Get In Touch
katarzyna.szczudlik@gmail.com
Tel: ‪+48 663 696 999‬
Work Inquiries
Schoenherr Attorneys at Law Plac Małachowskiego 1 Warsaw, Poland
ka.szczudlik@schoenherr.eu
Back

Does NIS2 Apply to Your Business in Poland? How to Find Out Before 3 October 2026

5 key takeaways

  • NIS2 applies in Poland through the amended KSC Act in force since 3 April 2026 — no individual decision needed, status applies automatically by law
  • Two categories: key entities (Annex 1, >250 employees or >€50M turnover) and important entities (Annex 1 medium-sized, or Annex 2 medium-sized and above)
  • Some entities are in scope regardless of size — DNS providers, trust service providers, TLD registries, critical infrastructure operators
  • Registration in the Wykaz KSC is mandatory by 3 October 2026 for entities that already qualified on 3 April 2026
  • Missing the deadline does not remove the obligation — fines up to €10M (key entities) or €7M (important entities), plus personal liability for the head of the entity

If your business operates in a regulated sector in Poland, determining whether you qualify as a NIS2 Poland essential important entity is now an urgent legal obligation — with a registration deadline of 3 Oc-tober 2026. On 3 April 2026, the amended Polish Act on the National Cybersecurity System (ustawa o krajowym systemie cyberbezpieczeństwa, the “KSC Act”) entered into force. Specifically, it transposes Directive (EU) 2022/2555 (NIS2) into Polish law. As a result, businesses that qualify as NIS2 Poland essential or important entities must apply for entry in the national register — the Wykaz KSC — no later than 3 October 2026.

Many businesses are only just realising that they may fall within scope. This post walks through who qualifies as a NIS2 Poland essential or important entity, how to self-assess, how registration works in practice, and what happens if you miss the deadline.


1. Which Businesses Qualify as a NIS2 Poland Essential or Important Entity?

The amending Act — the Act of 23 January 2026 amending the KSC Act and certain other acts, published as Dz.U. 2026, item 252 — replaces the old category of “operators of key services” (identified through individual administrative decisions) with two new statutory categories that apply automatically once the statutory criteria are met: key entities (podmioty kluczowe) and important entities (podmioty ważne).

Coverage is organised around two annexes to the amended Act:

Annex 1 — Key sectors (sektory kluczowe), mirroring NIS2 Annex I “sectors of high criticality”:

  • Energy (electricity, district heating, oil, gas, hydrogen, nuclear)
  • Transport (air, rail, water, road)
  • Banking and financial market infrastructure
  • Health
  • Drinking water and wastewater
  • Digital infrastructure
  • ICT service management (B2B)
  • Public administration
  • Space

Annex 2 — Important sectors (sektory ważne), mirroring NIS2 Annex II “other critical sectors”:

  • Postal and courier services
  • Waste management
  • Chemicals manufacturing and distribution
  • Food production and distribution
  • Manufacturing (medical devices, electronics, machinery, motor vehicles)
  • Digital service providers (online marketplaces, search engines, social networks)
  • Research organisations

Importantly, any entity — regardless of legal form, and whether private or public — that carries on an activity listed in either annex is potentially within scope, subject to the size test below. However, certain categories of entities fall within scope regardless of size: DNS service providers, qualified trust service providers, TLD registries, domain name registration service providers, and critical infrastructure operators, among others.


2. NIS2 Poland Essential Important Entity Classification: The Size and Sector Test

Whether your business qualifies as a NIS2 Poland essential entity or important entity depends primarily on two factors: which annex your activity falls under, and your size — measured against the EU definitions of micro, small, medium and large enterprises in Article 2(1) of Commission Regulation (EU) No 651/2014.

As a general rule:

Key entity (podmiot kluczowy): an entity listed in Annex 1 that exceeds the medium-sized enterprise thresholds — broadly, more than 250 employees or more than EUR 50 million in annual turnover (or more than EUR 43 million in balance sheet total).

Important entity (podmiot ważny): either (i) an entity listed in Annex 1 that meets but does not exceed the medium-sized thresholds, or (ii) an entity listed in Annex 2 that meets or exceeds those thresholds.

Some practical points worth flagging:

  • Size-independent categories: DNS providers, qualified trust service providers, critical infrastructure operators and public entities expressly listed in Annex 1 are always key entities. Some public entities and nuclear energy investors are always important entities.
  • Healthcare providers: non-commercial healthcare entities are treated separately — important entities if they employ 50 to 249 people, key entities if they employ 250 or more.
  • Group structures: a group entity that would otherwise exceed the medium-sized thresholds solely because of affiliated undertakings is not treated as a key or important entity if its information system operates independently and is not used jointly with those affiliates’ systems.
  • Regulatory designation: the competent cybersecurity authority may designate an entity as key or important by decision even where it does not meet the size thresholds — for example where it is the sole provider of a service critical to social or economic activity.

If your entity meets the criteria for both categories, it is treated as a key entity.


3. How Self-Verification Works Under the NIS2 Poland Framework

This is where the amended Act makes a fundamental departure from the old regime. Previously, an entity became an “operator of a key service” only once the competent authority issued an individual recognition decision. Consequently, many businesses simply waited to be told.

Under the new framework, key entity and important entity status is a matter of statutory fact — verified by the entity itself. In other words, there is no need to wait for an administrative decision. If your business carries on an activity within Annex 1 or 2 and meets the relevant size threshold, you are a key or important entity by operation of law from that moment.

