The 10 NIS2 Risk-Management Measures Under Article 21 — A Practical Checklist for Poland
What Article 21 actually requires
If your company falls under the Polish cybersecurity regime, the heart of your compliance obligation is a set of risk-management measures. These come from Article 21 of Directive (EU) 2022/2555 (NIS2) and are transposed into Polish law through the Ustawa o krajowym systemie cyberbezpieczeństwa (uKSC) (Dz.U. 2026 poz. 252).
Article 21(1) sets the standard. Essential and important entities must take *"appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of network and information systems"* they use — and to prevent or minimise the impact of incidents on the recipients of their services.
Two words matter here: appropriate and proportionate. The directive says you must take into account:
- the state-of-the-art and relevant European and international standards;
- the cost of implementation;
- your degree of exposure to risks;
- the size of your entity;
- the likelihood of incidents and their severity, including societal and economic impact.
In other words, a mid-sized manufacturer is not expected to build the same defences as a national telecom operator — but both must genuinely manage their risks. Article 21(2) then makes this concrete by listing ten minimum measures, based on an *all-hazards approach* covering both digital systems and their physical environment.
The 10 measures — your Article 21(2) checklist
Here is the full list from Article 21(2), points (a)–(j), presented as a practical checklist. These are the *minimum* — your risk assessment may require more.
| # | Point | Measure |
|---|---|---|
| 1 | (a) | Policies on risk analysis and information system security |
| 2 | (b) | Incident handling |
| 3 | (c) | Business continuity, such as backup management and disaster recovery, and crisis management |
| 4 | (d) | Supply chain security, including security aspects of relationships with direct suppliers or service providers |
| 5 | (e) | Security in network and information systems acquisition, development and maintenance, including vulnerability handling and disclosure |
| 6 | (f) | Policies and procedures to assess the effectiveness of cybersecurity risk-management measures |
| 7 | (g) | Basic cyber hygiene practices and cybersecurity training |
| 8 | (h) | Policies and procedures on the use of cryptography and, where appropriate, encryption |
| 9 | (i) | Human resources security, access control policies and asset management |
| 10 | (j) | Use of multi-factor authentication or continuous authentication, secured voice/video/text communications and secured emergency communication systems, where appropriate |
How to read this checklist: Points (a) and (f) form a management loop — you analyse risks, act, then measure whether your actions work. Points (b) and (c) prepare you for when something goes wrong. Points (d) and (e) push security outward into your suppliers and your software lifecycle. Points (g), (h), (i) and (j) are the everyday controls — training, encryption, access control, and multi-factor authentication — that stop the majority of common attacks.
Article 21(2) point (e) explicitly includes vulnerability handling and disclosure, and point (d) explicitly names the relationship between each entity and its direct suppliers. These two are often the weakest links, so treat them seriously rather than as box-ticking.
How Polish law transposes these obligations
The Polish transposition sits in the uKSC (Dz.U. 2026 poz. 252). The law distinguishes two categories of regulated organisation, and you should confirm which one applies to you before building your programme:
- Podmiot kluczowy (essential entity) — defined in uKSC art. 5 ust. 1. This covers, among others, entities listed in Annex 1 that exceed the medium-enterprise thresholds, electronic-communications undertakings, managed cybersecurity service providers, and — *regardless of size* — DNS service providers, qualified trust service providers, critical entities, TLD name registries and domain-name registration service providers.
- Podmiot ważny (important entity) — defined in uKSC art. 5 ust. 2. This covers medium-sized entities in the relevant annexes that are not essential entities, non-qualified trust service providers, micro/small electronic-communications undertakings, and certain public bodies.
Governance is a board-level duty. Under Article 20(1) of the directive, management bodies must *approve* the risk-management measures, *oversee* their implementation, and *can be held liable* for infringements of Article 21. This means the ten measures are not just an IT project — leadership carries the responsibility.
Fixing gaps is mandatory. Under Article 21(4), an entity that finds it does not comply with the measures must take, *without undue delay*, all necessary, appropriate and proportionate corrective measures. Finding a gap is not a violation in itself — ignoring it is.
The precise national provision restating the Article 21 measures and the sector-specific supervisory arrangements under the Polish multi-authority model are [TÄPSUSTAB PARTNER-JURIST].
Why getting this right matters: reporting and penalties
The ten measures do not exist in isolation. If a major incident (incydent poważny) occurs — defined in uKSC art. 2 pkt 7 as an incident that causes or may cause serious degradation or interruption of a service, financial loss, or serious material or non-material harm to others — your incident-handling measure under point (b) must feed directly into strict reporting deadlines to the relevant sectoral CSIRT:
- Early warning within 24 hours of detection (uKSC art. 11 ust. 1 pkt 4);
- Incident notification within 72 hours of detection (uKSC art. 11 ust. 1 pkt 4a);
- Periodic report on request of the sectoral CSIRT (uKSC art. 11 ust. 1 pkt 4b);
- Final report within one month of the notification (uKSC art. 11 ust. 1 pkt 4c).
Penalties for failing to manage risk are significant:
- For a podmiot kluczowy: up to EUR 10 000 000 or 2% of annual turnover, whichever is higher, and not less than PLN 20 000 (uKSC art. 73 ust. 3).
- For a podmiot ważny: up to EUR 7 000 000 or 1.4% of annual turnover, and not less than PLN 15 000 (uKSC art. 73 ust. 4).
- Where a breach causes a direct and serious cyber threat to defence, state security, public order, or human life and health — or threatens serious financial harm or serious service disruption — a penalty of up to PLN 100 000 000 may be imposed by the organ właściwy do spraw cyberbezpieczeństwa (uKSC art. 73 ust. 5).
Starting with the ten-point checklist above is the most efficient way to build a defensible programme. Use our free scoping and gap tool to map each Article 21(2) measure against what your organisation already has in place — and to see where your priorities lie.
Frequently asked questions
Where do the 10 NIS2 risk-management measures come from?
They are set out in Article 21(2), points (a) to (j), of Directive (EU) 2022/2555 (NIS2), which is transposed into Polish law through the Ustawa o krajowym systemie cyberbezpieczeństwa (uKSC), Dz.U. 2026 poz. 252. The list is the legal minimum, based on an all-hazards approach.
Do all ten measures apply to every organisation equally?
The ten measures are a minimum for both essential and important entities, but Article 21(1) requires them to be appropriate and proportionate. Proportionality takes account of your exposure to risk, your size, and the likelihood and severity of incidents, so implementation depth can differ.
What is the difference between podmiot kluczowy and podmiot ważny?
Podmiot kluczowy (essential entity) is defined in uKSC art. 5 ust. 1 and podmiot ważny (important entity) in uKSC art. 5 ust. 2. The categories differ in criteria such as sector, size and type of service, and they carry different maximum penalties under uKSC art. 73 ust. 3 and ust. 4.
What happens if we discover we do not comply with a measure?
Under Article 21(4) of the directive, an entity that finds it does not comply with the Article 21(2) measures must take all necessary, appropriate and proportionate corrective measures without undue delay. Identifying a gap and fixing it promptly is exactly what the law expects.
Check your NIS2 compliance
This article is general information, not legal advice. A partner lawyer confirms your specific situation.