The amended Act on the National Cybersecurity System (UKSC) has been in force since 3 April 2026. For transport sector undertakings, this means a specific compliance timeline, including an obligation to register with the National Cybersecurity System (KSC) registry by 3 October 2026. Failure to do so may result in substantial financial penalties, coupled with the risk of personal liability for senior management. Not every undertaking, however, automatically falls within the scope of the new regime. Read on to find out whether your organisation is affected and what you need to do before the deadline for preparation.
Does your transport company need to comply with the UKSC?
Certain organisations in the transport sector fall within the scope of the new regime as essential or important entities. This applies, in particular, to:
- Air carriers
- Airport managing bodies
- Aviation and security service providers and air navigation services
- Railway infrastructure managers
- Licensed railway carriers
- Operators of service infrastructure facilities, where they are carriers
- Sea and inland water transport companies
- Managing bodies of ports and port facilities
- Port entities supporting maritime transport and VTS
- ITS service providers
- Public road administrators
Important note for road transport operators: the mere provision of road transport services does not, in itself, trigger essential or important entity status.
Not directly subject to the UKSC? The requirements may still reach your organisation indirectly
Other transport companies may feel the effects of the regulation through, for example, contractual requirements imposed by larger operators, public sector clients or corporate groups.
There are three channels through which the regulation may reach your business:
- Supply chain. A client that is itself subject to the UKSC may flow down requirements into its contracts with you. These may cover, among other things, system access, backups, incident reporting and subcontractor oversight
- Criticality of the service. Even without an explicit regulatory status, what matters is whether a failure of your service would disrupt transport operations, check-in, terminal operations, ITS or communications
- Contracts and insurance. Increasingly, counterparties require evidence rather than declarations. This includes procedures, recovery tests, incident logs, contingency plans and access control policies
Quick test: formal obligation or operational risk?
Four short questions to help you determine whether your company will be formally subject to the UKSC (or whether the requirements will reach you through a client, a tender or an insurer):
- Is the company one of the transport entities specified in the UKSC, e.g. an air or rail carrier, an airport, port or infrastructure manager, a road administrator or an ITS operator?
- Does it meet the applicable size threshold or a special criterion for inclusion, taking into account the group and affiliated entities?
- Could a failure of a service or system disrupt transport operations, check-in, terminal operations, ticketing, ITS, communications or telematics?
- Does a client, a tender, an insurer or the corporate group require evidence of cybersecurity measures: MFA, backups, BCP/DRP, incident response procedure or supplier audits?
If you answered ‘yes’ to even one of these questions – act now. You may have less time than you think.
Essential or important entity? This affects the level of supervision, not the objective
The status does not affect the objective of implementation, as cybersecurity must be managed in both cases. The difference lies in the intensity of supervision and the risk of penalties.
UKSC – implementation timeline
The amended UKSC has been in force since 3 April 2026, with the first compliance obligations falling due by 3 October 2026.
However, October 2026 is closer than the calendar might suggest. Classification, data gathering, an internal audit and the preparation of documentation all take time. Don’t leave this until September.
UKSC – 6 areas of implementation
- Roles, decisions, risk register and persons responsible for services and systems. The management board should be aware of the progress of work and approve key decisions
- Risk and safeguards. Technical and organisational measures proportionate to the impact of an incident, the criticality of systems and failure scenarios
- Business continuity. Contingency and recovery plans for TMS, ITS, port, rail, ticketing, check-in, telematics and communications systems
- Supply chain. Requirements for IT suppliers, hosting providers, maintenance contractors, integrators, subcontractors and operational support
- Access and people. Multi-factor authentication, access rights, privileged accounts, employee offboarding, training and rules for working with systems
- Incidents and documentation. Procedures for detection, escalation, decision-making and reporting, together with records enabling the reconstruction of who did what and when
What not to do?
Don’t start by purchasing an IT tool or registering the company in the registry ‘just in case’.
First, you need to determine:
- The service
- The systems
- The obligation
- Responsibility (who is responsible for what)
Only then can you establish the procedures, contracts, suppliers and appropriate technical measures.
Management liability: this is not an IT-only project
This is the area that directly concerns senior management. And the one that is most often underestimated.
The greatest risk does not arise from the incident itself, but from the absence of a clear decision-making framework: who classifies the event, who escalates, who reports, who notifies clients and who approves remedial action.
Management should therefore be able to demonstrate that it has taken decisions regarding classification, budget, roles, timeline, oversight and periodic risk reviews.
Simply handing the project over to the IT department or the compliance team is definitely not enough.
What must be in place as a minimum standard of evidence? Management board decisions, a risk register, an implementation timeline, progress reports, test results and training confirmations.
Incidents: three clocks, three levels of information
When an incident occurs, time always works against you. Incident reporting therefore always involves three stages:
Penalties, corporate risk and personal risk to the management board
Penalties should be treated as a management risk.

Key takeaway for the management board: a penalty of up to 300% of remuneration is not a corporate risk but a personal one. It’s worth bearing in mind that delegating a project without exercising oversight offers no protection against it.
Important note: the financial penalties discussed above will only be imposed two years after the amended UKSC entered into force, i.e. from 4 April 2028 (with the exception of the extraordinary penalty, which may be imposed before the expiry of that period).
UKSC – 6 steps to implementation
Implementation follows six steps:
- Status assessment and registration: review the services provided, the UKSC framework, the company’s role, the size threshold and contracts, and determine whether the company falls within the scope of the regulation. Register the entity in the KSC registry
- Service and dependency mapping: map services to systems, suppliers, locations, data and contingency processes
- Failure scenarios: describe a number of situations, such as TMS/ITS system failure, a ransomware attack, a hosting failure, a supplier error or a loss of connectivity
- Gap analysis and action plan: separate critical gaps from less urgent ones; assign owners, deadlines and a means of confirming completion
- Contracts and suppliers: review provisions on incident reporting, audit rights, subcontractors, data location and inspection rights
- Incident response: establish who communicates, who decides, who reports the incident, what is communicated to customers and what needs to be documented
The outcome of this process should not be a description of the regulations, but a practical implementation toolkit and guide covering: a status assessment, a service map, an action plan, incident response procedures, contractual provisions and evidence of board-level decisions. It’s well worth preparing this in collaboration with specialists.
Have questions? Contact us



