The NIS-2 Directive is reshaping the cybersecurity landscape in Poland. Seven years of legislative work, three governments and dozens of draft versions — and in the end three weeks in January 2026 were enough for the Sejm and the Senate to pass the amendment to the National Cybersecurity System Act, Poland's NIS-2 implementing act (the KSC Act). On 2 March 2026 the act was published in the Journal of Laws. From 2 April 2026, some 38,000 organisations have twelve months to adapt to the new requirements — requirements that fundamentally change how Polish companies and institutions approach cybersecurity.
This guide was written to bring order to a subject that, amid the thicket of legal commentary, press articles and conference presentations, is often treated chaotically. No scaremongering about NIS-2 fines, no oversimplification — with the precision a matter of this weight demands.
What the NIS-2 Directive is and why it changes the rules of the game
The NIS-2 Directive (Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022) is EU law that replaced the first NIS Directive of 2016. The reason for the change was simple: the first directive did not work well enough. Member States implemented it in a fragmented way, its scope was too narrow, and its enforcement mechanisms were too lenient.
NIS-2 extends the scope from a handful of sectors to eighteen, introduces personal responsibility of the management body for cybersecurity, and establishes a uniform incident reporting framework on a 24 hours / 72 hours / 30 days schedule. This is not an evolution of the previous regulation — it is a change of paradigm.
For Polish organisations, the key point is that NIS-2 does not apply directly. It requires transposition into national law — and that is precisely the role of the amended National Cybersecurity System Act.
Timeline: from the directive to the Polish act
The legislative path of the amendment to the KSC Act was one of the longest in the history of Polish parliamentary work in the field of cybersecurity. These are the key dates:
14 December 2022 — the European Parliament and the Council of the EU adopt the NIS-2 Directive (2022/2555).
17 October 2024 — the original deadline for transposing NIS-2 into national law expires. Poland, like most Member States, did not make it.
23 January 2026 — the Sejm passes the amendment to the National Cybersecurity System Act.
28 January 2026 — the Senate adopts the act without amendments.
19 February 2026 — President Karol Nawrocki signs the act. At the same time, he refers it to the Constitutional Tribunal for ex post review.
2 March 2026 — the act is published in the Journal of Laws.
3 April 2026 — entry into force; the act was published in the Journal of Laws on 2 April 2026.
2 October 2026 — the six-month deadline for registration in the register of essential and important entities expires.
2 April 2027 — the twelve-month deadline for implementing risk management measures expires.
2 April 2028 — administrative fines may be imposed from this date onwards.
Who NIS-2 applies to in Poland — essential and important entities
One of the fundamental changes brought by NIS-2 is the radical extension of its scope. The first NIS Directive covered barely a few hundred organisations in Poland. The amendment to the KSC Act extends the obligations to an estimated 38,000 entities.
Key sectors (essential entities)
Sectors of high criticality, where disruption to services has a direct impact on public safety, health or the economy: energy (electricity, district heating, oil, gas, hydrogen), transport (air, rail, water, road), banking and financial market infrastructure, healthcare (hospitals, laboratories, medical device manufacturers, pharmacies), drinking water supply and waste water, digital infrastructure (DNS, TLD, data centres, cloud providers, CDN networks, trust service providers), ICT service management (B2B), public administration and space.
Important sectors (important entities)
Sectors where disruption to services has a significant, though not immediately critical, impact: postal and courier services, waste management, the manufacture of chemicals and food, manufacturing (medical devices, electronics, machinery, vehicles), digital service providers (search engines, online marketplaces, social networks) and research organisations.
The size criterion
As a rule, NIS-2 applies to medium-sized and large entities — those employing more than 50 people or with annual turnover above EUR 10 million. There are, however, exceptions: DNS service providers, domain name registrars, trust service providers and telecommunications network operators are subject to NIS-2 regardless of their size.
How to check whether your organisation is subject to NIS-2
Classification requires an analysis of three elements: the sector of activity (whether it falls within one of the eighteen sectors), the size of the undertaking (more than 50 employees or EUR 10 million turnover) and the nature of the services provided (whether they are critical within the meaning of the directive). In practice we recommend carrying out a formal classification analysis, because the boundaries between sectors are not always obvious — a logistics company serving hospitals may be subject to NIS-2 as part of the health sector supply chain, even though it does not itself provide medical services.
Five pillars of obligations — what exactly has to be implemented
The amended KSC Act imposes five groups of obligations on essential and important entities. These are not abstract requirements — each of them translates into specific organisational, technical and documentation work.
1. Risk management and security governance
The foundation of the whole NIS-2 construction. The organisation has to implement a cybersecurity risk management system covering: identification and assessment of risks relating to networks and information systems, implementation of proportionate technical and organisational measures, regular reviews and updates of the risk assessment, and documentation of the entire process in a way that allows supervisory authorities to verify it.
