KSC compliance and NIS2 implementation
The amendment to the Polish KSC Act transposing NIS2 significantly expands the catalogue of entities covered by regulation in Poland — essential services operators, digital service providers, and their supply chain. Fines reach €10 million or 2% of global turnover, with personal liability of management. We guide you from entity classification, through gap analysis and control implementation, to incident reporting to CSIRT and ongoing compliance maintenance.

What is KSC and NIS2 compliance?
KSC (Krajowy System Cyberbezpieczeństwa — Polish National Cybersecurity System) and NIS2 compliance is the process in which an organization classifies itself as an essential or important entity, audits gaps against the Polish KSC Act and the EU NIS2 Directive, implements required controls (ISMS, supply chain risk management, incident response, business continuity, cryptography, MFA), and builds an incident reporting process to CSIRT within the required deadlines (24h / 72h / 1 month). nFlo runs the full cycle: from entity classification and gap analysis, through implementation and documentation, to compliance maintenance and support during regulator inspections.
Fines up to €10 million and personal liability of management — KSC is not just paperwork
Three pillars of KSC and NIS2 compliance
Gap analysis
Entity classification and assessment of current state against the KSC Act and NIS2 Directive
Control implementation
ISMS, supply chain risk management, incident response, BCM, cryptography, MFA — documentation and technical controls
Maintenance and reporting
Ongoing oversight, incident reporting to CSIRT NASK within 24h / 72h / 1 month deadlines
What is KSC and NIS2 — in 60 seconds
KSC (Krajowy System Cyberbezpieczeństwa — Polish National Cybersecurity System) is the Polish act that builds the national information security management system and transposes the European Union directive NIS2 (Network and Information Security Directive 2) into Polish law. The amendment transposing NIS2 significantly expands the catalogue of entities covered by regulation — from a narrow group of essential services operators to the entire ecosystem of critical sectors and their supply chain.
| Attribute | Value |
|---|---|
| EU act | NIS2 Directive (2022/2555) |
| PL act | KSC Act (amended for NIS2) |
| Scope | 18 critical sectors + ICT supply chain |
| Maximum fine | €10 million or 2% of global turnover |
| Incident reporting deadline | 24h (early warning) / 72h (notification) / 1 month (final) |
| Competent authority in PL | CSIRT NASK, CSIRT GOV, sector-specific CSIRTs |
nFlo guides companies in Poland through the full cycle of KSC and NIS2 compliance — from entity classification, through gap analysis and control implementation, to ongoing compliance maintenance and incident reporting to CSIRT.
Essential services operator missed the reporting deadline — fine plus inspection
A mid-sized digital infrastructure provider had no formal incident classification procedure. After a ransomware attack, the IT team spent the first 18 hours trying to restore services and only after 30 hours formally reported the incident to CSIRT — breaching the 24h early warning threshold. The regulator initiated a review proceeding, during which it turned out that current ISMS documentation and ICT supplier records were also missing. The outcome: an administrative fine, an order to implement missing controls within 6 months, and a personal proceeding against the management board member responsible for cybersecurity.
Without KSC and NIS2 preparation:
- You risk fines up to €10 million or 2% of annual turnover
- You don’t know if you are subject to regulation (extended catalogue of 18 sectors)
- You lose contracts — recipients in the supply chain require proof of compliance
- The management board bears personal liability, including a possible ban on holding management positions
- The regulator may order suspension of service delivery
Who is covered by the 2024 amendment — entity matrix
The amendment to the KSC Act transposing NIS2 introduces three categories of covered entities. Classification determines the scope of obligations, reporting deadlines and the level of potential fines.
Essential entities
Medium and large enterprises in sectors of the highest critical significance:
- Energy — production, transmission and distribution of electricity, gas, oil, heat
- Transport — air, rail, water, road (infrastructure operators and transport service providers)
- Banking — credit institutions
- Financial market infrastructure — trading venue operators, CCPs
- Healthcare — hospitals, diagnostic laboratories, manufacturers of medicines and medical devices
- Drinking water and waste water
- Digital infrastructure — IXPs, DNS, TLDs, cloud providers, data centres, CDNs, trust service providers, electronic communications
- ICT service management (B2B) — MSP and MSSP providers
Important entities
Medium and large enterprises in the remaining sectors covered by the directive:
- Postal and courier services
- Waste management
- Production, processing and distribution of food
- Manufacturing (including medical devices, computers, electronic equipment, machinery, vehicles)
- Processing of chemicals
- E-commerce, online search engines and social platforms
- Scientific research
Supply chain of essential services operators
Indirectly covered are all ICT suppliers providing services to essential or important entities. Recipients have an obligation to run a SCRM (Supply Chain Risk Management) process and to require, by contract, defined controls from suppliers: incident reporting, right to audit, MFA, cryptography, vulnerability management and business continuity.
