The amended Polish Act on the National Cybersecurity System entered into force on 3 April 2026, transposing the NIS-2 Directive into national law. It covers eighteen sectors and thousands of organisations that previously had nothing to do with this regulation - from municipal companies and water utilities, through healthcare providers, to manufacturers and logistics firms. The first hard deadline falls on 3 October 2026: by that date the head of an essential or important entity must file for entry in the official registry. The legislator opted for self-identification, which means something important - no authority will send a notice that your organisation is now in scope. You must assess it yourself, and the declaration submitted by the head of the entity carries criminal liability under Article 233 § 6 of the Polish Criminal Code. We guide organisations through the whole path: establishing whether and in what capacity you fall under the Act, preparing the filing, and then building a system that will withstand an inspection.
Local government, municipal companies, water and district heating utilities
Healthcare providers, hospitals and diagnostic laboratories
Manufacturers, logistics operators and transport companies
Digital service, ICT and managed security service providers (MSSP)
Entities in energy, waste management, food and chemicals sectors
We guide the organisation through every stage - from determining whether it falls under the Act, to readiness for the first mandatory audit in 2028.
Entity classification - We establish whether the organisation meets the sectoral and size criteria - more than fifty employees or ten million euro in turnover - and which category applies. The outcome is a report on which the head of the entity can base their declaration.
Registry filing - We compile the data required by the Act: IP address ranges, domain names, contact person details, information on managed service providers. We prepare the application for submission through the S46 system before 3 October 2026.
Gap analysis - We compare the actual state against statutory requirements and identify gaps ranked by risk and urgency, with a realistic estimate of the effort each one demands.
Building the risk management system - We develop the security policy, risk assessment methodology, risk treatment plan and operating procedures - tailored to the scale of the organisation rather than copied from a template.
Incident procedures and training - We implement the process for reporting serious incidents to the CSIRT within statutory deadlines, and train both operational staff and management, who bear personal responsibility for cybersecurity.
Maintenance and audit readiness - We remain available for reviews, documentation updates and preparation for the mandatory security audit, which must be carried out for the first time by 3 April 2028.
You will not learn it from an official letter - the Act rests on self-identification. Three things need checking: whether the activity falls within one of the eighteen sectors listed in the annexes, whether the organisation exceeds the threshold of fifty employees or ten million euro in annual turnover, and whether one of the exceptions applies in which size is irrelevant - this covers, among others, domain name registrars, DNS service providers and trust service providers. Classification is often far from obvious, particularly where activities are mixed, and that is precisely where every project begins.
File an application for entry in the registry of essential and important entities. This is done by the head of the entity or a person they authorise, electronically through the S46 system, using a qualified electronic signature. The application requires identification data, the sector and type of activity, IP address ranges and domain names, details of at least two contact persons, and information on managed security service providers. The declaration by the head of the entity carries criminal liability under Article 233 § 6 of the Criminal Code, so it is worth basing it on sound analysis rather than assumption.
The Act provides for penalties of up to ten million euro or two per cent of total worldwide annual turnover for essential entities, and up to seven million euro or one point four per cent of turnover for important entities - in both cases the higher amount applies. Unprecedented in Polish law is the personal liability: the head of the entity may be fined up to six hundred per cent of their monthly remuneration, and in cases of gross negligence the authority may impose a temporary ban on holding management positions. Failure to register does not remove the obligations - the authority may enter the entity in the registry ex officio, and the duties apply regardless.
It is an excellent starting point and a substantial part of the work is already done - an information security management system covers most of the risk management requirements. The NCS Act, however, goes further in three areas: it imposes specific deadlines and formats for reporting incidents to the relevant CSIRT, it requires a formalised approach to supply chain security, and it assigns named responsibility to management, which the standard does not recognise. In practice this becomes a supplementary project rather than an implementation from scratch.
The registry filing itself typically takes two to three weeks from the moment we receive the data. A full implementation of the risk management system usually runs from three to six months, depending on the size of the organisation, the maturity of existing processes and the number of locations. The legislator allowed until 3 April 2027 for adaptation, and the first mandatory security audit must be completed by 3 April 2028 - we structure the schedule so that both deadlines are met without a scramble.