5 key takeaways
- Most genuine micro and small enterprises are excluded from NIS2 scope — but medium-sized enterprises (50+ employees or >€10M turnover) in listed sectors are in scope
- Some small entities are caught regardless of size — managed cybersecurity service providers, DNS providers, micro digital infrastructure providers
- Most SMEs qualify as important entities (not key entities) — meaning reactive supervision, no mandatory periodic audit, but identical substantive cybersecurity obligations
- Personal liability of the founder/CEO applies in full regardless of company size — an SME head faces the same personal fines as a large corporate board
- For SMEs, the most practical starting point is: gap assessment → prioritise incident handling, MFA and backup testing → consider a managed cybersecurity service provider → build lightweight living documentation
As one of Poland’s leading lawyers advising on NIS2 implementation, I have spent the past months working with organisations of all sizes on what the amended KSC Act actually requires – and where smaller businesses are most at risk of getting it wrong.
Most NIS2 coverage focuses on large operators – energy companies, banks, hospitals. However, NIS2 compliance for SMEs in Poland is equally pressing. A significant share of the businesses now caught by the regime are small and medium-sized enterprises: IT service providers, manufacturers, food producers and digital service companies that meet the size and sector thresholds set out in the KSC Act. For these businesses, NIS2 compliance often lands on a much smaller legal and IT team, with a much smaller budget – yet the substantive obligations are largely the same.
This post is the third in my NIS2 Poland series. If you are still working out whether NIS2 applies to your business, start with Does NIS2 Apply to Your Business in Poland? How to Find Out Before 3 October 2026. If you have already registered and need to understand what to build, see NIS2 Poland Cybersecurity Measures: 10 Things Your Organisation Must Build by April 2027. This post focuses specifically on what NIS2 compliance means for smaller businesses — and how to approach it proportionately.
NIS2 Compliance SMEs Poland: Who Is Actually Caught?
The amended Act on the National Cybersecurity System (KSC Act), which transposes Directive (EU) 2022/2555 (NIS2) into Polish law, applies to two categories of entities: key entities (podmioty kluczowe) and important entities (podmioty ważne). Coverage depends on sector and size.
As a general rule, genuine micro and small enterprises fall outside scope. However, medium-sized enterprises – broadly, 50 or more employees, or more than EUR 10 million in annual turnover – are in scope if they operate in a sector listed in Annex 1 or Annex 2 of the KSC Act. Additionally, some smaller entities are caught regardless of size. These include:
- Providers of public electronic communications networks or services
- Trust service providers and DNS service providers
- TLD registries
- Entities identified as the sole provider of a service critical to society
- Small managed cybersecurity service providers and micro digital infrastructure providers
Consequently, the SME population caught by NIS2 compliance in Poland falls into two groups. First, medium-sized enterprises meeting the size thresholds in a listed sector. Second, smaller entities covered regardless of size because of their specific activity.
Key entity or important entity — why it matters for SMEs
Most SMEs will qualify as important entities rather than key entities. In practice, this distinction matters in two ways. First, important entities face reactive supervision – inspections typically follow incidents, rather than occurring proactively. Second, and importantly, important entities are not subject to the mandatory periodic external audit that applies to key entities. Nevertheless, the competent authority can order an external audit following a serious incident. Furthermore, all substantive cybersecurity obligations apply equally to both categories.
For a detailed breakdown of the classification criteria and size thresholds, see my earlier post: Does NIS2 Apply to Your Business in Poland?
What NIS2 Compliance SMEs Poland Actually Requires
NIS2 rests on four pillars. Specifically, these apply in full to SMEs – there is no lighter substantive standard for smaller important entities under the Polish KSC Act.
Governance and personal liability
Management bodies must approve the cybersecurity risk-management measures the entity takes and oversee their implementation. Moreover, members of management bodies must complete cybersecurity training annually. Critically, the head of the entity is personally liable for compliance failures – regardless of company size. For an SME founder or managing director wearing multiple hats, this personal exposure is concentrated rather than diluted across a large board.
Ten risk-management measures
Entities must implement appropriate and proportionate measures across ten domains. However, proportionality is calibrated to size and risk exposure – a smaller business does not need to replicate a large enterprise’s compliance programme. The ten domains are: risk analysis and security policies, incident handling, business continuity and disaster recovery, supply chain security, secure system development, effectiveness testing, cyber hygiene and training, cryptography, access control and asset management, and secure communications.
For a full breakdown of each measure and what implementation looks like in practice, see NIS2 Poland Cybersecurity Measures: 10 Things Your Organisation Must Build by April 2027.
Incident reporting
Entities must notify significant incidents to their national CSIRT. In practice, this means an early warning within 24 hours of becoming aware of the incident, a formal notification within 72 hours, and a final report within one month. As a result, having an incident response plan in place before an incident occurs is not optional – it is a statutory requirement.
Supervision and enforcement
Competent authorities can inspect, audit and issue binding instructions. Additionally, they can impose administrative fines – up to EUR 7 million or 1.4% of global annual turnover for important entities. Furthermore, the head of the entity can be personally fined up to 300% of their statutory annual leave allowance remuneration for compliance failures.
Size-specific concessions worth knowing
Two provisions are explicitly calibrated to size. First, a micro or small enterprise only needs to designate one contact person for the national cybersecurity system, rather than the two required of larger entities. Second, important entities – where most SMEs will fall – are not subject to the mandatory periodic external audit unless ordered by the competent authority following an incident.
