A Warsaw-based technology company receives a letter from the national supervisory authority: it has been classified as an "important entity" under Poland's new cybersecurity framework. The board has 30 days to register. It has not yet assigned a cybersecurity officer, mapped its incident response chain, or reviewed its supply chain contracts. The clock is already running.

Poland is implementing the NIS2 Directive through a major amendment to the ustawa o krajowym systemie cyberbezpieczeństwa (Act on the National Cybersecurity System, KSC Act). The amended law introduces two categories of regulated entities – essential and important – and imposes mandatory risk management, incident reporting within 24 hours, and supply chain security obligations. Non-compliance exposes companies to administrative fines of up to EUR 10 million or 2% of global annual turnover, whichever is higher.

This guide explains the step-by-step compliance procedure, identifies the most common mistakes, and walks through three business scenarios: a Polish manufacturing group, a mid-size IT services firm, and a foreign investor entering the Polish market. Each section includes a concrete timeline or cost figure so you can plan with precision.

Which companies fall under NIS2 in Poland?

The amended KSC Act covers entities operating in 18 sectors defined by NIS2. The threshold test combines sector membership with size: companies with at least 50 employees or EUR 10 million in annual turnover are presumptively in scope. Smaller companies may also be covered if they provide critical infrastructure services or are designated by the Minister of Digitalisation.

The law creates two tiers. Essential entities include operators in energy, transport, banking, financial market infrastructure, health, water supply, digital infrastructure, and public administration. Important entities cover postal services, waste management, chemicals, food, manufacturing, digital providers, and research. The distinction matters: essential entities face more frequent supervisory audits and a shorter incident notification window.

Registration with the national supervisory authority is mandatory. In Poland, the primary authority is the Urząd ds. Cyberbezpieczeństwa – though in practice, sector-specific regulators such as the Urząd Komunikacji Elektronicznej (Office of Electronic Communications, UKE) and the Komisja Nadzoru Finansowego (Polish Financial Supervision Authority, KNF) exercise parallel oversight. Entities must self-assess their classification and submit registration within 30 days of meeting the threshold criteria. Failure to register is itself a sanctionable act.

Three common classification mistakes: treating the 50-employee threshold as absolute (it is not); assuming that a Polish subsidiary of a foreign group is exempt because the parent complies elsewhere; and overlooking managed service providers, which are expressly included as important entities regardless of size. If your company provides IT services to any regulated sector client, check your classification now.

What security measures does Polish NIS2 require?

The KSC Act mandates a risk-based cybersecurity management system. Every covered entity must implement technical and organisational measures proportionate to the risk, document them in a written security policy, and review that policy at least once every two years. The law does not prescribe a single standard, but alignment with ISO/IEC 27001 or NIST CSF satisfies the proportionality test in most supervisory assessments.

Mandatory measures fall into five categories. First, risk analysis and information security policies. Second, incident handling procedures covering detection, containment, and recovery. Third, business continuity and crisis management, including backup and disaster recovery. Fourth, supply chain security – entities must evaluate the cybersecurity practices of direct suppliers. Fifth, access control, multi-factor authentication, and encryption for sensitive systems.

  • Appoint a person responsible for cybersecurity (internal or outsourced)
  • Conduct and document a formal risk assessment
  • Establish a written incident response plan
  • Review all material supply chain contracts for security clauses
  • Train staff on cybersecurity awareness at least annually

The supply chain requirement deserves particular attention. Entities must assess whether their suppliers' security practices are adequate and, where necessary, impose contractual obligations. This directly affects IT outsourcing agreements, SaaS contracts, and cloud service arrangements. Companies that have not reviewed vendor contracts since 2022 will almost certainly need to renegotiate key provisions.

We advised a manufacturing client in Silesia (spring 2026) on restructuring its supplier framework after NIS2 classification. The process identified 14 contracts with no cybersecurity clauses whatsoever. Renegotiation took roughly six weeks and required legal input on proportionality assessments and liability allocation. Starting this process early avoids renegotiating under deadline pressure.

For companies already subject to AI Act high-risk classification obligations, NIS2 requirements interact directly with AI system security mandates. A single integrated risk management framework covering both regimes is more efficient than two parallel compliance programmes.

How does incident reporting work under the amended KSC Act?

Incident reporting is one of the most operationally demanding NIS2 obligations. The amended KSC Act introduces a three-stage notification procedure with hard deadlines. Missing any stage forfeits the ability to demonstrate good-faith compliance and can transform a minor incident into a major regulatory event.

