NIS2 and Poland's Cybersecurity Act: who is in scope, what you must do, by when
Poland's amended Cybersecurity Act, which implements NIS2, has applied since 3 April 2026. Five questions tell you whether your company is an essential or important entity, and what has to be done before 3 October.

The amendment to Poland's National Cybersecurity System Act took effect on 3 April 2026, and it is the act rather than the directive that binds companies here. No notice will arrive: the act runs on self-identification, so you assess your own status and you answer for the result.
NIS2 and the Polish act: which is which
NIS2 is a directive, and a directive does not bind companies directly. Your obligations come from Poland's National Cybersecurity System Act as amended. When a lawyer or an auditor asks for the legal basis, the answer is the act, not the directive.
The European Parliament and the Council adopted Directive 2022/2555 on 14 December 2022 and gave member states until 17 October 2024 to transpose it. Poland missed that deadline. For the next year and a half companies planned their programmes against a draft whose text kept changing, which for some of them meant reworking the same documentation twice.
That phase is over. The Act of 23 January 2026 amending the National Cybersecurity System Act was published on 2 March 2026 in the Journal of Laws under item 252 and took effect on 3 April, after a one-month vacatio legis. No new statute was created: this amends the act of 5 July 2018, so most of the existing article numbering survives.
Who NIS2 covers
The act covers entities that meet two conditions together: they carry out an activity listed in one of two annexes, and they exceed a size threshold. Meeting only one is not enough. The exception is a set of categories that are in scope regardless of size, described below.
Annex 1: essential sectors
- Energy, including mineral extraction, electricity, heat, oil, gas and hydrogen
- Air, rail, water and road transport
- Banking and financial market infrastructure
- Healthcare, including care providers, pharmacies, laboratories and medical device manufacturers
- Drinking water supply and wastewater treatment
- Digital infrastructure and electronic communications
- ICT service management, including managed service providers and managed security service providers
- Space
- Public entities
Annex 2: important sectors
- Postal and courier services
- Waste management
- Manufacture, production and distribution of chemicals
- Production, processing and distribution of food
- Manufacture of medical devices, electronics, machinery, vehicles and transport equipment
- Digital providers: online marketplaces, search engines, social networks
- Research
- Nuclear energy investments
The size threshold
The threshold refers to the definition of a medium-sized enterprise in Annex I to Commission Regulation (EU) No 651/2014, which comes down to three headcount bands:
- 50 to 249 employees: important entity
- 250 employees or more: essential entity
- Fewer than 50 employees: as a rule outside the scope of the act
Headcount is measured on 1 January of the given year, in full-time equivalents, counting employment contracts only. The assessment does not stop at headcount: Regulation 651/2014 also brings in financial ceilings and partner and linked enterprises. A company with a modest payroll that belongs to a large group crosses the threshold despite appearances.
Entities in scope regardless of size
For several categories the headcount threshold is irrelevant. They are covered even with a handful of staff:
- Trust service providers
- Top-level domain name registries and domain name registration service providers
- DNS service providers
- Electronic communications undertakings, on the conditions set out in the act
- Critical entities within the meaning of Directive 2022/2557
- Public entities listed in Annex 1
- Entities designated as essential by decision of the competent authority
Essential entity versus important entity
The substantive requirements are essentially the same for both categories. They diverge at supervision and penalties, and that difference is what drives cost.
| Criterion | Essential entity | Important entity |
|---|---|---|
| Supervision | Ex ante — the authority may inspect without any indication of a problem | Ex post — triggered as a rule only after an event |
| Mandatory audit | Yes, at its own cost: the first within 24 months, then at least once every 3 years | Not by operation of law, but the authority may order an external audit after a significant incident |
| Penalty ceiling | EUR 10,000,000 or 2% of turnover — whichever is higher | EUR 7,000,000 or 1.4% of turnover |
| Penalty floor | PLN 20,000 | PLN 15,000 |
| Basis where there is no turnover, or trading is under 12 months old | The equivalent of EUR 500,000 | The equivalent of EUR 250,000 |
The first row hurts most. Ex ante supervision removes the option of playing for time in the hope that nobody asks for documents until something goes wrong. The last row is worth a pause too: a special-purpose company with no turnover does not walk away with a zero fine, because the act substitutes the equivalent of half a million euro as the basis.
