NIS2/KSC · Gap analysis
Gap analysis
NIS2 gap analysis against the Polish KSC Act: scope, method, gap report, compliance matrix and an implementation plan to meet the 3 April 2027 deadline.
NIS2/KSC · Manufacturing
In Poland, NIS2 in the manufacturing sector applies to medium-sized and large manufacturers listed in Annex 2 to the National Cybersecurity System Act (KSC Act): makers of medical devices, computers and electronics, electrical equipment, machinery, motor vehicles and other transport equipment, as well as chemicals and food. They are important entities. We show how to check whether a manufacturing plant is in scope, what its obligations are and what this means for OT systems.
01Status
Manufacturing, chemicals and food are among the other critical sectors (Annex 2). What matters is the type of production and the size of the company.
The Act does not cover the whole of industry. The “Manufacturing” sector includes medical devices and in vitro diagnostic medical devices, as well as divisions 26-30 of section C of the NACE classification: computers, electronic and optical products; electrical equipment; machinery and equipment; motor vehicles, trailers and semi-trailers; and other transport equipment. Chemicals (the manufacture and distribution of substances and mixtures, and the production of articles from them) and food are separate sectors - but the food sector covers only wholesale distribution and industrial production and processing. According to the Ministry of Digital Affairs, restaurants and food retail do not belong to the sector (Q&A, question 1.47).
The activity is determined on the basis of PKD codes (the Polish classification of activities, based on NACE), licences and permits. The Act covers every activity listed in the annexes, both principal and ancillary (for water, waste water and waste, the annex requires the activity to be a principal or essential part of the business); several types of activity are shown separately in the application for registration (Art. 7d(2); Ministry of Digital Affairs, KSC amendment Q&A, question 2.8).
A manufacturer in these sectors is an important entity if it is at least a medium-sized enterprise: it employs at least 50 people, or both its turnover and its balance sheet total exceed EUR 10 million (Art. 5(2)(2)). A plant that belongs to an international group often exceeds the thresholds even if it is small on its own: size is calculated together with linked and partner enterprises; an entity that exceeds a threshold only because of them is not, on that basis, an essential or important entity if its information system is independent of theirs or it does not provide services jointly with them (Art. 5(6)-(7)).
According to the Ministry of Digital Affairs, size status changes only when the thresholds are exceeded (or no longer reached) in two consecutive financial years - as under Regulation 651/2014; the criteria are assessed as at the date on which the financial statements are prepared (Art. 4(2) of Annex I to Regulation (EU) No 651/2014, Art. 5(5) of the KSC Act; Ministry of Digital Affairs, Q&A of 1 October 2026, question 1.46).
You can check your status with our NIS2 scope checker, which includes questions about your group of companies.
| Type of entity | When it is subject to the Act | Legal basis |
|---|---|---|
| Manufacture or distribution of chemical substances and mixtures, or production of articles from them | Medium-sized and large enterprise - important | Annex 2, Manufacture, production and distribution of chemicals sector (REACH Regulation) |
| Wholesale distribution or industrial production and processing of food | Medium-sized and large enterprise - important | Annex 2, Production, processing and distribution of food sector |
| Manufacture of medical devices or in vitro diagnostic medical devices | Medium-sized and large enterprise - important | Annex 2, Manufacturing sector, Manufacture of medical devices and in vitro diagnostic medical devices subsector |
| Manufacture of computer, electronic and optical products | Medium-sized and large enterprise - important | Annex 2, Manufacturing sector (NACE Rev. 2, section C, division 26) |
| Manufacture of electrical equipment | Medium-sized and large enterprise - important | Annex 2, Manufacturing sector (NACE Rev. 2, section C, division 27) |
| Manufacture of machinery and equipment | Medium-sized and large enterprise - important | Annex 2, Manufacturing sector (NACE Rev. 2, section C, division 28) |
| Manufacture of motor vehicles, trailers and semi-trailers | Medium-sized and large enterprise - important | Annex 2, Manufacturing sector (NACE Rev. 2, section C, division 29) |
| Manufacture of other transport equipment | Medium-sized and large enterprise - important | Annex 2, Manufacturing sector (NACE Rev. 2, section C, division 30) |
02Obligations
The authority supervises important entities ex post - particularly where an infringement is suspected. A manufacturer is not subject to a recurring Art. 15 audit; the authority may order one after a significant incident or another infringement (Art. 15(1b)). An important entity faces a fine of up to EUR 7 million or 1.4% of revenue from business activity in the previous financial year; not less than PLN 15,000. Fines under Art. 73(1)-(4), Arts. 73a-73c and Art. 76b may be imposed for the first time 2 years after the amendment entered into force (according to the Ministry of Digital Affairs - after 3 April 2028). The moratorium does not cover the fine of up to PLN 100 million (Art. 35 of the amending act).
