NIS2/KSC · IT providers

NIS2 and the KSC Act for managed IT service providers

NIS2 for IT service providers in Poland: under the National Cybersecurity System Act (KSC Act), a managed service provider (MSP) is an important entity if it is a medium-sized enterprise and an essential entity if it is a large one, while a managed security service provider (MSSP) is an essential entity even as a small enterprise. The Act also covers cloud computing, data centre, CDN and DNS providers, and these digital providers apply the measures set out in Commission Implementing Regulation (EU) 2024/2690. We explain who is in scope and what the obligations are.

01Status

Which IT service providers are subject to NIS2 and the KSC Act

IT providers fall into two sectors of high criticality: ICT service management and digital infrastructure. Online marketplaces, search engines and social networking platforms belong to the other critical sectors (Annex 2).

Managed service provider (MSP)

The Act defines an MSP as an entity that provides services related to the installation, operation or maintenance of ICT products, services and processes or information systems - through assistance or active administration, either at the client's premises or remotely (Art. 2(4i)). This includes IT outsourcing, server and network administration and application maintenance. According to the Ministry of Digital Affairs, helpdesk services fall within the definition of a managed service provider, while software vendors are in principle not managed security service providers - they are regulated by the Cyber Resilience Act (CRA) (Art. 2(4i)-(4j); Ministry of Digital Affairs, Q&A of 1 October 2026, questions 1.23 and 1.34).

An MSP is subject to the general rule: a medium-sized one is an important entity, a large one an essential entity.

Managed security service provider (MSSP)

A managed security service provider (e.g. incident handling, security testing, audits, consultancy) is an essential entity even as a small enterprise (Art. 2(4j) and Art. 5(1)(3)). Only microenterprises are excluded - those with fewer than 10 people and turnover or balance sheet total up to EUR 2 million, calculated together with linked and partner enterprises. An IT company that performs cybersecurity tasks only for its own group is subject to the Act if it is at least a small enterprise, as it provides services to another entity (Art. 5(1)(3); Ministry of Digital Affairs, Q&A of 1 October 2026, questions 1.21 and 3.34).

Digital infrastructure

  • regardless of size (essential entity): DNS service providers (excluding root name servers), top-level domain name registries, domain name registration service providers and qualified trust service providers,
  • depending on size: providers of cloud computing services, data centre services, content delivery networks and internet exchange points, and electronic communications undertakings (special thresholds).

According to the Ministry of Digital Affairs, a reseller that only sells cloud services is not a cloud computing service provider (Q&A, question 1.38), and not every web application is a cloud service (question 1.43).

DNS service providers, TLD name registries, domain name registrars and providers of cloud computing services, data centre services, content delivery networks, managed services (including managed security services), online marketplaces, online search engines and social networking platforms are subject to the Polish Act where their main establishment is in Poland - that is, where the head of the entity who takes decisions on the information security management system is based (Art. 5a(3)-(4)).

Check your company's status in our NIS2 scope checker.

ICT service management and digital infrastructure providers (Annex 1) and digital providers (Annex 2)
Type of entity When it is subject to the Act Legal basis
Internet exchange point (IXP) Large enterprise - essential, medium-sized - important Annex 1, Digital infrastructure sector
Provider of DNS services - publicly available recursive or authoritative domain name resolution; excluding operators of root name servers. Essential regardless of size Annex 1, Digital infrastructure sector; Art. 5(1)(4)(a)
Top-level domain (TLD) name registry Essential regardless of size Annex 1, Digital infrastructure sector; Art. 5(1)(4)(i)
Domain name registration services Essential regardless of size Annex 1, Digital infrastructure sector; Art. 5(1)(4)(j)
Cloud computing service provider Large enterprise - essential, medium-sized - important Annex 1, Digital infrastructure sector
Data centre service provider Large enterprise - essential, medium-sized - important Annex 1, Digital infrastructure sector
Content delivery network (CDN) provider Large enterprise - essential, medium-sized - important Annex 1, Digital infrastructure sector
Trust service provider - e.g. electronic signatures and seals, time stamps, electronic registered delivery (eIDAS Regulation). Qualified - essential; non-qualified: micro, small and medium-sized - important, large - essential Annex 1, Digital infrastructure sector; Art. 5(1)(4)(b) and (2)(3)
Electronic communications undertaking - operators of electronic communications networks and services, e.g. internet access, telephony. Medium-sized and large - essential; micro and small - important Annex 1, Digital infrastructure sector, Electronic communications subsector; Art. 5(1)(2) and (2)(4)
Managed service provider (MSP) - installation, operation or maintenance of a client's ICT products, services and systems, through support or active administration on site or remotely. Large enterprise - essential, medium-sized - important Annex 1, ICT service management sector; Art. 2(4i)
Managed security service provider (MSSP) - carrying out or supporting cybersecurity risk management: incident handling, security testing, information system audits, consultancy. Essential from small enterprise size upwards (micro - out of scope) Annex 1, ICT service management sector; Art. 2(4j), Art. 5(1)(3)
Provider of an online marketplace Medium-sized and large enterprise - important Annex 2, Digital providers sector
Provider of an online search engine Medium-sized and large enterprise - important Annex 2, Digital providers sector
Provider of a social networking services platform Medium-sized and large enterprise - important Annex 2, Digital providers sector

