NIS2 and Poland’s KSC: from scope assessment to an action plan
First check which obligations apply to your organization. Then turn them into actions and evidence.
Hypothetical examples.
Use a current source
In Poland, start with the Ministry of Digital Affairs self-identification guidance. Activity, organization size and exceptions matter. Discuss uncertainty with a qualified legal adviser.
Record the basis of the assessment
Keep the source, review date and agreed scope. An online list is not a final determination for your company. For other EU countries, check the national implementation.
Assign specific actions
Each action needs an owner, due date and defined result. Pulsar helps manage this work and document decisions. It does not replace statutory submissions or legal assessment.
Sources
Polish Ministry of Digital Affairs — KSC self-identification
Sources checked 6 September 2026.
Try it on your process
Choose one issue without confidential data. Assess whether the document, responsible person and decision are easier to find.
Sources and scope
- Act of 23 January 2026 amending the National Cybersecurity System Act (Journal of Laws 2026, item 252)
- Obligations of essential and important entities — Polish Ministry of Digital Affairs
- The KSC amendment enters into force — Polish Ministry of Digital Affairs
- National Cybersecurity System Act amendment — gov.pl knowledge base
This informational article does not replace licensed standards or individual legal advice.