NIS2/KSC · Gap analysis
Gap analysis
NIS2 gap analysis against the Polish KSC Act: scope, method, gap report, compliance matrix and an implementation plan to meet the 3 April 2027 deadline.
NIS2/KSC · Healthcare
In Poland, NIS2 in healthcare means obligations under the National Cybersecurity System Act (KSC Act). A hospital run as an independent public healthcare institution (SP ZOZ) is an important entity if it employs 50-249 people and an essential entity if it employs 250 or more, while a hospital run as a company falls under the general rule for the health sector. We explain the status, the competent authority, incident reporting, the deadlines and how to prepare for the audit.
01Status
Health is one of the sectors of high criticality (Annex 1). A hospital's status depends on its legal form and its size.
For a healthcare provider that is not a business - above all an independent public healthcare institution (SP ZOZ), the legal form in which many Polish public hospitals operate - the Act sets separate thresholds: with 50 to 249 people employed it is an important entity, and with 250 or more an essential entity (Art. 5(8)). According to the Ministry of Digital Affairs, a healthcare provider that is not a business counts all persons engaged - under employment contracts and civil-law contracts, full-time and part-time - as at the date on which the financial statements are prepared; an independent public healthcare institution (SP ZOZ) employing fewer than 50 people is not subject to the Act (Art. 5(5) and (8); Ministry of Digital Affairs, Q&A of 1 October 2026, questions 3.20 and 3.23).
A hospital run as a company - including one in which local government holds shares - is a business, so the general rule applies: a medium-sized enterprise is an important entity and a large one an essential entity (Art. 5(1)(1) and (2)(1)). Size is calculated according to the EU definition of SMEs, together with linked and partner enterprises - so a group company that is small on its own may still be in scope.
A hospital that also runs a community pharmacy, operates a laboratory serving other providers or supplies water has to take each of these activities into account. The Act covers every activity listed in the annexes, both principal and ancillary (for water, waste water and waste, the annex requires the activity to be a principal or essential part of the business); several types of activity are shown separately in the application for registration (Art. 7d(2); Ministry of Digital Affairs, KSC amendment Q&A, question 2.8).
You can check your status quickly with our NIS2 scope checker, which opens with the health sector highlighted.
| Type of entity | When it is subject to the Act | Legal basis |
|---|---|---|
| Healthcare provider (hospital, outpatient clinic, other medical facility) - including providers with hospital emergency departments (SOR) and trauma centres. | Business: large - essential, medium-sized - important; non-business entity (e.g. SP ZOZ): 250 people or more - essential, 50-249 - important | Annex 1, Health sector, Healthcare provision and public health subsector; Art. 5(8) |
| Subcontractor of essential or important entities in healthcare - an entity that provides healthcare services as a subcontractor, e.g. a laboratory or diagnostic services. | Large enterprise - essential, medium-sized - important | Annex 1, Health sector (Art. 133 of the Act on Healthcare Services Financed from Public Funds) |
| Designated EU reference laboratory | Business: large enterprise - essential, medium-sized - important; non-business entity - essential regardless of size | Annex 1, Health sector (Art. 15 of Regulation (EU) 2022/2371) |
| Public health bodies - The Minister of Health's unit responsible for healthcare information systems, offices of the State Sanitary Inspection, the National Emergency Medical Services Monitoring Centre, public blood service units. | Essential regardless of size | Annex 1, Health sector |
| Medicinal products and active substances - manufacturer, importer (including parallel importer), distributor of active substances, marketing authorisation holder, manufacture of pharmaceuticals (NACE division 21), research and development of medicinal products. | Large enterprise - essential, medium-sized - important | Annex 1, Health sector, Manufacture and distribution of active substances, medicinal products and medical devices subsector |
| Pharmaceutical wholesaler | Large enterprise - essential, medium-sized - important | Annex 1, Health sector (Pharmaceutical Law) |
| Community pharmacy | Large enterprise - essential, medium-sized - important | Annex 1, Health sector (Pharmaceutical Law) |
| Manufacturer of medical devices considered critical during a public health emergency | Large enterprise - essential, medium-sized - important | Annex 1, Health sector (Art. 22 of Regulation (EU) 2022/123) |
| The Office for Registration of Medicinal Products (URPL) or a Pharmaceutical Inspection office | Essential regardless of size | Annex 1, Health sector |
02Authority and incidents
The competent cybersecurity authority for the health sector is the minister responsible for health, and for entities subordinate to the Minister of National Defence it is that minister (Art. 41(5)-(6)). The authority keeps the register of essential and important entities in its sector and supervises them: essential entities both ex ante and ex post, important entities ex post only.
