KSC Act 2026 — monitoring and incident reporting are now legal obligations!

  • We will verify whether your company is subject to the KSC Act 2026
  • We will identify specific gaps and prepare an action plan before the first inspection
  • We will implement the required solutions and support your organisation in achieving and maintaining compliance with the KSC Act 2026.


03.04.2026

The Act enters into force

03.10.2026

Deadline for self-identification and registration

03.04.2027

Full compliance deadline: monitoring, documentation and incident reporting

Scope of the Act

The scope of entities covered by the KSC Act is now much broader than “critical infrastructure”

Following the amendment, the Act is no longer limited to operators of essential services. It distinguishes two categories — essential entities and important entities — based on the business sector and company size, in accordance with the annexes to the Act implementing the NIS2 Directive.

1380 - VIRTUO SOC

Even if your company is not directly subject to the Act, you may still be required to meet its requirements as a subcontractor or B2B partner of an essential or important entity. Increasingly, clients require confirmation of security standards as a condition of cooperation. Final classification requires an individual assessment of the sector, company size and role in the supply chain.

First step

How and where to complete self-identification and registration in the KSC Register?

Before addressing monitoring or documentation, you must formally determine your status and register your company. This is how the process works.

Check whether you are covered
Verify your actual business profile (not only your PKD code) against the sectors listed in Annex 1 (essential entities) or Annex 2 (important entities) to the Act.

Check the size criterion
Check the number of employees and the company’s financial data, including capital-linked entities — these determine whether you qualify as an essential or important entity.

Register in the KSC Register
If the self-identification result is positive, submit an application for registration through the KSC Register application available at wykaz-ksc.gov.pl (part of the S46 System). Sign-in is handled through the National Node using a Trusted Profile, mObywatel or an electronic ID card.
wykaz-ksc.gov.pl

Complete the application
The application is a guided form divided into several sections: entity identification data, sector classification, contact details and legal declarations.

Keep the deadline in mind
The application for registration must be submitted by 3 October 2026. Certain entities — public-sector bodies, telecommunications entities, trust service providers and existing operators of essential services — were entered ex officio by the Minister of Digital Affairs. They receive a notification containing a link and access code and have six months to complete their data.

Registration provides access to the S46 Cyber Hub and serves as the entry point to the entire system, including incident reporting to the competent CSIRT. Unsure how to complete the process? We will help you determine the right steps.

Full overview of the Act

What exactly does the KSC Act require from you?

Compliance with the Act involves more than monitoring — it also includes organisational, documentation and legal requirements. Below is the full scope of obligations arising from the Act.

  • Self-identification and registration in the list of entities
  • Appointment of at least two persons for contact with the KSC system
  • Selection of the compliance delivery model: an internal team or an external provider (Article 14)
  • Risk assessment and information security policies
  • Supply chain security
  • Security in the acquisition, development and maintenance of systems
  • Continuous monitoring of the information system
  • Access control, multi-factor authentication and cryptography
  • Inventory and lifecycle management of ICT assets
  • Collection of information on threats and vulnerabilities
  • Incident handling and classification
  • Incident reporting to the CSIRT (24 hours / 72 hours / 30 days)
  • Business continuity plans (BCP)
  • Information system security documentation
  • Monitoring reports and incident records
  • Security audit at least once every three years (essential entities)
  • Cybersecurity education and training for personnel
  • Management training on responsibilities arising from the Act

Our role

How does VIRTUO SOC support compliance with the KSC Act?

Based on the obligations outlined above, this is our specific contribution in each area.

  • Organisational
    we help assess whether and how the Act applies to your company, and we can act as an external cybersecurity service provider within the meaning of Article 14 — taking over the operational delivery of your obligations.
  • Technical measures
    we provide continuous monitoring of the information system and maintain an up-to-date inventory of monitored IT assets.
  • Documentation and accountability
    we prepare monthly monitoring reports and incident documentation ready for an audit or regulatory inspection.
  • Risk management and ISMS
    the selection of safeguards is driven by the risk assessment — we provide their operational implementation through monitoring, event analysis and incident reporting.
  • Detection and response
    we collect threat and vulnerability information, classify events within the agreed SLA and support reporting to the CSIRT within the statutory deadlines.
  • People
    an e-learning cybersecurity training programme for teams and dedicated training for management, delivered as part of our Cybersecurity Training service.

If you need comprehensive support with KSC Act compliance beyond monitoring and incident handling, we and our trusted partners will guide your company through the entire process — from legal classification to audit preparation. Contact us and we will jointly determine the scope your company needs.

Our approach

Security controls proportionate to risk — no more than you need!

We implement solutions that fully meet the requirements of the KSC Act, and we stop there. We do not push clients to deploy safeguards that are not justified by actual risk or legal requirements.

The service is configured to genuinely meet the requirements of the Act — without expanding the scope beyond what follows from the law and your company’s risk assessment.

We configure the service to be as cost-effective as possible — you pay for safeguards appropriate to your company’s scale and risk, not for an entire catalogue of available technologies.

The selection of technical and organisational measures follows from the risk assessment, not from a predefined “everything at once” checklist.

Statutory obligations and the VIRTUO SOC service

Four obligations covered directly by VIRTUO SOC

Within the full scope of the Act, monitoring, detection, documentation and incident response are the obligations we deliver directly through a single service.

Obligations in practice

When a significant incident occurs, every hour matters

The Act establishes a strict reporting sequence — the clock starts when the incident is detected, not when the IT team has a complete picture of the situation.

