IT Partner? See how to deliver NIS2 audit-readiness

View partner offer →
By · Founder, Easy Cyber Protection · · How we write this

ECP vs KSC (Poland): CyFun vs the Polish National Cybersecurity System

The KSC (Krajowy System Cyberbezpieczeństwa — National Cybersecurity System) is Poland's legislative NIS2 implementation. The original KSC Act dates to 5 July 2018; its NIS2 amendment entered into force on 3 April 2026 (Dz.U. 2026, signed 19 February 2026). It mandates a comprehensive ISMS for operators of essential and important services across 18+ sectors, with biennial ISMS audits and three national CSIRTs. Easy Cyber Protection is a CyFun audit-readiness platform sold to MSPs. Both sit in the NIS2 compliance space — for different countries and different delivery models.

How do CyFun and KSC compare side by side?

The split is jurisdictional. Follow KSC for Polish entities under NIS2 — the Ministry of Digital Affairs and three national CSIRTs enforce it. Use CyFun through ECP for Belgian clients, where it is the official CCB-issued compliance path.

KSC (Poland) Easy Cyber Protection / CyFun
Owning authority Ministry of Digital Affairs (Ministerstwo Cyfryzacji) as competent authority; CSIRT NASK, CSIRT GOV, CSIRT MON as national CSIRTs CCB: Centre pour la Cybersécurité Belgique (ECP implements CyFun)
Legal basis / last update Ustawa o KSC (5 July 2018), NIS2 amendment enacted 23 January 2026, in force 3 April 2026 (Dz.U. 2026) CyFun 2025 (aligned with NIST CSF 2.0), CCB-issued
Legal status Mandatory; entities must register by 3 October 2026 and implement all Chapter 3 measures by 3 April 2027 Operational: Belgian CCB-issued NIS2 compliance path; CAB audits running
Entity coverage Medium + large enterprises in 18+ sectors (50+ employees or €10M+ turnover; some categories regardless of size) Belgian entities registered under NIS2 (CCB portal)
Structure No fixed control count; requires comprehensive ISMS per NIS2 Article 21 — incident response, BCP, supply chain, access, cryptography, training. ISO 27001 / ISO 22301 recognized. 3 cumulative tiers: Basic, Important, Essential, each with YAML-implemented controls; 34 Basic controls, 133 at Important, 218 at Essential
Certification / assessment No accredited certification body; ISMS audit every 2 years by independent auditor (CISA / ISO 27001 Lead Auditor / NASK-certified). Results submitted to competent authority. CAB audit by CCB-accredited body; ECP generates signed .ecpbundle.zip audit bundle
Compliance cost ISMS consulting: market estimates €20,000–€60,000 initial for a medium Polish entity + €5,000–€15,000 for the biennial audit (not an official government figure) ECP platform licence: one fee per client per month, by the client's employee count (full band table below), absorbed into the MSP service fee
MSP / portfolio model No multi-tenant track: entity-level framework. MSPs providing ICT services (B2B) are themselves regulated as important entities. Purpose-built for MSP portfolio delivery: partner dashboard, white-label, per-client management
ISO 27001 relationship Polish law explicitly names PN-EN ISO/IEC 27001 and ISO 22301 as standards meeting KSC requirements CyFun 2025 overlaps with NIST CSF 2.0; ISO 27001 support planned, not yet shipped
Geography Poland (Ministry of Digital Affairs jurisdiction) Belgium-first; Ireland co-adopting CyFun as national NIS2 scheme

Sources: Dz.U. 2026 (KSC amendment), nisd2.eu, eversheds-sutherland.com Poland KSC alert, ccb.belgium.be. Last verified 2026-09-28.

Where KSC applies

  • Your clients are Polish entities that fall within KSC's sector scope (energy, transport, health, digital infrastructure, ICT service management, manufacturing, etc.) and meet the size threshold (50+ employees or €10M+ turnover)
  • You deliver compliance services in Poland and need to align with the three-CSIRT structure (NASK for private sector, GOV for public admin, MON for military)
  • Your clients already hold ISO 27001 or ISO 22301 certification — Polish law explicitly recognizes these as meeting KSC requirements
  • You are a Polish MSP / ICT service provider: you are yourself regulated as an important entity and must comply with KSC for your own operations
  • You need a compliance path that fits a project-based ISMS consulting engagement model rather than a guided SaaS platform

Where ECP / CyFun applies

  • Your clients are Belgian (or Irish): CyFun is the CCB's official NIS2 compliance path, the one Belgian auditors and the CCB assess against
  • You are an MSP and want to package CyFun audit-readiness as a repeatable monthly service across your client portfolio, not a bespoke ISMS consulting project per client
  • You need NL / FR / EN materials with Belgian regulatory context (CCB alignment, VLAIO kmo-portefeuille leverage for Flemish clients)
  • You want predictable MSP economics: ECP charges one fee per client per month, by the client's size in employees: Nano 1 – 4: €49, Micro 5 – 12: €99, Core 13 – 29: €169, Growth 30 – 49: €229, Medium 50 – 249: €395, Large 250 – 999: €750, 1,000+ on request. Partners buy below the published rate; the partner rate card is on request.
  • Your clients need a CAB audit deliverable: ECP generates the signed .ecpbundle.zip that an accredited Belgian audit body accepts

What does compliance cost under KSC versus CyFun?

