BLUF
There is no "NIS2 certificate." Neither the Polish KSC Act nor Directive 2022/2555 nor any implementing act provides for one. Compliance with NIS2 (in Polish law: compliance with the KSC Act) is demonstrated by the entry in the registry of essential and important entities, an operational information-security management system, incident reporting to the relevant CSIRT, and the cybersecurity audit under Article 16 KSC. Anyone offering an "NIS2 certificate" or "full compliance" after an audit is selling a service whose product does not exist in EU or Polish law. Legal interpretation requires consultation with a law firm.
Key facts
- NIS2 is not a certification scheme. Directive 2022/2555 and the Polish KSC Act do not provide for any "NIS2 certificate." Compliance derives from the statute and is evidenced by the KSC registry entry.
- ISO 27001 ≠ NIS2 compliance. An ISMS helps meet part of the requirements but does not replace reporting duties, the registry entry, or the sector-specific obligations of Annexes I/II.
- The Article 16 cybersecurity audit is a compliance assessment against statutory requirements — it is not a "pentest" or "certification", only a statutory duty.
- Polish deadlines: KSC registry entry from 7.05.2026 to 3.10.2026, operational duties implemented by 3.04.2027, first audit by 3.04.2028.
- Article 73 penalties: up to EUR 10m / 2% of turnover for essential entities, up to EUR 7m / 1.4% for important entities — imposed regardless of any "certificate."
Myth vs Fact — structural denials
MYTH: "After an audit I get the NIS2 certificate"
FACT: Neither Directive 2022/2555 nor the KSC Act provides for a certificate after an audit. The Article 16 KSC cybersecurity audit is a statutory duty (deadline: 3.04.2028), and its outcome goes to the competent authority. You do not receive a "certificate" — you receive a report and, in case of non-conformity, an order for remediation.
MYTH: "A vendor sells me the NIS2 certificate"
FACT: The market offers "NIS2 certification" or "full NIS2 compliance". These are proposals without basis in law — neither the EU nor PL provide for such a document. You pay for a report, not for legal compliance. Compliance comes from the KSC registry entry and the implementation of statutory duties, not from a vendor invoice.
MYTH: "ISO 27001 = full NIS2 compliance"
FACT: ISO/IEC 27001 is an ISMS standard. It helps meet part of the NIS2 requirements (e.g. policy documentation, risk management), but does not cover CSIRT reporting duties (24/72/30), the KSC registry entry, or the sectoral requirements of Annexes I/II. ISO 27001 supports compliance but does not replace it.
MYTH: "The NIS2 audit is just a penetration test"
FACT: The Article 16 KSC cybersecurity audit is a compliance assessment against statutory requirements, carried out by an auditor from the minister's list. It is not a "pentest" — it is a review of policies, controls, processes and organisational capabilities, not an external vulnerability scan.
MYTH: "A small company does not need to register"
FACT: For some sectors (MSSPs in Annex II, e.g. ICT-B2B suppliers) the threshold is lowered to ~10 staff / EUR 2m turnover. Even a small entity may be in scope. Do not rely on PKD alone — check Annexes I/II.
Decision table — what actually builds NIS2/KSC compliance
| Area | Statutory requirement | What it does NOT replace | Recommended action (30 / 90 days) |
|---|---|---|---|
| KSC registry entry | Article 7c(1) — file by 3.10.2026 | Any "certificate" | 30 days: identify sector; 90 days: file via MC portal |
| Information-security management system | Article 8 — ISMS proportional to scale and risk | ISO 27001 on its own; needs mapping to NIS2 requirements | 30 days: gap analysis; 90 days: implementation plan with owners |
| Incident reporting | 24h / 72h / 30 days to CSIRT | Generic "procedures" without a CSIRT contact | 30 days: escalation playbook; 90 days: tabletop exercise |
| Cybersecurity audit | Article 16 — first by 3.04.2028 | A penetration test; the audit is a compliance review | 90 days: choose the form (internal vs external auditor) |
| Training and awareness | Article 8 and competency requirements | One-off webinars | 30 days: training plan; 90 days: two training cycles |
| Supplier management | Article 8 — ICT supply chain | Contracts without security requirements | 30 days: critical supplier map; 90 days: cyber clauses |
Perspective from Marcin Białczyk (CHORS.NET)
In earlier years the most common myth I heard at the table was: "If we have ISO, we comply with the Act." Today that myth comes back in a new form — "If we have an NIS2 certificate, we comply with the Act." Only this certificate does not exist. In CHORS.NET we start every P3_NIS2_READINESS audit with the question: what needs to be entered in the KSC registry, who will do it, when, and on the basis of what evidence? The entry is an administrative fact, not a certificate.
The second point I flag: the market is full of "NIS2 certification" offers. Most are honest advisory services, but wrapped in language that suggests legal compliance. If the offer reads "after our audit you get a compliance certificate for NIS2", that is either a misunderstanding or an abuse. As a client, ask about the basis in Article 16 KSC and about the KSC registry entry.
The third thing: I will return to the contrast between a company that received a "certificate" from a vendor and a company that simply entered the KSC registry and implemented the statutory duties — for now, a contrast, not a case study.
Frequently asked questions
Does the "NIS2 certificate" exist?
No. Compliance is demonstrated by the KSC registry entry, an implemented ISMS, CSIRT incident reporting, and the Article 16 KSC cybersecurity audit. Legal interpretation requires consultation with a law firm.
Is ISO 27001 enough?
No. ISO 27001 supports part of the NIS2 requirements, but does not replace the registry entry, reporting duties, or sectoral requirements. It can be one element of the ISMS required by Article 8 KSC.
How do I spot a fake "NIS2 certification" offer?
Any offer that promises a "certificate" or "full compliance" after an audit is an abuse — no such document follows from EU or Polish law. Ask for the basis in Article 16 KSC and about the KSC registry entry.
Does an NIS2 auditor hand out a certificate?
No — the Article 16 KSC audit ends with a report and, in case of non-conformity, an order for remediation. The document is not a "certificate".
What actually protects a company from penalties?
The KSC registry entry by 3.10.2026, an operational ISMS, incident-reporting procedures (24/72/30), and the Article 16 KSC report. Article 73 KSC penalties are imposed regardless of any "certificates".
How CHORS.NET helps
- See the full service catalogue: /en/services/ — including P3_NIS2_READINESS and IT/OT audit.
- NIS2/KSC pillar: /nis2-ksc/ — definition, process, myths.
- How we work at CHORS.NET: /en/contact/.
- Related articles: What is NIS2 — definition and scope · How to report NIS2 — step by step.
Scope and limitations
- We are not a 24/7 SOC and we do not guarantee detection of every incident. Our model is P0_PASSIVE_SNAPSHOT and P1_AUTH_VA — not continuous monitoring with a coverage promise.
- We do not certify NIS2/KSC compliance and we do not issue standalone legal opinions. We provide readiness assessment and ISMS implementation support, not a "compliance certificate".
- The deadlines and procedures in this article reflect the state as of 9 August 2026 and may require updates after subsequent implementing acts.
- For interpretation of KSC provisions, CHORS.NET works with partner law firms.
- This material is informational and technical; it does not constitute legal advice.