NIS2KSCSMECybersecuritySelf-identification

NIS2 for SMEs in Poland: self-identification and an action plan under the KSC amendment

A practical path for SMEs to assess sector, size, and exceptions, document self-identification, and build an accountable control-and-evidence plan.

Piotr Adamski· Review: Brillnet C-Team — operational and security review
NIS2 for SMEs in Poland: self-identification and an action plan under the KSC amendment

Not every SME is automatically in scope

“NIS2 for SMEs” can be misleading. Scope depends on factors including sector, service type, organizational size, linked enterprises, and statutory exceptions. The first task is not buying a tool or copying a generic checklist. It is documented self-identification.

This article structures operational work under the Polish KSC amendment. It does not determine the legal status of a specific organization. An ambiguous result requires qualified legal assessment.

1. Build an organization factsheet

Collect the facts used in qualification:

  • legal name and entity identifiers,
  • services and sectors served,
  • employee and financial data under the applicable calculation rules,
  • partner and linked-enterprise relationships,
  • territory in which services are provided,
  • special roles such as digital service provider or public entity,
  • the person accountable for approving the conclusion.

Record a source, date, and owner for every fact. A number without provenance quickly loses value during review.

2. Check sector, size, and exceptions

Follow the official self-identification path published by the Polish Ministry of Digital Affairs. Do not stop after one criterion. An organization below a typical size threshold may still require an exception analysis, while a medium-sized company does not enter scope solely because of size.

Record the outcome in a decision note:

  1. criteria checked,
  2. evidence used,
  3. criteria met or rejected,
  4. remaining uncertainty,
  5. approver and approval date,
  6. next review date.

3. Do not wait to improve controls

Even when legal status needs consultation, the organization can inventory processes and evidence that improve operational resilience regardless of scope:

  • owners of risks and critical assets,
  • incident handling and escalation channels,
  • business continuity and recovery,
  • supplier security,
  • access controls and MFA,
  • vulnerability and update management,
  • training and awareness acknowledgements,
  • implementation evidence and periodic review.

4. Run an evidence-based gap analysis

Link each obligation or control to an owner, frequency, and evidence item. A status of “implemented” without current evidence should not pass review.

A useful gap record contains:

  • requirement and source,
  • current control,
  • evidence and last review date,
  • gap or risk,
  • action, owner, and deadline,
  • closure criterion,
  • approver.

Prioritise gaps affecting incident detection, containment and notification, and the recovery of a critical service.

5. Maintain the decision over time

Self-identification is not a one-off document. Repeat it when services, sector, group structure, scale, or law changes. Assign the review owner and frequency in the control calendar.

Pulsar GRC can retain the relationship between source, requirement, control, risk, action, and evidence. Legal qualification and risk acceptance remain with the organization.

First 30-day checklist

  • Appoint a self-identification owner and deputy.
  • Approve the organization factsheet and sources.
  • Apply the official sector, size, and exception criteria.
  • Record the outcome, uncertainty, and consultation needs.
  • Inventory critical services, suppliers, risks, and controls.
  • Attach evidence to existing controls and record missing evidence as gaps.
  • Approve an action plan and next review date.

When the assessment reveals a control weakness, use CAPA with effectiveness review. Document readiness with an audit evidence pack without mixing organizational evidence with licensed standards or statutory text.

Sources and scope

This informational article does not replace licensed standards or individual legal advice.