Blog ITH ‒ Odkryj z nami świat nowoczesnych technologii

miejsce, gdzie dzielimy się wiedzą o innowacjach, trendach IT

ITH
YoutubeITH
Zobacz kanał ITH na Youtube

NIS2 for ISPs

NIS2 for ISPs

Did you receive a letter from UKE? Find out what obligations ISPs face

On April 13, 2026, the List of Key and Important Entities was launched. As of that date, entities began to be added to the list. Ex officio entries apply to selected categories of entities, including telecommunications operators. Most telecommunications operators have already received letters from the Office of Electronic Communications. These letters are not notices of the initiation of a procedure. Rather, they inform the operator that the entry has been made and that the operator has a specific, statutory deadline to complete the next step.

If your company has already received such a letter, it’s important to fully understand exactly what it says. This applies to both deadlines and obligations, which you need to start addressing right away.

What does a letter from UKE mean to you?

What exactly does the summons say?

The letter contains two key elements:

  • notification of the ex officio entry of a company into the list of key entities and important entities,
  • A request to provide missing data in the S46 system within 6 months of the date the request is served.

This is an important distinction. Inclusion in the list is not something you have to wait for. It was done automatically, ex officio. The six-month deadline, however, applies only to the completion of data entry in the system, not to the entire process of compliance with NIS2.

Does that mean you’re already subject to NIS2?

Yes. Since the entry in the registry was made ex officio, the obligations under the Act on the National Cybersecurity System apply to your organization as of now. This is the case regardless of whether the data in the S46 system has already been entered.

Importantly, according to the Ministry of Digital Affairs, the deadlines for fulfilling specific obligations are calculated from the date on which the statutory conditions for being designated as a key or important entity are met. In practice, for most operators, this is April 3, 2026—the date the amended Act enters into force—rather than the date of entry into the register or the date of data submission.

What are the actual deadlines?

For an operator that met the criteria as early as April 3, 2026, the schedule is as follows:

  • through October 3, 2026 – the deadline for entry into the registry (if it has not been done ex officio) or for providing additional information following a request. In your case, the 6-month period begins on the date the letter is delivered;
  • through April 3, 2027 – the deadline for connecting to the S46 system and for the initial implementation of the information security management system (ISMS);
  • through April 3, 2028 – the deadline for the first security audit for key entities (significant entities conduct an audit at the request of the supervisory authority).

Updating the data in the list is therefore only the first step. The actual implementation of security measures and documentation has its own timeline, which began earlier.

What should you do now?

First, log in to the S46 system and check what data is missing. Then, plan to complete the missing data well in advance. It’s best not to wait until the last week before the deadline. Support materials regarding the system and changes following the amendment to the law are available on the gov.pl and cyber.gov.pl websites.

At the same time, it’s a good idea to start organizing the technical areas. This primarily involves conducting an inventory of the infrastructure, performing a risk assessment, and preparing safety documentation—more on this later in the article.

Why were telecommunications operators included in NIS2?

Electronic communications providers are responsible for the infrastructure without which no other entity covered by NIS2 can function. This applies to hospitals, banks, government agencies, and energy companies. Each of these entities needs a stable network to fulfill its own business continuity obligations. The legislature has therefore included the telecommunications sector among the regulated sectors, as network stability and security are integral to the security of the entire economy.

Compared to the previous directive, the main change is that the regulation now covers a much larger number of entities. Furthermore, classification is now largely automatic and carried out ex officio, rather than based on individual administrative decisions.

Importantly, the KSC Act applies to all telecommunications providers, regardless of company size or revenue. Large and medium-sized operators are classified as “key entities,” while small and micro-operators are classified as “important entities.” Basic obligations, such as risk management, network protection, and incident reporting, are the same for both categories. The main difference lies in the method of oversight: regulatory authorities conduct regular inspections of key entities, while inspections of important entities are conducted primarily after an incident occurs or irregularities are reported.

What obligations arise from being listed in the registry?

Inclusion in the list of key or important entities imposes a specific set of obligations on telecommunications providers. We have outlined the most important of these below.

Risk Analysis

The operator must identify key infrastructure components: backbone nodes, routing systems, network management platforms, and BSS and OSS systems. Next, the operator must identify the threats and potential consequences of an incident for each of these components. This is not a one-time document prepared for an audit, but rather a process that must be updated after every significant change to the infrastructure.