The obligation to handle and report incidents applies from the first day the Act is in force — regardless of how far your company has progressed in implementing the remaining obligations. Monitoring must be ready before an incident occurs, not afterwards.

Incident detection

Early warning

Full incident notification

Final report

During the transitional period, notifications are submitted to CSIRT MON, CSIRT NASK or CSIRT GOV until the sectoral CSIRT for the relevant industry becomes operational.

How it works in practice: the monitoring system continuously collects data from your infrastructure in accordance with Article 8(1)(2)(g) of the Act. Event analysis, classification and incident response are performed by our team within the SLA agreed with you — not in a fully automated manner.

You do not need to build your own SOC team

Article 14 of the KSC Act

The Act allows cybersecurity obligations to be fulfilled in two ways: by establishing internal structures or by entering into an agreement with an external cybersecurity service provider. In the latter case, you have 14 days from signing or terminating the agreement to inform the competent authority of the provider’s details and the scope of the service.

VIRTUO SOC operates as such an external provider — we take over the operational delivery of monitoring, detection and response obligations, while you retain full control over decisions concerning your company.

Non-compliance risk

Lack of monitoring and reporting procedures is now one of the most common grounds for penalties

The Act provides for administrative penalties imposed on the entity and, in certain cases, personal liability for management.

Essential entity · Article 73(3)

whichever amount is higher — but not less than PLN 20,000.

Important entity · Article 73(4)

whichever amount is higher — but not less than PLN 15,000.

Up to PLN 100,000,000 for infringements causing a direct and serious threat to national security (Article 73(5)).

Personal liability of the head of an essential or important entity for the proper performance of obligations under the Act.

Service scope

What exactly do you receive as part of KSC compliance?

One service covering the operational side of statutory monitoring and incident-related obligations.

Continuous monitoring (data collection) across devices, networks and cloud services

Incident detection and classification by our team within the agreed SLA

Monthly reports and audit-ready documentation

Collection and analysis of threat and vulnerability information

Support in preparing notifications within 24 hours / 72 hours / 30 days

Access to a team of analysts during incident handling

Is it worth building this in-house?

In-house KSC compliance team vs. VIRTUO SOC as a Service

In-house KSC compliance team

  • Recruiting cybersecurity specialists takes months
  • Cost of SIEM/EDR licences and monitoring infrastructure
  • Night and weekend shifts are difficult to staff — while the 24-hour clock never stops
  • Preparing audit documentation in-house

VIRTUO SOC as a Service

  • Team and tools ready from day one — no recruitment required
  • All monitoring tools included in a single subscription
  • Continuous monitoring with event analysis performed within the agreed SLA
  • Reports and documentation ready for any inspection or audit

Key deadlines

The clock is already ticking

Indicative timeline for entities meeting the criteria for classification as essential or important on the date the Act entered into force.

03.04.2026

Entry into force of the Act

by 03.10.2026

Self-identification and registration

by 03.04.2027

Full compliance

by 03.04.2028

First security audit

Frequently asked questions

Questions about monitoring, incidents and the KSC Act

Self-identification involves checking whether your business profile corresponds to the sectors listed in Annex 1 or Annex 2 to the Act and whether you meet the size criteria. If so, the application for entry in the KSC Register is submitted through the application available at wykaz-ksc.gov.pl (part of the S46 System), using the National Node to sign in. A full step-by-step description is provided in the section “How and where to complete self-identification and registration in the KSC Register?” above.

If your company has been classified as an essential or important entity, Article 8(1)(2)(g) of the Act requires the information system used to provide the service to be continuously monitored. Classification depends on the business sector and company size — see the section “The scope of entities covered by the KSC Act” above or our NIS2 guide, which explains the directive implemented by the KSC Act.

The Act establishes a reporting sequence: an early warning within 24 hours of detecting a significant incident, a full notification within 72 hours and a final report within 30 days of the notification date (Articles 11–12 of the KSC Act).

These are two categories of entities covered by the Act, determined by business sector and company size. They also differ in administrative penalty thresholds and deadlines for the first security audit.

Yes. Article 14 of the KSC Act allows cybersecurity obligations to be fulfilled by entering into an agreement with an external cybersecurity service provider, for example under a SOC as a Service model. The competent authority must be informed within 14 days of entering into or terminating such an agreement.

For essential entities, the penalty may amount to up to EUR 10,000,000 or 2% of revenue (but not less than PLN 20,000); for important entities, up to EUR 7,000,000 or 1.4% of revenue (but not less than PLN 15,000). In cases threatening national security, the penalty may reach PLN 100,000,000, and the head of the entity may also incur personal liability.

Yes. Cybersecurity education for personnel is part of the information security management system required from essential and important entities. We deliver this through our Cybersecurity Training.

Contact Us

If you are interested in VIRTUO SOC or would like to learn more, contact our team today. We are ready to provide comprehensive protection against cyber threats and give you peace of mind regarding your IT security.

Contact Form

Use the contact form below. Simply complete the required fields and we will get back to you as soon as possible.


VIRTUO SOC
VIRTUO GROUP Sp. z o.o.
Tytusa Chałubińskiego 9/2,
02-004 Warsaw

Our consultants are available Monday to Friday from 9:00 a.m. to 5:00 p.m. to answer your questions and provide assistance. Feel free to contact us at any time — we are here to help.