The key change: responsibility for approving risk management measures rests directly with the organisation's management — the management board, the supervisory board or persons performing equivalent functions. This cannot be delegated to the IT department.
2. Incident management and reporting
NIS-2 introduces a strict schedule for reporting significant security incidents:
Early warning — within 24 hours of becoming aware of a significant incident. Purpose: to inform the competent CSIRT (in Poland: CSIRT NASK, CSIRT GOV or CSIRT MON) that an incident has occurred, together with an initial assessment of its nature and any potential cross-border impact.
Incident notification — within 72 hours of becoming aware of the incident. Purpose: to provide a detailed assessment of the incident, its severity and impact, together with indicators of compromise (IoC) where available.
Final report — within 30 days (or up to 60 days in justified cases). Purpose: to present a full description of the incident, its root cause, the remedial action taken and any cross-border impact.
An incident is considered significant if it has caused or is capable of causing severe operational disruption of services or significant financial loss, or if it has affected or is capable of affecting other natural or legal persons by causing considerable damage.
3. Business continuity
Entities covered by NIS-2 must have business continuity and disaster recovery plans covering at least: backup and restore procedures, crisis management plans, emergency procedures ensuring the continuity of critical services, and regular testing of those plans.
In practice this means implementing — or adapting an existing — business continuity management system. Organisations certified to ISO 22301 have a significant advantage here.
4. Supply chain security
A novelty compared with the first NIS Directive. Essential and important entities must: assess the risks associated with their suppliers and partners, include security requirements in supplier contracts, monitor the security posture of their suppliers, and implement procedures for vetting critical suppliers.
This requirement has far-reaching consequences — it means that even a company not itself subject to NIS-2 may receive security requirements derived from the directive from its own client. The domino effect along the supply chain is intended by the legislator.
5. Training and security awareness
Members of the management of essential and important entities must undergo regular cybersecurity training — sufficient to enable them to identify risks and assess risk management practices. The obligation also extends to providing regular training for employees.
This is not a formality. NIS-2 ties management competence to personal liability — a board that does not understand cyber threats cannot effectively approve risk management measures, and a lack of competence is not a mitigating circumstance.
NIS-2 fines and liability — what it really costs
The sanctions regime in the amended KSC Act operates on several levels. NIS-2 fines apply both to the organisation and to the individuals holding management positions.
Administrative fines for organisations
Essential entities: up to EUR 10 million or 2% of total worldwide annual turnover — whichever is higher.
Important entities: up to EUR 7 million or 1.4% of total worldwide annual turnover — whichever is higher.
Personal liability of management
The amended KSC Act introduces mechanisms without precedent in Polish cybersecurity law: a financial penalty for the head of an essential or important entity of up to 600% of monthly remuneration for gross neglect of duties, and a temporary ban on holding management positions — for up to 2 years — for particularly serious breaches.
This is a fundamental shift in perspective. Cybersecurity ceases to be a technical problem delegated to the IT department and becomes a management responsibility, comparable to responsibility for financial reporting.
The grace period
The legislator has provided for a two-year period during which fines will not be imposed, counted from the date the act enters into force. Fines may therefore be imposed no earlier than 2 April 2028. That does not mean nothing needs to be done until then — the deadline for implementing risk management measures falls as early as 2 April 2027.
NIS-2 and GDPR — two pillars, one goal
Organisations subject to NIS-2 are almost always subject to GDPR (the General Data Protection Regulation) as well. The two acts work in a complementary way: GDPR protects personal data, NIS-2 protects networks and information systems. In practice this means that a cybersecurity incident is often also a personal data breach — and the organisation then has an obligation to report to two different authorities: the CSIRT (under NIS-2, on the 24h/72h/30-day schedule) and Poland's data protection authority (UODO) (under GDPR, within 72 hours of becoming aware of the breach).
It is therefore worth coordinating NIS-2 implementation with a review of personal data protection procedures. Organisations with an effective data protection officer (DPO) function have an advantage — existing GDPR breach response procedures provide a solid foundation for the NIS-2 reporting schedule. The differences lie in scope (GDPR covers personal data, NIS-2 covers all cybersecurity incidents) and in who the reports go to, but the logic of the process is the same.
Sector-specific requirements — what deserves particular attention
NIS-2 covers eighteen sectors, but it does not treat them identically. Each sector has its own specifics, and the supervisory authorities will assess compliance in the light of the industry context.
Energy
The sector with the highest level of criticality. Distribution network operators, energy producers and entities managing fuel infrastructure have to take account of securing OT (Operational Technology) systems — and these follow different rules from classic IT. Industrial protocols (Modbus, DNP3, IEC 61850) require dedicated security measures. The sector regulator — the minister responsible for energy — is likely to be one of the most active supervisory authorities, given the geopolitical significance of energy security.