02Obligations

Obligations of IT providers: Art. 8, Regulation 2024/2690 and Art. 8g

The management system and the 2024/2690 measures

IT providers implement an information security management system under Art. 8. Within that system, digital providers (including cloud computing, data centre and DNS service providers, managed service providers and managed security service providers) apply the measures set out in Commission Implementing Regulation (EU) 2024/2690 (Art. 8b(1)). The regulation sets out detailed requirements for, among other things, policies, incident management, business continuity, the supply chain, access control and cryptography, as well as the thresholds at which an incident affecting a digital provider is significant (Art. 11(4)).

Deadline: by 3 April 2027 for companies that met the criteria on 3 April 2026; for others, within 12 months from meeting the criteria.

Publication of information by MSSPs

An essential entity that is a managed security service provider offering incident handling publishes on its website, among other things, its scope of activity, incident handling policy and contact details with information on public keys (Art. 8g).

Other obligations

  • Registration in the S46 system, stating your main establishment. The original deadline has passed, but according to the Ministry of Digital Affairs, self-registration in the register is available at all times; 3 October 2026 was the last day for entities that met the criteria on the date the amendment entered into force (Ministry of Digital Affairs, Q&A of 1 October 2026, question 2.32).
  • Reporting significant incidents: an early warning within 24 hours, a notification within 72 hours and a final report within one month.
  • Annual training for the head of the entity, contact persons and documentation.
  • Essential entities: a security audit at least once every 3 years, the first by 3 April 2028.

03Authority

Competent authority, CSIRT and supervision

The competent authority for ICT service management, digital infrastructure (excluding electronic communications) and digital providers is the minister responsible for digital affairs (Art. 41(8), (9b) and (9j)); for electronic communications, it is the President of the Office of Electronic Communications (UKE). Significant incidents are reported through S46 to a CSIRT (computer security incident response team). For digital infrastructure (excluding electronic communications), the Minister of Digital Affairs established CSIRT Cyfra on 30 June 2026; it will take over notifications once its operational capability has been announced (Art. 42(2) and Art. 44 of the amending act; Dz.Urz. MC 2026 item 20). Until then, notifications go to a national-level CSIRT - CSIRT GOV, CSIRT NASK or CSIRT MON (Art. 44 of the amending act).

Fines for essential entities are up to EUR 10 million or 2% of revenue from business activity in the previous financial year, whichever is higher; not less than PLN 20,000 (Art. 73(3)). Fines under Art. 73(1)-(4), Arts. 73a-73c and Art. 76b may be imposed for the first time 2 years after the amendment entered into force (according to the Ministry of Digital Affairs - after 3 April 2028). The moratorium does not cover the fine of up to PLN 100 million (Art. 35 of the amending act).

04Clients

Client requirements: the supply chain and DORA

Clients subject to the KSC Act

Essential and important entities must ensure the security of their ICT supply chain - taking into account supplier vulnerabilities, the quality of suppliers' products, services and processes, and the results of coordinated risk assessments (Art. 8(1)(2)(e) and Art. 8(2)). In practice, IT providers receive security questionnaires, contractual requirements and requests for test results - even if they are not subject to the Act themselves.

