Executive Summary
- NIS2, formally Directive (EU) 2022/2555, is the European Union's second Network and Information Security directive. It widens the scope of cybersecurity regulation well beyond the original 2016 NIS1, pulling tens of thousands of mid-market companies into a regime they were previously outside.
- Poland has transposed NIS2 through an amendment to the Act on the National Cybersecurity System (the KSC, ‘Ustawa o krajowym systemie cyberbezpieczeństwa’). The President signed it on 19 February 2026 and it entered into force on 3 April 2026, starting a hard compliance clock: registration by 3 October 2026 and full compliance by 3 April 2027.
- The obligations are concrete and auditable. They include ten baseline risk-management measure areas under Article 21, a strict 24-hour / 72-hour / one-month incident-reporting cascade, personal accountability for the management body, and administrative fines reaching €10 million or 2% of global annual turnover for essential entities.
- We treat NIS2 as an operational programme, not a binder of policies. We run a 24/7 Managed SOC, build the detection-and-reporting pipeline that actually meets the deadlines, and tell you honestly which controls are genuinely missing versus which your existing estate already covers.
What Is NIS2, and How Does It Differ From NIS1?
NIS2 (Directive (EU) 2022/2555) is an EU-wide law that sets a minimum baseline of cybersecurity risk-management and incident-reporting obligations for organizations operating critical or important services. It repeals and replaces the first NIS Directive (Directive (EU) 2016/1148), commonly called NIS1. A directive is not directly binding on companies. Each member state must transpose it into national law, which is why the rules that bind your Polish entity live in the amended KSC, not in the directive text itself.
Key fact: NIS1 left member states wide latitude to decide who was an ‘operator of essential services’, which produced inconsistent coverage across the EU. NIS2 removes most of that discretion by defining sectors and size thresholds directly in the directive, so a manufacturer or IT-services provider in Poland faces broadly the same baseline as its counterpart in Germany or France.
What Actually Changed
- Far broader sector coverage. NIS2 extends the in-scope list well beyond energy, transport, banking, health, and digital infrastructure to sectors such as public electronic communications, digital providers, wastewater and waste management, manufacturing of critical products, food, chemicals, postal and courier services, research, and ICT service management.
- Automatic scoping by size. Instead of regulators hand-picking operators, entities are generally in scope if they operate in a listed sector and meet a size threshold. This removes the guesswork that defined NIS1.
- Stronger enforcement. NIS2 introduces harmonized supervisory powers, meaningful fines, and direct accountability for senior management. These teeth were largely absent from NIS1.
- Supply-chain focus. The directive explicitly requires entities to manage risk in their supplier and service-provider relationships, not just their own perimeter.
Who Does NIS2 Apply To?
NIS2 splits regulated organizations into two tiers: essential entities and important entities. The distinction matters because it drives both the intensity of supervision and the size of the penalties.
Key Plain-language Definitions
- Essential entities are larger organizations in the most critical sectors, for example energy, transport, banking, financial market infrastructure, health, drinking water, digital infrastructure, and public administration. They face proactive supervision: regulators can audit and inspect them without waiting for an incident.
- Important entities are organizations in the remaining in-scope sectors, plus medium-sized entities in critical sectors. They face reactive supervision, meaning oversight is generally triggered by evidence of a problem.
Quick answer: If your company is a medium or large enterprise operating in one of the NIS2 sectors, assume you are in scope until a structured assessment proves otherwise. The default has flipped from ‘probably exempt’ under NIS1 to ‘probably in scope’ under NIS2.
The Size Thresholds and the Size-cap Rule
NIS2 generally uses the EU definition of medium and large enterprises as its trigger. In practical terms, an entity in a listed sector is captured if it has at least 50 employees, or an annual turnover and balance-sheet total above €10 million. This is the so-called ‘size-cap’ rule: below the medium-enterprise threshold, an organization is normally out of scope by default.
The size-cap is not absolute. NIS2 also pulls in certain entities regardless of size where their role is critical, for example providers of public electronic communications networks, DNS service providers, top-level-domain registries, trust service providers, and sole providers of an essential service in a member state. A small company can therefore be in scope if what it does is structurally important, even with modest headcount. The only way to be sure is to map your activities against the sector annexes rather than rely on employee count alone.
How Does Poland Transpose NIS2?
Poland implements NIS2 by amending its existing cybersecurity framework, the Act on the National Cybersecurity System (KSC). This is sometimes referred to in the market as ‘KSC 2.0’. Rather than writing a brand-new statute, the legislator extended the 2018 KSC to cover the new sectors, the essential/important classification, the Article 21 measures, the reporting cascade, and the supervisory and penalty regime.
Key fact: Poland missed the EU transposition deadline of 17 October 2024, as did most member states. The European Commission issued a reasoned opinion against Poland on 7 May 2025 for failing to notify full transposition. Poland then completed the legislative process: the President signed the amendment on 19 February 2026, and it entered into force on 3 April 2026.
The Polish Compliance Timeline You Need to Plan Against
- 3 April 2026: the amended KSC enters into force. The legal clock starts.
- By 3 October 2026 (roughly six months after entry into force): in-scope entities must self-identify and submit their application to be entered on the relevant register. Self-identification is your responsibility. The regulator does not send you an invitation.
- By 3 April 2027 (roughly twelve months after entry into force): entities must have their technical and organizational risk-management measures fully in place.
The first six months are deliberately weighted toward analysis and registration. Use them to determine scope, classify your entity, register, and complete a gap assessment, so that the second six months go to remediation rather than discovery. Exact deadlines and procedural details continue to be clarified through implementing regulations, so confirm the current text before relying on a specific date.
