KS-CYBER_

Insights / Compliance

What are the penalties for NIS2 non-compliance in Poland?

Updated: September 2026 · approx. 6 min read

Poland's Act on the National Cybersecurity System (Journal of Laws 2026 item 252) sets two levels of liability: administrative fines for the entity and — a distinctive feature of the Polish implementation — a personal fine for the head of the entity of up to 300% of their remuneration.

Personal fine for the head: up to 300% of remuneration

For failing to provide the mandatory annual management training and to document it, the act provides a fine for the person heading the entity of up to 300% of their monthly remuneration. It targets a person, not the company — which is exactly why this now reaches boards, not just IT.

Administrative fines for the entity

Against an essential or important entity, the supervisory authority may apply measures from post-audit recommendations, through orders to remedy shortcomings, up to administrative fines. Their level depends on the entity's status, the severity of the breach and whether it was persistent. Supervision covers risk-management measures and timely reporting of significant incidents.

AreaTypical breach
TrainingNo staff education; no annual head training; no proof of attendance.
Risk managementNo technical and organisational measures appropriate to the risk.
IncidentsFailure to report a significant incident to the competent CSIRT on time.
SupervisionWithholding information or ignoring an authority's order.

How to avoid a fine — in practice

The cheapest part of compliance is the one easiest to prove: documented training and cyber hygiene. A programme that teaches, tests and leaves evidence (who, when, with what result) closes the most frequently audited area and protects the head from the personal fine. See the catalogue of 24 modules with an exam and a named certificate.

This text is informational and is not legal advice. The level and grounds of fines follow from the act and the practice of the supervisory authorities.