NIS2 in Poland: Who Is in Scope Under the uKSC?
What law transposes NIS2 in Poland?
Poland implements the NIS2 Directive through the Ustawa o krajowym systemie cyberbezpieczeństwa (uKSC), as amended (Dz.U. 2026 poz. 252). The law divides organisations into two statutory categories:
- podmiot kluczowy (essential entity)
- podmiot ważny (important entity)
Which category you fall into determines the intensity of supervision and the level of financial penalties that apply. Both categories must meet the core obligations under the underlying NIS2 Directive (EU) 2022/2555, including cybersecurity risk-management measures (art 21) and incident reporting (art 23).
The key question for most Polish businesses is simple: am I in scope at all, and if so, as a podmiot kluczowy or a podmiot ważny? Three factors decide this — your sector (Annex 1 or Annex 2 of the law), your size, and certain special rules that apply regardless of size.
Who is a podmiot kluczowy (essential entity)?
Under uKSC art. 5 ust. 1, a podmiot kluczowy includes, among others:
- A natural person, legal person or organisational unit without legal personality listed in Annex 1 (załącznik nr 1) to the law that exceeds the requirements for a medium-sized enterprise as defined in art. 2 ust. 1 of Annex I to Commission Regulation (EU) No 651/2014.
- An electronic communications operator that at least meets or exceeds the medium-sized enterprise threshold.
- A managed cybersecurity services provider that at least meets or exceeds the small or medium-sized enterprise threshold.
In addition, the following are podmioty kluczowe regardless of size (uKSC art. 5 ust. 1 pkt 4):
- DNS service providers
- Qualified trust service providers (within the meaning of art. 3 pkt 20 of Regulation 910/2014)
- Critical entities (podmiot krytyczny)
- Public entities listed in Annex 1 within the public entities sector
- Entities identified as key on the basis of art. 7l ust. 2 pkt 1, or state legal persons identified under art. 7m
- Operators of a nuclear power facility as referred to in the relevant nuclear investment act
- Top-level domain (TLD) name registries and domain name registration service providers
In short: if you are in an Annex 1 sector and larger than a medium enterprise, you are typically a podmiot kluczowy — but several roles (DNS, TLD, qualified trust services, etc.) are captured no matter how small you are.
Who is a podmiot ważny (important entity)?
Under uKSC art. 5 ust. 2, a podmiot ważny includes, among others:
- An entity listed in Annex 1 that meets the medium-sized enterprise threshold (art. 2 ust. 1 of Annex I to Regulation 651/2014) and is not a podmiot kluczowy.
- An entity listed in Annex 2 (załącznik nr 2) that meets or exceeds the medium-sized enterprise threshold and is not a podmiot kluczowy.
- A non-qualified trust service provider that is a micro, small or medium enterprise.
- An electronic communications operator that is a micro or small enterprise (art. 2 ust. 2 i 3 of Annex I to Regulation 651/2014).
- An investor in a nuclear power facility that has obtained the principal decision (decyzja zasadnicza) — regardless of size.
- Entities identified as important on the basis of art. 7l ust. 2 pkt 2.
- Non-business entities listed in Annex 2 by name or by type.
- A public entity that is not a podmiot kluczowy and is a local-government budgetary unit, budgetary establishment, cultural institution, or a public-utility company (within the meaning of art. 1 ust. 2 of the Act of 20 December 1996 on municipal management), where it performs a public task using information systems.
The practical distinction: podmiot ważny generally covers medium-sized organisations and Annex 2 sectors, while larger Annex 1 organisations tend to be podmiot kluczowy.
Why the classification matters: obligations and penalties
Both essential and important entities must implement cybersecurity risk-management measures and report significant incidents. Under the NIS2 Directive that Poland transposes:
- Risk-management measures (art 21) must follow an all-hazards approach and cover areas such as incident handling, business continuity, supply chain security, access control and multi-factor authentication (art 21(2)).
- Management bodies must approve and oversee these measures and can be held liable for infringements (art 20(1)).
Incident reporting timelines (uKSC art. 11 ust. 1):
| Step | Deadline | Reference |
|---|---|---|
| Early warning of a major incident | within 24 hours of detection | art. 11 ust. 1 pkt 4 |
| Incident notification | within 72 hours of detection | art. 11 ust. 1 pkt 4a |
| Periodic report | on request of the sectoral CSIRT | art. 11 ust. 1 pkt 4b |
| Final report | within one month of the notification | art. 11 ust. 1 pkt 4c |
Reports go to the relevant CSIRT sektorowy. The competent authority and any registration obligation depend on the sector (a multi-authority model) and should be confirmed with a partner lawyer.
Financial penalties differ by category:
- Podmiot kluczowy (uKSC art. 73 ust. 3): up to EUR 10 000 000 or 2% of annual turnover, whichever is higher; not less than PLN 20 000.
- Podmiot ważny (uKSC art. 73 ust. 4): up to EUR 7 000 000 or 1,4% of annual turnover; not less than PLN 15 000.
- Where a breach causes a serious cyber threat to state security or public order, or risks serious material damage, the competent authority may impose a penalty of up to PLN 100 000 000 (uKSC art. 73 ust. 5).
Not sure which Annex your sector falls under, or whether you cross the size threshold? Use our free scoping and gap tool to self-identify and see where you stand before the deadlines apply.
Frequently asked questions
How do I know if I am a podmiot kluczowy or a podmiot ważny?
It depends on three things: your sector (whether you appear in Annex 1 or Annex 2 to the uKSC), your size measured against the medium-sized enterprise definition in Regulation (EU) No 651/2014, and special rules. Broadly, larger Annex 1 organisations are podmiot kluczowy (art. 5 ust. 1), while medium-sized organisations and Annex 2 sectors tend to be podmiot ważny (art. 5 ust. 2). Some roles, such as DNS providers, TLD registries and qualified trust service providers, are essential regardless of size.
Are small companies ever in scope of the Polish NIS2 law?
Yes, in specific cases. Even though the general threshold references the medium-sized enterprise size, the uKSC brings certain organisations into scope regardless of size — for example DNS service providers, qualified trust service providers, TLD registries, critical entities and certain nuclear-sector entities (art. 5 ust. 1 pkt 4). Non-qualified trust service providers and micro/small electronic communications operators can also be podmiot ważny (art. 5 ust. 2).
What are the incident reporting deadlines under the uKSC?
For a major incident, entities must submit an early warning within 24 hours of detection (art. 11 ust. 1 pkt 4), a full notification within 72 hours (art. 11 ust. 1 pkt 4a), and a final report within one month of the notification (art. 11 ust. 1 pkt 4c). Reports are made to the relevant sectoral CSIRT (CSIRT sektorowy).
What penalties apply if we fail to comply?
A podmiot kluczowy can face up to EUR 10 000 000 or 2% of annual turnover, whichever is higher (art. 73 ust. 3). A podmiot ważny can face up to EUR 7 000 000 or 1,4% of annual turnover (art. 73 ust. 4). In cases causing a serious cyber threat to state security or public order, penalties of up to PLN 100 000 000 may apply (art. 73 ust. 5).
Check your NIS2 compliance
This article is general information, not legal advice. A partner lawyer confirms your specific situation.