NIS2 and the National Cybersecurity System Act in transport: what you need to do before October 2026

29 July 2026 | Knowledge, News, The Right Focus

The amended Act on the National Cybersecurity System (UKSC) has been in force since 3 April 2026. For transport sector undertakings, this means a specific compliance timeline, including an obligation to register with the National Cybersecurity System (KSC) registry by 3 October 2026. Failure to do so may result in substantial financial penalties, coupled with the risk of personal liability for senior management. Not every undertaking, however, automatically falls within the scope of the new regime. Read on to find out whether your organisation is affected and what you need to do before the deadline for preparation.

Does your transport company need to comply with the UKSC?

Certain organisations in the transport sector fall within the scope of the new regime as essential or important entities. This applies, in particular, to:

  • Air carriers
  • Airport managing bodies
  • Aviation and security service providers and air navigation services
  • Railway infrastructure managers
  • Licensed railway carriers
  • Operators of service infrastructure facilities, where they are carriers
  • Sea and inland water transport companies
  • Managing bodies of ports and port facilities
  • Port entities supporting maritime transport and VTS
  • ITS service providers
  • Public road administrators

Important note for road transport operators: the mere provision of road transport services does not, in itself, trigger essential or important entity status.

Not directly subject to the UKSC? The requirements may still reach your organisation indirectly

Other transport companies may feel the effects of the regulation through, for example, contractual requirements imposed by larger operators, public sector clients or corporate groups.

There are three channels through which the regulation may reach your business:

  • Supply chain. A client that is itself subject to the UKSC may flow down requirements into its contracts with you. These may cover, among other things, system access, backups, incident reporting and subcontractor oversight
  • Criticality of the service. Even without an explicit regulatory status, what matters is whether a failure of your service would disrupt transport operations, check-in, terminal operations, ITS or communications
  • Contracts and insurance. Increasingly, counterparties require evidence rather than declarations. This includes procedures, recovery tests, incident logs, contingency plans and access control policies

Quick test: formal obligation or operational risk?

Four short questions to help you determine whether your company will be formally subject to the UKSC (or whether the requirements will reach you through a client, a tender or an insurer):

  • Is the company one of the transport entities specified in the UKSC, e.g. an air or rail carrier, an airport, port or infrastructure manager, a road administrator or an ITS operator?
  • Does it meet the applicable size threshold or a special criterion for inclusion, taking into account the group and affiliated entities?
  • Could a failure of a service or system disrupt transport operations, check-in, terminal operations, ticketing, ITS, communications or telematics?
  • Does a client, a tender, an insurer or the corporate group require evidence of cybersecurity measures: MFA, backups, BCP/DRP, incident response procedure or supplier audits?

If you answered ‘yes’ to even one of these questions – act now. You may have less time than you think.

Essential or important entity? This affects the level of supervision, not the objective

The status does not affect the objective of implementation, as cybersecurity must be managed in both cases. The difference lies in the intensity of supervision and the risk of penalties.

2 

UKSC – implementation timeline

The amended UKSC has been in force since 3 April 2026, with the first compliance obligations falling due by 3 October 2026.

4 

However, October 2026 is closer than the calendar might suggest. Classification, data gathering, an internal audit and the preparation of documentation all take time. Don’t leave this until September.

UKSC – 6 areas of implementation

  • Roles, decisions, risk register and persons responsible for services and systems. The management board should be aware of the progress of work and approve key decisions
  • Risk and safeguards. Technical and organisational measures proportionate to the impact of an incident, the criticality of systems and failure scenarios
  • Business continuity. Contingency and recovery plans for TMS, ITS, port, rail, ticketing, check-in, telematics and communications systems
  • Supply chain. Requirements for IT suppliers, hosting providers, maintenance contractors, integrators, subcontractors and operational support
  • Access and people. Multi-factor authentication, access rights, privileged accounts, employee offboarding, training and rules for working with systems
  • Incidents and documentation. Procedures for detection, escalation, decision-making and reporting, together with records enabling the reconstruction of who did what and when

What not to do?

Don’t start by purchasing an IT tool or registering the company in the registry ‘just in case’.

First, you need to determine:

  • The service
  • The systems
  • The obligation
  • Responsibility (who is responsible for what)

Only then can you establish the procedures, contracts, suppliers and appropriate technical measures.

Management liability: this is not an IT-only project

This is the area that directly concerns senior management. And the one that is most often underestimated.

The greatest risk does not arise from the incident itself, but from the absence of a clear decision-making framework: who classifies the event, who escalates, who reports, who notifies clients and who approves remedial action.

Management should therefore be able to demonstrate that it has taken decisions regarding classification, budget, roles, timeline, oversight and periodic risk reviews.

Simply handing the project over to the IT department or the compliance team is definitely not enough.

What must be in place as a minimum standard of evidence? Management board decisions, a risk register, an implementation timeline, progress reports, test results and training confirmations.

Incidents: three clocks, three levels of information

When an incident occurs, time always works against you. Incident reporting therefore always involves three stages:

6 

Penalties, corporate risk and personal risk to the management board

Penalties should be treated as a management risk.

8

Key takeaway for the management board: a penalty of up to 300% of remuneration is not a corporate risk but a personal one. It’s worth bearing in mind that delegating a project without exercising oversight offers no protection against it.

Important note: the financial penalties discussed above will only be imposed two years after the amended UKSC entered into force, i.e. from 4 April 2028 (with the exception of the extraordinary penalty, which may be imposed before the expiry of that period).

