SNOK KSC-CHECK · free
SAP readiness assessment for the Polish cybersecurity act and NIS2
Registering in the state register is a form. Detecting an incident and proving the detection is the hard part - and in most of the projects we run, SAP produces neither.
25 questions about your landscape, 8 to 12 minutes. You see the score immediately and receive the PDF report by email.
The clock is already running
Register deadline: 3 October 2026
Detection capability takes months to build
Filing the register application takes hours. Building the ability to detect an incident takes months, which makes registration the last step rather than the first.
- 3 April 2026
- The amended act applies. Incident handling and reporting duties apply from day one
- 7 May 2026
- Self-registration in the register of key and important entities opens
- 3 October 2026
- Deadline to file the register application
- 3 April 2028
- First audit of key entities, assessing evidence from 2026 and 2027

What you get once you finish
Score on screen immediately
Points across five areas, a readiness level and the three largest gaps with their regulatory consequence stated plainly. No waiting for a sales call.
PDF report by email
Statutory deadlines, a 30-day and a 12-month plan, and an honest split between what you can do yourselves and what genuinely needs support.
Questions about SAP only
A general NIS2 questionnaire gives you one question about critical systems. Here you get 25 about the layer that holds the money.
The assessment is a self-assessment, not an audit and not a confirmation of compliance. It shows where to look for gaps and puts the actions in order - verification on the systems is separate work.
Your score
0
/ 100 points
Five areas
Three largest gaps
Want to walk this result through on real systems
We run the readiness review on your landscape, not on slides: evidence collected, a prioritised list of gaps and an effort estimate. A conversation commits you to nothing.
Write to usThis is a self-assessment, not an audit and not a confirmation of compliance with the Polish cybersecurity act or the NIS2 directive. The result rests solely on your answers, with no verification on the systems. Interpretation of the legislation requires confirmation by a lawyer.
Straight answers
Four questions that keep coming back
What the 3 October 2026 date means
It is the deadline to file the application for entry in the Polish register of key and important entities, set by the amendment to the act on the national cybersecurity system (Journal of Laws 2026 item 252), which entered into force on 3 April 2026. Registration runs through wykaz-ksc.gov.pl, open to self-registration since 7 May 2026.
Source: Journal of Laws 2026 item 252, Ministry of Digital Affairs announcement
What 24 hours from detection means
An early warning about a significant incident is due within 24 hours, counted from the moment of detection rather than occurrence. If an organisation has no means of detecting the event, the clock formally never starts - in proceedings, though, a supervisory authority will most likely read that as an absence of technical measures proportionate to risk rather than an absence of incidents.
Source: Polish cybersecurity act as amended, NIS2 Article 23
Is MFA required
The NIS2 directive names multi-factor or continuous authentication among risk management measures in Article 21(2)(j). The Polish act requires measures proportionate to risk, so for access to production systems holding financial and personal data a second factor is effectively unavoidable.
Source: Directive (EU) 2022/2555, Article 21(2)(j)
Deferred penalties - does that remove the urgency
The deferral covers typical administrative fines, not the obligations, and it excludes the extraordinary penalty and part of the supervisory measures. Incident handling and reporting duties apply from 3 April 2026, and the first audit of key entities is to take place by 3 April 2028, assessing evidence from the whole transition period.
Source: Polish cybersecurity act as amended
The longer discussion sits in our articleNIS2 and the Polish act in SAP: register entry by 3 October
Frequently asked questions
When is the register application due in Poland?
By 3 October 2026 for entities that met the criteria when the amended act entered into force on 3 April 2026. Applications have been accepted since 7 May 2026 through wykaz-ksc.gov.pl. Entities meeting the criteria later have six months from that point.
How long do you have to report a significant incident?
Early warning within 24 hours and full notification within 72 hours, both counted from detection, plus a final report within one month of the notification. An entity served by a sectoral CSIRT reports to it, and that team passes the case to the national CSIRT within 8 hours.
Does the Polish act require multi-factor authentication?
The NIS2 directive names multi-factor or continuous authentication among risk management measures in Article 21(2)(j), and the Polish act requires measures proportionate to risk. For access to production SAP systems holding financial and personal data, a second factor is hard to leave out of that logic.
Is KSC-CHECK an audit?
No. It is a self-assessment completed by someone in your organisation, with no verification on the systems. It does not confirm compliance with the act or the directive and does not replace legal advice. It shows where to look for gaps and puts the actions in order.
How long does it take, and is there a charge?
8 to 12 minutes, 25 questions, free of charge. The score appears on screen immediately and the PDF report goes to the address you give. Contact details serve to deliver the report; commercial contact happens only with separate consent.
