In Poland, three things decide whether NIS2 applies to your company - and whether you are an essential entity, an important entity or outside the scope of the National Cybersecurity System Act (KSC Act): the sector listed in an annex to the Act, the size of your organisation and the exceptions in Art. 5. Our scope checker takes you through these criteria in 3 minutes and shows the result with the legal provisions, obligations and deadlines. Your answers never leave your browser.
NIS2 scope assessment: is your organisation subject to the KSC Act?
Three steps: type of activity, size and special cases. At the end, you get a result with the reasoning, obligations and deadlines - ready to print or save as a PDF.
Prefer not to use the tool? See the decision tree - the same rules, with the legal provisions.
Step 1 of 3
What does your organisation do?
Choose your type of activity from the annexes to the Act. Type a word (e.g. hospital, municipality, DNS, railway) or browse the list. If you operate in several sectors, check each of them - the higher status applies.
The list has 74 entries in 19 groups.
Details and size of your organisation
Answer the questions that apply to the type of activity you have chosen. If you are not sure about something, select “I don't know” - we will show you what the result depends on.
Special cases
Decisions by the authorities and exceptions that change the status regardless of size.
Result
Why
Key obligations
Deadlines
Good to know
Your answers
The result is indicative and does not constitute legal advice. The final classification depends on the details of your activity and on decisions of the authorities. Legal status as of , rules version 1.0.
02-Scope
Who NIS2 and the KSC Act apply to: the sectors in the annexes
The NIS2 Directive sets a minimum standard for the whole EU, but in Poland the question of who is covered is decided by the National Cybersecurity System Act, as amended by the Act of 23 January 2026 (Dz.U. 2026 item 252), in force since 3 April 2026. Art. 5 of the Act divides organisations into essential entities and important entities. The starting point is always the type of activity listed in Annex 1 (sectors of high criticality) or Annex 2 (other critical sectors) - both annexes are summarised below, with examples of the types of entities they cover.
No decision by an authority is needed for the obligations to apply: an organisation checks for itself whether it meets the criteria and applies for entry in the register of essential and important entities on its own initiative. The Act covers every activity listed in the annexes, both principal and ancillary (for water, waste water and waste, the annex requires the activity to be a principal or essential part of the business); several types of activity are shown separately in the application for registration (Art. 7d(2); Ministry of Digital Affairs, KSC amendment Q&A, question 2.8).
Annex 1 - sectors of high criticality
Energy: extraction of minerals under a licence; electricity generation (licensed); electricity transmission or distribution (licensed); electricity trading (licensed) and others.
NIS2 in the energy sector
Transport: air carrier; airport managing body; ground handling and security screening at airports; air navigation service provider and others.
NIS2 in transport and logistics
Banking and financial market infrastructures: bank, credit institution, branch of a foreign bank, credit union (SKOK); financial market infrastructure.
Health: healthcare provider (hospital, outpatient clinic, other medical facility); subcontractor of essential or important entities in healthcare; designated EU reference laboratory; public health bodies and others.
NIS2 in hospitals
Drinking water and waste water: supplier of water intended for human consumption; waste water disposal or treatment.
Digital infrastructure: internet exchange point (IXP); provider of DNS services; top-level domain (TLD) name registry; domain name registration services and others.
NIS2 for IT service providers
ICT service management: managed service provider (MSP); managed security service provider (MSSP).
NIS2 for IT service providers
Space: operator of ground-based infrastructure supporting space-based services; The Polish Space Agency (POLSA).
Public administration: government administration and other public entities listed in Annex 1; regional (voivodeship) government: budgetary units and establishments; district (powiat) office; municipal (gmina) or city office.
NIS2 in local government
Annex 2 - other critical sectors
Local government budgetary units, cultural institutions and municipal companies: local government budgetary unit or establishment; local government cultural institution; municipal company performing public utility tasks.
NIS2 in local government
Nuclear energy investments: investor in a nuclear power facility.
Waste management: waste collection, transport or treatment, waste dealer or broker.
Chemicals: manufacture or distribution of chemical substances and mixtures, or production of articles from them.
Food: wholesale distribution or industrial production and processing of food.
Manufacturing: manufacture of medical devices or in vitro diagnostic medical devices; manufacture of computer, electronic and optical products; manufacture of electrical equipment; manufacture of machinery and equipment and others.
