NIS2 in Poland: Who Is in Scope Under the uKSC?

Published: · AIPOS OÜ · nis2europe.eu

What law transposes NIS2 in Poland?

Poland implements the NIS2 Directive through the Ustawa o krajowym systemie cyberbezpieczeństwa (uKSC), as amended (Dz.U. 2026 poz. 252). The law divides organisations into two statutory categories:

Which category you fall into determines the intensity of supervision and the level of financial penalties that apply. Both categories must meet the core obligations under the underlying NIS2 Directive (EU) 2022/2555, including cybersecurity risk-management measures (art 21) and incident reporting (art 23).

The key question for most Polish businesses is simple: am I in scope at all, and if so, as a podmiot kluczowy or a podmiot ważny? Three factors decide this — your sector (Annex 1 or Annex 2 of the law), your size, and certain special rules that apply regardless of size.

Who is a podmiot kluczowy (essential entity)?

Under uKSC art. 5 ust. 1, a podmiot kluczowy includes, among others:

In addition, the following are podmioty kluczowe regardless of size (uKSC art. 5 ust. 1 pkt 4):

In short: if you are in an Annex 1 sector and larger than a medium enterprise, you are typically a podmiot kluczowy — but several roles (DNS, TLD, qualified trust services, etc.) are captured no matter how small you are.

Who is a podmiot ważny (important entity)?

Under uKSC art. 5 ust. 2, a podmiot ważny includes, among others:

The practical distinction: podmiot ważny generally covers medium-sized organisations and Annex 2 sectors, while larger Annex 1 organisations tend to be podmiot kluczowy.

Why the classification matters: obligations and penalties

Both essential and important entities must implement cybersecurity risk-management measures and report significant incidents. Under the NIS2 Directive that Poland transposes:

Incident reporting timelines (uKSC art. 11 ust. 1):

StepDeadlineReference
Early warning of a major incidentwithin 24 hours of detectionart. 11 ust. 1 pkt 4
Incident notificationwithin 72 hours of detectionart. 11 ust. 1 pkt 4a
Periodic reporton request of the sectoral CSIRTart. 11 ust. 1 pkt 4b
Final reportwithin one month of the notificationart. 11 ust. 1 pkt 4c

Reports go to the relevant CSIRT sektorowy. The competent authority and any registration obligation depend on the sector (a multi-authority model) and should be confirmed with a partner lawyer.

Financial penalties differ by category:

Not sure which Annex your sector falls under, or whether you cross the size threshold? Use our free scoping and gap tool to self-identify and see where you stand before the deadlines apply.

Frequently asked questions

How do I know if I am a podmiot kluczowy or a podmiot ważny?

It depends on three things: your sector (whether you appear in Annex 1 or Annex 2 to the uKSC), your size measured against the medium-sized enterprise definition in Regulation (EU) No 651/2014, and special rules. Broadly, larger Annex 1 organisations are podmiot kluczowy (art. 5 ust. 1), while medium-sized organisations and Annex 2 sectors tend to be podmiot ważny (art. 5 ust. 2). Some roles, such as DNS providers, TLD registries and qualified trust service providers, are essential regardless of size.

Are small companies ever in scope of the Polish NIS2 law?

Yes, in specific cases. Even though the general threshold references the medium-sized enterprise size, the uKSC brings certain organisations into scope regardless of size — for example DNS service providers, qualified trust service providers, TLD registries, critical entities and certain nuclear-sector entities (art. 5 ust. 1 pkt 4). Non-qualified trust service providers and micro/small electronic communications operators can also be podmiot ważny (art. 5 ust. 2).

What are the incident reporting deadlines under the uKSC?

For a major incident, entities must submit an early warning within 24 hours of detection (art. 11 ust. 1 pkt 4), a full notification within 72 hours (art. 11 ust. 1 pkt 4a), and a final report within one month of the notification (art. 11 ust. 1 pkt 4c). Reports are made to the relevant sectoral CSIRT (CSIRT sektorowy).

What penalties apply if we fail to comply?

A podmiot kluczowy can face up to EUR 10 000 000 or 2% of annual turnover, whichever is higher (art. 73 ust. 3). A podmiot ważny can face up to EUR 7 000 000 or 1,4% of annual turnover (art. 73 ust. 4). In cases causing a serious cyber threat to state security or public order, penalties of up to PLN 100 000 000 may apply (art. 73 ust. 5).

Check your NIS2 compliance

Start the free scoping test

Run the free gap analysis Run the free surface scan

This article is general information, not legal advice. A partner lawyer confirms your specific situation.

Back to home