory and recommended controls, and provides mapping to ISO/IEC 27001 and NIST CSF, if the organization wants to maintain a single coherent programme.

Step 4 — Control implementation

We support the actual implementation of controls — from drafting ISMS documentation, through tool configuration (MFA, EDR, SIEM, cryptography, backup), to internal communications and training. Where needed, we engage a vCISO as a permanent advisor who oversees implementation on the organizational and process side.

Step 5 — Validation

We verify the effectiveness of implemented controls through penetration testing, internal audit and tabletop exercises — incident simulations in which the team walks through the full path from detection to CSIRT notification. Validation fulfils the NIS2 Article 21 requirement for regular assessment of effectiveness.

Step 6 — 24h reporting and maintenance

We deploy an operational procedure for reporting incidents to CSIRT, backed by our 24/7 SOC, with response times agreed in the retainer. In the retainer model we provide ongoing compliance oversight: quarterly reviews, documentation updates following infrastructure changes, support during regulator inspections, and periodic verification tests and tabletop exercises.

What we deliver

  • Entity classification with legal justification (at a level that can be presented to the regulator)
  • Gap analysis report against the KSC Act, NIS2 and sector-specific guidelines
  • Implementation roadmap with timeline, budget, owners and milestones
  • Full ISMS documentation: policies, procedures, roles, asset and risk registers
  • SCRM programme: supplier register, criticality classification, contractual clauses, assessment process
  • Incident Response plan with runbooks for 6–10 scenarios
  • Business continuity plan (BCP) and disaster recovery plan (DRP) with RTO/RPO for critical functions
  • Incident reporting procedure to CSIRT (24h / 72h / 1 month) with forms and communication channels
  • Training materials for the management board, IT/security teams and all employees (awareness)
  • Verification penetration test reports and tabletop exercise results
  • Support during regulator inspections (documentation preparation, assistance, responses to requests)
  • Optionally: ongoing compliance oversight (vCISO) and 24/7 SOC

Pricing — three engagement models

Model 1 — Gap analysis

A one-off project ending with a gap report and an implementation roadmap. Scope: entity classification, control assessment, documentation of existing gaps with prioritization, remediation plan. Typical duration: 3–6 weeks. Best suited for organizations that want to understand the scale of work before deciding on a full implementation, or that need a formal report for the management board.

Model 2 — Full implementation

A project covering all steps from classification through validation to handover of the incident reporting procedure. Scope: gap analysis, roadmap, ISMS/SCRM/IR/BCM documentation, implementation support, training, verification tests, tabletop exercise. Typical duration: 3–9 months depending on the maturity and scale of the organization. Best suited for essential and important entities starting from scratch or with significant gaps.

Model 3 — Compliance maintenance (retainer)

Ongoing oversight of KSC and NIS2 compliance with a dedicated account manager and access to a 24/7 SOC for incident notifications. Scope: quarterly ISMS reviews, documentation updates following infrastructure changes, periodic verification tests, tabletop exercises, support during regulator inspections, mentoring of the cybersecurity team. Best suited for entities that have already achieved compliance and want to maintain it, and for essential entities mandatorily reporting incidents within 24h.

We prepare an individual quote after an initial scoping conversation (15–30 min) — at no cost to the client.

Why nFlo

  • 200+ clients in cybersecurity, including entities in sectors covered by KSC and NIS2 (energy, healthcare, finance, digital infrastructure, public administration)
  • 98% client retention — an indicator that shows our clients stay with us in long-term maintenance models
  • 24/7 SOC with response times agreed in the retainer — the operational base for meeting the 24h early warning requirement to CSIRT
  • The team holds CISSP, CISA, ISO 27001 Lead Auditor, OSCP and CEH certifications — full coverage of audit, implementation and verification testing
  • Experience with penetration testing aligned with the control effectiveness assessment requirement (NIS2 Article 21)
  • A full service ecosystem: from KSC compliance through vCISO, incident response and sectoral programmes such as Cybersecure Local Government for local government units and NIS2 compliance for other sectors

Learn more about the key concepts related to this service:

Contact your account manager

Discuss KSC compliance and NIS2 implementation with your dedicated account manager.

Sales Representative
Grzegorz Gnych

Grzegorz Gnych

Sales Representative

Response within 24 hours
Free consultation
Custom quote

Providing your phone number will speed up contact.

How we work

Our proven service delivery process.

