NIS2/KSC · Gap analysis
Gap analysis
NIS2 gap analysis against the Polish KSC Act: scope, method, gap report, compliance matrix and an implementation plan to meet the 3 April 2027 deadline.
NIS2/KSC · IT providers
NIS2 for IT service providers in Poland: under the National Cybersecurity System Act (KSC Act), a managed service provider (MSP) is an important entity if it is a medium-sized enterprise and an essential entity if it is a large one, while a managed security service provider (MSSP) is an essential entity even as a small enterprise. The Act also covers cloud computing, data centre, CDN and DNS providers, and these digital providers apply the measures set out in Commission Implementing Regulation (EU) 2024/2690. We explain who is in scope and what the obligations are.
01Status
IT providers fall into two sectors of high criticality: ICT service management and digital infrastructure. Online marketplaces, search engines and social networking platforms belong to the other critical sectors (Annex 2).
The Act defines an MSP as an entity that provides services related to the installation, operation or maintenance of ICT products, services and processes or information systems - through assistance or active administration, either at the client's premises or remotely (Art. 2(4i)). This includes IT outsourcing, server and network administration and application maintenance. According to the Ministry of Digital Affairs, helpdesk services fall within the definition of a managed service provider, while software vendors are in principle not managed security service providers - they are regulated by the Cyber Resilience Act (CRA) (Art. 2(4i)-(4j); Ministry of Digital Affairs, Q&A of 1 October 2026, questions 1.23 and 1.34).
An MSP is subject to the general rule: a medium-sized one is an important entity, a large one an essential entity.
A managed security service provider (e.g. incident handling, security testing, audits, consultancy) is an essential entity even as a small enterprise (Art. 2(4j) and Art. 5(1)(3)). Only microenterprises are excluded - those with fewer than 10 people and turnover or balance sheet total up to EUR 2 million, calculated together with linked and partner enterprises. An IT company that performs cybersecurity tasks only for its own group is subject to the Act if it is at least a small enterprise, as it provides services to another entity (Art. 5(1)(3); Ministry of Digital Affairs, Q&A of 1 October 2026, questions 1.21 and 3.34).
According to the Ministry of Digital Affairs, a reseller that only sells cloud services is not a cloud computing service provider (Q&A, question 1.38), and not every web application is a cloud service (question 1.43).
DNS service providers, TLD name registries, domain name registrars and providers of cloud computing services, data centre services, content delivery networks, managed services (including managed security services), online marketplaces, online search engines and social networking platforms are subject to the Polish Act where their main establishment is in Poland - that is, where the head of the entity who takes decisions on the information security management system is based (Art. 5a(3)-(4)).
Check your company's status in our NIS2 scope checker.
| Type of entity | When it is subject to the Act | Legal basis |
|---|---|---|
| Internet exchange point (IXP) | Large enterprise - essential, medium-sized - important | Annex 1, Digital infrastructure sector |
| Provider of DNS services - publicly available recursive or authoritative domain name resolution; excluding operators of root name servers. | Essential regardless of size | Annex 1, Digital infrastructure sector; Art. 5(1)(4)(a) |
| Top-level domain (TLD) name registry | Essential regardless of size | Annex 1, Digital infrastructure sector; Art. 5(1)(4)(i) |
| Domain name registration services | Essential regardless of size | Annex 1, Digital infrastructure sector; Art. 5(1)(4)(j) |
| Cloud computing service provider | Large enterprise - essential, medium-sized - important | Annex 1, Digital infrastructure sector |
| Data centre service provider | Large enterprise - essential, medium-sized - important | Annex 1, Digital infrastructure sector |
| Content delivery network (CDN) provider | Large enterprise - essential, medium-sized - important | Annex 1, Digital infrastructure sector |
| Trust service provider - e.g. electronic signatures and seals, time stamps, electronic registered delivery (eIDAS Regulation). | Qualified - essential; non-qualified: micro, small and medium-sized - important, large - essential | Annex 1, Digital infrastructure sector; Art. 5(1)(4)(b) and (2)(3) |
| Electronic communications undertaking - operators of electronic communications networks and services, e.g. internet access, telephony. | Medium-sized and large - essential; micro and small - important | Annex 1, Digital infrastructure sector, Electronic communications subsector; Art. 5(1)(2) and (2)(4) |
| Managed service provider (MSP) - installation, operation or maintenance of a client's ICT products, services and systems, through support or active administration on site or remotely. | Large enterprise - essential, medium-sized - important | Annex 1, ICT service management sector; Art. 2(4i) |
| Managed security service provider (MSSP) - carrying out or supporting cybersecurity risk management: incident handling, security testing, information system audits, consultancy. | Essential from small enterprise size upwards (micro - out of scope) | Annex 1, ICT service management sector; Art. 2(4j), Art. 5(1)(3) |
| Provider of an online marketplace | Medium-sized and large enterprise - important | Annex 2, Digital providers sector |
| Provider of an online search engine | Medium-sized and large enterprise - important | Annex 2, Digital providers sector |
| Provider of a social networking services platform | Medium-sized and large enterprise - important | Annex 2, Digital providers sector |
02Obligations
IT providers implement an information security management system under Art. 8. Within that system, digital providers (including cloud computing, data centre and DNS service providers, managed service providers and managed security service providers) apply the measures set out in Commission Implementing Regulation (EU) 2024/2690 (Art. 8b(1)). The regulation sets out detailed requirements for, among other things, policies, incident management, business continuity, the supply chain, access control and cryptography, as well as the thresholds at which an incident affecting a digital provider is significant (Art. 11(4)).
