NIS2 Fines and Sanctions in Poland: What Your Company Risks Under the uKSC

Published: · AIPOS OÜ · nis2europe.eu

The legal basis: NIS2 in Poland via the uKSC

Poland transposes the NIS2 Directive through the Ustawa o krajowym systemie cyberbezpieczeństwa (uKSC) (as amended, Dz.U. 2026 poz. 252). The law introduces two categories of regulated organisations:

Which category you fall into determines your obligations *and* the maximum administrative fine you could face. Enforcement sits with the organ właściwy do spraw cyberbezpieczeństwa (the competent authority for cybersecurity), working alongside sectoral CSIRTs (CSIRT MON, CSIRT NASK, CSIRT GOV, CSIRT sektorowe).

The classification rules are detailed: for example, a podmiot kluczowy includes organisations listed in załącznik nr 1 that exceed the medium-enterprise thresholds, electronic-communication undertakings, managed cybersecurity service providers, DNS providers, qualified trust service providers, critical entities and certain public bodies — regardless of size in several cases (art. 5 ust. 1). A podmiot ważny typically includes medium-sized entities from załącznik nr 1 or nr 2 that are not key entities, non-qualified trust service providers, and certain micro/small electronic-communication undertakings (art. 5 ust. 2).

Maximum fines for key entities (podmiot kluczowy)

For a podmiot kluczowy, the penalty ceiling is set in uKSC art. 73 ust. 3:

In other words, the authority applies the *higher* of the two ceilings (the fixed euro amount or the percentage of turnover), with a statutory floor of PLN 20 000.

Maximum fines for important entities (podmiot ważny)

For a podmiot ważny, the ceiling is lower, per uKSC art. 73 ust. 4:

The same provision notes that art. 73 ust. 3a applies accordingly, with the base for calculating the penalty taken as the equivalent of EUR 250 000.

CategoryFixed maximumTurnover-based maximumMinimum fine
podmiot kluczowy (art. 73 ust. 3)EUR 10 000 0002% of annual revenue (higher amount applies)PLN 20 000
podmiot ważny (art. 73 ust. 4)EUR 7 000 0001.4% of annual revenuePLN 15 000

The escalated penalty: up to PLN 100 000 000

There is a separate, much higher sanction for the most serious breaches. Under uKSC art. 73 ust. 5, if a podmiot kluczowy or podmiot ważny breaches the Act and thereby causes:

1. a direct and serious cyber threat to national defence, state security, public safety and order, or the life and health of people; or 2. a threat of serious material damage or serious disruption to the provision of services,

then the organ właściwy do spraw cyberbezpieczeństwa imposes a fine of up to PLN 100 000 000.

This provision applies to both categories of entity and reflects the gravity attached to incidents that endanger public safety or essential services.

Management responsibility and the personal dimension

NIS2 places accountability at the top of the organisation. Under Article 20(1) of Directive (EU) 2022/2555, Member States must ensure that the management bodies of essential and important entities:

The directive also preserves national rules on the liability of public institutions, public servants and elected or appointed officials.

The underlying obligation those managers must oversee is set out in Article 21(1)–(2): appropriate and proportionate technical, operational and organisational measures based on an all-hazards approach, including risk analysis policies, incident handling, business continuity and backups, supply chain security, vulnerability handling, cyber hygiene and training, cryptography, access control and multi-factor authentication. Where an entity finds it is not compliant, Article 21(4) requires corrective measures without undue delay.

The precise scope of individual/personal management sanctions and any additional supervisory measures as applied under Polish law is [TÄPSUSTAB PARTNER-JURIST].

Practical takeaway: the ability to hold management accountable means cybersecurity is a board-level duty, not just an IT task. Approving and monitoring the measures is itself a legal obligation.

How to reduce your exposure

Fines under the uKSC are triggered by non-compliance, so the first step is knowing where you stand:

Use our free scoping and gap-analysis tool to check whether you are in scope and identify where your compliance gaps sit — the fastest way to understand your real exposure to these penalties.

Frequently asked questions

What is the maximum NIS2 fine for a key entity in Poland?

Under uKSC art. 73 ust. 3, a podmiot kluczowy can be fined up to EUR 10 000 000 (expressed in złoty at the NBP rate applicable on 31 December of the year before the penalty decision) or 2% of its annual business revenue from the preceding financial year — whichever amount is higher. The fine cannot be lower than PLN 20 000.

How much can an important entity be fined?

Under uKSC art. 73 ust. 4, a podmiot ważny can be fined up to EUR 7 000 000 (in złoty at the relevant NBP rate) or 1.4% of its annual business revenue from the preceding financial year. The fine cannot be lower than PLN 15 000.

Is there a higher fine for serious breaches?

Yes. Under uKSC art. 73 ust. 5, where a key or important entity's breach causes a direct and serious cyber threat to defence, state security, public safety and order, or people's life and health — or a threat of serious material damage or serious service disruption — the competent authority (organ właściwy do spraw cyberbezpieczeństwa) imposes a fine of up to PLN 100 000 000.

Can managers be held personally responsible under NIS2?

Article 20(1) of Directive (EU) 2022/2555 requires that management bodies of essential and important entities approve the cybersecurity risk-management measures, oversee their implementation, and can be held liable for the entity's infringements. The precise scope of personal sanctions under Polish law is [TÄPSUSTAB PARTNER-JURIST].

Check your NIS2 compliance

Start the free scoping test

Run the free gap analysis Run the free surface scan

This article is general information, not legal advice. A partner lawyer confirms your specific situation.

Back to home