Knowledge · Regulation: AI Act and NIS2 · 9 minutes
NIS2: who it applies to and how to comply in Poland in 2026
NIS2 in Poland is the amended National Cybersecurity System Act, in force since 3 April 2026. Who it covers, requirements, deadlines and fines.
Last updated: October 5, 2026
What is NIS2?
NIS2 is Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 on measures for a high common level of cybersecurity across the Union. It replaced the first NIS Directive and broadened the list of sectors and obligations.
A directive does not apply directly; each country has to write it into national law. The deadline was 17 October 2024. Poland did so with the Act of 23 January 2026 amending the National Cybersecurity System Act and certain other acts. It was published on 2 March 2026 (Journal of Laws 2026, item 252) and entered into force a month later, on 3 April 2026.
The amendment replaced the former operators of essential services with two groups: essential entities and important entities. It also changed how a company learns it is covered: it now has to assess that itself. It also introduced a procedure for designating a hardware or software supplier as a high-risk supplier.
Who does NIS2 apply to?
Two things decide whether a company is covered: sector and size. Sectors are listed in Annex 1 (including energy, transport, banking, health, water, digital infrastructure, ICT service management, space and public administration) and Annex 2 (including postal services, waste management, chemicals, food, manufacturing of certain products, digital providers and research) to the Polish act.
Size follows the EU SME definition in Annex I to Commission Regulation (EU) No 651/2014. Roughly: a medium-sized company has at least 50 employees or annual turnover and balance sheet total above EUR 10 million. A large one has at least 250 employees or turnover above EUR 50 million and balance sheet total above EUR 43 million. The relevant date is when the financial statements are prepared.
An essential entity is, roughly, a large company in an Annex 1 sector. An important entity is a medium company in Annex 1 or a medium or large company in Annex 2. Some entities are covered regardless of size, such as DNS service providers, qualified trust service providers, domain registries and public bodies named in the act.
Linked and partner enterprises count towards size. The act makes an exception when the company's information system is independent of the rest of the group.
NIS2 requirements: what essential and important entities must do
Both groups have the same obligations under Chapter 3 of the act. The central one is an information security management system: risk assessment, technical and organisational measures, incident handling, business continuity, supply chain security and training.
A significant incident is reported in three steps: an early warning within 24 hours of detection, an incident notification within 72 hours and a final report within one month of the notification.
Responsibility sits with the head of the entity. Under Article 8d they decide on the security management system, budget for it and make sure staff know their duties. Under Article 8e they complete cybersecurity training once every calendar year, and attendance must be documented.
Essential entities must also have their information system security audited. The first audit is due within 24 months, then at least every three years.
How to implement NIS2: the Polish timeline
3 April 2026: the amendment enters into force. 7 May to 3 October 2026: self-registration in the register of essential and important entities through wykaz-ksc.gov.pl, per the Minister of Digital Affairs' notice of 8 April 2026. Some entities are registered ex officio by the minister: public bodies, telecommunications providers, trust service providers and former operators of essential services. They receive a request and have 6 months to complete their data.
3 April 2027: end of the 12 months to implement the Chapter 3 obligations for entities that met the criteria when the act entered into force. 3 April 2028: deadline for the first audit of essential entities.
A company that becomes essential or important later, for example by crossing a size threshold, applies for registration within 6 months of meeting the criteria and has 12 months to implement the obligations.
Order of work: 1. Assess whether and how you are covered. 2. Apply for registration if you have not yet. 3. Name a responsible person and schedule management training. 4. Do a risk assessment and an incident plan with the 24 and 72 hour deadlines. 5. Review contracts with IT suppliers. 6. Implement the security management system before 3 April 2027.
Missed the 3 October registration deadline?
Apply now. The act provides for a fine for missing the deadline, but fines under Article 73(1)-(4), Articles 73a-73c and Article 76b can first be imposed two years after the act entered into force, that is from 3 April 2028.
That is no reason to wait. According to the Ministry of Digital Affairs, registration gives access to the S46 Cyber Hub and lets a company meet its duties under the act, including incident reporting.
What are the NIS2 fines in Poland?
Essential entity: up to EUR 10 million or 2% of revenue from the previous financial year, whichever is higher, and no less than PLN 20,000. Important entity: up to EUR 7 million or 1.4% of revenue, and no less than PLN 15,000.
If a breach causes a direct and serious cyber threat, for example to state security or human life, the authority imposes a fine of up to PLN 100 million. This provision is not deferred by two years.
The head of the entity can be fined personally too, for example for failing the Article 8d duties or skipping the annual training under Article 8e.
NIS2 for small businesses and suppliers
A small company is usually not covered by NIS2 directly. It will be affected indirectly if it supplies IT services, software or support to an essential or important entity. That entity has to secure its supply chain, so it will start asking suppliers about security and writing requirements into contracts.
How to answer such questions and read supplier assessments is covered in how to read a vendor security assessment. You can check some basics yourself: a free check of your domain shows, among other things, whether you have SPF and DMARC email protection that makes it harder to impersonate your company.
Many incidents start with a fake email. How to spot one is covered in how to tell if an email is genuine. If your company uses AI, also see how this fits with the EU AI Act.
In short
- Poland transposed NIS2 by amending the National Cybersecurity System Act (Journal of Laws 2026, item 252), in force since 3 April 2026.
- It mainly covers medium and large companies in sectors listed in Annexes 1 and 2 to the act, plus some entities regardless of size.
- The self-registration deadline passed on 3 October 2026. If you missed it, apply now.
- Chapter 3 obligations must be in place by 3 April 2027, and the first audit of an essential entity by 3 April 2028.
- Significant incident: early warning within 24 hours, notification within 72 hours, final report within a month.
Have a website, app or email address that looks suspicious?
Frequently asked questions
Does NIS2 apply to my company?
Check whether your business is listed in Annex 1 or 2 to the Polish act and whether you have at least 50 employees or turnover and balance sheet total above EUR 10 million. If both are true, you are most likely an important or essential entity.
Is NIS2 already in force in Poland?
Yes. The amended National Cybersecurity System Act transposing NIS2 has applied since 3 April 2026.
What is the difference between an essential and an important entity?
The Chapter 3 obligations are the same. An essential entity must also undergo an audit at least every three years and faces higher fines, up to EUR 10 million or 2% of revenue.
What is the NIS2 compliance deadline in Poland?
Entities covered from the day the act entered into force have until 3 April 2027 for the Chapter 3 obligations, and essential entities until 3 April 2028 for their first audit.
What happens if you are not in the KSC register?
The act provides for a fine, but it can be imposed from 3 April 2028 at the earliest. According to the Ministry of Digital Affairs, however, registration is what gives access to the S46 system used for incident reporting.
Sources
- Directive (EU) 2022/2555 (NIS2), EUR-Lex
- Polish Act of 23 January 2026 amending the National Cybersecurity System Act, Journal of Laws 2026 item 252
- Notice of the Polish Minister of Digital Affairs of 8 April 2026 on the registration schedule
- Polish Ministry of Digital Affairs: self-registration in the register of essential and important entities
- Commission Regulation (EU) No 651/2014, Annex I (SME definition), EUR-Lex
Accurate as of the article's last update. Laws and vendor terms change, so check the source before you decide.