Hospitals and other healthcare providers apply for registration themselves, in the S46 system. Registration is declaratory - the obligations arise from the Act, not from the entry in the register. According to the Ministry of Digital Affairs, self-registration in the register is available at all times; 3 October 2026 was the last day for entities that met the criteria on the date the amendment entered into force (Ministry of Digital Affairs, Q&A of 1 October 2026, question 2.32). If you missed the deadline, apply as soon as possible - we explain what this means in practice in our NIS2/KSC audit guide.
In Poland, incident notifications go to CSIRTs (computer security incident response teams). In the health sector, the sectoral team is CSIRT Centrum e-Zdrowia (the e-Health Centre's CSIRT), set up by the Ministry of Health on 1 December 2023; sectoral teams set up before 2025 count as sectoral CSIRTs without an announcement of operational capability (Art. 44(3) and Art. 46 of the amending act; CSIRT CeZ). A hospital reports a significant incident through S46: an early warning within 24 hours of detection, an incident notification within 72 hours and a final report within one month (Art. 11(1)(4)-(4c)).
In practice, reporting falls to the same team that is responsible for business continuity in the hospital: when the hospital information system fails, it has to switch to contingency procedures and meet the reporting deadlines at the same time.
03Risks
A hospital is not an ordinary office - downtime affects patients, and the data is covered by medical confidentiality.
04Preparation
This list follows from the obligations in Art. 8 of the Act and from the specific nature of a hospital. You will find the full list of questions in our NIS2/KSC checklist.
All the questions, together with the relevant provisions, are collected in our printable NIS2/KSC checklist.
05How we help
Essential entities undergo a security audit at least once every 3 years, the first one by 3 April 2028. We carry out the Art. 15 audit in cooperation with a partner whose auditors meet the statutory requirements - and we do not audit a hospital that we helped to implement its security management system in the year before the audit.
We also build software for the healthcare sector - see healthcare software development. A public hospital buys these services through public procurement - how to prepare the request for proposals is described in our NIS2 audit pricing guide.
06Deadlines
Not every one. An independent public healthcare institution (SP ZOZ) or another healthcare provider that is not a business is subject to the Act if it employs at least 50 people: with 50-249 people it is an important entity, and with 250 or more an essential entity (Art. 5(8)). According to the Ministry of Digital Affairs, an SP ZOZ employing fewer than 50 people is not subject to the Act. A hospital run as a company is a business - a medium-sized one is an important entity and a large one an essential entity. You can check this quickly with our NIS2 scope checker.
According to the Ministry of Digital Affairs, a healthcare provider that is not a business counts everyone it engages - under employment contracts and civil-law contracts, full-time and part-time - without converting them into full-time equivalents, as at the date on which the financial statements are prepared (Ministry of Digital Affairs Q&A of 1 October 2026, question 3.23). This is a different method from the one used by companies, which count staff according to the EU definition of SMEs.
The head of the entity - in an SP ZOZ, the head of the public finance sector unit, usually the director; in a company, the management board (Art. 2(8a)). The head of the entity remains responsible for obligations entrusted to other people and undergoes documented training once every calendar year (Arts. 8c and 8e). They face a fine of up to 300% of their remuneration, although fines can only be imposed after 3 April 2028.
Through the S46 system: an early warning within 24 hours of detection, an incident notification within 72 hours and a final report within one month (Art. 11). The health sector has its own computer security incident response team, CSIRT Centrum e-Zdrowia (the e-Health Centre's CSIRT), set up as a sectoral team before 2025 - such teams count as sectoral CSIRTs without a separate announcement of operational capability (Art. 44(3) and Art. 46 of the amending act).
It can be. Healthcare providers run as companies, community pharmacies, pharmaceutical wholesalers and subcontractors of essential or important entities in the health sector (e.g. laboratories) are listed in Annex 1, but as businesses they are subject to the size rule, with size calculated together with linked enterprises: a medium-sized one is an important entity and a large one an essential entity. A small clinic or a single pharmacy generally remains outside the Act - unless it belongs to a larger group.
NIS2/KSC · Gap analysis
NIS2 gap analysis against the Polish KSC Act: scope, method, gap report, compliance matrix and an implementation plan to meet the 3 April 2027 deadline.
NIS2/KSC · Implementation
NIS2 implementation step by step: registration, risk analysis, policies, technical measures, incidents, suppliers and audit, with a timeline to 3 April 2027.
NIS2/KSC scope checker
Does NIS2 apply to your company in Poland? Free scope checker: sector, size and Art. 5 exceptions under the KSC Act - with reasoning, obligations and deadlines.
Industries · Healthcare
Healthcare software development: special category data (GDPR), patient confidentiality, medical records, Polish e-health integration, NIS2/KSC, accessibility.
Tell us briefly what you need - we will come back with proposed next steps. We work in English and Polish.
or call +48 575 621 877