NIS2 Fines and Sanctions in Poland: What Your Company Risks Under the uKSC
The legal basis: NIS2 in Poland via the uKSC
Poland transposes the NIS2 Directive through the Ustawa o krajowym systemie cyberbezpieczeństwa (uKSC) (as amended, Dz.U. 2026 poz. 252). The law introduces two categories of regulated organisations:
- podmiot kluczowy (key entity) — defined in uKSC art. 5 ust. 1
- podmiot ważny (important entity) — defined in uKSC art. 5 ust. 2
Which category you fall into determines your obligations *and* the maximum administrative fine you could face. Enforcement sits with the organ właściwy do spraw cyberbezpieczeństwa (the competent authority for cybersecurity), working alongside sectoral CSIRTs (CSIRT MON, CSIRT NASK, CSIRT GOV, CSIRT sektorowe).
The classification rules are detailed: for example, a podmiot kluczowy includes organisations listed in załącznik nr 1 that exceed the medium-enterprise thresholds, electronic-communication undertakings, managed cybersecurity service providers, DNS providers, qualified trust service providers, critical entities and certain public bodies — regardless of size in several cases (art. 5 ust. 1). A podmiot ważny typically includes medium-sized entities from załącznik nr 1 or nr 2 that are not key entities, non-qualified trust service providers, and certain micro/small electronic-communication undertakings (art. 5 ust. 2).
Maximum fines for key entities (podmiot kluczowy)
For a podmiot kluczowy, the penalty ceiling is set in uKSC art. 73 ust. 3:
- The fine may not exceed EUR 10 000 000 (expressed in złoty using the average NBP exchange rate applicable on 31 December of the year preceding the year in which the penalty decision is issued), or 2% of the revenue earned by the key entity from business activity in the financial year preceding the imposition of the penalty — whichever amount is higher.
- The fine may not be lower than PLN 20 000.
In other words, the authority applies the *higher* of the two ceilings (the fixed euro amount or the percentage of turnover), with a statutory floor of PLN 20 000.
Maximum fines for important entities (podmiot ważny)
For a podmiot ważny, the ceiling is lower, per uKSC art. 73 ust. 4:
- The fine may not exceed EUR 7 000 000 (expressed in złoty using the average NBP rate applicable on 31 December of the year preceding the penalty decision), or 1.4% of the revenue earned by the important entity from business activity in the preceding financial year.
- The fine may not be lower than PLN 15 000.
The same provision notes that art. 73 ust. 3a applies accordingly, with the base for calculating the penalty taken as the equivalent of EUR 250 000.
| Category | Fixed maximum | Turnover-based maximum | Minimum fine |
|---|---|---|---|
| podmiot kluczowy (art. 73 ust. 3) | EUR 10 000 000 | 2% of annual revenue (higher amount applies) | PLN 20 000 |
| podmiot ważny (art. 73 ust. 4) | EUR 7 000 000 | 1.4% of annual revenue | PLN 15 000 |
The escalated penalty: up to PLN 100 000 000
There is a separate, much higher sanction for the most serious breaches. Under uKSC art. 73 ust. 5, if a podmiot kluczowy or podmiot ważny breaches the Act and thereby causes:
1. a direct and serious cyber threat to national defence, state security, public safety and order, or the life and health of people; or 2. a threat of serious material damage or serious disruption to the provision of services,
then the organ właściwy do spraw cyberbezpieczeństwa imposes a fine of up to PLN 100 000 000.
This provision applies to both categories of entity and reflects the gravity attached to incidents that endanger public safety or essential services.
Management responsibility and the personal dimension
NIS2 places accountability at the top of the organisation. Under Article 20(1) of Directive (EU) 2022/2555, Member States must ensure that the management bodies of essential and important entities:
- approve the cybersecurity risk-management measures taken to comply with Article 21;
- oversee their implementation; and
- can be held liable for the entity's infringements of that Article.
The directive also preserves national rules on the liability of public institutions, public servants and elected or appointed officials.
The underlying obligation those managers must oversee is set out in Article 21(1)–(2): appropriate and proportionate technical, operational and organisational measures based on an all-hazards approach, including risk analysis policies, incident handling, business continuity and backups, supply chain security, vulnerability handling, cyber hygiene and training, cryptography, access control and multi-factor authentication. Where an entity finds it is not compliant, Article 21(4) requires corrective measures without undue delay.
The precise scope of individual/personal management sanctions and any additional supervisory measures as applied under Polish law is [TÄPSUSTAB PARTNER-JURIST].
Practical takeaway: the ability to hold management accountable means cybersecurity is a board-level duty, not just an IT task. Approving and monitoring the measures is itself a legal obligation.
How to reduce your exposure
Fines under the uKSC are triggered by non-compliance, so the first step is knowing where you stand:
- Confirm your classification — are you a *podmiot kluczowy* (art. 5 ust. 1) or *podmiot ważny* (art. 5 ust. 2)? This sets your penalty ceiling.
- Map your obligations — including the risk-management measures in Article 21(2) and the incident-reporting deadlines (early warning within 24 hours per uKSC art. 11 ust. 1 pkt 4; incident notification within 72 hours per art. 11 ust. 1 pkt 4a; final report within one month per art. 11 ust. 1 pkt 4c).
- Document management approval and oversight — to meet the Article 20(1) governance requirement.
- Close the gaps before an incident forces the issue.
Use our free scoping and gap-analysis tool to check whether you are in scope and identify where your compliance gaps sit — the fastest way to understand your real exposure to these penalties.
Frequently asked questions
What is the maximum NIS2 fine for a key entity in Poland?
Under uKSC art. 73 ust. 3, a podmiot kluczowy can be fined up to EUR 10 000 000 (expressed in złoty at the NBP rate applicable on 31 December of the year before the penalty decision) or 2% of its annual business revenue from the preceding financial year — whichever amount is higher. The fine cannot be lower than PLN 20 000.
How much can an important entity be fined?
Under uKSC art. 73 ust. 4, a podmiot ważny can be fined up to EUR 7 000 000 (in złoty at the relevant NBP rate) or 1.4% of its annual business revenue from the preceding financial year. The fine cannot be lower than PLN 15 000.
Is there a higher fine for serious breaches?
Yes. Under uKSC art. 73 ust. 5, where a key or important entity's breach causes a direct and serious cyber threat to defence, state security, public safety and order, or people's life and health — or a threat of serious material damage or serious service disruption — the competent authority (organ właściwy do spraw cyberbezpieczeństwa) imposes a fine of up to PLN 100 000 000.
Can managers be held personally responsible under NIS2?
Article 20(1) of Directive (EU) 2022/2555 requires that management bodies of essential and important entities approve the cybersecurity risk-management measures, oversee their implementation, and can be held liable for the entity's infringements. The precise scope of personal sanctions under Polish law is [TÄPSUSTAB PARTNER-JURIST].
Check your NIS2 compliance
This article is general information, not legal advice. A partner lawyer confirms your specific situation.