
NIS2 in Poland – what exactly does it mean for companies
Not sure exactly what NIS2 is? Or maybe you need to organize your knowledge? This article will help you understand what NIS2 is really all about!
The implementation of the NIS2 Directive into Polish law through an amendment to the Act on the National Cybersecurity System (KSC Act) is one of the most significant regulatory changes in the IT sector in recent years.
However, this is not just another “compliance formality.” It is a change that has a real impact on how companies manage IT, security, and business continuity – and the responsibility for it rests with the management board.
In this article, we explain not only what the law says, but above all, what it means in practice for organizations.
NIS2 - What Is It Really All About?
The NIS2 Directive has one main objective: to strengthen the resilience of organizations and the state against cyber threats and to ensure the continuity of services critical to the economy and society.
In practice, this means three things:
- Cybersecurity is no longer the exclusive domain of the IT department,
- Responsibility is shifted to the executive level (board of directors),
- Security must be managed systematically, rather than on a “project-by-project” basis.
Poland’s implementation is based on the National Cybersecurity System Act, which defines specific obligations, deadlines, and sanctions. The National Cybersecurity System includes, among others, critical and important entities, incident response teams (CSIRT NASK, CSIRT GOV, CSIRT MON, and sector-specific CSIRTs), and the authorities responsible for cybersecurity in individual sectors.
Who Is Affected by NIS2? More Companies Than You Might Think
The scope of the regulations is very broad, and a complete list of industries is provided in Appendices 1 and 2 to the KSC Act.
Essential Entities (High Criticality)
- Energy (electricity, gas, fuels and oil, heat),
- Transportation (air, rail, water, road),
- Banking and financial market infrastructure,
- Healthcare (including manufacturers of essential medicines and medical devices, EU reference laboratories),
- Drinking water and wastewater,
- Digital infrastructure (data centers, cloud, electronic communications networks and services),
- ICT service management,
- Space,
- Selected public entities.
Important Entities
This is where the largest group of companies that do not expect to be subject to regulation is found:
- Postal and courier services,
- Waste management,
- Production, processing, and distribution of chemicals and food,
- Manufacturing (including medical devices, electronics, machinery, vehicles, and transportation equipment),
- Digital service providers (e-commerce platforms, search engines, social networks),
- Scientific research,
- Investments in nuclear energy,
- Selected regional public entities.
NIS2 therefore covers a significant portion of the SME sector – particularly companies that are part of larger supply chains.
Essential Entity vs. Important Entity - The Key Difference
Whether a company is subject to the regulation depends not only on the industry but also on the company’s size (thresholds set out in EU Regulation 651/2014):
- Essential entities – primarily large companies in key sectors and selected entities regardless of size (including DNS providers, TLD registries, qualified trust service providers, nuclear facility operators, and certain public entities),
- Important entities – most often medium-sized businesses in key sectors, as well as medium- and large-sized businesses in important sectors.
| Area | Essential Entity | Important Entity |
|---|---|---|
| Supervision | Continuous (active) | Follow-up (reactive) |
| Inspections | regular | after an incident/breach |
| Audit | at least once every 3 years | upon request by the authority |
| Penalties | higher | lower |
Most importantly: the company itself must classify itself and report accordingly. No one will send a notification – incorrect classification or failure to classify poses a real risk of sanctions.
When the Act Applies (Territorial Scope)
The regulations apply, among others, to entities operating in Poland (headquarters, branch, or cross-border operations) and to companies from outside the EU offering services in Poland – the latter must appoint a representative with an organizational unit in the EU. Digital service providers are subject to the regulations based on their principal place of business.
Deadlines – When You Need to Take Action
The KSC Act has been in effect since April 3, 2026, and the implementation of the requirements is phased in over time. What matters is when the company met the criteria for being designated as a key or important entity.
In practice: Most companies should already be in the process of implementation, not just in the analysis phase.
Registration in the list of essential and important entities
The list is maintained by the competent authorities in the S46 information and communication technology system. The application for entry is submitted electronically by the entity’s manager (or an authorized person) within 6 months of meeting the criteria; changes to the data must be reported within 14 days. The entry is declaratory in nature – if a company fails to fulfil this obligation, it may be entered ex officio. Data from the list is not public information; only aggregate statistics are publicly available.
Key Responsibilities
1. Risk Management and Safety Measures
The law does not impose a single set of tools – the measures are to be proportionate to the risk and tailored to the size of the company. However, the minimum scope includes, among other things:
- Risk analysis and information systems security policies
- Incident response,
- Business continuity and backups (backup, disaster recovery plans, crisis management),
- Supply chain security,
- Security in the procurement, development, and maintenance of systems, including vulnerability management,
- Assessment of the effectiveness of implemented measures,
- Cybersecurity awareness and staff training,
- Cryptography and encryption,
- Human resources security, access control, and asset management,
- Multi-factor authentication (MFA) and secure communication.
