Is your company subject to NIS2/KSC?
Employee headcount or PKD codes alone are often insufficient. We will analyse your actual operations, organization size, capital group connections, and specific criteria of the KSC Act (Polish implementation of NIS2). You will receive a written opinion: essential entity, important entity, or out of scope — along with justification and a plan for next steps.
The call is free. We will confirm if a full assessment is required and provide the scope and price.
What you receive
Clear conclusion
Essential entity, important entity, or out of scope of the Act.
Justification
Mapping your operations to the relevant sector, size criteria, and analysis of specific conditions.
Capital group analysis
If applicable: the impact of connections, shared IT systems, and joint service provision.
Plan for next steps
Deadlines, entry to the Polish KSC Register of essential and important entities, and recommendations for subsequent actions.
Document for the board and legal department
A brief executive summary and an annex with the detailed analysis.
How we work
Free call — 30 minutes
We get a preliminary understanding of your operations, structure, and the source of uncertainty.
Data and workshop
We collect documents, information about operations, group structure, and IT systems used.
Legal and technical analysis
We assess the criteria of the KSC Act and the actual manner of providing services.
Written opinion — 1–2 weeks
We deliver the conclusion, justification, and recommendations during a summary meeting.
Pricing
From 10,000 PLN net
Fixed price after a brief qualification call. The final quote depends, among other things, on the complexity of operations and group structure.
Book a 30-minute qualification callWhat's next — NIS2 roadmap
NIS2/KSC applicability assessment and written opinion
Whether you are subject to the act and in what capacity.
Gap assessment
Which requirements are not yet met.
Roadmap and implementation
Policies, processes, and security controls.
vCISO / SOC
Continuous oversight and security maintenance.
The opinion does not obligate you to purchase further services. If the organisation falls under the KSC Act, we can also support it with gap assessment, requirements implementation, and continuous vCISO/SOC oversight.
Why Redmoon
We combine experience in cybersecurity, infrastructure, and regulated sectors with legal analysis. We don't limit ourselves to PKD codes or automated forms — we examine the actual way your organisation operates.