The audit: who runs it, how often, and who cannot
An essential entity audits the information system it uses to deliver the service at its own cost, at least once every 3 years. The clock runs from the day the previous audit report was signed rather than from the end of a calendar year, so one date set early shifts the whole later schedule. The first audit has to close within 24 months of meeting the criteria.
One provision in here can upend a budget plan. The audit cannot be carried out by anyone who performs cybersecurity duties at the audited entity, nor by anyone who performed them there in the year before the audit began. Your own security team therefore cannot audit your own company, and a specialist just hired away from your previous provider is out as well. Separately, the authority can order an external audit after a significant incident, and that decision is immediately enforceable.
A five-question test: is your company in scope?
Work through the questions in order. Each answer comes from documents you already hold, so you can run the test without an outside adviser.
1. Is your activity listed in Annex 1 or Annex 2?
Check by type of activity, not by industry label or business classification code. The annexes describe entities through cross-references to other statutes, such as the Energy Law or the Postal Law. If you hold a licence, permit or registry entry named in one of those references, you are in the annex. A negative answer ends the test, but look at question four before you close it.
2. How many people do you employ in full-time equivalents?
Take the position on 1 January of the current year. The 50 to 249 band gives you the status of an important entity; 250 and above makes you essential. Below fifty, move to question four, because the threshold is not the only route into scope.
3. Do you belong to a corporate group?
The size assessment takes in partner and linked enterprises. A company with forty employees that is controlled by one employing a thousand counts together with it. This is the most common reason a company wrongly concludes it is exempt, especially in groups built out of many special-purpose vehicles.
4. Do you fall into a category covered regardless of size?
Trust service providers, domain registries, DNS providers, electronic communications undertakings, critical entities and some public entities are covered whatever their headcount. If any of those roles describes what you do, your answers to questions two and three stop mattering.
5. Do you supply an essential or important entity?
This question does not settle whether the act applies to you, only whether its requirements will reach you anyway. Entities in scope are accountable for supply chain security, so they push obligations onto suppliers through contracts. Your formal status stays unchanged, and the security questionnaire still arrives with the first contract renewal.
The result in one sentence: a yes to question one combined with crossing the threshold in question two or three means you are in scope and must apply for entry in the register. Question four leads to the same conclusion without the threshold. If you are only caught by question five, you have no statutory duties, but the market will hold you to the same standard.
blog.nis2.h3.auditpath
blog.nis2.p.auditpath1
| blog.nis2.tbl.audit.h1 | blog.nis2.tbl.audit.h2 | blog.nis2.tbl.audit.h3 | blog.nis2.tbl.audit.h4 |
|---|---|---|---|
| blog.nis2.tbl.audit.r1c1 | blog.nis2.tbl.audit.r1c2 | blog.nis2.tbl.audit.r1c3 | blog.nis2.tbl.audit.r1c4 |
| blog.nis2.tbl.audit.r2c1 | blog.nis2.tbl.audit.r2c2 | blog.nis2.tbl.audit.r2c3 | blog.nis2.tbl.audit.r2c4 |
| blog.nis2.tbl.audit.r3c1 | blog.nis2.tbl.audit.r3c2 | blog.nis2.tbl.audit.r3c3 | blog.nis2.tbl.audit.r3c4 |
| blog.nis2.tbl.audit.r4c1 | blog.nis2.tbl.audit.r4c2 | blog.nis2.tbl.audit.r4c3 | blog.nis2.tbl.audit.r4c4 |
- blog.nis2.warn.auditor
blog.nis2.p.auditpath2
What the obligations are
The requirements fall into three groups: risk management, incident handling and reporting, and management accountability. What follows is the part that takes real work and real budget rather than a declaration.
An information security management system
The act requires an information security management system covering the information systems used to deliver the service. Measures must be proportionate to assessed risk and reflect the state of the art. The scope includes, among other things:
- Systematic risk assessment and risk treatment
- Security policies and procedures, with document control
- Incident handling: detection, classification, logging and response
- Business continuity, backups and disaster recovery
- Access control, multi-factor authentication and identity management
- Encryption, plus security in system acquisition and maintenance
- Training and basic cyber hygiene
Supply chain security
You have to account for risk introduced by suppliers and service providers, including the quality of their security practices and how the software you depend on is built. That translates into a contract review, security requirements in procurement, and a way to verify them. This is the channel through which the regulation reaches past the entities formally in scope and into their technology bench.