Healthcare
Hospitals, laboratories and medical device manufacturers face a double challenge: medical systems (such as PACS, HIS and RIS) have to be protected, yet cannot be taken offline for updates without putting continuity of patient care at risk. NIS-2 demands particularly careful business continuity planning from the health sector — maintenance windows in a hospital look nothing like those in an IT company.
Public administration and local authorities
Local government units — communes, counties and voivodeships — are already subject to obligations under the KRI regulation (the National Interoperability Framework). NIS-2 extends those obligations to incident management on the 24h/72h/30-day schedule and to management liability. In practice, the head of a commune, a town mayor or a city mayor becomes personally responsible for the cybersecurity of the authority — with the possibility of a fine of up to 600% of remuneration. For local authorities that have so far treated KRI as their only point of reference, NIS-2 represents a substantial extension of their obligations.
The digital sector
Cloud service providers, data centres, CDN networks and DNS service providers are subject to NIS-2 regardless of size — the 50-employee criterion does not apply to them. For smaller technology companies that have not until now been subject to any cybersecurity regulation, this is a fundamental change.
We show what these requirements look like in practice using examples from district heating and the water and waste water sector.
NIS-2 and ISO 27001 — what they share and where they differ
This is one of the most frequently asked questions: does holding an ISO 27001 certificate mean compliance with NIS-2? The answer is nuanced.
What ISO 27001 covers
ISO 27001:2022 provides a framework for an information security management system (ISMS) that overlaps to a large extent with NIS-2 requirements in the areas of: risk management (Annex A, controls 5.1-5.38), incident management (A.5.24-5.28), business continuity (A.5.29-5.30), supply chain security (A.5.19-5.23) and training and awareness (A.6.3).
What ISO 27001 does not cover
ISO 27001 does not satisfy the NIS-2 requirements concerning: formal classification as an essential or important entity, registration in the register of entities (deadline: six months from the entry into force of the act), incident reporting to the competent CSIRT on the 24h/72h/30-day schedule, submission to supervision and inspections by the competent authority, and sector-specific requirements.
Recommendation
An organisation with an implemented and maintained ISMS conforming to ISO 27001:2022 has around 70-80% of the NIS-2 risk management requirements covered. The remaining 20-30% consists of legal and regulatory requirements that call for additional work — but the starting point is incomparably better than for an organisation starting from scratch.
How to prepare — a practical implementation plan
Twelve months for implementation looks like a lot. In practice — for an organisation without a formal ISMS — it is an ambitious deadline. The plan below assumes a systematic approach in three phases.
Phase 1: Diagnosis (months 1-3)
The first step is to establish whether, and to what extent, the organisation is subject to NIS-2. That requires: a classification analysis — which sector the organisation belongs to and whether it meets the size criterion; an inventory of the networks and information systems supporting the services covered by the directive; a gap analysis — comparing the current state of security controls with NIS-2 requirements; and preparation of an implementation schedule with milestones.
Phase 2: Implementation (months 3-10)
On the basis of the gap analysis results — building or extending the information security management system (ISMS). The scope of work covers several parallel tracks:
Documentation and processes: implementing or updating the information security policy, risk management procedures, incident management procedures (taking account of the 24h/72h/30-day schedule), business continuity plans and change management procedures. This is not a paper exercise — the documentation has to reflect actual processes rather than being a collection of aspirations.
Supply chain: reviewing contracts with critical suppliers against security requirements, introducing clauses on incident reporting and audit rights, and assessing supplier risk in the light of their position in the chain. In our experience this is one of the most time-consuming tasks — renegotiating contracts with several dozen suppliers can take weeks.
Technical measures: implementing or extending monitoring (SIEM), incident detection, vulnerability management and incident response systems. The scope depends on the starting point — an organisation with a mature SOC needs only adjustments, whereas a company with no central monitoring faces a serious investment.
Training: a training programme for management (mandatory under NIS-2) and security awareness training for all employees. Management has to understand cyber risks well enough to approve risk management measures knowingly — and compliance with that requirement will be verified.
Phase 3: Validation and registration (months 10-12)
Finalising the implementation and formally discharging the obligations: an internal audit of NIS-2 readiness, registration in the register of essential or important entities (deadline: 2 October 2026), testing of incident response procedures, a management review with the participation of senior management, and preparation of documentation for a possible inspection by the supervisory authority.
DORA and NIS-2 — what financial institutions need to know
Financial institutions covered by the DORA Regulation (the Digital Operational Resilience Act — Regulation (EU) 2022/2554) may be wondering how DORA relates to NIS-2. The key principle: DORA is sector-specific legislation (lex specialis) which, in the area of cybersecurity, takes precedence over NIS-2 for financial entities. In practice this means that a bank, insurer or investment firm that meets DORA requirements simultaneously meets NIS-2 requirements to the extent that the two overlap. This does not, however, remove the obligation to register in the register of essential entities where the organisation meets the NIS-2 criteria.