This is a framework-vs-platform comparison, not tool-vs-tool. KSC is a legislative obligation — there is no product to buy. Compliance means running an ISMS consulting project or hiring a CISO. ECP is a platform that MSPs pay for and deliver to clients. The figures below compare a typical Polish medium entity's KSC compliance path with an equivalent-size Belgian SME's CyFun path via ECP.

KSC compliance: Polish medium entity, ~50 employees

  • • KSC Act text: free (Dz.U. 2026 at isap.sejm.gov.pl)
  • • ISMS implementation project (gap analysis, policy writing, controls): market estimates €20,000–€60,000 for a medium entity
  • • Biennial ISMS audit by independent certified auditor: market estimates €5,000–€15,000 per audit cycle
  • • Internal CISO or external consultant required: no guided platform; the entity manages the ISMS in-house
  • • Fines up to €7M or 1.4% of turnover for important entities; €10M or 2% for essential entities

ISMS consulting cost estimates are based on Polish market rates reported by legal and consulting firms (see fact-check table). No official government figure for KSC compliance project costs has been published. Actual costs vary by entity complexity, sector, and existing maturity.

ECP / CyFun: Belgian SME via MSP (Core-band client, 13 – 29 employees)

  • • Direct end-client price (Core band, 13 – 29 employees): €169 / month
  • • Smaller clients start lower: Nano (1 – 4 employees) is €49 / month
  • • Billed per client per month; no separate platform project cost
  • • MSP delivers the service and sets its own client-facing fee
  • • Client's annual cost: €2,028 — vs €20,000+ direct ISMS consulting engagement

ECP charges one fee per client per month, by the client's size in employees: Nano 1 – 4: €49, Micro 5 – 12: €99, Core 13 – 29: €169, Growth 30 – 49: €229, Medium 50 – 249: €395, Large 250 – 999: €750, 1,000+ on request. Partners buy below the published rate; the partner rate card is on request. Every client gets the full feature set including AI and integrations from day one. One-time €400 MSP onboarding fee per partner.

Where do CyFun and KSC overlap?

KSC and CyFun both implement NIS2 Article 21 security requirements — one for Poland, one for Belgium. The control areas overlap substantially because they share the same EU-level foundation. The difference is jurisdiction, audit path, and delivery model.

Control area KSC (Poland) CyFun / ECP
Governance & risk management ISMS requirement per NIS2 Art. 21; entity-level risk assessment; management accountability CyFun Basic + Important governance controls; ECP wiki enforces policy ownership per control
Access control & identity Art. 21(2)(i): privileged access management + MFA for essential entities CyFun PR.AC controls; ECP access register + evidence collection
Incident detection & response Mandatory incident reporting to CSIRT NASK/GOV/MON within 24h early warning, 72h notification; BCP required CyFun DE.CM + RS controls; ECP incident log + CSIRT notification workflow
Supply chain / ecosystem Art. 21(2)(d): supply chain security including ICT service providers and software security CyFun ID.SC; ECP vendor register template
Vulnerability management Art. 21(2)(m): vulnerability disclosure and handling; biennial ISMS audit CyFun DE.CM + PR.IP; ECP patch management templates
Cryptography & data security Art. 21(2)(h): encryption of data at rest and in transit CyFun PR.DS controls in Basic and above
ISO 27001 relationship Polish law names PN-EN ISO/IEC 27001 and ISO 22301 as recognized standards for KSC compliance Overlap significant with NIST CSF 2.0; dedicated ISO 27001 support planned, not yet shipped
NIS2 Article 21 compliance Yes: KSC is Poland's transposition of NIS2 Article 21 and 23 obligations Yes: CyFun is Belgium's implementation of Article 21; CCB-issued

Sources: Ustawa o KSC (Dz.U. 2026), NIS2 Directive Art. 21, CCB CyFun 2025 documentation. Mapping is indicative. Actual gap analysis requires professional assessment.

Frequently asked questions

Does following KSC satisfy NIS2 in Belgium?

No. KSC is Poland's national NIS2 compliance framework. Belgium's NIS2 compliance path is CyFun, issued by the CCB. A Belgian entity audited by a Belgian CAB body is assessed against CyFun, not KSC. The two frameworks overlap substantially — both implement NIS2 Article 21 — but they are not mutually recognized across borders. A Polish entity operating in Belgium must satisfy both the Ministry of Digital Affairs (KSC) and the CCB (CyFun) for each jurisdiction.