How SMEs Can Approach NIS2 Compliance in Poland Proportionately
Step 1: Start with a scoped self-assessment
Before building anything, confirm exactly which annex and sector heading applies, which size test governs your classification, and which specific obligations follow. Getting this right early avoids over-building compliance infrastructure you do not need – and under-building what you do.
Step 2: Prioritise the highest-impact measures first
For most SMEs, four measures deliver the largest risk reduction for the lowest cost and complexity:
- Incident handling – a documented response plan with clear escalation paths
- Access control – multi-factor authentication on privileged and remote-access accounts
- Backup and recovery testing – backups that are actually tested for restorability
- Basic staff cyber hygiene training – mandatory for all personnel
Subsequently, supply chain security and formal effectiveness-testing policies can follow once foundational controls are in place.
Step 3: Consider a managed cybersecurity service provider
The KSC Act expressly allows key and important entities to satisfy their operational cybersecurity obligations through a managed cybersecurity service provider rather than building in-house capability. For an SME, this route enables outsourcing of incident monitoring, response support and documentation work to a specialist. Importantly, if this route is used, the contract and information about the provider must be recorded as part of the entity’s registration data in the Wykaz KSC.
Step 4: Build lightweight, living documentation
The statutory documentation requirement – security policy, risk assessment and treatment plan, business continuity plan, and operational records evidencing the system is being followed – does not need to be lengthy. It needs to be accurate, current and genuinely followed. For a smaller organisation, a handful of short, well-maintained documents that reflect what actually happens operationally will withstand scrutiny far better than an extensive policy set that nobody follows.
Step 5: Treat management training as governance, not paperwork
Because personal liability attaches to the head of the entity regardless of company size, the annual training requirement and management’s approval of risk-management measures should generate a documented paper trail showing the decision was actually made and understood – not a box-ticking exercise.
Step 6: Phase the budget against the statutory deadlines
An SME can sequence spend across the 12-month implementation window: immediate low-cost actions first (MFA, patching cadence, incident response plan), followed by documentation and training, with larger investments planned against the April 2027 deadline rather than incurred all at once.
Why NIS2 Compliance Can Be More Than a Cost Centre
For an SME facing new legal costs and operational overhead, it is worth setting out clearly where compliance also creates value.
Reduced incident risk. The ten risk-management measures are, in substance, cybersecurity good practice. Implementing them properly reduces the likelihood and severity of ransomware, phishing and supply-chain attacks – which disproportionately affect smaller businesses with weaker baseline defences than larger competitors.
Commercial credibility with larger customers. Many essential and important entities must, under Article 21(2)(d) of the Directive, assess the cybersecurity practices of their direct suppliers. Consequently, an SME that can demonstrate a documented, audit-ready security posture is better positioned to win and retain contracts with larger customers who are under the same obligation to vet their vendors.
A structured compliance framework rather than an ad hoc one. Before NIS2, many SMEs approached cybersecurity reactively. The statutory obligation to implement an information security management system gives smaller businesses a clear, legally defined structure to build around – rather than designing a security programme from a blank page.
Improved access to insurance and financing. Insurers offering cyber liability cover, and lenders assessing operational risk, increasingly ask for evidence of basic security controls, incident response capability and governance oversight. Demonstrable NIS2 compliance SMEs Poland can support more favourable terms in both markets.
A single framework across the EU market. Because NIS2 is transposed in broadly similar terms across all Member States, an SME that builds its compliance programme around the Directive’s ten measures is better placed to expand into other EU markets without redesigning its security programme from scratch.
The Right Mindset Going Forward
For most SMEs now working through their Wykaz KSC registration and their 12-month implementation window, the most useful mindset is to treat NIS2 not as a one-off compliance project to be closed out, but as the minimum operating standard the business will be held to on an ongoing basis. Implemented proportionately, NIS2 compliance SMEs Poland can reduce real operational risk and strengthen the business’s standing with customers, insurers and partners at the same time.
If you have questions about NIS2 applicability or implementation for your business in Poland, get in touch. You can also find more information about my work in this area on the Cybersecurity, NIS2 & DORA practice area page.
NIS2 Poland Series – Full Reading List
This post is part of an ongoing series on NIS2 implementation in Poland. The full series:
- Does NIS2 Apply to Your Business in Poland? How to Find Out Before 3 October 2026 — who qualifies, how to self-assess, and what happens if you miss the registration deadline
- NIS2 Poland Cybersecurity Measures: 10 Things Your Organisation Must Build by April 2027 — a practical breakdown of all ten Article 8 measures, SZBI implementation and board liability
- NIS2 Compliance SMEs Poland (this post) — what the framework means for smaller businesses and how to implement it proportionately
This post reflects Directive (EU) 2022/2555 (NIS2) and the Polish Act on the National Cybersecurity System as amended by the Act of 23 January 2026 (Dz.U. 2026, item 252). It is provided for general informational purposes and does not constitute legal advice.
Katarzyna Szczudlik is a Partner at Schoenherr in Warsaw and one of Poland’s leading lawyers advising on NIS2 implementation, DORA, cybersecurity law and EU regulatory compliance. She advises technology companies, financial institutions and international businesses on cybersecurity obligations under the amended KSC Act. She is ranked by Chambers & Partners (FinTech) and Legal 500 EMEA (Data Protection & TMT). If NIS2 compliance is on your agenda, let’s talk.