Quantitative thresholds
- Medium enterprise — 50–249 employees OR turnover up to €50 million / balance sheet total up to €43 million
- Large enterprise — over 250 employees OR turnover above €50 million
Regardless of size, fully covered are, among others, qualified trust service providers, DNS, TLD and IXP providers, and public administration to the extent defined in the KSC Act.
Your obligations in 5 areas
The NIS2 Directive and the KSC Act require risk management controls in five key areas. Each is reviewed during the audit process and during regulator inspections.
1. ISMS — Information Security Management System
A board-approved security policy, an asset inventory, defined roles and responsibilities, information classification procedures, access management (MFA, least privilege), cryptography (data at rest and in transit), backup and restore policy, vulnerability management, security patching, monitoring and event logging. Best built on a recognised standard — ISO/IEC 27001, NIST CSF or CIS Controls.
2. SCRM — Supply Chain Risk Management
An inventory of all ICT suppliers, classification of criticality, supply chain risk assessment (including cloud and open source providers), contractual clauses requiring incident reporting and right to audit, security assessment of new suppliers before contract signature. A requirement of NIS2 Article 21(2)(d).
3. Incident Response
An incident response plan (IR plan), runbooks for the most common scenarios (ransomware, phishing, BEC, DDoS, Active Directory compromise), tabletop exercises at least once a year, an IR team with clearly assigned roles, and an incident reporting procedure to CSIRT within the required deadlines. Minimum: a 24/7 SOC or an Incident Response retainer with a guaranteed response time.
4. BCM — Business Continuity Management
Business continuity plan (BCP) and disaster recovery plan (DRP), Recovery Time Objective and Recovery Point Objective for critical functions, regular recovery testing, network segmentation, offline (immutable) backups resistant to ransomware, geographic redundancy for essential entities. BCP tests at least once a year, with documented results.
5. Incident reporting
An incident classification procedure (when does an event become a “significant incident”), an early warning template, a communication channel with CSIRT NASK / CSIRT GOV / sector-specific CSIRT, internal escalation to the management board, an incident log, and a mechanism for periodic review of control effectiveness. Three thresholds: 24h (early warning), 72h (notification), 1 month (final report).
Our implementation process (6 steps)
Step 1 — Entity classification
We check whether the organization is an essential entity, an important entity, or part of the supply chain of an essential services operator. We analyse activity, sector, size (employees, turnover, balance sheet total), products and services provided to entities covered by regulation. Outcome: a documented classification with legal justification that can be presented to the regulator.
Step 2 — Gap analysis
We compare the current state of controls with the requirements of the KSC Act, the NIS2 Directive and relevant sector-specific standards. We analyse documents (policies, procedures, registers), technical configurations (firewall, EDR, IAM, backup, SIEM) and organizational processes (incident response, BCM, SCRM). Outcome: a gap report with risk assessment and prioritization.
Step 3 — Implementation plan (roadmap)
We build a prioritized roadmap with timeline, budget, task owners and milestones. We highlight quick wins (configuration changes, policies) and long-term projects (SIEM, segmentation, IAM, cryptography). The roadmap distinguishes mandatory and recommended controls, and provides mapping to ISO/IEC 27001 and NIST CSF, if the organization wants to maintain a single coherent programme.
Step 4 — Control implementation
We support the actual implementation of controls — from drafting ISMS documentation, through tool configuration (MFA, EDR, SIEM, cryptography, backup), to internal communications and training. Where needed, we engage a vCISO as a permanent advisor who oversees implementation on the organizational and process side.
Step 5 — Validation
We verify the effectiveness of implemented controls through penetration testing, internal audit and tabletop exercises — incident simulations in which the team walks through the full path from detection to CSIRT notification. Validation fulfils the NIS2 Article 21 requirement for regular assessment of effectiveness.
Step 6 — 24h reporting and maintenance
We deploy an operational procedure for reporting incidents to CSIRT, backed by our 24/7 SOC, with response times agreed in the retainer. In the retainer model we provide ongoing compliance oversight: quarterly reviews, documentation updates following infrastructure changes, support during regulator inspections, and periodic verification tests and tabletop exercises.
