Guide chapters
Cybersecurity and KSC/NIS2
Security is not an add-on to GDPR. The marketplace stores seller identification data, customer addresses, purchase history, and compliance documents. Full payout statements may remain with Stripe/PSP, but account takeover in the marketplace can still allow changes to the offer, price, contact details, or payment account linkage.
Minimum for every operator#
- MFA for administration and for local high-risk operations. If account changes and payouts are handled exclusively by Stripe in its hosted process, MFA/step-up for this activity is provided by Stripe - Artovnia does not duplicate the screen or the account;
- principle of least privilege and separation of customer service, finance, compliance, and administration;
- transmission encryption, secure storage of secrets, and encryption of sensitive repositories;
- log of changes to seller data, prices, products, permissions, and payouts;
- if the platform itself allows changing the account or PSP account - confirmation outside the current session; if the Artovnia panel only shows history and statistics, secure authentication of the panel is sufficient, along with verification that local actions cannot change payout details;
- security patches, vulnerability scanning, and testing before major changes;
- backups separated from the production environment and regular restore testing;
- abuse monitoring: account takeovers, unusual payouts, mass offer changes, return of blocked products;
- vulnerability reporting and incident handling process;
- business continuity plan and contact list for PSP, hosting, UODO, CSIRT, UOKiK, and product authorities.
When an average marketplace falls under KSC#
The amendment to the KSC implementing NIS2 is effective from April 3, 2026. A provider of an online trading platform is located in the digital sector. An entity meeting size and sectoral criteria may be a significant entity. In simplified terms, a typical small and medium-sized enterprise – fewer than 250 people and revenue up to EUR 50 million or a balance sheet total up to EUR 43 million, but not meeting the criteria for a small enterprise – should conduct a formal self-identification. Affiliated entities and statutory exceptions are also considered.
What to implement after qualification#
- risk-based information security management system;
- approved management responsibility and training;
- incident, continuity, crisis, backup, and recovery management;
- digital supply chain security: hosting, cloud, Stripe/PSP, email, helpdesk, analytics, software vendors, and administrators. This does not concern seller couriers unless the operator itself provides or organizes logistics as its own service;
- secure acquisition, development, and maintenance of systems, and vulnerability handling;
- cryptography, access, asset, personnel, and MFA policies;
- performance indicators and periodic reviews;
- registration, communication, and reporting through appropriate KSC/S46 channels.
A serious incident requires early warning no later than 24 hours after detection and reporting no later than 72 hours; further information and the final report are provided in accordance with the Act and instructions from the relevant CSIRT. The internal process should escalate immediately, not at the 23rd hour.
Basis and sources: KSC amendment - Journal of Laws 2026, item 252; Ministry of Digital Affairs - entities and obligations; Key KSC deadlines; KSC FAQ.
I design multi-vendor platforms with onboarding, payments, moderation, and operational workflows.
Explore marketplace development