NIS2 implementation

NIS2 implementation — compliance with the Polish NCSA

The amended Polish National Cybersecurity Act (NCSA) enters into force on 3 April 2026. Essential and important entities have only until 3 October 2026 to complete their self-assessment and register in the S46 system — we guide your company through the whole process, from qualification to an operating security management system.

Check with the NIS2 calculator

Benefits

What you get

Certainty about qualification

A formal analysis of whether — and in what role (essential/important entity) — your company falls under the Act, with rationale ready for the board.

Error-free registration

Preparing and filing your entry into the register of essential and important entities in the S46 system before the 3 October 2026 deadline.

An ISMS sized to your company

Information security policies and procedures tailored to your organisation — not a corporate binder.

Incident readiness

Procedure for handling and reporting incidents to the relevant CSIRT within the required deadlines (early warning 24 h, notification 72 h).

Supply-chain security

Review of contracts with ICT suppliers and the security requirements that any NIS2 customer will pass down to you.

Protection for management

NIS2 introduces personal liability for management — we deliver training and due-diligence documentation.

Scope

What exactly this service covers

  • Entity qualification analysis (sector, size, role in the supply chain)
  • Registration in the register of essential and important entities (S46 system)
  • Risk analysis and ISMS implementation aligned with the Polish NCSA
  • Incident reporting procedures to the relevant CSIRT (24 h / 72 h / final report)
  • Technical safeguards: MFA, EDR, backup, segmentation, monitoring
  • Training for management and staff, plus annual reviews

Why MAD System

Foundations of our work

32 years of experience

Three decades on the IT market — hundreds of projects delivered for companies of every size.

Warsaw and Mazovia

Fast response on-site and remotely across Warsaw and the whole Mazovia region.

SLA and transparent contracts

Guaranteed response times, a clear scope of services, no hidden costs.

Certified engineers

A team certified by Microsoft, Cisco, Fortinet and other leading vendors.

Details

Statutory timeline — how much time you have

3 April 2026

The amended NCSA enters into force — obligations start.

3 October 2026

Deadline for self-assessment and application to the S46 register.

3 April 2027

Deadline for implementing the information security management system (ISMS).

3 April 2028

First cybersecurity audit of essential entities; then every 3 years.

How it works

Cooperation process

01

Audit

We learn your infrastructure and goals.

02

Analysis

Recommendations with priorities and cost.

03

Deployment

Delivery with no downtime and a clear plan.

04

Care

Monitoring, SLA, continuous improvement.

Order an IT audit

See the state of your infrastructure and investment priorities in a clear report.

Order an IT audit

Frequently asked questions

From the blog

Expand your knowledge

Contact

Write to us

We respond the same business day.