In practice, self-verification means working through two questions:

  1. Does our activity fall within a sector or sub-sector listed in Annex 1 or Annex 2 — and under which “type of entity” heading?
  2. Does our headcount and turnover or balance sheet meet the relevant threshold?

Where your business carries on several qualifying activities, each activity must be assessed and disclosed separately in the registration application.

One important procedural point: the application must include a statutory declaration by the head of the entity. This declaration confirms — under criminal liability for a false declaration under Article 233 § 6 of the Criminal Code — that the information provided is accurate. Subsequently, the competent authority can verify entries and require corrections. Furthermore, it may register an entity by decision if that entity should have self-registered but failed to do so.


4. How to Register in the Wykaz KSC

The amended Act creates a single national register of key and important entities — the Wykaz KSC — replacing the previous, narrower register of key service operators. The register is administered jointly: the Minister of Digital Affairs maintains the IT system, while the competent sectoral cybersecurity authority for each sector acts as the data controller for entries in that sector.

The practical steps are as follows:

Step 1 — Determine your status. Complete the self-verification described in Section 3 for each qualifying activity.

Step 2 — File the application by 3 October 2026. Entities that met the criteria when the amended Act entered into force must file by the date set in the ministerial timetable (harmonogram) — currently 3 October 2026. Entities that first meet the criteria after that date have six months from the date they first qualify.

Step 3 — Prepare the required information. The application must include, among other things:

  • Entity name, sector, sub-sector and type of entity per Annex 1 or 2
  • Registered and correspondence addresses
  • Electronic delivery address and email
  • NIP and REGON numbers
  • Public IP address ranges and internet domains used on a continuous basis
  • Contact details for at least two designated contact persons
  • A declaration of enterprise size
  • EU member states in which the entity operates

Step 4 — Submit electronically. The head of the entity — or an authorised representative — must sign the application using a qualified electronic signature, a trusted signature (*profil zaufany*), a personal signature, or a qualified electronic seal. Finally, submit the signed application via the dedicated IT system under Article 46(1) of the Act.

Step 5 — Keep the entry up to date. Once registered, the entity must file an update application within 14 days of any change to the registered data and must notify the register if it ceases to meet the qualifying criteria.

Entry, amendment and deregistration all take effect from the moment the application is filed — these are declaratory acts, not decisions granting status.


5. What Happens if a NIS2 Poland Essential Important Entity Misses the Deadline?

The short answer: the consequences are significant — and they fall on both the entity and its management personally.

For key entities:

  • Maximum administrative fine: the higher of EUR 10,000,000 (in zloty equivalent) or 2% of annual turnover
  • Statutory minimum: PLN 20,000

For important entities:

  • Maximum fine: the higher of EUR 7,000,000 or 1.4% of annual turnover
  • Statutory minimum: PLN 15,000

Enhanced penalty for serious breaches: where a breach creates a direct and serious cyber threat to state defence, security, public order, or life and health, or a risk of serious financial loss or service disruption, the competent authority may impose a fine of up to PLN 100,000,000.

Personal liability of the head of the entity: the entity-level fine is not the only exposure. Additionally, the head of a key or important entity faces personal fines of up to 300% of their statutory annual leave allowance remuneration (up to 100% for heads of public-sector entities). This personal liability covers fai-lures including missed registration, failure to implement an informa-tion security management system, missed incident reporting, and non-cooperation with audits.

One important nuance: the amended Act provides that these financial penalties may not be imposed for the first time until two years after the Act’s entry into force — meaning early enforcement is limited until April 2028. Nevertheless, this transitional relief affects only the timing of enforcement, not whether the underlying obligations apply. Registration and compliance obligations apply now.


The Bottom Line: What to Do This Week

If your business operates in any of the sectors listed above and you have not yet worked through the self-verification test, the time to do so is now — not in September.

The 3 October 2026 deadline is not just a registration formality. It is the starting point for a 12-month implementation window within which key and important entities must put their information security management systems (systemy zarządzania bezpieczeństwem informacji, SZBI) in place. In other words, the clock for substantive NIS2 compliance is already running.

Three immediate steps:

  1. Self-assess your status — work through the sector and size test for each activity your business carries on
  2. Appoint your contact persons — the registration requires at least two designated contacts
  3. Begin your gap analysis — registration and SZBI implementation run in parallel, and 12 months goes faster than it looks

If you have questions about whether NIS2 applies to your business or how to approach registration, get in touch.


This post reflects the Polish Act on the National Cybersecurity System as amended by the Act of 23 January 2026 (Dz.U. 2026, item 252), which transposes Directive (EU) 2022/2555 (NIS2). It is provided for general informational purposes and does not constitute legal advice.

Katarzyna Szczudlik is a Partner at Schoenherr in Warsaw, advising technology companies, financial institutions and international businesses on NIS2, DORA, cybersecurity law and EU regulatory compliance. She is ranked by Chambers & Partners and Legal 500 EMEA. If NIS2 compliance is on your agenda, let’s talk.

Katarzyna Szczudlik
Katarzyna Szczudlik
http://www.techlawyer.pl
I help international companies enter and scale in Poland - with a strong focus on fintech, financial regulation and technology-driven businesses. I am one of Poland's leading lawyers specialising in fintech regulation, MiCA and AI law.

Leave a Reply

This website stores cookies on your computer. Cookie Policy