Law, a statutory obligation

NIS 2 (Polish KSC act)

NIS 2 is the EU cybersecurity directive (Directive (EU) 2022/2555) covering 18 sectors of the economy. It obliges essential and important entities to manage cyber risk, report incidents within strict deadlines and hold management personally accountable — with fines of up to EUR 10 million or 2% of worldwide turnover.

Start assessmentRead about the standard
67
controls in Guardiso
32
free-test questions
PL · EN
two languages

What is NIS 2?

NIS 2 is Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 on measures for a high common level of cybersecurity across the Union. It replaces the original 2016 NIS Directive, significantly broadening the range of covered entities, harmonising requirements across the Union and tightening supervision and sanctions. Member states were required to transpose it into national law by 17 October 2024.

In Poland, NIS 2 is implemented through an amendment to the Act on the National Cybersecurity System (UKSC). It is this national act — not the directive itself — that sets the final catalogue of obligations, registration deadlines, competent CSIRTs and supervisory authorities for each sector.

Who does it apply to?

NIS 2 divides covered organisations into essential and important entities — the categories differ in supervision intensity and fine levels. The directive covers 18 sectors: 11 sectors of high criticality (including energy, transport, banking, financial market infrastructure, health, drinking water, waste water, digital infrastructure, ICT service management, public administration and space) and 7 other critical sectors (including postal and courier services, waste management, chemicals, food, manufacturing, digital providers and research).

As a rule a size-cap applies: the directive covers medium and large enterprises — those with at least 50 employees or at least EUR 10 million in annual turnover. Regardless of size, however, entities of particular importance may be covered — for example DNS service providers, top-level domain registries, trust service providers or entities designated as critical by the state. In practice requirements also cascade to smaller suppliers through their customers’ supply chain security obligations.

Key obligations

The core of the directive is Article 21, which requires appropriate and proportionate cybersecurity risk-management measures, and Article 23, which sets out a multi-stage scheme for reporting significant incidents.

  • Article 21 measures: risk analysis and system security policies, incident handling, business continuity and crisis management (backups, DR), supply chain security, secure acquisition and development of systems, effectiveness assessment of measures, cyber hygiene and training, cryptography and encryption, human resources security and access control, multi-factor authentication and secured communications.
  • Significant incident reporting in three steps: an early warning to the CSIRT within 24 hours of awareness, a full incident notification within 72 hours, and a final report within one month (with progress reports for ongoing incidents).
  • Management accountability: management bodies must approve risk-management measures, oversee their implementation and can be held personally liable for infringements.
  • Mandatory cybersecurity training for management body members and regular training for employees.
  • Registration of the entity in the relevant national list and cooperation with supervisory authorities and CSIRTs as required by national law.

Incident reporting deadlines step by step

The Article 23 reporting scheme applies to significant incidents — those that have caused or are capable of causing severe operational disruption of services or financial loss for the entity, or that have affected or are capable of affecting other natural or legal persons by causing considerable damage. Crucially, the clock starts from "becoming aware" of the incident — so the procedure must clearly define who determines that an incident is significant, and on what basis, including at night and on weekends.

  • Step 1 — early warning, within 24 hours of becoming aware: a short notification to the competent CSIRT indicating whether the incident is suspected to result from unlawful or malicious action and whether it could have cross-border impact.
  • Step 2 — incident notification, within 72 hours: an update of the early warning information plus an initial assessment of the incident — its severity, impact and, where available, indicators of compromise.
  • Step 3 — intermediate report, upon CSIRT request: status updates during incident handling, if the CSIRT or authority asks for them.
  • Step 4 — final report, within 1 month of the incident notification: a detailed description of the incident (severity and impact), the type of threat and root cause, applied and ongoing mitigation measures, and — where applicable — cross-border impact. If the incident is still ongoing, a progress report is submitted instead, with the final report due within one month of the incident being handled.
  • In parallel — service recipients: where applicable, the entity informs the recipients of its services without undue delay about a significant incident that may adversely affect service provision, and about a significant cyber threat — including possible remedial measures the recipients can take.
  • Beware of overlapping obligations: if the incident involves personal data, the separate 72-hour GDPR deadline for notifying the data protection authority runs independently — these are two distinct notifications to two different authorities.

Penalties

NIS 2 introduces administrative fines comparable to GDPR levels, differentiated by entity category. In addition, supervisory authorities can impose measures such as binding instructions and remediation orders, and for essential entities even temporary suspension of certifications or management accountability measures.

