NIS2 Directive / Polish KSC Law

NIS2 (EU Directive 2022/2555) is a new piece of legislation concerning cybersecurity, which replaces the previous NIS1 Directive. NIS2 came into effect at the level of EU on 16 January 2023. Member States had until 17 October 2024 to comply with its requirements.

In the Polish legal system, NIS2 has been implemented by way of extensive amendments to the Law on the National Cybersecurity System (KSC). In Poland, the implementation was delayed: the amendments to the KSC Law went through the legislative process in 2025 and 2026. In the end, they were adopted on 23 January 2026 and published in the official gazette on 2 March 2026 (Dz. U. of 2026, item 252). They came into effect on 3 April 2026. Every organization that meets the criteria specified in the amended Law is required to enter itself into the register of entities of the national cybersecurity system (having 6 months to do so) and start complying with legal requirements (within 12 months of identifying that it is subject to the Law).

NIS2 Directive / Polish KSC Law – comprehensive support from Cybernite

Why was NIS2 adopted?

NIS2 is the EU’s answer to:

  • The growing number and complexity of cyber attacks,
  • Higher exposure of the economy to ransomware, phishing, and attacks on supply chains,
  • The need to increase the resilience of key sectors of the economy, from the energy sector to public administration.

The regulation introduces a wider range of sectors, more rigorous principles of risk management, and obligations in terms of reporting incidents. In practice, the idea is to improve the resilience of the entire EU market to cyberthreats. The main task of NIS2 is to consolidate the level of security in all Member States and force organizations to actively manage digital risk.

The key goals of NIS2 are to:

  1. Increase the level of cybersecurity in the European Union
  2. Mitigate the risk of interferences in key services and sectors
  3. Consolidate the principles of managing risks and reporting incidents
  4. Increase the responsibility of executive personnel
  5. Improve cooperation between Member States

NIS2 treats cybersecurity as a business and operational risk and not just a technical problem of the IT department.

Who does NIS2/KSC apply to?

These regulations do not apply to all companies, but focus on entities of strategic importance for the state and the economy. The key criterion is the size of the company (typically medium and large enterprises employing more than 50 people) and the sector in which it operates.

These entities are divided into two groups, which differ in terms of intensity of supervision:

1. Essential entities

These operate in the most important sectors and are subject to the most rigorous and proactive inspections:

  • The energy sector (power, gas, oil, heating).
  • Transport (air, railways, water, roads).
  • Banking and financial markets infrastructure.
  • Health care (hospitals, laboratories, manufacturers of medications).
  • Drinking water and waste water.
  • Digital infrastructure (providers of clouds, data centers, communication networks).

2. Important entities

These function in sectors subject to follow-up supervision (usually after an incident has occurred):

  • Postal and courier services.
  • Waste management.
  • Manufacture and distribution of chemicals.
  • Food production (processing and wholesale)
  • Manufacture of goods (electronics, machines, vehicles).
  • Providers of digital services (e.g. online marketplaces, search engines).

Main requirements for organizations

NIS2/KSC imposes specific obligations that need to become a part of everyday functioning of a company:

  • Risk management: The company has to have written security policies, carry out regular audits, and analyze what could go wrong in its IT systems.
  • Business continuity: In the event of a ransomware attack or a system failure, the organization has to have emergency plans and back-up copies ready, so as to restore the functioning of services.
  • Supply chain security: The company is not only responsible for itself, but also has to verify whether its providers of software and IT services take care of security.
  • Encryption and MFA: Implementation of modern security measures, such as data encryption and multi-factor authentication (e.g. using a smartphone application to confirm logging in).
  • Reporting obligation: If a major incident occurs, the company has to notify the relevant state services (CSIRT) within a specific time limit:
    1. 24 hours to send the first warning
    2. 72 hours to fully evaluate the incident

What does that mean for business?

For companies, NIS2/KSC means:

  • The need to review and update security processes,
  • Building a risk management system,
  • Improving the security of the supply chain,
  • Introducing regular security audits,
  • Higher requirements for IT providers, service operators, and software houses,
  • The obligation to quickly report incidents and maintain documentation.

The directive covers a much larger number of entities than previously, including medium ones and some of the smaller enterprises in the critical sectors.

Responsibility of the management

This is one of the most important elements of NIS2/KSC. Cybersecurity is no longer a problem of just the IT department.

  • Management approves security measures and supervises their implementation.
  • Members of managing bodies may be held personally accountable for gross negligence.
  • The management has a statutory obligation to regularly attend training seminars on cyberthreats.

Penalties for non-compliance

The financial penalties specified in NIS2/KSC are similar to those laid down in GDPR and may be imposed directly by supervisory authorities:

  • For essential entities: up to EUR 10 million or 2% of global annual turnover
  • For important entities: up to EUR 7 million or 1.4% of global annual turnover

In addition to financial penalties, supervisory authorities may issue corrective orders, warnings, and even temporarily suspend certification of services or, in extreme cases, prohibit the responsible persons from holding managerial positions.

Summary

NIS2 is one of the most important European pieces of legislation concerning cybersecurity. Its purpose is to improve the resilience of the economy as a whole to growing cyberthreats and to introduce uniform protection standards.

In Poland, the directive has been implemented by way of amendments to the Law on the National Cybersecurity System (KSC), which were adopted on 23 January 2026 and came into effect on 3 April 2026.

For business, NIS2/KSC means the need to adapt processes, improve security standards, and prepare for strict reporting and inspection requirements. Even though implementation may be a challenge, it will increase the organization’s resilience and the security of the entire ecosystem.

Text by professor Grzegorz Strupczewski

Within the framework of Cybernite Status we help assess the organization’s current level of security and regulatory preparedness.

Through Cybernite Safe, we provide regular support in terms of cybersecurity management, performance of regulatory obligations, and compliance with industry standards, using the Cybersecurity as a Service (CSaaS) model.

Do you need support with respect to NIS2/KSC, CRA, DORA, or the AI Act, from confirming that you are subject to them, through gap analysis, to verification and supplementation of existing actions?
Cybernite helps organize documentation, implement the missing elements, and maintain compliance in practice.

Schedule a free meeting