- Home
- NIS2 implementation
NIS2 implementation — compliance with the Polish NCSA
The amended Polish National Cybersecurity Act (NCSA) enters into force on 3 April 2026. Essential and important entities have only until 3 October 2026 to complete their self-assessment and register in the S46 system — we guide your company through the whole process, from qualification to an operating security management system.
Benefits
What you get
Certainty about qualification
A formal analysis of whether — and in what role (essential/important entity) — your company falls under the Act, with rationale ready for the board.
Error-free registration
Preparing and filing your entry into the register of essential and important entities in the S46 system before the 3 October 2026 deadline.
An ISMS sized to your company
Information security policies and procedures tailored to your organisation — not a corporate binder.
Incident readiness
Procedure for handling and reporting incidents to the relevant CSIRT within the required deadlines (early warning 24 h, notification 72 h).
Supply-chain security
Review of contracts with ICT suppliers and the security requirements that any NIS2 customer will pass down to you.
Protection for management
NIS2 introduces personal liability for management — we deliver training and due-diligence documentation.
Scope
What exactly this service covers
- Entity qualification analysis (sector, size, role in the supply chain)
- Registration in the register of essential and important entities (S46 system)
- Risk analysis and ISMS implementation aligned with the Polish NCSA
- Incident reporting procedures to the relevant CSIRT (24 h / 72 h / final report)
- Technical safeguards: MFA, EDR, backup, segmentation, monitoring
- Training for management and staff, plus annual reviews
Why MAD System
Foundations of our work
32 years of experience
Three decades on the IT market — hundreds of projects delivered for companies of every size.
Warsaw and Mazovia
Fast response on-site and remotely across Warsaw and the whole Mazovia region.
SLA and transparent contracts
Guaranteed response times, a clear scope of services, no hidden costs.
Certified engineers
A team certified by Microsoft, Cisco, Fortinet and other leading vendors.
Details
Statutory timeline — how much time you have
3 April 2026
The amended NCSA enters into force — obligations start.
3 October 2026
Deadline for self-assessment and application to the S46 register.
3 April 2027
Deadline for implementing the information security management system (ISMS).
3 April 2028
First cybersecurity audit of essential entities; then every 3 years.
How it works
Cooperation process
Audit
We learn your infrastructure and goals.
Analysis
Recommendations with priorities and cost.
Deployment
Delivery with no downtime and a clear plan.
Care
Monitoring, SLA, continuous improvement.
Order an IT audit
See the state of your infrastructure and investment priorities in a clear report.
Frequently asked questions
Also see
Other MAD System services
IT Outsourcing
IT outsourcing for companies in Warsaw and Mazovia. End-to-end infrastructure care, helpdesk, security, SLA. Book a free consultation.
About IT OutsourcingIT support
End-to-end IT support for companies in Warsaw. Engagement models tailored to your size, SLA, fast incident response.
About IT supportIT Audit
Professional IT infrastructure and security audit. Report with recommendations, priorities and cost estimates.
About IT AuditFrom the blog
Expand your knowledge
Ransomware — how to protect your company effectively
What an attack looks like from the inside, five layers of protection, an incident response plan and the question nobody wants to ask: should you pay the ransom.
Read article CybersecurityPhishing at work — how to spot it and train the team
People are the weakest link. Teach them vigilance.
Read article CybersecurityNIS2 — obligations for companies in Poland
NIS2 is coming hard. Check whether it applies to you.
Read articleContact
Write to us
We respond the same business day.