What we deliver
- Entity classification with legal justification (at a level that can be presented to the regulator)
- Gap analysis report against the KSC Act, NIS2 and sector-specific guidelines
- Implementation roadmap with timeline, budget, owners and milestones
- Full ISMS documentation: policies, procedures, roles, asset and risk registers
- SCRM programme: supplier register, criticality classification, contractual clauses, assessment process
- Incident Response plan with runbooks for 6–10 scenarios
- Business continuity plan (BCP) and disaster recovery plan (DRP) with RTO/RPO for critical functions
- Incident reporting procedure to CSIRT (24h / 72h / 1 month) with forms and communication channels
- Training materials for the management board, IT/security teams and all employees (awareness)
- Verification penetration test reports and tabletop exercise results
- Support during regulator inspections (documentation preparation, assistance, responses to requests)
- Optionally: ongoing compliance oversight (vCISO) and 24/7 SOC
Pricing — three engagement models
Model 1 — Gap analysis
A one-off project ending with a gap report and an implementation roadmap. Scope: entity classification, control assessment, documentation of existing gaps with prioritization, remediation plan. Typical duration: 3–6 weeks. Best suited for organizations that want to understand the scale of work before deciding on a full implementation, or that need a formal report for the management board.
Model 2 — Full implementation
A project covering all steps from classification through validation to handover of the incident reporting procedure. Scope: gap analysis, roadmap, ISMS/SCRM/IR/BCM documentation, implementation support, training, verification tests, tabletop exercise. Typical duration: 3–9 months depending on the maturity and scale of the organization. Best suited for essential and important entities starting from scratch or with significant gaps.
Model 3 — Compliance maintenance (retainer)
Ongoing oversight of KSC and NIS2 compliance with a dedicated account manager and access to a 24/7 SOC for incident notifications. Scope: quarterly ISMS reviews, documentation updates following infrastructure changes, periodic verification tests, tabletop exercises, support during regulator inspections, mentoring of the cybersecurity team. Best suited for entities that have already achieved compliance and want to maintain it, and for essential entities mandatorily reporting incidents within 24h.
We prepare an individual quote after an initial scoping conversation (15–30 min) — at no cost to the client.
Why nFlo
- 200+ clients in cybersecurity, including entities in sectors covered by KSC and NIS2 (energy, healthcare, finance, digital infrastructure, public administration)
- 98% client retention — an indicator that shows our clients stay with us in long-term maintenance models
- 24/7 SOC with response times agreed in the retainer — the operational base for meeting the 24h early warning requirement to CSIRT
- The team holds CISSP, CISA, ISO 27001 Lead Auditor, OSCP and CEH certifications — full coverage of audit, implementation and verification testing
- Experience with penetration testing aligned with the control effectiveness assessment requirement (NIS2 Article 21)
- A full service ecosystem: from KSC compliance through vCISO, incident response and sectoral programmes such as Cybersecure Local Government for local government units and NIS2 compliance for other sectors
Related concepts
Learn more about the key concepts related to this service:
Related services
- NIS2 and DORA Compliance — general NIS2 and DORA implementation for 18 critical sectors
- Cybersecure Local Government — dedicated path for local government units with a grant of up to PLN 2 million
- Penetration testing — verification penetration tests required by NIS2 Article 21
- vCISO — ongoing oversight of the cybersecurity programme and KSC compliance
Contact your account manager
Discuss KSC compliance and NIS2 implementation with your dedicated account manager.

How we work
Our proven service delivery process.
Entity classification
We check whether you are an essential entity, an important entity or part of the supply chain of an essential services operator
Gap analysis
Assessment against the KSC Act, NIS2 and sector-specific guidelines
Implementation plan
Prioritized roadmap with timeline, budget and task owners
Control implementation
ISMS, supply chain risk management, IR, BCM, cryptography, MFA, verification tests, training
Validation
Penetration tests, internal audit, incident notification rehearsal (tabletop exercise)
24h reporting
Procedure for notifying CSIRT NASK, retainer for 24/7 SOC, support during regulator inspections
Benefits for your business
What you gain by choosing this service.
Avoid fines up to €10 million
KSC and NIS2 requirements met for essential and important entities
Inspection readiness
Full ISMS, SCRM, IR and BCM documentation aligned with regulator requirements
24h reporting
Procedure and 24/7 SOC meeting the early warning deadline to CSIRT
Resilient supply chain
Audit and contractual requirements for ICT suppliers (SCRM)
Related Articles
Expand your knowledge with our resources.
