Does NIS2 apply to every medium-sized or large business in Poland?
No. Size is only one part of the test. The business must also match a type of entity listed in Annex 1 or Annex 2 to the KSC Act, or fall within a special category identified directly in Article 5.
Essential sectors include energy, transport, banking and financial-market infrastructure, healthcare, drinking water, wastewater, digital infrastructure, electronic communications and ICT service management. Important sectors include postal services, waste management, the manufacture or distribution of chemicals and food, selected manufacturing activities, digital providers and research organisations.
In a typical case, the business must reach at least the relevant medium-enterprise threshold. The assessment should not, however, stop at the headcount of one Polish company. EU rules on partner and linked enterprises may require group data to be taken into account. The KSC Act also contains specific rules relating to independent information systems and services jointly supplied within a group.
Some entities are covered regardless of size or under different thresholds. Examples include DNS providers, qualified trust-service providers, top-level domain registries, domain-name registration service providers and certain electronic-communications or managed cybersecurity service providers. “We have fewer than 250 employees” is therefore not a complete analysis.
How should a business perform its scope assessment?
The first step is to map the services the entity actually provides, rather than relying only on Polish business-activity codes or a product’s marketing description. Those services should then be matched against the entity types in the KSC annexes and any sector-specific conditions.
The second step is the size analysis under the relevant EU rules, including ownership and control relationships. Only after combining the sector and size tests can the business determine whether it is an essential entity, an important entity or outside the statutory scope.
The conclusion should be recorded in a short assessment memorandum. If the business concludes that it is not covered, the record should identify the data, sector classification and legal reasoning used. This helps demonstrate that management carried out a real assessment instead of simply assuming that no duty existed.
Who must enter the KSC Register and by when?
The minister responsible for digital affairs enters certain entities automatically, including specified public bodies, telecommunications undertakings, trust-service providers and critical entities. Other essential and important entities must apply themselves.
Entities that met the criteria when the amendment entered into force are subject to a transitional timetable. The self-registration period runs from 7 May to 3 October 2026. The application is submitted electronically through the KSC Register platform and must bear the required electronic signature.
An entity that first meets the criteria later generally has six months from that date to apply. Changes to registered data must also be updated within the statutory period. Registration is therefore not a one-off filing disconnected from later changes in the business or group structure.
What information is needed for registration?
The filing goes beyond ordinary corporate particulars. It includes the sector and entity type, addresses, Polish tax and statistical numbers, continuously used public IP ranges and domains, contact persons, a size declaration, other EU Member States in which the entity operates and information about any managed cybersecurity service provider engaged for statutory tasks.
Legal, IT, security and finance teams should reconcile the information before filing. A mistaken sector classification, incomplete domain list or unsuitable contact person may make subsequent communication and S46 onboarding more difficult.
What must the business implement after registration?
An essential or important entity must implement an information security management system for the information systems used in processes affecting the covered service. The system must address risk assessment, supplier security, business continuity, monitoring, incident management, cyber hygiene, access control, cryptography, updates and staff awareness.
The business also needs normative and operational documentation, designated contact persons, an incident handling and reporting process, S46 access and either an internal cybersecurity structure or an agreement with a managed cybersecurity service provider. Outsourcing may support delivery but does not replace the entity’s oversight of scope, reporting or access to information.
Supplier contracts should deal with reaction times, incident and vulnerability information, audit rights, subcontracting, continuity and support with regulatory reporting. A general statement that a supplier is “NIS2 compliant” does not establish those mechanisms. The supplier-review logic is comparable to the approach described in the article on data processing agreements, although the KSC Act and GDPR impose separate duties.
What is management responsible for?
The head of the entity is responsible for compliance with the cybersecurity duties. If the management function is performed by a collective body and no responsible person has been identified, all members are accountable. The Act expressly provides that delegating tasks to another person does not remove that responsibility.
Management must make decisions on the information security system, allocate sufficient funding, assign and supervise tasks and ensure staff awareness. The head of the entity and any person entrusted with the head’s cybersecurity duties must complete documented training every calendar year.
This makes implementation a governance project, not merely the purchase of an IT tool. Management should receive regular reporting on risk, implementation progress, incidents, supplier dependencies and budget gaps.
How the issue appears in practice
Hypothetical example: a food distributor assumes that NIS2 only concerns critical infrastructure
Hypothetical example: a food distributor assumes that NIS2 only concerns critical infrastructure A Polish company employs more than 50 people, distributes food on a wholesale basis and relies on a warehouse-management system, an ordering platform and an outsourced IT operator. Management initially assumes that the KSC Act cannot apply because the company is not a bank, energy operator or public body. Food production, processing and distribution are, however, included among the important sectors. The company must therefore check the precise activity, employment and financial data, and group relationships. If the criteria are met, it should register on time, appoint contact persons and plan the information-security system. Its IT agreement should be amended to cover rapid incident reporting, access to information, S46 cooperation, subcontractors and continuity testing. Outsourcing the systems does not transfer the company’s statutory accountability to the provider.
Matters to determine or verify before proceeding
- Which services does the business actually provide and which KSC entity types may cover them?
- Does coverage depend on size, or is the relevant category covered irrespective of size?
- How do partner entities, linked enterprises and shared group systems affect the assessment?
- Will the business be registered automatically or must it file its own application?
- Which domains, public IP ranges and contact persons should be included?
- Which systems and processes affect delivery of the covered service and belong within the security-management scope?
- Do supplier contracts provide the information, reaction times, continuity and incident support required?
- Who within management owns the implementation, budget, training and progress reporting?
Key issues at a glance
| Issue | Key information |
|---|---|
| Amendment entered into force | 3 April 2026 |
| Self-registration for entities covered on that date | 7 May to 3 October 2026 |
| S46 onboarding and transitional implementation | Generally by 3 April 2027 |
| First audit for new essential entities | By 3 April 2028; periodic statutory audits apply to essential entities |
| New monetary penalties | Generally available from 3 April 2028 |
| Management accountability | Remains in place despite internal delegation or outsourcing |
Legal basis
- Act of 5 July 2018 on the National Cybersecurity System, in particular Articles 5–16 and Annexes 1–2
- Act of 23 January 2026 amending the Act on the National Cybersecurity System and certain other acts, in particular Articles 33–35
- Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 on measures for a high common level of cybersecurity across the Union
- Commission Regulation (EU) No 651/2014 of 17 June 2014, Annex I
This article provides general information and does not constitute legal advice for a specific matter. The appropriate solution depends on the facts, documents and business objective.
Summary
The most urgent task is not buying a security tool but performing the scope assessment correctly. Only the sector, size and entity analysis can determine the registration duty, the systems covered by the information-security framework and the implementation timetable. ---