Safety Measures

Measures expected by NIS2 in practice include, among others, multi-factor authentication for administrative access and the segmentation of network management environments from client environments. It is also important to secure routing, for example using mechanisms such as RPKI, as well as to continuously monitor network events and anomalies.

Incident Reporting

The Act establishes specific deadlines for reporting to the relevant CSIRT:

  • Initial report: within 24 hours of the incident being detected;
  • supplementary report: within 72 hours of becoming aware of the incident;
  • Final report: within one month of the incident’s conclusion.

The clock starts ticking the moment the organization becomes aware of the incident, not the moment it actually occurs. Therefore, without the ability to quickly detect threats, it is difficult to meet these deadlines at all.

Business continuity

NIS2 requires business continuity plans that cover not only technical failures but also cyberattack scenarios. This includes, for example, the compromise of an infrastructure management system. The key question is whether you have ever actually measured the time needed to restore a secure configuration and resume services, or whether you have merely described this in a procedure.

Supplier Safety

The operator must assess the risks associated with suppliers of ICT hardware, software, and services—from router manufacturers to network management system providers. It is therefore important to verify whether the contracts include provisions regarding security requirements. It is also advisable to verify new solutions before implementation and to monitor vulnerabilities in the equipment in use on an ongoing basis.

Documentation

Security policies, incident response procedures, risk assessment results, and supplier management policies must be documented. The documentation should be in a format that the organization can present during an audit. The lack of documentation—even when processes are functioning properly—is one of the most common findings in compliance audits.

Why shouldn’t you wait?

Waiting until the very last day of the deadline to complete the paperwork does not provide any additional time for implementation. The clock for fulfilling the substantive obligations has been ticking since April 2026, regardless of the pace at which data is added to the registry.

It’s also worth considering the timeline for the tasks that need to be completed. Implementing security procedures—from incident response to vendor management—realistically takes weeks, and in larger organizations, even months. It’s also worth noting that this process requires coordination between the technical department, management, and often external partners. Furthermore, a thorough risk analysis requires an inventory of the infrastructure and an assessment of the risks for each key component, which, with an extensive network, is not a task that can be completed in a single meeting.

Added to this is a factor beyond the operator’s control: at the same time, many other telecommunications companies that have received similar letters are making similar preparations. As a result, the workload on consulting and auditing firms is increasing, and with it, the wait time for external support is growing as deadlines approach.

What should you do in the coming weeks?

  • Log in to the S46 system and check what information about your company is already stored there.
  • Determine what information is missing, and plan to fill in the gaps with plenty of time to spare.
  • Select the team that will be responsible for coordinating activities related to NIS2.
  • Conduct an inventory of network infrastructure components and IT systems.
  • Check to see if you have documented incident response procedures. These should be separate from the procedures for handling routine malfunctions.
  • Review your organization’s policies regarding access to network management systems and determine whether you use multi-factor authentication.
  • Review your contracts with ICT providers for provisions related to security.
  • Talk to the board members about the responsibilities imposed by the NIS2 Directive.
  • Schedule a compliance audit that will identify gaps and pinpoint where to start taking action.

Discuss your situation with ITH experts

The letter from UKE is a good reminder to get your facts in order. This applies both to the data in the S46 system and to your company’s actual readiness to meet NIS2 requirements. ITH supports telecommunications operators at every stage of this process: from auditing and preparing documentation, through step-by-step NIS2 implementation, to cybersecurity training for teams and management.

ITH’s support covers both the technological layer and the development of an Information Security Management System (ISMS). The technological layer includes the configuration and securing of network infrastructure, access management systems, and threat monitoring systems. The ISMS, on the other hand, is a comprehensive set of procedures, security policies, training programs, and technical safeguards that integrates the NIS2 requirements into a single, coherent, and manageable system—rather than a collection of disparate documents prepared for the purposes of a single audit.

By combining these two areas, the operator does not have to integrate technical, organizational, and regulatory expertise on its own. The ITH team guides the organization through the entire process: from the initial gap analysis, through the implementation of security measures and documentation, to ongoing compliance maintenance.

If you’d like to assess your company’s readiness, check out ITH’s offerings for ISPs or schedule a brief call with our team.