What Security Measures Does Article 21 Actually Require?
Article 21 of NIS2 is the operational heart of the directive. It requires entities to take ‘appropriate and proportionate technical, operational and organizational measures’ to manage risk, using an all-hazards approach. The directive names ten measure areas that, at minimum, those measures must cover.
- Policies on risk analysis and information system security.
- Incident handling, meaning detection, response, and the reporting obligations described below.
- Business continuity, including backup management, disaster recovery, and crisis management.
- Supply-chain security, including security in relationships with direct suppliers and service providers.
- Security in network and information systems acquisition, development, and maintenance, including vulnerability handling and disclosure.
- Policies and procedures to assess the effectiveness of the risk-management measures.
- Basic cyber hygiene practices and cybersecurity training.
- Policies and procedures on the use of cryptography and, where appropriate, encryption.
- Human resources security, access-control policies, and asset management.
- The use of multi-factor authentication, secured voice, video, and text communications, and secured emergency communication systems where appropriate.
None of these are novel to anyone who has worked through ISO/IEC 27001 or a serious security program. The shift NIS2 introduces is that these are now legal obligations subject to inspection and fines, and that the management body, not just the IT department, is answerable for them.
What Are the Incident-reporting Obligations and Timelines?
For a ‘significant incident’, one that causes or is capable of causing severe operational disruption or financial loss, NIS2 imposes a three-stage reporting cascade to the national CSIRT or competent authority. In Poland these reports flow through the national CSIRT structures.
- Early warning within 24 hours of becoming aware of the incident. This is a short notification indicating whether the incident is suspected to be caused by unlawful or malicious action and whether it could have cross-border impact.
- Incident notification within 72 hours of awareness. This updates the early warning with an initial assessment of severity, impact, and any indicators of compromise.
- Final report within one month of the notification. This provides a detailed description, the type of threat or root cause, applied and ongoing mitigation, and any cross-border impact.
Quick answer: The 24-hour clock is the one most organizations underestimate. It starts when you become aware of a significant incident, not when you have finished investigating. If you cannot triage a suspected incident, decide whether it is reportable, and file an early warning inside 24 hours, the gap is your operational readiness, not your paperwork. This is precisely where a 24/7 Managed SOC earns its place: continuous monitoring, defined escalation paths, and a standing reporting runbook are what make the deadline achievable on a Sunday at 03:00.
Who Is Accountable, and What Are the Penalties?
NIS2 makes cybersecurity a board-level responsibility in law, not just in principle. The management body must approve the risk-management measures, oversee their implementation, and undergo training. Members of the management body can be held personally liable for breaches, and supervisory authorities can, in serious cases, temporarily suspend a person from exercising managerial functions in an essential entity. This is a deliberate change of incentive: it stops cybersecurity from being delegated downward and then ignored.
Key fact: The administrative fines are tiered by entity class. Essential entities face fines of up to €10 million or 2% of total worldwide annual turnover, whichever is higher. Important entities face fines of up to €7 million or 1.4% of total worldwide annual turnover, whichever is higher. These are EU-level floors. Member states may set higher ceilings in national law, so verify the figures in the Polish KSC text for your specific case.
Beyond fines, supervisory authorities can issue binding instructions, order entities to inform affected customers, mandate specific remediation within a deadline, and, for essential entities, conduct on-site inspections and security audits at the entity's expense.
Where Should You Start? A Prioritized Roadmap
Compliance programs fail when they try to do everything at once. Sequence the work so that legally binding deadlines and the highest-risk gaps come first.
- Determine scope and classify (weeks 1 to 4). Map every legal entity and its activities against the NIS2 sector annexes and the size thresholds, including the size-cap exceptions. Decide whether each entity is essential, important, or out of scope, and document the reasoning. This output drives your registration filing.
- Register on time. Submit your application for entry on the Polish register before the October 2026 deadline. Registration is a hard administrative obligation, independent of how mature your controls are.
- Run a gap assessment against Article 21. Measure your current state against the ten measure areas. Most regulated companies already have 40 to 60% in place through existing ISO 27001 or internal programs. The value is in finding the real gaps, not re-papering what already works.
- Stand up incident detection and reporting first. The 24/72-hour cascade is unforgiving and tests operational capability, not documentation. Prioritize logging, monitoring, an escalation runbook, and a tested reporting path. A Managed SOC closes this gap fastest.
- Close the technical control gaps. Address multi-factor authentication, access control, backup and recovery testing, vulnerability management, and encryption where they are weak.
- Address the supply chain. Inventory critical suppliers and service providers, add security clauses to contracts, and assess their posture. This area is consistently the least mature in mid-market estates.
- Embed governance. Get the management body to formally approve the measures, schedule their training, and set a recurring review cadence so compliance does not decay after the deadline.
What Are the Common Pitfalls?
- Assuming you are exempt. The default under NIS2 is broad inclusion. ‘We were not covered under NIS1’ is not a defensible position.
- Treating it as a documentation exercise. Policies do not file a 24-hour report. Operational detection and response capability does.
- Ignoring the supply chain. Your obligations extend to how you manage supplier risk, and this is where audits increasingly focus.
- Leaving the board out. Personal liability means the management body must be genuinely engaged, not merely informed after the fact.
- Starting in 2027. The registration window and the gap-remediation window run in parallel with day-to-day operations. Late starts compress remediation into a period that is too short to test properly.
If you operate in Poland or across the EU and need to know exactly where you stand under NIS2 and the amended KSC, we run scoping and gap assessments grounded in real operational delivery, backed by our 24/7 Managed SOC. To discuss a NIS2 readiness assessment, or how our security services map to your obligations, get in touch with our team.