Deadline: by 3 April 2027 for companies that met the criteria on 3 April 2026; for others, within 12 months from meeting the criteria.
An essential entity that is a managed security service provider offering incident handling publishes on its website, among other things, its scope of activity, incident handling policy and contact details with information on public keys (Art. 8g).
03Authority
The competent authority for ICT service management, digital infrastructure (excluding electronic communications) and digital providers is the minister responsible for digital affairs (Art. 41(8), (9b) and (9j)); for electronic communications, it is the President of the Office of Electronic Communications (UKE). Significant incidents are reported through S46 to a CSIRT (computer security incident response team). For digital infrastructure (excluding electronic communications), the Minister of Digital Affairs established CSIRT Cyfra on 30 June 2026; it will take over notifications once its operational capability has been announced (Art. 42(2) and Art. 44 of the amending act; Dz.Urz. MC 2026 item 20). Until then, notifications go to a national-level CSIRT - CSIRT GOV, CSIRT NASK or CSIRT MON (Art. 44 of the amending act).
Fines for essential entities are up to EUR 10 million or 2% of revenue from business activity in the previous financial year, whichever is higher; not less than PLN 20,000 (Art. 73(3)). Fines under Art. 73(1)-(4), Arts. 73a-73c and Art. 76b may be imposed for the first time 2 years after the amendment entered into force (according to the Ministry of Digital Affairs - after 3 April 2028). The moratorium does not cover the fine of up to PLN 100 million (Art. 35 of the amending act).
04Clients
Essential and important entities must ensure the security of their ICT supply chain - taking into account supplier vulnerabilities, the quality of suppliers' products, services and processes, and the results of coordinated risk assessments (Art. 8(1)(2)(e) and Art. 8(2)). In practice, IT providers receive security questionnaires, contractual requirements and requests for test results - even if they are not subject to the Act themselves.
Banks, insurers and other financial entities apply DORA requirements to their ICT service providers - including requirements on contractual provisions and testing. We describe them on our DORA: resilience testing and ICT risk page.
Independent penetration tests of applications, APIs and infrastructure are the simplest way to answer a client with evidence rather than a declaration.
05How we help
We carry out the Art. 15 security audit in cooperation with a partner whose auditors meet the statutory requirements - and we do not audit a company that we helped to implement its security management system in the year before the audit. We also build security into software from the design stage - see secure software (secure by design).
Our NIS2/KSC checklist lists the questions to check before an audit.
Not for software development alone - according to the Ministry of Digital Affairs, software vendors are in principle not managed security service providers, because their products are regulated by the Cyber Resilience Act (Q&A of 1 October 2026, question 1.23). A software house may, however, be a managed service provider (MSP) if it maintains and administers its clients' systems - according to the Ministry, this includes, for example, helpdesk services (question 1.34) - or a cloud computing service provider if it makes an application available in a way that meets the definition of cloud computing (question 1.43). In that case, size decides.
The definition of a managed security service provider covers services that consist of carrying out or supporting cybersecurity risk management activities, including incident handling, security testing, information system audits and consultancy (Art. 2(4j)). Such a provider is an essential entity if it is at least a small enterprise (Art. 5(1)(3)). According to the Ministry of Digital Affairs, merely providing staff to a client, without processing data from the client's security management system, is not such a service (question 1.37).
Yes. According to the Ministry of Digital Affairs, a company that performs cybersecurity tasks for entities in its group provides services to another entity and is subject to the Act if it is at least a small enterprise (questions 1.21 and 3.34). In that case, it publishes the Art. 8g information on a publicly accessible website, not on an intranet (question 3.45).
It is a European Commission act setting out technical and methodological requirements for cybersecurity risk management for digital providers - including DNS service providers, TLD name registries, cloud computing, data centre and CDN providers, managed service providers and MSSPs, online marketplaces, online search engines and social networking platforms (Art. 8b(1)). It also specifies when an incident affecting them is significant. According to the Ministry of Digital Affairs, it applies to the activities covered by the regulation, not to the whole company (question 3.47).
An essential entity that is an MSSP providing incident handling publishes on its website at least its name, its scope of activity (type of support, rules of cooperation and information exchange, communication policy), the services it offers and its incident handling policy, and its contact details, including information on public keys and how to report incidents (Art. 8g). According to the Ministry of Digital Affairs, a short text file following the RFC 2350 template, on a domain notified for the register, is sufficient (question 3.13).
NIS2/KSC · Gap analysis
NIS2 gap analysis against the Polish KSC Act: scope, method, gap report, compliance matrix and an implementation plan to meet the 3 April 2027 deadline.
NIS2/KSC · Implementation
NIS2 implementation step by step: registration, risk analysis, policies, technical measures, incidents, suppliers and audit, with a timeline to 3 April 2027.
NIS2/KSC scope checker
Does NIS2 apply to your company in Poland? Free scope checker: sector, size and Art. 5 exceptions under the KSC Act - with reasoning, obligations and deadlines.
Cybersecurity · Penetration testing
Penetration testing services for web and mobile apps, APIs, infrastructure, cloud and source code. OWASP and PTES, evidence-based reports and retests.
Tell us briefly what you need - we will come back with proposed next steps. We work in English and Polish.
or call +48 575 621 877