Clients in the financial sector

Banks, insurers and other financial entities apply DORA requirements to their ICT service providers - including requirements on contractual provisions and testing. We describe them on our DORA: resilience testing and ICT risk page.

Independent penetration tests of applications, APIs and infrastructure are the simplest way to answer a client with evidence rather than a declaration.

05How we help

Gap analysis, implementation and testing for IT providers

  • NIS2 gap analysis - scope assessment of your services (MSP, MSSP, cloud), a review of gaps against Art. 8 and Regulation 2024/2690, and an implementation plan.
  • NIS2 implementation - policies, incident procedures, business continuity and requirements for subcontractors.
  • Penetration testing - applications, APIs, cloud and infrastructure, with a report you can show to your clients.

We carry out the Art. 15 security audit in cooperation with a partner whose auditors meet the statutory requirements - and we do not audit a company that we helped to implement its security management system in the year before the audit. We also build security into software from the design stage - see secure software (secure by design).

Our NIS2/KSC checklist lists the questions to check before an audit.

Frequently asked questions

Is a software house subject to NIS2?

Not for software development alone - according to the Ministry of Digital Affairs, software vendors are in principle not managed security service providers, because their products are regulated by the Cyber Resilience Act (Q&A of 1 October 2026, question 1.23). A software house may, however, be a managed service provider (MSP) if it maintains and administers its clients' systems - according to the Ministry, this includes, for example, helpdesk services (question 1.34) - or a cloud computing service provider if it makes an application available in a way that meets the definition of cloud computing (question 1.43). In that case, size decides.

Is a company that carries out penetration tests and audits an MSSP?

The definition of a managed security service provider covers services that consist of carrying out or supporting cybersecurity risk management activities, including incident handling, security testing, information system audits and consultancy (Art. 2(4j)). Such a provider is an essential entity if it is at least a small enterprise (Art. 5(1)(3)). According to the Ministry of Digital Affairs, merely providing staff to a client, without processing data from the client's security management system, is not such a service (question 1.37).

Is an IT company that serves only its own group subject to the Act?

Yes. According to the Ministry of Digital Affairs, a company that performs cybersecurity tasks for entities in its group provides services to another entity and is subject to the Act if it is at least a small enterprise (questions 1.21 and 3.34). In that case, it publishes the Art. 8g information on a publicly accessible website, not on an intranet (question 3.45).

What is Implementing Regulation 2024/2690 and who does it apply to?

It is a European Commission act setting out technical and methodological requirements for cybersecurity risk management for digital providers - including DNS service providers, TLD name registries, cloud computing, data centre and CDN providers, managed service providers and MSSPs, online marketplaces, online search engines and social networking platforms (Art. 8b(1)). It also specifies when an incident affecting them is significant. According to the Ministry of Digital Affairs, it applies to the activities covered by the regulation, not to the whole company (question 3.47).

What must an MSSP that provides incident handling publish?

An essential entity that is an MSSP providing incident handling publishes on its website at least its name, its scope of activity (type of support, rules of cooperation and information exchange, communication policy), the services it offers and its incident handling policy, and its contact details, including information on public keys and how to report incidents (Art. 8g). According to the Ministry of Digital Affairs, a short text file following the RFC 2350 template, on a domain notified for the register, is sufficient (question 3.13).

Sources

  1. Act of 23 January 2026 amending the National Cybersecurity System Act and certain other acts (Dz.U. 2026 item 252) (in Polish) ()
  2. National Cybersecurity System Act - act metadata and amending acts (Sejm ELI API) (in Polish) ()
  3. Ministry of Digital Affairs - Q&A on the amendment to the KSC Act, October 2026 update (1 October 2026; explanatory document, not legally binding) (in Polish) ()
  4. Commission Implementing Regulation (EU) 2024/2690 - technical and methodological requirements of cybersecurity risk-management measures ()
  5. Order No. 15 of the Minister of Digital Affairs of 30 June 2026 establishing the Sectoral Computer Security Incident Response Team (CSIRT Cyfra) (Dz.Urz. MC 2026 item 20) (in Polish) ()

Legal status as of Updated

Related services

Let's talk about your project or audit

Tell us briefly what you need - we will come back with proposed next steps. We work in English and Polish.

or call +48 575 621 877