KSC Act 2026 · Journal of Laws 2026, item 252 · in force since 3 April 2026
KSC Act 2026 — monitoring and incident reporting are now legal obligations!
The amendment to the Act on the National Cybersecurity System entered into force on 3 April 2026 and introduced continuous system monitoring and incident reporting within strictly defined deadlines for new groups of companies. Check whether your company is subject to the Act and how VIRTUO SOC covers these requirements within a single service.
03.04.2026
The Act enters into force
03.10.2026
Deadline for self-identification and registration
03.04.2027
Full compliance deadline: monitoring, documentation and incident reporting
Scope of the Act
The scope of entities covered by the KSC Act is now much broader than “critical infrastructure”
Following the amendment, the Act is no longer limited to operators of essential services. It distinguishes two categories — essential entities and important entities — based on the business sector and company size, in accordance with the annexes to the Act implementing the NIS2 Directive.

Important entity
Most commonly, medium-sized companies (typically 50+ employees or turnover and balance-sheet total above approximately EUR 10 million) operating in sectors such as manufacturing, transport and logistics, food, chemicals, digital services, waste management, and postal and courier services.
Essential entity
Larger organisations and sectors of particular importance to the state and the economy: energy, banking and financial market infrastructure, healthcare, digital infrastructure, water supply and public administration.
Even if your company is not directly subject to the Act, you may still be required to meet its requirements as a subcontractor or B2B partner of an essential or important entity. Increasingly, clients require confirmation of security standards as a condition of cooperation. Final classification requires an individual assessment of the sector, company size and role in the supply chain.
First step
How and where to complete self-identification and registration in the KSC Register?
Before addressing monitoring or documentation, you must formally determine your status and register your company. This is how the process works.
Check whether you are covered
Verify your actual business profile (not only your PKD code) against the sectors listed in Annex 1 (essential entities) or Annex 2 (important entities) to the Act.
Check the size criterion
Check the number of employees and the company’s financial data, including capital-linked entities — these determine whether you qualify as an essential or important entity.
Register in the KSC Register
If the self-identification result is positive, submit an application for registration through the KSC Register application available at wykaz-ksc.gov.pl (part of the S46 System). Sign-in is handled through the National Node using a Trusted Profile, mObywatel or an electronic ID card.
wykaz-ksc.gov.pl
Complete the application
The application is a guided form divided into several sections: entity identification data, sector classification, contact details and legal declarations.
Keep the deadline in mind
The application for registration must be submitted by 3 October 2026. Certain entities — public-sector bodies, telecommunications entities, trust service providers and existing operators of essential services — were entered ex officio by the Minister of Digital Affairs. They receive a notification containing a link and access code and have six months to complete their data.
Registration provides access to the S46 Cyber Hub and serves as the entry point to the entire system, including incident reporting to the competent CSIRT. Unsure how to complete the process? We will help you determine the right steps.
Full overview of the Act
What exactly does the KSC Act require from you?
Compliance with the Act involves more than monitoring — it also includes organisational, documentation and legal requirements. Below is the full scope of obligations arising from the Act.
Organisational
Risk management and ISMS
Technical measures
Detection and response
Documentation and accountability
People
Our role
How does VIRTUO SOC support compliance with the KSC Act?
Based on the obligations outlined above, this is our specific contribution in each area.
If you need comprehensive support with KSC Act compliance beyond monitoring and incident handling, we and our trusted partners will guide your company through the entire process — from legal classification to audit preparation. Contact us and we will jointly determine the scope your company needs.
Our approach
Security controls proportionate to risk — no more than you need!
We implement solutions that fully meet the requirements of the KSC Act, and we stop there. We do not push clients to deploy safeguards that are not justified by actual risk or legal requirements.
Compliance, not overengineering
The service is configured to genuinely meet the requirements of the Act — without expanding the scope beyond what follows from the law and your company’s risk assessment.
Cost aligned with your needs
We configure the service to be as cost-effective as possible — you pay for safeguards appropriate to your company’s scale and risk, not for an entire catalogue of available technologies.
Security proportionate to risk
The selection of technical and organisational measures follows from the risk assessment, not from a predefined “everything at once” checklist.
Statutory obligations and the VIRTUO SOC service
Four obligations covered directly by VIRTUO SOC
Within the full scope of the Act, monitoring, detection, documentation and incident response are the obligations we deliver directly through a single service.
Collection
Article 8(1)(3)
The obligation to collect information on cyber threats and vulnerabilities affecting the information system used to provide the service.
