Get In Touch
katarzyna.szczudlik@gmail.com
Tel: ‪+48 663 696 999‬
Work Inquiries
Schoenherr Attorneys at Law Plac Małachowskiego 1 Warsaw, Poland
ka.szczudlik@schoenherr.eu
Back

Key Entity vs Important Entity Under NIS2 in Poland — What Is the Difference?

5 key takeaways

  • NIS2 in Poland creates two categories: key entities (podmioty kluczowe) and important entities (podmioty ważne) — both are subject to the same 10 cybersecurity measures, but differ in supervision intensity and fine levels
  • Key entities face proactive, ex-ante supervision — regular inspections regardless of whether an incident has occurred
  • Important entities face reactive, ex-post supervision — inspections typically follow incidents or complaints
  • Maximum fines: €10M or 2% of turnover for key entities vs €7M or 1.4% of turnover for important entities
  • If an entity meets the criteria for both categories, it is treated as a key entity

As one of Poland’s leading lawyers advising on NIS2 implementation, I regularly get one question more than any other: what is the difference between a key entity and an important entity under NIS2 in Poland — and does it actually matter?

The short answer: yes, it matters — but less than most people expect. Both categories carry identical substantive cybersecurity obligations. The differences lie in how you are supervised, how quickly an authority can act against you, and how large the fines can be.

This is part of my NIS2 Poland series. For the full classification criteria and registration process, see Does NIS2 Apply to Your Business in Poland?


Key Entity vs Important Entity NIS2 Poland: The Core Difference

The single most important thing to understand: both key entities and important entities must implement all 10 cybersecurity measures under Article 8 of the amended KSC Act. Consequently, the classification does not reduce your substantive compliance obligations. What it changes is how the regulator watches you — and what happens if something goes wrong.


Classification Criteria: How to Know Which Category You Are

Key entity (podmiot kluczowy)

An entity is a key entity if it meets either of the following:

  • It operates in a sector listed in Annex 1 of the KSC Act (energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, ICT service management B2B, public administration, space) and exceeds the medium-sized enterprise thresholds — broadly, more than 250 employees or more than €50 million in annual turnover (or more than €43 million balance sheet total)
  • It falls into a size-independent category regardless of headcount or turnover — including DNS service providers, qualified trust service providers, TLD registries, domain name registration service providers, and critical infrastructure operators
  • It is a public entity expressly named in Annex 1

Important entity (podmiot ważny)

An entity is an important entity if it meets either of the following:

  • It operates in an Annex 1 sector and meets (but does not exceed) the medium-sized thresholds — broadly, 50–249 employees or €10–50 million in turnover
  • It operates in a sector listed in Annex 2 of the KSC Act (postal services, waste management, chemicals, food, manufacturing, digital providers, research organisations) and meets or exceeds the medium-sized thresholds

The comparison table

CriterionKey entityImportant entity
Annex 1 sector>250 employees or >€50M turnover50–249 employees or €10–50M turnover
Annex 2 sectorNot applicable≥50 employees or >€10M turnover
Size-independentDNS, QTSP, TLD, critical infrastructureSome public entities, nuclear investors
If criteria overlapAlways treated as key entity

Key Entity vs Important Entity NIS2 Poland: The Supervision Difference

This is where the classification has real practical consequences.

Key entities — proactive (ex-ante) supervision

The competent cybersecurity authority supervises key entities proactively — meaning it can conduct inspections, request documentation and issue binding instructions at any time, without waiting for an incident to occur. Furthermore, key entities are subject to mandatory periodic external security audits at least every 3 years, at their own cost.

In practice: if you are a key entity, assume the regulator can arrive for an inspection at any time. Your SZBI documentation, incident response records, and Register of Information must be audit-ready on an ongoing basis.

Important entities — reactive (ex-post) supervision

The competent cybersecurity authority supervises important entities reactively — meaning inspections and audits are typically triggered by an incident, a complaint, or a specific supervisory concern. Additionally, important entities are not subject to the mandatory periodic external audit — unless the competent authority orders one following a serious incident.

In practice: if you are an important entity, the regulator is less likely to knock on your door proactively. However, this does not mean your compliance obligations are lighter — it means the enforcement trigger is different.


Key Entity vs Important Entity NIS2 Poland: The Fines Difference

Key entity fines

  • Maximum administrative fine: the higher of €10,000,000 (in PLN equivalent) or 2% of global annual turnover
  • Statutory minimum: PLN 20,000
  • Enhanced penalty for serious breaches (direct threat to state security, life, health, or serious financial loss): up to PLN 100,000,000

Important entity fines

  • Maximum administrative fine: the higher of €7,000,000 (in PLN equivalent) or 1.4% of global annual turnover
  • Statutory minimum: PLN 15,000
  • Enhanced penalty: same PLN 100,000,000 cap applies

Personal liability — applies equally to both

Regardless of whether you are a key or important entity, the head of the entity can be personally fined up to 300% of their statutory annual leave allowance remuneration (100% for public sector heads) for compliance failures including missed registration, SZBI implementation failures, and non-cooperation with audits.

The fine comparison table

Fine typeKey entityImportant entity
Standard maximum€10M or 2% turnover€7M or 1.4% turnover
Statutory minimumPLN 20,000PLN 15,000
Enhanced (serious breach)PLN 100,000,000PLN 100,000,000
Personal (head of entity)300% annual leave remuneration300% annual leave remuneration

What Both Categories Share

Despite the supervision and fine differences, key entities and important entities share the following obligations in full:

  • All 10 Article 8 cybersecurity measures
  • Registration in the Wykaz KSC
  • SZBI implementation by April 2027
  • Incident reporting (24h early warning, 72h notification, 1-month final report)
  • Designation of contact persons
  • Personal liability of the head of the entity
  • 12-month implementation window from the date qualifying criteria are met

Bottom Line: Does the Classification Matter?

Yes — but not because one category has lighter compliance obligations. The classification matters because it determines how intensively you are supervised, how quickly the regulator can act, and what the maximum fine exposure is.

For most organisations, the more important question is not “are we key or important?” but “are we compliant?” — because the underlying obligations are identical.

If you have questions about NIS2 classification or compliance, get in touch.

Related posts:

Katarzyna Szczudlik is a Partner at Schoenherr in Warsaw and one of Poland’s leading lawyers advising on NIS2 implementation. Ranked by Chambers & Partners (FinTech) and Legal 500 EMEA (Data Protection & TMT). Get in touch.

Katarzyna Szczudlik
Katarzyna Szczudlik
http://www.techlawyer.pl
I help international companies enter and scale in Poland - with a strong focus on fintech, financial regulation and technology-driven businesses. I am one of Poland's leading lawyers specialising in fintech regulation, MiCA and AI law.

Leave a Reply

This website stores cookies on your computer. Cookie Policy