NIS2/KSC · Manufacturing

NIS2 and the KSC Act in manufacturing

In Poland, NIS2 in the manufacturing sector applies to medium-sized and large manufacturers listed in Annex 2 to the National Cybersecurity System Act (KSC Act): makers of medical devices, computers and electronics, electrical equipment, machinery, motor vehicles and other transport equipment, as well as chemicals and food. They are important entities. We show how to check whether a manufacturing plant is in scope, what its obligations are and what this means for OT systems.

01Status

NIS2 in the manufacturing sector: which plants are in scope

Manufacturing, chemicals and food are among the other critical sectors (Annex 2). What matters is the type of production and the size of the company.

Type of production

The Act does not cover the whole of industry. The “Manufacturing” sector includes medical devices and in vitro diagnostic medical devices, as well as divisions 26-30 of section C of the NACE classification: computers, electronic and optical products; electrical equipment; machinery and equipment; motor vehicles, trailers and semi-trailers; and other transport equipment. Chemicals (the manufacture and distribution of substances and mixtures, and the production of articles from them) and food are separate sectors - but the food sector covers only wholesale distribution and industrial production and processing. According to the Ministry of Digital Affairs, restaurants and food retail do not belong to the sector (Q&A, question 1.47).

The activity is determined on the basis of PKD codes (the Polish classification of activities, based on NACE), licences and permits. The Act covers every activity listed in the annexes, both principal and ancillary (for water, waste water and waste, the annex requires the activity to be a principal or essential part of the business); several types of activity are shown separately in the application for registration (Art. 7d(2); Ministry of Digital Affairs, KSC amendment Q&A, question 2.8).

Size

A manufacturer in these sectors is an important entity if it is at least a medium-sized enterprise: it employs at least 50 people, or both its turnover and its balance sheet total exceed EUR 10 million (Art. 5(2)(2)). A plant that belongs to an international group often exceeds the thresholds even if it is small on its own: size is calculated together with linked and partner enterprises; an entity that exceeds a threshold only because of them is not, on that basis, an essential or important entity if its information system is independent of theirs or it does not provide services jointly with them (Art. 5(6)-(7)).

According to the Ministry of Digital Affairs, size status changes only when the thresholds are exceeded (or no longer reached) in two consecutive financial years - as under Regulation 651/2014; the criteria are assessed as at the date on which the financial statements are prepared (Art. 4(2) of Annex I to Regulation (EU) No 651/2014, Art. 5(5) of the KSC Act; Ministry of Digital Affairs, Q&A of 1 October 2026, question 1.46).

You can check your status with our NIS2 scope checker, which includes questions about your group of companies.

Types of entity in the manufacturing, chemicals and food sectors (Annex 2 to the KSC Act)
Type of entity When it is subject to the Act Legal basis
Manufacture or distribution of chemical substances and mixtures, or production of articles from them Medium-sized and large enterprise - important Annex 2, Manufacture, production and distribution of chemicals sector (REACH Regulation)
Wholesale distribution or industrial production and processing of food Medium-sized and large enterprise - important Annex 2, Production, processing and distribution of food sector
Manufacture of medical devices or in vitro diagnostic medical devices Medium-sized and large enterprise - important Annex 2, Manufacturing sector, Manufacture of medical devices and in vitro diagnostic medical devices subsector
Manufacture of computer, electronic and optical products Medium-sized and large enterprise - important Annex 2, Manufacturing sector (NACE Rev. 2, section C, division 26)
Manufacture of electrical equipment Medium-sized and large enterprise - important Annex 2, Manufacturing sector (NACE Rev. 2, section C, division 27)
Manufacture of machinery and equipment Medium-sized and large enterprise - important Annex 2, Manufacturing sector (NACE Rev. 2, section C, division 28)
Manufacture of motor vehicles, trailers and semi-trailers Medium-sized and large enterprise - important Annex 2, Manufacturing sector (NACE Rev. 2, section C, division 29)
Manufacture of other transport equipment Medium-sized and large enterprise - important Annex 2, Manufacturing sector (NACE Rev. 2, section C, division 30)

02Obligations

A manufacturer's obligations as an important entity

What must be in place by 3 April 2027

  • an application for registration in the S46 system - the deadline for companies that met the criteria on 3 April 2026 passed on 3 October 2026, but registration is declaratory, so apply without delay,
  • an information security management system under Art. 8: risk assessment, policies, business continuity, supply chain security, monitoring, cryptography and access control,
  • a procedure for handling and reporting significant incidents within 24 and 72 hours and one month,
  • documentation, contact persons and annual training for the board (Art. 8e).

Supervision and audit

The authority supervises important entities ex post - particularly where an infringement is suspected. A manufacturer is not subject to a recurring Art. 15 audit; the authority may order one after a significant incident or another infringement (Art. 15(1b)). An important entity faces a fine of up to EUR 7 million or 1.4% of revenue from business activity in the previous financial year; not less than PLN 15,000. Fines under Art. 73(1)-(4), Arts. 73a-73c and Art. 76b may be imposed for the first time 2 years after the amendment entered into force (according to the Ministry of Digital Affairs - after 3 April 2028). The moratorium does not cover the fine of up to PLN 100 million (Art. 35 of the amending act).

Competent authority

For manufacturing and chemicals, the competent authority is the minister responsible for the economy; for medical devices, the minister responsible for health; and for food, the minister responsible for agriculture (Arts. 41 and 41a). Incidents are reported through S46; until the sectoral computer security incident response team (CSIRT) announces its readiness, they go to the national-level CSIRTs (Art. 44 of the amending act).