IT services outsourcing — how to choose a provider and where to draw the line of responsibility
Outsourcing IT services is not a decision about whether to outsource, but a decision about where the line of responsibility runs. This article compares three delivery models, shows what stays on your side despite the contract, and lists the questions worth asking a provider before you sign.
Read more →Penetration test vs vulnerability scan: what really differs
A company that buys a scan instead of a pentest is not buying the same thing for less — it is buying different information. Here is exactly where the boundary runs and how to arrange both into one process.
Read more →Web application penetration testing cost and what creates it
Three quotes for testing the same application can differ several times over — and rarely because someone applies a different margin. Each one prices different work. Here is what that difference is made of, and how to write a request that makes quotes comparable.
Read more →Frequently Asked Questions
Common questions about KSC compliance and NIS2 implementation.
What is the difference between KSC and NIS2?
NIS2 is a European Union directive that by itself does not create direct obligations for companies in Poland — it requires transposition into national law. KSC (Krajowy System Cyberbezpieczeństwa — Polish National Cybersecurity System) is the Polish act that transposes these requirements. In practice: if you are subject to NIS2 in the EU, in Poland you fulfil obligations under the KSC Act as amended for NIS2. We perform compliance audits against both acts at the same time, because definitions, deadlines and penalties are interlinked.
Who is covered by the KSC Act amendment transposing NIS2?
The amendment expands the catalogue of entities. Covered are: essential services operators (OUK) in sectors such as energy, transport, banking, healthcare, water, digital infrastructure; digital service providers (cloud, marketplace, search engine); public administration entities, and medium and large enterprises in 18 critical sectors. On top of this comes indirect coverage of the supply chain — ICT suppliers of essential entities must meet contractual SCRM requirements.
What penalties apply for failure to comply with KSC and NIS2?
For essential entities, the maximum fine is €10 million or 2% of global turnover (whichever is higher). For important entities — €7 million or 1.4% of turnover. The NIS2 Directive also introduces personal liability of management, including the possibility of a temporary ban on holding management positions. The Polish KSC Act adds administrative fines and sanctions for failure to report an incident within the required deadline.
Within what deadline must I report an incident to CSIRT?
Three reporting levels apply. Early warning — within 24 hours of detection of a significant incident, with basic information. Notification — within 72 hours, with initial assessment and technical data. Final report — within 1 month of the incident, with root cause analysis, description of remediation actions and conclusions. Notifications are sent to the competent CSIRT — in Poland most often CSIRT NASK for civilian entities.
Do KSC and NIS2 require penetration testing?
Yes. Article 21 of the NIS2 Directive explicitly requires regular assessment of the effectiveness of risk management measures, which in practice is carried out through penetration tests, security audits and red team exercises. For financial sector entities, TLPT (Threat-Led Penetration Testing) additionally applies under DORA. We deliver verification penetration tests as part of our [penetration testing service](https://nflo.tech/services/penetration-testing/) — these are recommended at least once a year and after any material change in infrastructure.
How is this service different from the Cyberbezpieczny Samorząd programme?
The [Cyberbezpieczny Samorząd (Cybersecure Local Government)](https://nflo.tech/services/local-government-cybersecurity/) programme is dedicated to local government units (municipalities, counties, voivodeships) and is based on a grant of up to PLN 2 million. This KSC compliance service is aimed at essential services operators, digital service providers, supply chain entities, and medium and large enterprises outside local government — without the grant track, but with full support in entity classification, ISMS/SCRM implementation, CSIRT reporting and compliance maintenance.
Does my client's supply chain force KSC compliance on me?
Yes — if you provide ICT services (cloud, software, integration, hosting, MSP) to an entity classified as essential under KSC/NIS2, that entity has an obligation to require from you contractually defined security controls as part of its SCRM (Supply Chain Risk Management) process. In practice, this means clauses on incident reporting, right to audit, MFA, cryptography, vulnerability management and business continuity. As part of this service we help both recipients (how to build an SCRM programme for suppliers) and suppliers (how to meet contractual requirements and remain competitive).
How long does KSC and NIS2 compliance implementation take?
Implementation time depends on the maturity of the organization and the current state of controls. Gap analysis and entity classification typically take 3–6 weeks. Implementation of missing controls (ISMS, SCRM, IR, BCM, cryptography, MFA, reporting) — from 3 to 9 months depending on scale. Compliance maintenance and reporting is an ongoing process, most often in a retainer model with a dedicated account manager and access to a 24/7 SOC for incident notifications.