NIS2 in Poland without the chaos.
From scope assessment to implementation.
I help organisations determine whether they fall under Poland's amended Act on the National Cybersecurity System (uKSC), build a practical NIS2 compliance roadmap, organise their ISMS, risk, incident and supply-chain processes, and prepare for audit.

technology · risk · compliance · execution
Focused paths for the problems organisations actually have
Support for NIS2 Poland, uKSC applicability, audit readiness, cybersecurity programmes and employee security awareness training.
uKSC applicability assessment
Sector, actual activities, entity size, group relationships and Article 5. Clear outcome: essential, important or outside scope.
02↗NIS2 / uKSC implementation
Gap analysis, ISMS, risk, incident handling, supply chain, management responsibilities and a prioritised compliance roadmap.
03↗uKSC audit readiness
Evidence and control review, documentation, remediation plan and readiness check before the statutory audit.
04↗Cybersecurity consulting
ISO 27001, GRC, risk management, policies, suppliers, business continuity and operational security.
Need fast, flexible security awareness training for a regulatory requirement or after an incident?
Practical 3-hour programme covering phishing, social engineering, MFA, cyber hygiene, incidents, risk, suppliers and business continuity. The content can be tailored to the audience and the organisation's context.
Cybersecurity and strategic management for startups.
I help founders connect security with business decisions: set priorities, clarify ownership, prepare for enterprise customers and due diligence, and build a scalable operating model without copying corporate bureaucracy.
Cybersecurity + strategy
- Security baseline: access, MFA, backup, incidents, suppliers and 30/60/90-day priorities.
- Enterprise readiness: security questionnaires, contractual requirements, due diligence and ISO 27001 roadmap.
- Strategic management: priorities, objectives, roadmap, operating model and clear ownership.
- Business development: B2B offer, sales process, partnerships and go-to-market decisions.
- Governance and execution: lightweight PMO, management cadence, KPIs and delivery discipline.
What organisations operating in Poland should have on the radar
The amendment implementing NIS2 entered into force on 3 April 2026. Transitional deadlines apply to entities that met the relevant criteria on that date.
Amendment enters into force
New rules for identifying essential and important entities and new cybersecurity obligations.
KSC Register
Deadline indicated for entities meeting the criteria at entry into force and subject to self-registration.
Implementation deadline
Including ISMS, incident management, contact roles and organisational and technical requirements.
First audit for essential entities
For essential entities covered by the transitional rule — first audit within 24 months.
Scope and risk first. Documentation second.
This reduces implementation cost and avoids building policies that exist only on paper.
Typical engagement
- uKSC scope assessment and confirmation of regulatory perimeter,
- NIS2 / uKSC gap analysis against the existing ISMS,
- 30/60/90-day priorities and action owners,
- risk, incident procedures and supplier management updates,
- evidence pack and audit-readiness review.
NIS2 Poland and uKSC — common questions
Is NIS2 already applicable in Poland?
Yes. The amendment to the Polish Act on the National Cybersecurity System implementing NIS2 entered into force on 3 April 2026.
How do I check whether my company is in scope of uKSC?
Assess the actual activity and sector, the entity's size including partner and linked enterprises, and the specific conditions in Article 5 of the Act.
What is the deadline for entry in the KSC Register?
For entities that met the criteria when the amendment entered into force, the Ministry of Digital Affairs indicates 3 October 2026 for the relevant self-registration process.
Does every important entity need a recurring statutory audit?
The recurring statutory audit at least once every three years applies to essential entities. In circumstances defined by the Act, the competent authority may also order an audit of an important entity.
Where should NIS2 / uKSC implementation start?
Start with scope, gap analysis, risk and clear ownership. Build documentation and the ISMS implementation plan around those priorities.
Not sure whether uKSC applies to your organisation?
Send your industry, company size and a short description of the services you actually provide. We can establish what data is needed for a defensible applicability assessment.