Stage one: early warning within 24 hours of detecting a significant incident. This is a brief alert – it need not contain a full root-cause analysis, but must identify the nature of the incident and any cross-border impact. Stage two: full incident notification within 72 hours. This must include an initial assessment of severity, the systems affected, and preliminary containment measures. Stage three: a final incident report within one month, including a full description, impact assessment, and corrective actions taken.

A "significant incident" is defined by the KSC Act as one that causes, or is capable of causing, serious operational disruption or financial loss to the entity, or that affects other persons by causing considerable material or non-material damage. This is a low threshold. A ransomware attack that encrypts even a secondary server is likely reportable. A successful phishing attempt that compromises a single administrator account probably meets the test.

The reporting channel is the national CSIRT (Computer Security Incident Response Team). Poland operates three CSIRTs: CSIRT GOV (for public administration), CSIRT MON (for defence), and CSIRT NASK (for the remaining private and public entities). Most companies in the private sector report to CSIRT NASK. Sector-specific entities in financial services additionally notify KNF under parallel DORA compliance obligations, which run concurrently from January 2025.

Internal preparation is essential. Companies need a documented escalation matrix showing who decides whether an incident is "significant," who drafts the 24-hour alert, and who has authority to submit the report. Without this matrix, the 24-hour window is practically impossible to meet.

What are the three business scenarios for NIS2 compliance?

Compliance timelines and costs vary significantly by company type. The following three scenarios reflect the most common situations we encounter in practice. Each scenario includes a realistic cost range and critical path item.

Scenario 1 – Polish manufacturing group. A mid-size manufacturer with 400 employees supplying components to automotive OEMs. It qualifies as an important entity in the manufacturing sector. The critical path item is supply chain assessment: automotive supply chains involve dozens of sub-suppliers, each of which must be evaluated. Estimated compliance cost: PLN 150,000–300,000 for the first year, including gap assessment, policy documentation, staff training, and legal review of supplier contracts. Timeline: four to six months from classification.

Scenario 2 – IT services company. A Warsaw-based software house with 80 developers providing managed IT services to healthcare and energy clients. It qualifies as an important entity (managed service provider). The critical path item is incident response infrastructure: the company must implement a 24/7 detection and alerting capability, which typically requires either dedicated tooling or an outsourced SOC arrangement. Estimated cost: PLN 80,000–200,000 depending on whether the SOC is built internally or contracted. Timeline: three to five months.

Scenario 3 – Foreign investor entering Poland. A German technology company establishing a Polish subsidiary to serve Central European clients. The subsidiary will immediately qualify as an important entity if it provides digital infrastructure services. The critical path item is legal structure: the parent company's existing ISO 27001 certification does not automatically satisfy Polish KSC Act requirements. A Polish-law compliance assessment is needed before operations begin. For foreign investors, coordination with IP protection strategy considerations is often relevant at the same stage. Estimated cost: PLN 60,000–120,000 for legal and advisory setup. Timeline: two to three months.

We assisted a Mazowieckie-region IT provider (autumn 2025) in completing its NIS2 gap assessment and registering with CSIRT NASK within the statutory 30-day window. The process required simultaneous work on incident response procedures, staff training documentation, and three vendor contract renegotiations. Early engagement reduced the total compliance cost by approximately 30% compared to companies that waited for supervisory pressure.

Across all three scenarios, one factor consistently determines whether compliance is achieved on time: the early appointment of a responsible person. This individual does not need to be a CISO-level hire. A designated compliance coordinator with clear authority and a documented mandate is sufficient for most important-entity cases.

What are the penalties and how is personal liability triggered?

The financial penalties under the amended KSC Act are among the highest in Polish administrative law. Essential entities face fines of up to EUR 10 million or 2% of global annual turnover. Important entities face up to EUR 7 million or 1.4% of global annual turnover. These are maximum figures; the supervisory authority applies a proportionality test. But the starting point for a significant incident involving no documented risk management system is severe.

Personal liability is the feature that concentrates board attention. The KSC Act allows the supervisory authority to impose a temporary ban on performing management functions on individuals responsible for the company's cybersecurity compliance. This ban can last up to five years. It applies to members of the management board, not just designated cybersecurity officers. The condition is a finding that the individual's negligence contributed to a serious compliance failure. This consequence is largely irreversible – it cannot be undone by subsequent remediation.

Three triggers for personal liability in practice: failure to implement a risk management system despite being notified of classification; failure to report a significant incident within the statutory window; and failure to take corrective action following a supervisory audit recommendation. Each of these is an independent basis for the management ban.