Can ECP help Polish clients comply with KSC?

Not natively today. ECP implements CyFun (the Belgian CCB framework). Because both KSC and CyFun derive from NIS2 Article 21 and share NIST CSF 2.0 influences, a Polish entity using ECP would build strong foundations — governance, evidence collection, incident workflows, vendor registers — that directly address KSC requirements. But ECP does not generate a KSC-ready ISMS package or map to the Polish CSIRT reporting structure. KSC support is on the product radar as part of the multi-framework engine; it is not yet scheduled.

Why is KSC compliance so much more expensive than CyFun via ECP?

Different delivery models. KSC is a legislative obligation — it sets what must be done but provides no guided platform, policy templates, or structured evidence collection. Compliance requires hiring consultants or a CISO to build and run an ISMS from scratch, which is why market estimates for a medium Polish entity run €20,000–€60,000 for initial implementation alone. ECP packages CyFun compliance into a guided platform with policy templates, evidence workflows, and a structured audit bundle. The MSP delivers this as a monthly service, not a one-time project. The platform absorbs the complexity; the per-client cost drops dramatically.

Are MSPs and IT service providers regulated under KSC in Poland?

Yes, in their own right. Polish MSPs and ICT service providers (managed service providers, managed security service providers, cloud computing, data centres) fall under the "ICT service management (B2B)" sector in NIS2 — which means they are themselves classified as important entities and must comply with KSC for their own operations. They are not exempt because they serve clients. If you are a Polish MSP with 50+ employees or €10M+ revenue, you have your own KSC registration and ISMS obligation, separate from your clients'.

Can ISO 27001 certification satisfy KSC requirements in Poland?

Largely yes. Polish law explicitly names PN-EN ISO/IEC 27001 and ISO 22301 as recognized standards meeting KSC ISMS requirements. An entity with a current ISO 27001 certification would be well-positioned to demonstrate KSC compliance, though the auditor will still assess KSC-specific obligations (sector-specific requirements, CSIRT reporting, registration). ISO 27001 does not automatically satisfy KSC, but it covers the bulk of the technical and governance layer. This is a real advantage of KSC over CyFun: Belgian CAB auditors assess against CyFun controls specifically; an ISO 27001 certificate does not substitute, though CyFun 2025 is NIST CSF 2.0 aligned.

Deliver CyFun audit-readiness to your Belgian clients

If you are a Belgian MSP, CyFun — not KSC — is the compliance path your clients need. ECP packages it as a monthly service: guided workflows, evidence collection, white-label reports, and a signed audit bundle your CAB auditor accepts.

Related

What did we verify, and when?

ClaimSourceAccessed
KSC NIS2 amendment adopted 23 January 2026, signed 19 February 2026, in force 3 April 2026 (Dz.U. 2026) nisd2.eu: NIS2 status Poland timeline + SKP Law alert 2026-09-28
Registration deadline 3 October 2026; full implementation by 3 April 2027 Eversheds Sutherland Poland: Legal Alert KSC NIS2 amendment 2026-09-28
Three CSIRTs: CSIRT NASK (private sector), CSIRT GOV (public admin), CSIRT MON (military) Schoenherr: Poland new cybersecurity rules NIS2 implementation 2026-09-28
Medium+ enterprises (50+ employees or €10M+ turnover) in 18+ sectors; some categories regardless of size Dudkowiak & Putyra: NIS2 Directive in Poland — scope and entity thresholds 2026-09-28
ISMS audit every 2 years by independent auditor (CISA / ISO 27001 Lead Auditor / NASK certificate) nisd2.eu + KluczeSoft KSC 2026 technical requirements checklist 2026-09-28
ISO 27001 (PN-EN ISO/IEC 27001) and ISO 22301 explicitly named in Polish law as meeting KSC requirements Resiliently: NIS2 Poland NCSA compliance guide 2026 2026-09-28
Fines up to €10M or 2% of revenue for essential entities; €7M or 1.4% for important entities NIS2 Directive Art. 34 as transposed; NIS-2-directive.com Poland transposition page 2026-09-28
ISMS consulting cost estimates €20,000–€60,000 initial; biennial audit €5,000–€15,000 (market estimates, not official) Omnimes: NIS2 and KSC 2.0 Act 2026 for Polish manufacturers; general Polish cybersecurity consulting market data 2026-09-28
ECP pricing: one fee per client per month, by employees (Nano 1 – 4: €49, Micro 5 – 12: €99, Core 13 – 29: €169, Growth 30 – 49: €229, Medium 50 – 249: €395, Large 250 – 999: €750, 1,000+ on request); partners buy below the published rate ECP ADR-0035 per-client-only pricing (by employee count) 2026-09-28
CyFun is Belgium's official NIS2 compliance path, CCB-issued CCB Centre pour la Cybersécurité Belgique 2026-09-28