  • Essential entities: fines of up to EUR 10,000,000 or 2% of total annual worldwide turnover — whichever is higher.
  • Important entities: fines of up to EUR 7,000,000 or 1.4% of total annual worldwide turnover — whichever is higher.
  • Possible personal liability of managers, including a temporary ban from exercising managerial functions in essential entities.

NIS 2 and the Polish act (UKSC)

The NIS 2 Directive does not apply to companies directly — it operates through national law. In Poland that role is played by the Act on the National Cybersecurity System (UKSC), amended to implement NIS 2. The EU transposition deadline passed on 17 October 2024, and the Polish legislative process has run long — which does not change the fact that the Article 21 catalogue of measures forms the core of the act’s requirements, and they can (indeed should) be implemented without waiting for the final legislative amendments.

It is the national act that settles what the directive leaves open: how essential and important entities are identified and registered, the deadlines for fulfilling obligations, the competent national-level CSIRTs (CSIRT NASK, CSIRT GOV, CSIRT MON), the authorities responsible for each sector, and the detailed procedure for incident reporting and imposing fines. For companies this means two layers of work: the substantive layer (Article 21 measures — common across the Union) and the formal layer (registration, the competent CSIRT, deadlines — set by the Polish act).

Guardiso maps both layers: the compliance module contains the full catalogue of 261 requirements of the Polish Act on the National Cybersecurity System — a complete mapping of the law, not a summary — cross-mapped to ISO/IEC 27001 controls, so work done in your information security management system counts towards the statutory requirements.

How to prepare in 90 days

Full NIS 2 compliance is a programme measured in months, but a solid foundation — one that survives a first inspection and a real incident — can be built in three months, working in 30-day stages. The order matters: first, knowledge of your own situation and management accountability; then the processes with hard statutory deadlines; finally suppliers, training and effectiveness verification.

  • Days 1-30 — reconnaissance and foundation: determine your entity status (essential or important) and complete registration; run a gap analysis against the Article 21 measures; assign accountability — a board resolution approving the programme and a designated cybersecurity coordinator; inventory key services, systems and assets.
  • Days 31-60 — processes with hard deadlines: adopt the security policy and risk assessment methodology and perform the first assessment; implement the incident handling and reporting procedure with the 24h/72h/1-month deadlines (significant incident criteria, on-call arrangements, report templates, contact details of the competent CSIRT); put backups and the business continuity plan in order; enforce MFA for remote and administrative access.
  • Days 61-90 — suppliers, people and verification: classify suppliers and add security clauses to contracts; train the board and employees; exercise the incident reporting process against a scenario (a tabletop exercise timing the path to 24h); perform the first effectiveness assessment of the measures and present the board with a report and a plan of further actions.
  • After 90 days: the system must run in cycles — recurring risk assessments, access reviews, restore tests, annual training and regular board reports. The free NIS 2 self-assessment in Guardiso shows your starting point and generates the gap list worth starting from on day one.

How does Guardiso help?

Guardiso guides you through NIS 2 compliance from the first question — "does this even apply to me?" — to day-to-day management of the obligations. The free NIS 2 qualifier assesses within minutes whether your organisation is an essential or important entity and which obligations apply. The compliance module contains the full catalogue of 261 requirements of the Polish Act on the National Cybersecurity System — a complete mapping of the law, not a summary — cross-mapped to ISO/IEC 27001 controls, so your existing management system feeds your NIS 2 compliance.

For digital service providers Guardiso offers a dedicated module for Implementing Regulation 2024/2690, which details the technical requirements for that group. Built-in incident management tracks the statutory 24-hour, 72-hour and one-month deadlines — with ready-made report templates and an incident timeline — while the compliance dashboard shows management the current implementation status, supporting the oversight the directive requires.

Official sources
Step 1: Not sure whether NIS 2 applies to you at all?
Take the free qualifier (~2 minutes) — sector and company size decide. The readiness test below is Step 2.
Open the qualifier →
01Select standard›02Complete the self assessment›03Close gaps in Guardiso
—
NIS 2 (Polish KSC act) readiness score
0/32 answered
The score updates live as you answer.

Other standards to assess

ISO 27001GlobalGDPREUSOC 2GlobalDORAEUTISAXAutomotiveISO 9001GlobalISO 42001 (AI)GlobalKRIPLPCI DSSGlobalNIST CSFUSANIST 800-53USAHIPAAUSACMMC 2.0USACyber EssentialsUKSOX ITGCUSABIO2NLEU AI ActEUISO 27701GlobalISO 22301GlobalISO 14001GlobalISO 45001GlobalISO 13485MedicalIEC 62304MedicalMDREU · MedicalISO 14971MedicalDCB0129UKMiCAEUIEC 62443GlobalISO 21434Automotive
Browse all 30 standards