Insights / Compliance
Does my company fall under NIS2 in Poland?
Short answer: if you operate in one of the sectors named by the act and you are at least a medium-sized enterprise, you most likely qualify as an essential or important entity. The final classification is decided by the competent authority, but you can check the criteria yourself in a few minutes.
Two conditions that must both be met
Poland's Act on the National Cybersecurity System (Journal of Laws 2026 item 252), which implements NIS2 and has been in force since 3 April 2026, covers an entity when it meets both of the following:
| Condition | What it means |
|---|---|
| Sector | Activity in a covered sector (energy, transport, banking, health, water, digital infrastructure, ICT service management, public administration and more — plus "important" sectors such as manufacturing, chemicals, food, waste, digital services). |
| Size | As a rule, medium enterprise or larger — roughly from 50 staff or over EUR 10M turnover / balance sheet. For some entities (e.g. critical digital infrastructure, public administration) the size threshold does not apply. |
The sector determines whether you are an essential or an important entity. The difference mainly concerns the intensity of supervision and sanctions, not the obligation to have security measures in place.
I'm covered — what now
Being covered means risk-management measures, reporting of significant incidents, and — often a surprise — staff education and management training. We cover the training duty in the training-obligation article, and the consequences of ignoring it in the penalties article.