We help you get ready for NIS2 in Poland
Poland transposed NIS2 by amending its National Cybersecurity System Act, the KSC.
Audit41 Readiness assesses you against the Polish requirements, shows you exactly where you stand, and gives you the ranked actions to close each gap.
This page covers the Polish NIS2 obligations. The Audit41 Readiness NIS2 variant for Poland is not available yet - the free self-check below determines your scope, and ISO 27001 and NIST SP 800-53 assessments are available now.
- 1
Registration
3 October 2026
- 2
Measures
3 April 2027
- 3
Audit
3 April 2028
Every 3 years
Which tier are you?
Podmiot kluczowy. Larger organisations in the Annex 1 key sectors, plus certain entities regardless of size such as DNS providers, TLD registries, qualified trust service providers, and critical entities. Key entities carry the recurring mandatory security audit. If you meet the conditions for both tiers, you are treated as a key entity.
Penalties
Up to the NIS2 statutory maximum, whichever is higher of the fixed cap or a percentage of worldwide annual turnover, with proactive supervision and personal liability for management.
Podmiot ważny. Organisations in the covered sectors that meet the size thresholds but are not key entities. A lighter obligation set, without the recurring mandatory audit.
Penalties
Up to the statutory maximum, with supervision triggered by indication of non-compliance.
Your obligations under the amended KSC Act
Check whether you operate in an Annex 1 or Annex 2 sector and meet the size or special-category criteria, and whether your own activity, not your customers, puts you in scope.
Apply for entry in the register of key and important entities within the statutory window after you meet the criteria.
Implement a formal information security management system and the technical and organisational measures the Act requires.
Manage supply chain security under the Act, assessing and contractually binding your ICT suppliers.
Key entities: complete the first security audit within the statutory window, then repeat it on the recurring cycle the Act sets.
Report significant incidents to the relevant CSIRT under the statutory timelines.
Be ready to provide documentation and information to the competent authority for your sector on request.
The amended KSC Act requires a formal information security management system. An ISO 27001 certification maps closely onto that requirement and gives you a recognised structure, but certification does not replace the statutory measures or the security audit for key entities.
Sectors in scope
No single cyber regulator
Poland does not supervise NIS2 through one authority. Competent authorities differ by sector, for example the financial and telecom regulators for their sectors, and incident reporting goes to one of the national CSIRTs. Knowing which authority and which CSIRT apply to you is part of getting the basics right.
A three-year audit cycle, not two
Poland requires key entities to repeat the security audit at least once every three years, a longer cycle than several neighbouring countries. The obligation still starts from your entry in the register.
The supply chain pulls in firms that think they are exempt
The Act obliges regulated entities to manage the security of their ICT supply chain. A firm that is not directly in scope can still face security requirements as a supplier to a key or important entity, so being out of scope yourself is not the end of the question.
A high-risk supplier mechanism, still contested
Poland introduced a high-risk supplier procedure, under which a designated ICT supplier can be restricted and its products phased out over a statutory window. This provision is among those referred by the President to the Constitutional Tribunal for review, so its final shape is not yet settled. Mapping your ICT supplier dependencies now is prudent regardless.
From gap report to audit-ready
Between registering and passing the security audit, most key entities reach for a consultant. Audit41 Readiness assesses you against the measures the KSC Act requires and gives you the part that actually gets you ready: every gap ranked by severity, with the specific action that closes each one. Sage, the advisor built into the platform, explains what a requirement means when it is not obvious and helps you draft the policy text a fix needs. You leave with a prioritised list of what to do, not a number to interpret.

Know where you stand on NIS2 in Poland
The free self-check applies the Polish rules, tells you your entity type, and recommends the right assessment.
Check your Poland NIS2 scopeThis self-check result is for information only. Audit41 and EMP42 Consulting Kft. accept no liability for the accuracy of the classification. Consult a qualified legal advisor before making a final decision.