UKSC – 6 steps to implementation

Implementation follows six steps:

  • Status assessment and registration: review the services provided, the UKSC framework, the company’s role, the size threshold and contracts, and determine whether the company falls within the scope of the regulation. Register the entity in the KSC registry
  • Service and dependency mapping: map services to systems, suppliers, locations, data and contingency processes
  • Failure scenarios: describe a number of situations, such as TMS/ITS system failure, a ransomware attack, a hosting failure, a supplier error or a loss of connectivity
  • Gap analysis and action plan: separate critical gaps from less urgent ones; assign owners, deadlines and a means of confirming completion
  • Contracts and suppliers: review provisions on incident reporting, audit rights, subcontractors, data location and inspection rights
  • Incident response: establish who communicates, who decides, who reports the incident, what is communicated to customers and what needs to be documented

The outcome of this process should not be a description of the regulations, but a practical implementation toolkit and guide covering: a status assessment, a service map, an action plan, incident response procedures, contractual provisions and evidence of board-level decisions. It’s well worth preparing this in collaboration with specialists.

Have questions? Contact us

Latest Knowledge

Family foundations: the government has done the maths and presented the bill

Three years. That’s how long we’ve been waiting for what the Council of Ministers had seen in the data from the outset – and has now disclosed in its review of the Family Foundation Act. The document not only diagnoses the problems, but also previews substantial changes to rules that founders and their advisers treated as settled and stable. And therein lies a problem that goes far beyond tax matters. If the rules of the game are changed while the game is being played, there can be neither planning stability nor trust in the law. It is no coincidence that one of the greatest concerns among entrepreneurs considering setting up a foundation is not the level of taxation, but the stability of the legal framework – which today is once again being called into question.

What the new swiss franc act means for banks

We now have a new Act on Special Measures for the Adjudication of Cases Concerning Loan Agreements Denominated in or Indexed to the Swiss Franc. The provisions come into force 14 days after publication. So now is a good time to look at what lies ahead and what banks should be doing today.

New draft Pay Transparency Act – what has changed since December 2025?

A second version of the draft act on strengthening the application of the right to equal pay for equal work or work of equal value between men and women has now been published. It refines procedures and deadlines and introduces a new supervisory body. We have already discussed the changes affecting the recruitment stage and the three pillars of the forthcoming pay transparency framework, noting that Poland will miss the EU transposition deadline of 7 June 2026. Now, we take a closer look at the further changes, new developments and risks that have emerged in the latest, April version of the draft.

Payment Services Regulation (PSR) – between consumer protection and due diligence

The draft Payment Services Regulation (PSR) is one of the most significant elements of the reform of the EU legal framework for payment services. Its principal aim is to enhance the security of cashless transactions and to reduce the scale of financial fraud, in particular that arising from the growth of digital channels. At the same time, the new rules are intended to introduce a liability model that will not result in risk being transferred entirely to financial institutions, whilst retaining an important role for independent due diligence on the part of the user.

Energy deregulation – key changes for businesses and energy consumers

The President has now signed the Energy Deregulation Act (UDER92). The new provisions cover both the relationships between energy undertakings and consumers, and matters relating to investment, district heating, and the administrative obligations of energy market participants. The Act introduces changes in the areas of billing, communication with consumers, grid connection, and the operations of undertakings in the energy and district heating sectors. We set out the key points to note.

Banking sector overview | Banking today and tomorrow | July 2026

Under the draft legislation, banks will be required to offer existing borrowers a switch from WIBOR-based to POLSTR-based interest rates, a mechanism intended to speed up the voluntary transition of financial instruments to the new benchmark. The banking sector has responded positively to the proposal, according to Tadeusz Białek, President of the Polish Bank Association.

“Withdraw from contract here” – what next for the new button in online shops, on trading platforms and in mobile apps?

From 19 June, national legislation was to require businesses in the European Union entering into distance contracts with consumers via an online interface to provide consumers with the option to withdraw from the contract via a dedicated function/button. However, due to Poland’s delay in transposing Directive 2023/2673, which requires the use of such a button, this obligation has been postponed in our country. We look at what remote contract withdrawal entails and which transactions the new feature will apply to.

Municipal master plans – new deadline, same old challenges

On 11 June 2026, the President signed into law a bill extending the deadline for municipalities to adopt their master plans (plany ogólne). The key deadline for adopting master plans was moved from 30 June to 31 August 2026. We examine the reasons behind this change and consider what the absence of a master plan might mean for potential investors and their future projects.

Record fines and the upcoming 21st sanctions package – what should businesses expect?

The past year has brought a series of enforcement actions that clearly signal a tightening approach by the Polish customs and revenue authorities towards breaches of the sanctions regime. Importantly, businesses should already be preparing for further changes, as the European Union has announced its 21st sanctions package and updated the list of designated persons and entities. We examine the key developments and offer guidance on how to minimise the risk of non-compliance.

Contact us:

Robert Brodzik

Robert Brodzik

Advocate / Counsel / NewTech / Data Protection and Cybersecurity

+48 532 206 479

r.brodzik@kochanski.pl

Magdalena Róża Petrow-Ganew

Magdalena Róża Petrow-Ganew

Senior Associate / NewTech / Data Protection and Cyber Security

+48 602 107 673

m.petrow-ganew@kochanski.pl