Skip to content

SNOK KSC-CHECK · free

SAP readiness assessment for the Polish cybersecurity act and NIS2

Registering in the state register is a form. Detecting an incident and proving the detection is the hard part - and in most of the projects we run, SAP produces neither.

25 questions about your landscape, 8 to 12 minutes. You see the score immediately and receive the PDF report by email.

The clock is already running

Register deadline: 3 October 2026

Detection capability takes months to build

Filing the register application takes hours. Building the ability to detect an incident takes months, which makes registration the last step rather than the first.

3 April 2026
The amended act applies. Incident handling and reporting duties apply from day one
7 May 2026
Self-registration in the register of key and important entities opens
3 October 2026
Deadline to file the register application
3 April 2028
First audit of key entities, assessing evidence from 2026 and 2027
Timeline of duties under Poland's cybersecurity act: 3 April 2026 entry into force with incident reporting from day one, 3 October 2026 deadline for the register entry, 3 April 2028 first audit of key entities assessing evidence from 2026 and 2027
The 2028 audit looks backwards - at evidence from the period running right now

What you get once you finish

Score on screen immediately

Points across five areas, a readiness level and the three largest gaps with their regulatory consequence stated plainly. No waiting for a sales call.

PDF report by email

Statutory deadlines, a 30-day and a 12-month plan, and an honest split between what you can do yourselves and what genuinely needs support.

Questions about SAP only

A general NIS2 questionnaire gives you one question about critical systems. Here you get 25 about the layer that holds the money.

The assessment is a self-assessment, not an audit and not a confirmation of compliance. It shows where to look for gaps and puts the actions in order - verification on the systems is separate work.

Straight answers

Four questions that keep coming back

What the 3 October 2026 date means

It is the deadline to file the application for entry in the Polish register of key and important entities, set by the amendment to the act on the national cybersecurity system (Journal of Laws 2026 item 252), which entered into force on 3 April 2026. Registration runs through wykaz-ksc.gov.pl, open to self-registration since 7 May 2026.

Source: Journal of Laws 2026 item 252, Ministry of Digital Affairs announcement

What 24 hours from detection means

An early warning about a significant incident is due within 24 hours, counted from the moment of detection rather than occurrence. If an organisation has no means of detecting the event, the clock formally never starts - in proceedings, though, a supervisory authority will most likely read that as an absence of technical measures proportionate to risk rather than an absence of incidents.

Source: Polish cybersecurity act as amended, NIS2 Article 23

Is MFA required

The NIS2 directive names multi-factor or continuous authentication among risk management measures in Article 21(2)(j). The Polish act requires measures proportionate to risk, so for access to production systems holding financial and personal data a second factor is effectively unavoidable.

Source: Directive (EU) 2022/2555, Article 21(2)(j)

Deferred penalties - does that remove the urgency

The deferral covers typical administrative fines, not the obligations, and it excludes the extraordinary penalty and part of the supervisory measures. Incident handling and reporting duties apply from 3 April 2026, and the first audit of key entities is to take place by 3 April 2028, assessing evidence from the whole transition period.

Source: Polish cybersecurity act as amended

The longer discussion sits in our articleNIS2 and the Polish act in SAP: register entry by 3 October

Frequently asked questions

When is the register application due in Poland?

By 3 October 2026 for entities that met the criteria when the amended act entered into force on 3 April 2026. Applications have been accepted since 7 May 2026 through wykaz-ksc.gov.pl. Entities meeting the criteria later have six months from that point.

How long do you have to report a significant incident?

Early warning within 24 hours and full notification within 72 hours, both counted from detection, plus a final report within one month of the notification. An entity served by a sectoral CSIRT reports to it, and that team passes the case to the national CSIRT within 8 hours.

Does the Polish act require multi-factor authentication?

The NIS2 directive names multi-factor or continuous authentication among risk management measures in Article 21(2)(j), and the Polish act requires measures proportionate to risk. For access to production SAP systems holding financial and personal data, a second factor is hard to leave out of that logic.

Is KSC-CHECK an audit?

No. It is a self-assessment completed by someone in your organisation, with no verification on the systems. It does not confirm compliance with the act or the directive and does not replace legal advice. It shows where to look for gaps and puts the actions in order.

How long does it take, and is there a charge?

8 to 12 minutes, 25 questions, free of charge. The score appears on screen immediately and the PDF report goes to the address you give. Contact details serve to deliver the report; commercial contact happens only with separate consent.

Get in touch