We help you get ready for NIS2 in Poland

Poland transposed NIS2 by amending its National Cybersecurity System Act, the KSC.

Audit41 Readiness assesses you against the Polish requirements, shows you exactly where you stand, and gives you the ranked actions to close each gap.

This page covers the Polish NIS2 obligations. The Audit41 Readiness NIS2 variant for Poland is not available yet - the free self-check below determines your scope, and ISO 27001 and NIST SP 800-53 assessments are available now.

Check your Poland NIS2 scope
  1. 1

    Registration

    3 October 2026

  2. 2

    Measures

    3 April 2027

  3. 3

    Audit

    3 April 2028

Every 3 years

Which tier are you?

Key entity

Podmiot kluczowy. Larger organisations in the Annex 1 key sectors, plus certain entities regardless of size such as DNS providers, TLD registries, qualified trust service providers, and critical entities. Key entities carry the recurring mandatory security audit. If you meet the conditions for both tiers, you are treated as a key entity.

Penalties

Up to the NIS2 statutory maximum, whichever is higher of the fixed cap or a percentage of worldwide annual turnover, with proactive supervision and personal liability for management.

Important entity

Podmiot ważny. Organisations in the covered sectors that meet the size thresholds but are not key entities. A lighter obligation set, without the recurring mandatory audit.

Penalties

Up to the statutory maximum, with supervision triggered by indication of non-compliance.

Your obligations under the amended KSC Act

1

Check whether you operate in an Annex 1 or Annex 2 sector and meet the size or special-category criteria, and whether your own activity, not your customers, puts you in scope.

2

Apply for entry in the register of key and important entities within the statutory window after you meet the criteria.

3

Implement a formal information security management system and the technical and organisational measures the Act requires.

4

Manage supply chain security under the Act, assessing and contractually binding your ICT suppliers.

5

Key entities: complete the first security audit within the statutory window, then repeat it on the recurring cycle the Act sets.

6

Report significant incidents to the relevant CSIRT under the statutory timelines.

7

Be ready to provide documentation and information to the competent authority for your sector on request.

The amended KSC Act requires a formal information security management system. An ISO 27001 certification maps closely onto that requirement and gives you a recognised structure, but certification does not replace the statutory measures or the security audit for key entities.

Sectors in scope

EnergyTransportBankingFinancial market infrastructureHealthDrinking waterWaste waterDigital infrastructureICT service managementPublic administrationSpacePostal and courier servicesWaste managementChemicalsFoodManufacturingDigital providersResearch

No single cyber regulator

Poland does not supervise NIS2 through one authority. Competent authorities differ by sector, for example the financial and telecom regulators for their sectors, and incident reporting goes to one of the national CSIRTs. Knowing which authority and which CSIRT apply to you is part of getting the basics right.

A three-year audit cycle, not two

Poland requires key entities to repeat the security audit at least once every three years, a longer cycle than several neighbouring countries. The obligation still starts from your entry in the register.

The supply chain pulls in firms that think they are exempt

The Act obliges regulated entities to manage the security of their ICT supply chain. A firm that is not directly in scope can still face security requirements as a supplier to a key or important entity, so being out of scope yourself is not the end of the question.

A high-risk supplier mechanism, still contested

Poland introduced a high-risk supplier procedure, under which a designated ICT supplier can be restricted and its products phased out over a statutory window. This provision is among those referred by the President to the Constitutional Tribunal for review, so its final shape is not yet settled. Mapping your ICT supplier dependencies now is prudent regardless.

From gap report to audit-ready

Between registering and passing the security audit, most key entities reach for a consultant. Audit41 Readiness assesses you against the measures the KSC Act requires and gives you the part that actually gets you ready: every gap ranked by severity, with the specific action that closes each one. Sage, the advisor built into the platform, explains what a requirement means when it is not obvious and helps you draft the policy text a fix needs. You leave with a prioritised list of what to do, not a number to interpret.

Page one of an Audit41 Readiness Assessment Report, showing a readiness score, the four band scale, a control breakdown, and the top critical gaps and priority actions.

Know where you stand on NIS2 in Poland

The free self-check applies the Polish rules, tells you your entity type, and recommends the right assessment.

Check your Poland NIS2 scope

This self-check result is for information only. Audit41 and EMP42 Consulting Kft. accept no liability for the accuracy of the classification. Consult a qualified legal advisor before making a final decision.