KS-CYBER_

Insights / Compliance

Does my company fall under NIS2 in Poland?

Updated: September 2026 · approx. 6 min read

Short answer: if you operate in one of the sectors named by the act and you are at least a medium-sized enterprise, you most likely qualify as an essential or important entity. The final classification is decided by the competent authority, but you can check the criteria yourself in a few minutes.

Two conditions that must both be met

Poland's Act on the National Cybersecurity System (Journal of Laws 2026 item 252), which implements NIS2 and has been in force since 3 April 2026, covers an entity when it meets both of the following:

ConditionWhat it means
SectorActivity in a covered sector (energy, transport, banking, health, water, digital infrastructure, ICT service management, public administration and more — plus "important" sectors such as manufacturing, chemicals, food, waste, digital services).
SizeAs a rule, medium enterprise or larger — roughly from 50 staff or over EUR 10M turnover / balance sheet. For some entities (e.g. critical digital infrastructure, public administration) the size threshold does not apply.

The sector determines whether you are an essential or an important entity. The difference mainly concerns the intensity of supervision and sanctions, not the obligation to have security measures in place.

Rule of thumb. "Listed sector + at least medium size = you're in." The exceptions run one way: some entities are covered regardless of size. If you're on the border, treat it as a prompt to check, not to postpone.

I'm covered — what now

Being covered means risk-management measures, reporting of significant incidents, and — often a surprise — staff education and management training. We cover the training duty in the training-obligation article, and the consequences of ignoring it in the penalties article.

This text is informational and is not legal advice. The final classification of an entity follows from the act and the decision of the competent authority.