For manufacturing and chemicals, the competent authority is the minister responsible for the economy; for medical devices, the minister responsible for health; and for food, the minister responsible for agriculture (Arts. 41 and 41a). Incidents are reported through S46; until the sectoral computer security incident response team (CSIRT) announces its readiness, they go to the national-level CSIRTs (Art. 44 of the amending act).
03Risks
The industry standard for the security of industrial automation and control systems is the IEC 62443 series - the Act does not require it, but it helps to bring structure to OT security.
04Products
A manufacturer of machinery, electrical equipment or electronics with software often has to deal with two regimes at once. The KSC Act concerns the organisation: its systems, its processes and incident reporting. The Cyber Resilience Act (CRA, Regulation (EU) 2024/2847) concerns products with digital elements placed on the market. The CRA covers software and hardware products that connect to a device or network and are made available on the market in the course of a commercial activity, together with their remote data processing solutions (Art. 2(1) and Art. 3(1), (2) and (22) CRA).
We build security into software products from the design stage - see secure by design software development.
05How we help
We also build software for manufacturing and logistics companies - system integrations and applications for plants and warehouses: see manufacturing and logistics software development.
All the obligations, with questions to check against, are collected in our printable NIS2/KSC checklist.
No. Annex 2 lists specific types of manufacturing: medical devices and in vitro diagnostic medical devices, divisions 26-30 of the NACE classification (electronics, electrical equipment, machinery, motor vehicles, other transport equipment) and, as separate sectors, chemicals and food (wholesale distribution and industrial production and processing). A manufacturer in these areas is subject to the Act if it is at least a medium-sized enterprise - counted together with linked and partner enterprises. Furniture or textile manufacturing, for example, does not appear in the annexes.
Not under the general rule - the Annex 2 sectors make even large companies important entities (Art. 5(2)(2)). A manufacturer will be an essential entity if it also carries out an activity listed in Annex 1 (e.g. it generates energy under a licence and is large), if it is recognised as a critical entity, or if the authority designates it as an essential entity by a decision under Art. 7l.
The Ministry of Digital Affairs recommends starting with the PKD codes (the Polish classification of activities, based on NACE) declared in the business register, and with your licences and permits (Q&A of 1 October 2026, question 1.1). The Act covers an activity listed in the annexes whether it is the principal or an ancillary activity (question 2.8). If machinery or electronics manufacturing is only part of your business, you should still assess it. An example from the Q&A: a cosmetics manufacturer that makes its products from chemical substances belongs to the chemicals sector (question 1.48).
The information security management system covers the information system used in the processes that affect the provision of the service (Art. 8(1)). In a manufacturing plant, this usually means not only the office systems and the ERP, but also the MES, SCADA systems and controllers on which production depends. Define the scope in your risk assessment and document it, so that you can defend it during an inspection.
The KSC Act regulates the security of the organisation - its systems and processes. The CRA regulates the security of products with digital elements that a manufacturer places on the market: design requirements, vulnerability handling and reporting. A manufacturer of machinery or equipment with software may be subject to both at the same time.
NIS2/KSC · Gap analysis
NIS2 gap analysis against the Polish KSC Act: scope, method, gap report, compliance matrix and an implementation plan to meet the 3 April 2027 deadline.
NIS2/KSC · Implementation
NIS2 implementation step by step: registration, risk analysis, policies, technical measures, incidents, suppliers and audit, with a timeline to 3 April 2027.
NIS2/KSC scope checker
Does NIS2 apply to your company in Poland? Free scope checker: sector, size and Art. 5 exceptions under the KSC Act - with reasoning, obligations and deadlines.
Industries · Manufacturing and logistics
Software for manufacturing, transport and logistics: ERP, MES and WMS integration, systems for hauliers, shop-floor apps, NIS2/KSC and business continuity.
Tell us briefly what you need - we will come back with proposed next steps. We work in English and Polish.
or call +48 575 621 877