09.10.2026

After being added to the KSC Registry—what should the organization do next?

The deadline for submitting an application for inclusion in the registry is October 3, 2026. Many organizations view registration in the S46 system as the end of the matter. This is a mistake. The entry does not fulfill any substantive obligation under the Act. It merely confirms that the organization is subject to it, and from that point on, the competent authority knows whom it can audit.

In our practice, we see the greatest legal risks in four areas.

1. Liability of the Entity’s Manager

The amended Act on the National Cybersecurity System imposes obligations directly on the entity’s manager. The manager is responsible for fulfilling cybersecurity obligations. The manager must also complete training at least once per calendar year. In the event of violations, the authority may impose a fine on the manager personally, regardless of any penalty imposed on the entity.

2. Information Security Management System

Entities that met the criteria on the date the Act took effect have until April 3, 2027, to implement an ISMS (Information Security Management System). The system is based on a documented risk assessment. The selection of technical and organizational measures must be derived from this assessment, as only then can the system be defended during an audit.

3. Incident Handling

A serious incident must be reported to the appropriate CSIRT (Computer Security Incident Response Team) in three stages: an early warning within 24 hours, a report within 72 hours, and a final report within one month. These deadlines begin upon detection of the incident, so the organization needs qualification criteria and a decision-making process in place before an incident occurs.

4. Supply Chain

Supply chain security is one of the mandatory elements of risk management. This also applies to risks associated with suppliers whom the law permits to be classified as high-risk suppliers.


After being added to the list: what the organization should now put in order.

Management:

– a person entrusted by the manager with cybersecurity responsibilities

– annual training for the manager, documented

– procedure for updating data in the registry (the deadline is 14 days from the change)

Risk and Information Security Management System (ISMS):

– inventory of information systems and dependencies

– documented risk assessment

– ISMS implementation schedule by April 3, 2027

Incidents:

– incident response procedure adhering to 24-hour, 72-hour, and monthly deadlines

– criteria for a serious incident

– procedure testing in the form of an exercise

Business Continuity:

– business continuity and disaster recovery plans

– backup restoration tests

Vendors:

– register of ICT (Information and Communication Technology) vendors with criticality assessment

– contractual clauses regarding security and incident reporting

– review of external access

Supervision:

– For critical entities, the first audit must be conducted by April 3, 2028, with subsequent audits at least once every three years

– Periodic review of the Information Security Management System (ISMS)

Administrative fines can reach 10 million euros or 2% of global annual turnover for critical entities and 7 million euros or 1.4% of turnover for important entities. The higher amount is taken into account. However, these figures are not the most important consideration. In the event of an incident, the authority will primarily assess whether the organization managed the risk proactively before it occurred.

#NIS2 #KSC #cybersecurity #compliance #newtechnologylaw

You might be also interested in...