Management accountability
The provision that surprises boards most often, because it can neither be delegated nor bought in with a service:
- The head of the entity is accountable for meeting the obligations under the act
- Members of management are required to undergo cybersecurity training
- A fine may be imposed directly on the head of the entity, calculated as a percentage of their remuneration
- People performing security duties must produce a certificate of no criminal record
Incident reporting: 24 hours, 72 hours, one month
The clock starts when a significant incident is detected, not when it has been classified or the analysis is closed. Reports go to the relevant sectoral CSIRT:
- Early warning: without delay and no later than 24 hours from detection
- Incident notification: without delay and no later than 72 hours from detection
- Interim report on incident handling: at the request of the sectoral CSIRT
- Final report: no later than one month after the notification

Twenty-four hours for an early warning looks generous until the first incident detected early on a Saturday. Without an on-call rota and an escalation path, the day can be spent working out who has the authority to sign the report. Settle that question in writing before an incident forces it, and rehearse the scenario dry — a walkthrough on a quiet afternoon is the cheapest way to find out where the path breaks.
Deadlines: what and by when
Every key date runs from 3 April 2026. The Minister of Digital Affairs set out the schedule for entries in the register in a separate communication of 8 April 2026.
3 April 2026: the act takes effect
The new catalogue of entities and the new definitions start to apply. The register of essential and important entities opened on 13 April, and by 6 May the minister had entered existing operators of essential services, trust service providers, telecoms undertakings and public entities into it ex officio. If you are in that group you do not file an application, but it is worth checking the entry: the ministry populated it from public registers, and some details need correcting by the entity itself.
12 June 2026: S46 Cyber Hub opens to new entities
From this date entities listed in the KSC Register can connect to System S46, the channel used to report incidents and communicate with the CSIRTs. The date is not a cut-off — the duty to connect closes on 3 April 2027 — but it is when the real integration window starts.
3 October 2026: application for entry in the register
Self-registration has been open since 7 May 2026, and it is the one deadline on this list that later effort cannot make up. Entities that meet the criteria at some point in the future have six months from that day to apply. Changes to registered data must be reported within 14 days.
3 April 2027: obligations in place
Twelve months for the information security management system, the documentation, the incident handling process and supply chain requirements. A year looks comfortable right up to the moment someone counts how many of those items need a board resolution and money budgeted for the following year.
3 April 2028: first audit, first fines
Essential entities carry out their first security audit within 24 months. The same date ends the period during which fines under the act cannot be imposed.
The KSC Register is not System S46
These two names get confused constantly, and behind them sit two separate obligations with separate deadlines. The KSC Register is the register of essential and important entities at wykaz-ksc.gov.pl — that is where you file for entry by 3 October 2026. System S46 is the reporting channel you later use for incidents and for communicating with the CSIRTs. The register runs as a service within S46, but being entered in it does not mean you are connected to the system.
S46 Cyber Hub opened to new entities on 12 June 2026, and the deadline to connect is 3 April 2027, alongside the rest of the obligations. This is an integration task rather than a formality, and it belongs on the same schedule as your incident process: without a working reporting channel, the 24-hour deadline is theoretical.
That two-year grace period reads easily as two quiet years, and the reading is expensive. Supervisory measures other than fines apply from day one, and the grace period itself is narrower than most people assume.
- The registration deadline — 3 October 2026 applies regardless of the grace period, and no amount of later work makes it up
- Supervisory measures other than fines: the authority can order remediation, commission an audit or issue binding recommendations from the day the act took effect
- The deadline to connect to System S46, or the deadline to implement the obligations — both fall on 3 April 2027
- Contractual exposure to your customers, which runs to its own rhythm and knows nothing of statutory grace periods
Penalties
For an essential entity the fine may not exceed EUR 10,000,000 or 2 per cent of revenue for the previous financial year, whichever is higher. For an important entity the ceilings are EUR 7,000,000 and 1.4 per cent respectively. The złoty equivalent is set using the National Bank of Poland average rate on 31 December of the year preceding the decision.