01

Entity classification

We check whether you are an essential entity, an important entity or part of the supply chain of an essential services operator

02

Gap analysis

Assessment against the KSC Act, NIS2 and sector-specific guidelines

03

Implementation plan

Prioritized roadmap with timeline, budget and task owners

04

Control implementation

ISMS, supply chain risk management, IR, BCM, cryptography, MFA, verification tests, training

05

Validation

Penetration tests, internal audit, incident notification rehearsal (tabletop exercise)

06

24h reporting

Procedure for notifying CSIRT NASK, retainer for 24/7 SOC, support during regulator inspections

Benefits for your business

What you gain by choosing this service.

Avoid fines up to €10 million

KSC and NIS2 requirements met for essential and important entities

Inspection readiness

Full ISMS, SCRM, IR and BCM documentation aligned with regulator requirements

24h reporting

Procedure and 24/7 SOC meeting the early warning deadline to CSIRT

Resilient supply chain

Audit and contractual requirements for ICT suppliers (SCRM)

Frequently Asked Questions

Common questions about KSC compliance and NIS2 implementation.

What is the difference between KSC and NIS2?

NIS2 is a European Union directive that by itself does not create direct obligations for companies in Poland — it requires transposition into national law. KSC (Krajowy System Cyberbezpieczeństwa — Polish National Cybersecurity System) is the Polish act that transposes these requirements. In practice: if you are subject to NIS2 in the EU, in Poland you fulfil obligations under the KSC Act as amended for NIS2. We perform compliance audits against both acts at the same time, because definitions, deadlines and penalties are interlinked.

Who is covered by the KSC Act amendment transposing NIS2?

The amendment expands the catalogue of entities. Covered are: essential services operators (OUK) in sectors such as energy, transport, banking, healthcare, water, digital infrastructure; digital service providers (cloud, marketplace, search engine); public administration entities, and medium and large enterprises in 18 critical sectors. On top of this comes indirect coverage of the supply chain — ICT suppliers of essential entities must meet contractual SCRM requirements.

What penalties apply for failure to comply with KSC and NIS2?

For essential entities, the maximum fine is €10 million or 2% of global turnover (whichever is higher). For important entities — €7 million or 1.4% of turnover. The NIS2 Directive also introduces personal liability of management, including the possibility of a temporary ban on holding management positions. The Polish KSC Act adds administrative fines and sanctions for failure to report an incident within the required deadline.

Within what deadline must I report an incident to CSIRT?

Three reporting levels apply. Early warning — within 24 hours of detection of a significant incident, with basic information. Notification — within 72 hours, with initial assessment and technical data. Final report — within 1 month of the incident, with root cause analysis, description of remediation actions and conclusions. Notifications are sent to the competent CSIRT — in Poland most often CSIRT NASK for civilian entities.

Do KSC and NIS2 require penetration testing?

Yes. Article 21 of the NIS2 Directive explicitly requires regular assessment of the effectiveness of risk management measures, which in practice is carried out through penetration tests, security audits and red team exercises. For financial sector entities, TLPT (Threat-Led Penetration Testing) additionally applies under DORA. We deliver verification penetration tests as part of our [penetration testing service](https://nflo.tech/services/penetration-testing/) — these are recommended at least once a year and after any material change in infrastructure.

How is this service different from the Cyberbezpieczny Samorząd programme?

The [Cyberbezpieczny Samorząd (Cybersecure Local Government)](https://nflo.tech/services/local-government-cybersecurity/) programme is dedicated to local government units (municipalities, counties, voivodeships) and is based on a grant of up to PLN 2 million. This KSC compliance service is aimed at essential services operators, digital service providers, supply chain entities, and medium and large enterprises outside local government — without the grant track, but with full support in entity classification, ISMS/SCRM implementation, CSIRT reporting and compliance maintenance.

Does my client's supply chain force KSC compliance on me?

Yes — if you provide ICT services (cloud, software, integration, hosting, MSP) to an entity classified as essential under KSC/NIS2, that entity has an obligation to require from you contractually defined security controls as part of its SCRM (Supply Chain Risk Management) process. In practice, this means clauses on incident reporting, right to audit, MFA, cryptography, vulnerability management and business continuity. As part of this service we help both recipients (how to build an SCRM programme for suppliers) and suppliers (how to meet contractual requirements and remain competitive).

How long does KSC and NIS2 compliance implementation take?

Implementation time depends on the maturity of the organization and the current state of controls. Gap analysis and entity classification typically take 3–6 weeks. Implementation of missing controls (ISMS, SCRM, IR, BCM, cryptography, MFA, reporting) — from 3 to 9 months depending on scale. Compliance maintenance and reporting is an ongoing process, most often in a retainer model with a dedicated account manager and access to a 24/7 SOC for incident notifications.

Want to Reduce IT Risk and Costs?

Book a free consultation - we respond within 24h

Response in 24h Free quote No obligations

Or download free guide:

Download NIS2 Checklist