Insights / Compliance
What are the penalties for NIS2 non-compliance in Poland?
Poland's Act on the National Cybersecurity System (Journal of Laws 2026 item 252) sets two levels of liability: administrative fines for the entity and — a distinctive feature of the Polish implementation — a personal fine for the head of the entity of up to 300% of their remuneration.
Personal fine for the head: up to 300% of remuneration
For failing to provide the mandatory annual management training and to document it, the act provides a fine for the person heading the entity of up to 300% of their monthly remuneration. It targets a person, not the company — which is exactly why this now reaches boards, not just IT.
Administrative fines for the entity
Against an essential or important entity, the supervisory authority may apply measures from post-audit recommendations, through orders to remedy shortcomings, up to administrative fines. Their level depends on the entity's status, the severity of the breach and whether it was persistent. Supervision covers risk-management measures and timely reporting of significant incidents.
| Area | Typical breach |
|---|---|
| Training | No staff education; no annual head training; no proof of attendance. |
| Risk management | No technical and organisational measures appropriate to the risk. |
| Incidents | Failure to report a significant incident to the competent CSIRT on time. |
| Supervision | Withholding information or ignoring an authority's order. |
How to avoid a fine — in practice
The cheapest part of compliance is the one easiest to prove: documented training and cyber hygiene. A programme that teaches, tests and leaves evidence (who, when, with what result) closes the most frequently audited area and protects the head from the personal fine. See the catalogue of 24 modules with an exam and a named certificate.