We cover the financial regime separately in our guide to DORA — digital operational resilience.
Frequently asked questions about NIS-2
Does NIS-2 apply to local authorities and public sector bodies?
Yes. Public administration is one of the key sectors under NIS-2. Local government units that provide digital services or manage critical infrastructure may be subject to the new obligations. It is worth remembering that local authorities also have obligations under the KRI regulation (the National Interoperability Framework) — the two systems have to be treated as complementary, not alternative.
How much does NIS-2 implementation cost?
The cost depends on the organisation's starting point. A company with an ISO 27001 certificate mainly needs regulatory adjustments — a cost in the order of tens of thousands of PLN. An organisation with no formal ISMS has to reckon with costs from several hundred thousand to several million PLN, depending on the scale and complexity of its infrastructure.
Do I need an ISO 27001 certificate to comply with NIS-2?
No. An ISO 27001 certificate is not required by NIS-2. The ISO 27001 standard does, however, provide the best practically proven framework for meeting NIS-2 risk management requirements. For organisations that do not yet have an ISMS, we recommend implementing a system conforming to ISO 27001 as the foundation for NIS-2 — this solves two problems at once.
What happens if I do not implement NIS-2 on time?
Administrative fines may be imposed from 2 April 2028. Before then, the supervisory authority may issue recommendations and orders. Failure to implement does not mean an immediate fine, but it does mean risk — both regulatory (orders, inspections) and operational (a lack of readiness for an incident that may happen at any moment).
Who is the NIS-2 supervisory authority in Poland?
It depends on the sector: the minister responsible for digitalisation (for most sectors), the minister responsible for energy (for the energy sector), the Polish Financial Supervision Authority (KNF) (for the financial sector, in areas not covered by DORA), and other sector authorities designated in the act.
Can small companies (fewer than 50 employees) be subject to NIS-2?
As a rule, no — NIS-2 applies a size criterion (more than 50 employees or EUR 10 million turnover). The exceptions cover DNS service providers, domain name registrars, trust service providers and telecommunications network operators, which are subject to NIS-2 regardless of size. In addition, small companies may feel the indirect effect of NIS-2 through supply chain security requirements imposed by their clients.
How does NIS-2 differ from GDPR when it comes to incident reporting?
Both acts require incidents to be reported, but they differ in scope and in the recipient. GDPR requires a personal data breach to be reported to UODO within 72 hours — but only where the incident concerns personal data. NIS-2 requires every significant cybersecurity incident to be reported to the competent CSIRT on the 24h/72h/30-day schedule — regardless of whether personal data is involved. In practice, a cyberattack on the infrastructure of an energy company that does not compromise personal data falls under NIS-2 but not GDPR. A ransomware attack that encrypts a customer database falls under both regimes at once.
Does NIS-2 require penetration testing?
NIS-2 does not expressly require penetration testing, but it does require "regular testing and assessment of the effectiveness of risk management measures". In practice, penetration testing and vulnerability analysis are among the most effective ways of meeting that requirement. Regular pentests make it possible to verify whether the controls in place actually work — and that is exactly what the directive expects.
Does an organisation have to appoint a person responsible for NIS-2?
The act does not require a specific "NIS-2 officer" post to be created, but organisational practice clearly shows that someone has to coordinate implementation and ongoing compliance. In many organisations that role is held by the information security officer or the CISO (Chief Information Security Officer). Organisations without such a position in-house can outsource the function.
How Fib.Code can help with NIS-2
For more than six years the Fib.Code team has been supporting organisations in implementing information security management systems — from local authorities and municipal companies through to companies in the energy, financial and IT sectors. We have delivered more than 500 projects, including ISO 27001 and ISO 22301 implementations, KRI audits and the outsourcing of the DPO and information security officer functions.
As part of our legal advisory services for NIS-2 implementation we offer: classification analysis — whether and to what extent the organisation is subject to NIS-2; gap analysis — assessing the gap between the current state and the requirements; implementation or extension of an ISMS conforming to ISO 27001 and to NIS-2 requirements; building an incident management process that reflects the 24h/72h/30-day schedule; supply chain security audits; training for management and employees; and ongoing support as an external information security officer.
We begin every project with a conversation — not with a quote. We would be glad to discuss what NIS-2 means specifically for your organisation.
Book a free consultation: l.grabowski@fibcode.com | fibcode.com
This article reflects the legal position as at 9 March 2026. The amendment to the National Cybersecurity System Act was published in the Journal of Laws on 2 March 2026 and enters into force on 2 April 2026.