The intersection with GDPR Poland obligations is significant. A cybersecurity incident that also constitutes a personal data breach triggers parallel notification obligations to the Urząd Ochrony Danych Osobowych (Personal Data Protection Office, UODO) within 72 hours. Managing both notification chains simultaneously requires pre-built procedures. Companies that handle them sequentially – finishing the UODO notification before starting the CSIRT notification – routinely miss the KSC Act deadline.

What is the step-by-step compliance checklist?

The compliance process has a logical sequence. Skipping steps does not save time – it creates rework. The following checklist applies to both essential and important entities, with the understanding that essential entities face shorter deadlines and more intensive audit scrutiny.

  • Step 1 – Classification assessment: determine whether your company meets the size and sector thresholds; document the analysis in writing
  • Step 2 – Registration: submit the mandatory notification to the relevant supervisory authority within 30 days of meeting the threshold
  • Step 3 – Gap analysis: compare current security practices against the KSC Act requirements; identify deficiencies
  • Step 4 – Policy documentation: draft or update the cybersecurity security policy, incident response plan, and business continuity plan
  • Step 5 – Supply chain review: audit supplier contracts and impose security obligations where missing

After completing the checklist, two ongoing obligations remain. First, the security policy must be reviewed every two years, or after any significant incident. Second, staff training must occur at least annually. Both obligations are independently auditable. Supervisory inspections typically begin by requesting the training log and the last policy review date.

For companies operating across multiple jurisdictions, note that NIS2 applies on a "main establishment" basis. A company with its main EU establishment in Poland is subject to Polish supervisory jurisdiction for all EU operations. This has direct implications for AI Act Poland compliance programmes, where risk management documentation must align across jurisdictions. An IP lawyer Warsaw-based team familiar with both regimes can map the overlap efficiently.

One practical point on costs: the largest variable is not legal fees but internal project management time. Companies that assign a dedicated coordinator for the compliance project complete it in three to four months. Companies that treat it as a background task for the IT department alongside other priorities typically take eight to twelve months – and incur higher costs because the project restarts repeatedly.

Frequently asked questions

Q: Does NIS2 apply to my Polish subsidiary if the parent company is already NIS2-compliant in Germany?

A: Yes. Each legal entity is assessed separately under the KSC Act. A parent company's compliance in Germany does not satisfy the Polish registration and security obligations. The Polish subsidiary must conduct its own classification assessment, register with the relevant Polish authority, and implement a security management system that meets Polish statutory requirements. Shared group policies may form the basis of the Polish system, but they must be formally adopted and adapted to the KSC Act framework.

Q: How long does the compliance process take, and what does it cost for a company with around 100 employees?

A: For an important entity with approximately 100 employees and no existing ISO 27001 certification, a realistic timeline is four to six months from the classification decision. Costs typically range from PLN 80,000 to PLN 180,000 for the first year, covering gap assessment, policy documentation, legal review of supplier contracts, and staff training. Companies with existing information security frameworks can reduce this by 30–40%. The largest single cost driver is supply chain contract review, particularly where the company has numerous IT vendors.

Q: Is it a common misconception that only technology companies are covered by NIS2?

A: It is one of the most frequent misunderstandings we encounter. NIS2 covers 18 sectors, including food production, chemicals, waste management, and manufacturing. A food processing company with EUR 10 million in turnover and 50 employees qualifies as an important entity in the food sector. The technology bias in public discussion reflects the fact that digital infrastructure entities were covered under the original NIS Directive. Under NIS2, the scope is dramatically broader. Any company meeting the size threshold in a covered sector should conduct a classification assessment, regardless of how "non-technical" its operations appear.

Specific situations require individual analysis. If your company has been notified of classification, is approaching the size threshold, or is restructuring operations in a covered sector, the assessment cannot wait.

To receive an expert assessment of your NIS2 classification and compliance obligations in Poland, contact info@kordeckipartners.com. Our team will map your sector classification, identify the critical path items, and structure a compliance programme that fits your timeline and budget.

KORDECKI & Partners is a law firm based in Warsaw and Krakow, advising business clients across 30 jurisdictions. Our team combines expertise in Polish and international law with a practical approach to technology regulation, cybersecurity compliance, and IP protection. We work with Polish entrepreneurs, foreign investors, and in-house legal teams navigating NIS2, the AI Act, DORA, and related digital regulation frameworks. To discuss your situation, contact info@kordeckipartners.com.

Disclaimer: This publication is provided for informational purposes only and does not constitute legal advice. The information herein should not be relied upon as a substitute for professional legal counsel tailored to your specific circumstances. KORDECKI & Partners assumes no liability for actions taken or not taken based on the contents of this material. For advice regarding your particular situation, please contact info@kordeckipartners.com.