The act closes this off at both ends, which is rarely written about. A fine cannot fall below PLN 20,000 for an essential entity and PLN 15,000 for an important one, so a floor exists regardless of how minor the breach. If the entity has no turnover or has been trading for under 12 months, the basis becomes the equivalent of EUR 500,000 for an essential entity and EUR 250,000 for an important one. The "2% of nothing is nothing" arithmetic does not work.
The fine on the head of the entity
Separately, a fine can be levied on the head of the entity, and it is usually what reorders board priorities fastest. The ceiling is 300% of the remuneration received, calculated on the rules used for holiday pay equivalent. For the head of a public entity the limit is lower at 100%, though where such a body is also in scope through another sector in Annex 1 or 2, the 300% rate returns. The fine on the individual and the fine on the entity can be imposed independently — neither absorbs the other.
The extraordinary penalty of up to PLN 100 million
Beyond the ordinary ceilings, the act provides for a penalty of up to PLN 100,000,000. The authority reaches for it where a breach causes a direct and serious cyber threat to defence, state security, public safety and order, or human life and health, or risks serious financial loss or serious disruption to the service. This one rarely appears in NIS2 round-ups because it is not in the directive — it is a domestic addition, like the fine on the head of the entity.
KEY TAKEAWAYS
- 1The obligations come from the Polish act, not from the directive itself. It has applied since 3 April 2026
- 2Qualification runs on self-identification: nobody will tell you that you are in scope
- 3Applications for entry in the register are due by 3 October 2026
- 4The essential versus important distinction affects supervision and fines, not the requirements themselves
- 5The reporting clock starts at detection: 24 hours, 72 hours, one month
- 6The KSC Register and System S46 are two separate obligations: entry by 3 October 2026, connection by 3 April 2027
- 7A fine can fall on the head of the entity personally and reaches 300% of their remuneration, or 100% at a public entity
NIS2 or DORA: which one applies to you
Financial entities fall under DORA, which is lex specialis to the Polish act on ICT risk management and incident reporting. A bank therefore does not run two parallel reporting tracks. If you operate in finance, the starting point is DORA and what the KNF expects, and the Cybersecurity Act moves to the background. Outside financial services the relationship is reversed.
Where to start
If the test came out positive, sequence matters. The first three steps are cheap and remove most of the procedural risk:
- NowBoard and legalRun the qualification and document it
One page explaining why you are an essential entity, an important entity or neither, with the annex basis and a headcount calculation that accounts for group structure. It is the first document an inspection asks for, and the only one that cannot credibly be reconstructed after the fact.
- By 3.10.2026Head of the entityFile for entry in the KSC Register
You file through wykaz-ksc.gov.pl and, while you are there, appoint at least two contact people for dealings with other entities in the national cybersecurity system. Changes to those details are then reported within 14 days. This is the one deadline on the list that no amount of later work makes up.
- By 3.10.2026Security and ITStand up incident handling with a real on-call rota
The 24-hour clock runs at four on a Saturday morning too, so you need an escalation path and someone authorised to sign the report. Name that person and a deputy now, and confirm both are reachable outside office hours.
- First quarter of the programmeSecurity and financeRun a gap analysis, then plan the budget
The order is the reverse of the usual one: without a gap analysis the budget gets built from vendors' wish lists rather than from the statute. Bear in mind that several items need a board resolution and a line in next year's plan, so the decision lands well before 3 April 2027 would suggest.
- By 3.04.2027IT and procurementConnect to S46 and review supplier contracts
Connecting to System S46 is an integration task carrying the same deadline as the rest of the obligations. In parallel, review contracts for security requirements and audit rights — security questionnaires from customers in scope arrive regardless, usually at the first renewal.
- By 3.04.2028BoardClose the first audit and the management training
The audit applies to essential entities and requires an auditor independent of whoever performs your security duties, so the engagement has to be contracted well ahead. Schedule the management training earlier and separately: it is a statutory duty, not good practice.
Frequently asked questions
Will I be notified that NIS2 applies to me?
No, setting aside the ex officio entry reserved for existing operators of essential services and some public entities. Everyone else assesses their own position and files their own application. Not having been told is not a mitigating circumstance.
Can a small company be in scope?
Yes, in two situations. The first is membership of a category covered regardless of size, such as trust service or DNS providers. The second is corporate linkage, where headcount is counted across the whole group.
Does an ISO 27001 certificate mean compliance with the act?