03Risks

OT systems, the supply chain and risks in the plant

Systems to include in the risk analysis

  • OT and production control - controllers, SCADA and HMI systems, often older and difficult to update.
  • MES and ERP - production planning and costing, integrations with customer and supplier systems.
  • Remote servicing - machine suppliers connect to production lines; every such connection needs to be controlled.
  • Quality and documentation systems - in the production of medical devices and food, also needed for compliance with other regulations.

The most common sources of risk

  • no separation between the production network and the office network,
  • shared service accounts and remote access without multi-factor authentication,
  • no plan for what to do when a line stops because of an incident,
  • customer requirements: essential and important entities assess the security of their suppliers (Art. 8(2)) and increasingly write these requirements into contracts.

The industry standard for the security of industrial automation and control systems is the IEC 62443 series - the Act does not require it, but it helps to bring structure to OT security.

04Products

NIS2 and the Cyber Resilience Act (CRA)

A manufacturer of machinery, electrical equipment or electronics with software often has to deal with two regimes at once. The KSC Act concerns the organisation: its systems, its processes and incident reporting. The Cyber Resilience Act (CRA, Regulation (EU) 2024/2847) concerns products with digital elements placed on the market. The CRA covers software and hardware products that connect to a device or network and are made available on the market in the course of a commercial activity, together with their remote data processing solutions (Art. 2(1) and Art. 3(1), (2) and (22) CRA).

  • The obligation to report actively exploited vulnerabilities and severe incidents applies from 11 September 2026, including to products placed on the market earlier (Arts. 71(2) and 69(3) CRA).
  • The remaining CRA obligations, including the essential cybersecurity requirements in Annex I, apply from 11 December 2027 (Art. 71(2) CRA).
  • The manufacturer carries out effective and regular security tests and reviews of the product (Annex I, Part II, point 3 CRA).

We build security into software products from the design stage - see secure by design software development.

05How we help

Gap analysis, implementation and testing for manufacturers

  • NIS2 gap analysis - scope assessment (including within a group of companies), a review of the gaps against Art. 8 and an implementation plan to meet the 3 April 2027 deadline.
  • NIS2 implementation - policies, incident and business continuity procedures, and requirements for suppliers and machine service providers.
  • Infrastructure and network penetration testing - including the boundary between the office and production networks.
  • Board training - the duties of the head of the entity under Arts. 8c-8e.

We also build software for manufacturing and logistics companies - system integrations and applications for plants and warehouses: see manufacturing and logistics software development.

All the obligations, with questions to check against, are collected in our printable NIS2/KSC checklist.

Frequently asked questions

Is every manufacturing company subject to NIS2?

No. Annex 2 lists specific types of manufacturing: medical devices and in vitro diagnostic medical devices, divisions 26-30 of the NACE classification (electronics, electrical equipment, machinery, motor vehicles, other transport equipment) and, as separate sectors, chemicals and food (wholesale distribution and industrial production and processing). A manufacturer in these areas is subject to the Act if it is at least a medium-sized enterprise - counted together with linked and partner enterprises. Furniture or textile manufacturing, for example, does not appear in the annexes.

Can a manufacturing plant be an essential entity?

Not under the general rule - the Annex 2 sectors make even large companies important entities (Art. 5(2)(2)). A manufacturer will be an essential entity if it also carries out an activity listed in Annex 1 (e.g. it generates energy under a licence and is large), if it is recognised as a critical entity, or if the authority designates it as an essential entity by a decision under Art. 7l.

How do we check whether our activity falls within NACE divisions 26-30?

The Ministry of Digital Affairs recommends starting with the PKD codes (the Polish classification of activities, based on NACE) declared in the business register, and with your licences and permits (Q&A of 1 October 2026, question 1.1). The Act covers an activity listed in the annexes whether it is the principal or an ancillary activity (question 2.8). If machinery or electronics manufacturing is only part of your business, you should still assess it. An example from the Q&A: a cosmetics manufacturer that makes its products from chemical substances belongs to the chemicals sector (question 1.48).

Are OT and production control systems covered by the Act?

The information security management system covers the information system used in the processes that affect the provision of the service (Art. 8(1)). In a manufacturing plant, this usually means not only the office systems and the ERP, but also the MES, SCADA systems and controllers on which production depends. Define the scope in your risk assessment and document it, so that you can defend it during an inspection.

How does NIS2 differ from the Cyber Resilience Act (CRA)?

The KSC Act regulates the security of the organisation - its systems and processes. The CRA regulates the security of products with digital elements that a manufacturer places on the market: design requirements, vulnerability handling and reporting. A manufacturer of machinery or equipment with software may be subject to both at the same time.

Sources

  1. Act of 23 January 2026 amending the National Cybersecurity System Act and certain other acts (Dz.U. 2026 item 252) (in Polish) ()
  2. National Cybersecurity System Act - act metadata and amending acts (Sejm ELI API) (in Polish) ()
  3. Ministry of Digital Affairs - Q&A on the amendment to the KSC Act, October 2026 update (1 October 2026; explanatory document, not legally binding) (in Polish) ()
  4. Commission Regulation (EU) No 651/2014 of 17 June 2014 declaring certain categories of aid compatible with the internal market in application of Articles 107 and 108 of the Treaty, Annex I - SME definition (OJ L 187, 26.6.2014) ()
  5. Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024 on horizontal cybersecurity requirements for products with digital elements (Cyber Resilience Act, CRA), OJ L, 2024/2847 ()

Legal status as of Updated

Related services

Let's talk about your project or audit

Tell us briefly what you need - we will come back with proposed next steps. We work in English and Polish.

or call +48 575 621 877