GOVERNANCE · NIS2 / KSC

Cyber TrustCERT

NIS2 and the Polish act implementing it do not fit into a single document. Staff have to be trained, management is personally accountable, and procedures have to work on the day of an incident. Cyber TrustCERT runs that part and documents it, with the same mechanics as AI TrustCERT, only on different rules.

What it covers

  • Training for staff Cyber hygiene in a form you can account for: a path, an exam, a result.
  • A separate path for management The directive requires training from management bodies too, not just the IT team.
  • Named certificates Proof of training with a date and scope, ready to show during an inspection.
  • Policies and procedures Document templates for the risk-management measures the directive requires.
  • Incident readiness The reporting procedure and role split rehearsed before an incident actually happens.
  • Reports and records Who completed training, what expires, what is missing from the documentation.

The duties it handles

  • Management accountability

    The directive moves responsibility for security measures onto management bodies and requires their members to undergo training. We run a separate path for them.

  • Cyber hygiene and staff training

    Basic cyber hygiene practices and cybersecurity training are among the risk-management measures the directive names explicitly. This is the part the platform handles directly.

  • Risk analysis and policies

    Information system security policies, access control, asset management, cryptography and human resources security - you get templates to fill in with your own reality.

  • Incident handling and reporting

    The directive introduces staged incident reporting. You prepare the procedure and the role split in advance, and the team knows it from the training.

  • Business continuity

    Backups, disaster recovery and crisis management - written into procedures and rehearsed with the team.

  • Supply chain security

    Supplier relationships and the security requirements placed on them, captured in documentation and records.

What the rollout looks like

  1. Scoping We check whether, and as what kind of entity, the organisation falls under the rules, and what follows from that.
  2. Platform setup Accounts, training paths and a place for the documentation.
  3. Training Staff separately, management separately. Everyone finishes with an exam.
  4. Documentation and procedures Policies, records and the incident reporting procedure filled in with the organisation’s own data.
  5. Upkeep New joiners, periodic refreshers and updates after the rules change.

Deadlines already running

The amendment to the Polish national cybersecurity system act, which implements NIS2 into national law, has been in force since 3 April 2026. The dates below are public - each one comes with its source.

  1. 3 April 2026 The KSC Act amendment implementing NIS2 entered into force. source
  2. 3 October 2026 Deadline for self-identification and applying to the KSC Register via the S46 system - for entities that met the criteria on 3 April 2026. source
  3. 3 April 2027 Twelve months to implement risk-management measures. source
  4. 3 April 2028 Twenty-four months to the first audit for essential entities. source

Reporting a serious incident

Three stages, counted from detection: an early warning within 24 hours, the report itself within 72 hours, and a final report within 30 days. That is why the procedure and the role split are prepared in advance, not on the day of the incident.

Penalties

For essential entities up to EUR 10m or 2% of annual turnover, for important entities up to EUR 7m or 1.4% - in both cases whichever is higher.

What this page does not settle

We do not rule on whether your organisation is covered. The Polish model rests on self-identification: the organisation itself assesses whether it meets the sector and size criteria in Annexes 1 and 2 to the act. This page gives deadlines and duties, not the status of a particular entity - that we work out case by case, and it is worth confirming with a lawyer.

Not sure whether the rules cover you? A free check in a few minutes, computed in your own browser. Open the Cyber Ready Check →

The full Cyber TrustCERT description is coming soon.

Frequently asked questions

What is Cyber TrustCERT?
A governance solution for organisations covered by NIS2. It works like AI TrustCERT, only in cybersecurity: training with an exam and a certificate for staff and management, policy and procedure templates, and reporting that lets you show the duties are being met.
Who do NIS2 and the KSC act apply to?
Directive (EU) 2022/2555 covers essential and important entities in the listed sectors - among others energy, transport, banking, health, water, digital infrastructure, public administration, waste management, manufacturing and digital services. In Poland it is implemented by the amended national cybersecurity system act, in force since 3 April 2026, with the sectors listed in Annexes 1 and 2. The model rests on self-identification: the organisation itself assesses whether it meets the sector and size criteria.
By when must you register in the KSC Register?
Entities that met the criteria on 3 April 2026 have until 3 October 2026 to self-identify and apply for entry in the KSC Register via the S46 system. The act allows twelve months to implement risk-management measures, so until 3 April 2027, and essential entities have twenty-four months to their first audit.
Is management training really mandatory?
NIS2 explicitly requires members of management bodies to undergo training that lets them identify risks and assess risk-management practices. That is why we run a separate, shorter path for them.
Does this replace a security audit?
No. Cyber TrustCERT covers the people-and-paperwork layer: training, proof of training, policies, procedures and records. Technical security testing is separate work, done in parallel.
Do I need an IT department?
Not to run the platform - one administrator is enough. Filling in the technical policies is easier with someone who knows the organisation’s infrastructure.
What does it cost?
We price it case by case. The scope depends on what kind of entity the organisation is, how many people the training covers and how much documentation has to be prepared.

The same model, different rules

Cyber TrustCERT runs on the same mechanics as AI TrustCERT: training with an exam, documentation and records in one place. If you are after the AI Act side, start with the AI Literacy training.

Let us work out whether NIS2 applies to you, and how far

Tell us what the organisation does and how many people the training would cover. We will come back with what follows from that and where to start.

Let us scope it →

Not sure where to start?

Check in 3 minutes which AI Act obligations apply to your organisation. No commitment.

The AI Act is now in force. Transparency obligations under Article 50 of the AI Act have applied since 2 August 2026, and the European Commission has started enforcing the rules. Documented diligence is what counts.
Check your AI Act readiness →