No. An implemented information security management system covers a large share of the substantive requirements and shortens the road considerably, but it does not replace the procedural duties: entry in the register, incident reporting within statutory deadlines, or management accountability. The certificate makes the conversation with the authority easier; it exempts you from nothing.
Do customers have to be told about an incident?
Reporting to the sectoral CSIRT is unconditional, while informing service recipients comes into play when the incident may adversely affect the service, and the authority can require it. Separately, a personal data breach triggers its own track under the GDPR, with 72 hours to notify the supervisory authority. Two regimes, two clocks, one incident.
What is the difference between the KSC Register and System S46?
The KSC Register is the register of essential and important entities at wykaz-ksc.gov.pl, where you file for entry by 3 October 2026. System S46 is the reporting channel used for incidents and for communicating with the CSIRTs, with a connection deadline of 3 April 2027. The register runs as a service within S46, but entry in the register does not mean you are connected to the system. Two obligations, two deadlines.
Can our own security team carry out the audit?
No. The audit cannot be performed by anyone who carries out cybersecurity duties at the audited entity, nor by anyone who did so in the year before the audit began. That rules out both your in-house team and a specialist just hired away from your incumbent provider. The duty applies to essential entities, which audit at their own cost at least once every 3 years.
In summary
The most expensive mistake with NIS2 is not picking the wrong tools. It is qualifying late, because the registration deadline passes regardless of how far along your implementation is. Run the test, document the outcome, and only then talk about budget. If you need someone to steer this from the management side, that is what a vCISO engagement is for, and the technical half is closed out by monitoring and incident detection.
The act does not ask whether you realised in time that it applied to you. It asks whether you filed on time.
Sources
- 1.Ustawa z dnia 23 stycznia 2026 r. o zmianie ustawy o krajowym systemie cyberbezpieczeństwa oraz niektórych innych ustaw (Dz.U. 2026 poz. 252)ISAP — Sejm RP · 2026-03-02 · accessed 2026-08-08The amending act as promulgated. Every article number, penalty ceiling and deadline cited in this piece traces back to it.
- 2.Ustawa z dnia 5 lipca 2018 r. o krajowym systemie cyberbezpieczeństwa (Dz.U. 2018 poz. 1560)ISAP — Sejm RP · 2018-07-05 · accessed 2026-08-08The act being amended. Most article numbering survived, so references to art. 8, 11 or 15 point here.
- 3.Nowelizacja ustawy o KSC — najważniejsze terminyMinisterstwo Cyfryzacji · 2026-04-10 · accessed 2026-08-08The official implementation schedule: register launch, self-registration window, S46 availability and the statutory cut-offs.
- 4.Nowelizacja ustawy o KSC — kogo obejmuje?Ministerstwo Cyfryzacji · 2026-04-20 · accessed 2026-08-08Source of the estimate of roughly 38,000 entities in scope, including some 27,000 public sector bodies.
- 5.Nowelizacja ustawy o KSC — obowiązki podmiotów kluczowych i ważnychMinisterstwo Cyfryzacji · 2026-06-08 · accessed 2026-08-08The ministry's own summary of what essential and important entities must do, and by when.
- 6.Wykaz podmiotów kluczowych i podmiotów ważnych — komunikat Ministra Cyfryzacji z 8 kwietnia 2026 r.CyberPolicy NASK · 2026-04 · accessed 2026-08-08The communication setting the schedule for register entries and for starting to use the reporting system.
- 7.Zmiany w Systemie S46 po nowelizacji i uruchomienie Wykazu podmiotów kluczowych i podmiotów ważnychMinisterstwo Cyfryzacji — System S46 · 2026 · accessed 2026-08-08How System S46 relates to the KSC Register, and how new entities connect to it.
- 8.Dyrektywa Parlamentu Europejskiego i Rady (UE) 2022/2555 (NIS 2), Dz. Urz. UE L 333 z 27.12.2022, s. 80Parlament Europejski i Rada UE · 2022-12-14 · accessed 2026-08-08The EU act the statute transposes. Cited for completeness — for Polish companies the source of obligations is the act, not the directive.
Find out whether NIS2 applies to your company
We run the qualification, the gap analysis and the implementation of the act's requirements. It starts with one thing: a documented answer to whether you are in scope, and in what capacity.