2. Information Security Management System (SZBI)
Key and important entities must implement an information security management system (SZBI) covering the entire lifecycle of the IT systems used to provide services – including policies, roles and responsibilities, operational procedures, security monitoring and testing, and systematic risk analysis. An existing ISO/IEC 27001 certification significantly shortens the path to compliance.
3. Incident Management – with Specific Deadlines
This is one of the most practical aspects of NIS2. A serious incident is reported to the relevant CSIRT in stages:
- 24 hours – early warning (whether the incident was intentional or has a cross-border dimension),
- 72 hours – a formal report assessing the impact, causes, and actions taken,
- Upon request – an interim report,
- 1 month – a final report (and if the incident is ongoing, within one month of its resolution).
In practice, this means that a company must have a process in place and personnel capable of responding within 24 hours – this cannot be “put together” in the middle of an attack. Note: Trust service providers must report an incident within 24 hours.
4. Supply Chain
The company is also responsible for the security of its suppliers and ICT partners – it must assess their risks and incorporate security requirements into its business relationships. In practice, even SMEs that fall outside the scope of the law are sometimes required to implement appropriate measures because their larger customers demand it.
5. Documentation and Audits
A complete audit trail is required: normative documentation (policies, procedures, plans) and operational documentation (implementation records, system logs), which must be protected, version-controlled, and retained for at least 2 years after the system is no longer in use. Key entities must conduct a security audit at least once every 3 years; the authority may also order an external audit.
Management's Responsibility
The entity’s management (e.g., a company’s board of directors) is responsible for fulfilling these obligations – even when the tasks have been delegated to someone else. In particular, management:
- Approves security measures and oversees their implementation,
- Provides organizational and financial resources,
- Designates at least two people to serve as points of contact with the KSC (one person in micro and small businesses),
- Is required to complete cybersecurity training.
The Act provides for monetary penalties imposed directly on managers and requires that individuals performing cybersecurity tasks have no criminal record.
Penalties
Before imposing a penalty, the authority typically employs “soft” measures – such as recommendations, orders to implement specific measures, inspections or audits, and deadlines for rectifying violations. Failure to respond, however, results in financial sanctions.
| Essential Entity | Important Entity |
|---|---|
| Up to 10 million EUR or 2% of annual revenue(whichever is higher; not less than 20,000 PLN) | Up to 7 million EUR or 1.4% of annual revenue(whichever is higher; not less than 15,000 PLN) |
The maximum administrative penalty under the national system can be as high as 100 mln zł. The authority may also require the implementation of measures, conduct an audit, or impose operational restrictions.
High-Risk Supplier - A New Risk in the Supply Chain
The minister responsible for digitization may designate a hardware or software supplier as a high-risk supplier if it poses a threat to national security. The decision (published in Monitor Polski) means, among other things, that companies using such products:
- A ban on putting into service the ICT products, services, or processes covered by the decision,
- An obligation to phase out solutions already in use – generally within 7 years (4 years for critical telecommunications functions).
This is a practical aspect of procurement planning and IT architecture – it’s worth mapping your dependence on key suppliers today.
Security Measures for Critical Incidents
In the event of a critical incident, the minister responsible for digital transformation may issue an immediately enforceable security directive (e.g., an order to install a patch, implement a specific configuration, suspend software distribution, or restrict network traffic), which may remain in effect for up to 2 years. Companies must be able to implement such a directive quickly.
What NIS2 Really Changes for Companies
1. IT is no longer just “support”
Cybersecurity is becoming an integral part of business management—not just operational, but strategic.
2. Senior management is personally accountable
Decisions regarding risk tolerance, the security budget, and investment priorities are no longer delegated exclusively to IT.
3. Compliance without implementation doesn’t work
Documents without actual processes will not pass an audit, will not mitigate risk, and will not protect against penalties.
The most common mistakes we see
- “We still have time” – implementation usually takes 6 – 12 months.
- “We’ll prepare the documentation” – NIS2 requires action, not paperwork.
- “We’re not a critical sector” – most companies fall into the “important” category, and some are included through the supply chain.
How to Approach NIS2
- Quick assessment (2 – 4 weeks): Does the company fall under NIS2? What is its classification? What gaps exist relative to the requirements?
- Implementation plan: priorities, roadmap, budget.
- System implementation: information security management system (ISMS), processes, tools, integration with S46.
- Audit preparation and ongoing incident reporting.
Summary
NIS2 is not an IT project or a one-time implementation – it is a change in the way an organization operates in the area of security. Companies that approach this strategically will increase their operational resilience, streamline their IT processes, and gain a competitive advantage. The rest will operate under time pressure and the risk of sanctions.
Sources:
- The NIS2 Directive (EU) 2022/2555 and the Act on the National Cybersecurity System (Annexes 1 and 2).
- biznes.gov.pl
- cyber.gov.pl