VIRTUO SOC: a continuous feed of threat and vulnerability data concerning your infrastructure, updated on an ongoing basis.
Detection
Article 8(1)(2)(g)
The obligation to place the information system under continuous monitoring.
VIRTUO SOC: continuous monitoring (data collection) across devices, networks and cloud services; identified events are analysed and classified within the agreed SLA.
Documentation
Article 10
The obligation to maintain information system security documentation, including descriptions of safeguards and events.
VIRTUO SOC: monthly monitoring reports and incident documentation ready for an audit or regulatory inspection.
Response
Articles 11–12
The obligation to handle and report significant incidents to the competent CSIRT within 24 hours, 72 hours and one month.
VIRTUO SOC: our analysts classify the incident within the agreed SLA and support your team in preparing reports within the statutory deadlines.
Obligations in practice
When a significant incident occurs, every hour matters
The Act establishes a strict reporting sequence — the clock starts when the incident is detected, not when the IT team has a complete picture of the situation.
The obligation to handle and report incidents applies from the first day the Act is in force — regardless of how far your company has progressed in implementing the remaining obligations. Monitoring must be ready before an incident occurs, not afterwards.
T + 0
Incident detection
The event is identified and classified as a significant incident based on monitoring and team analysis, within the agreed SLA.
24 h
Early warning
We prepare the data required for an early warning to the competent CSIRT in accordance with Article 11(1) of the Act.
72 h
Full incident notification
Support in preparing the complete incident notification, including an assessment of its impact and causes.
30 days
Final report
Documentation of the incident and the measures applied, ready for case closure.
During the transitional period, notifications are submitted to CSIRT MON, CSIRT NASK or CSIRT GOV until the sectoral CSIRT for the relevant industry becomes operational.
How it works in practice: the monitoring system continuously collects data from your infrastructure in accordance with Article 8(1)(2)(g) of the Act. Event analysis, classification and incident response are performed by our team within the SLA agreed with you — not in a fully automated manner.
You do not need to build your own SOC team
Article 14 of the KSC Act
The Act allows cybersecurity obligations to be fulfilled in two ways: by establishing internal structures or by entering into an agreement with an external cybersecurity service provider. In the latter case, you have 14 days from signing or terminating the agreement to inform the competent authority of the provider’s details and the scope of the service.
VIRTUO SOC operates as such an external provider — we take over the operational delivery of monitoring, detection and response obligations, while you retain full control over decisions concerning your company.
Non-compliance risk
Lack of monitoring and reporting procedures is now one of the most common grounds for penalties
The Act provides for administrative penalties imposed on the entity and, in certain cases, personal liability for management.
Essential entity · Article 73(3)
up to EUR 10,000,000 or 2% of revenue
whichever amount is higher — but not less than PLN 20,000.
Important entity · Article 73(4)
up to EUR 7,000,000 or 1.4% of revenue
whichever amount is higher — but not less than PLN 15,000.
Up to PLN 100,000,000 for infringements causing a direct and serious threat to national security (Article 73(5)).
Personal liability of the head of an essential or important entity for the proper performance of obligations under the Act.
Service scope
What exactly do you receive as part of KSC compliance?
One service covering the operational side of statutory monitoring and incident-related obligations.
Continuous monitoring (data collection) across devices, networks and cloud services
Incident detection and classification by our team within the agreed SLA
Monthly reports and audit-ready documentation
Collection and analysis of threat and vulnerability information
Support in preparing notifications within 24 hours / 72 hours / 30 days
Access to a team of analysts during incident handling
Is it worth building this in-house?
In-house KSC compliance team vs. VIRTUO SOC as a Service
In-house KSC compliance team
VIRTUO SOC as a Service
Key deadlines
The clock is already ticking
Indicative timeline for entities meeting the criteria for classification as essential or important on the date the Act entered into force.
03.04.2026
Entry into force of the Act
Effective date of the KSC amendment (Journal of Laws 2026, item 252).
by 03.10.2026
Self-identification and registration
Six months to register as an essential or important entity.
by 03.04.2027
Full compliance
Twelve months to implement the ISMS, documentation and incident reporting.
by 03.04.2028
First security audit
For newly covered essential entities — an audit of the information system.
Frequently asked questions
Questions about monitoring, incidents and the KSC Act
Contact Us
If you are interested in VIRTUO SOC or would like to learn more, contact our team today. We are ready to provide comprehensive protection against cyber threats and give you peace of mind regarding your IT security.
Contact Form
Use the contact form below. Simply complete the required fields and we will get back to you as soon as possible.