NIS2 in manufacturing
Digital providers: provider of an online marketplace; provider of an online search engine; provider of a social networking services platform.
Research: research organisation; higher education institution, the Polish Academy of Sciences (PAN) and its institutes, the Łukasiewicz Research Network.
03-Size
Size criteria: staff headcount, turnover and groups of companies
Size is determined using the SME definition in Commission Regulation (EU) No 651/2014 - the same thresholds you may know from EU grant programmes.
Enterprise size thresholds (Art. 2 of Annex I to Regulation 651/2014)
Size
Staff headcount
Turnover or balance sheet total
Micro
fewer than 10 people
turnover or balance sheet total up to EUR 2 million
Small
fewer than 50 people
turnover or balance sheet total up to EUR 10 million
Medium-sized
fewer than 250 people
turnover up to EUR 50 million or balance sheet total up to EUR 43 million
Large
250 people or more
above the thresholds for a medium-sized enterprise
How to calculate size
You must stay within the staff headcount ceiling, but only within one of the two financial ceilings - a company with 30 staff, EUR 60 million in turnover and a balance sheet total of EUR 30 million is therefore medium-sized, not large. Staff are counted in annual work units: employees, persons working for the enterprise who are considered employees, owner-managers and partners - excluding apprentices and students as well as periods of maternity and parental leave. According to the Ministry of Digital Affairs, persons working under mandate contracts, agency contracts and contracts for specific work are also included (Art. 5 of Annex I to Regulation (EU) No 651/2014; Ministry of Digital Affairs, Q&A, question 1.5).
According to the Ministry of Digital Affairs, a healthcare provider that is not a business counts all persons engaged - under employment contracts and civil-law contracts, full-time and part-time - as at the date on which the financial statements are prepared; an independent public healthcare institution (SP ZOZ) employing fewer than 50 people is not subject to the Act (Art. 5(5) and (8); Ministry of Digital Affairs, Q&A of 1 October 2026, questions 3.20 and 3.23).
According to the Ministry of Digital Affairs, size status changes only when the thresholds are exceeded (or no longer reached) in two consecutive financial years - as under Regulation 651/2014; the criteria are assessed as at the date on which the financial statements are prepared (Art. 4(2) of Annex I to Regulation (EU) No 651/2014, Art. 5(5) of the KSC Act; Ministry of Digital Affairs, Q&A of 1 October 2026, question 1.46).
Groups of companies
A partner enterprise means a holding of at least 25% of the capital or voting rights; a linked enterprise means, among other things, a majority of voting rights or a dominant influence. The data of partner enterprises is added in proportion to the holding, and that of linked enterprises in full (Arts. 3 and 6 of Annex I to Regulation (EU) No 651/2014). Size is calculated together with linked and partner enterprises; an entity that exceeds a threshold only because of them is not, on that basis, an essential or important entity if its information system is independent of theirs or it does not provide services jointly with them (Art. 5(6)-(7)).
According to the Ministry of Digital Affairs, if the entity does not provide the same service covered by the Act together with a partner or linked enterprise, the data of that enterprise is not included when determining size - this should be documented (Ministry of Digital Affairs, KSC amendment Q&A, question 1.6 (not legally binding)). The scope checker asks separately about the size of the organisation itself and about the independence of its information system, and if you answer “I don't know”, it shows both possible results.
04-Status
Essential or important entity: what difference the status makes
Most obligations are the same for both: an information security management system, incident reporting, documentation, contact persons and annual training for the head of the entity. The differences lie in the audit, the type of supervision and the fines. The full comparison of obligations is in our guide to the NIS2 audit and the KSC Act.
Key differences (Arts. 15, 53 and 73 of the KSC Act)
Area
Essential entity
Important entity
Security audit (Art. 15)
At least once every 3 years, at own expense; copy of the report to the authority within 3 working days
Only when ordered by the authority - after a significant incident or other infringement
Supervision (Art. 53(3))
Ex ante and ex post
Ex post, particularly where an infringement is suspected
Maximum fine (Art. 73)
EUR 10 million or 2% of revenue (whichever is higher), min. PLN 20,000
EUR 7 million or 1.4% of revenue, min. PLN 15,000
05-Exceptions
Exceptions to the size rule and exclusions
Entities covered regardless of size
DNS service providers, top-level domain name registries and domain name registration service providers
qualified trust service providers
critical entities within the meaning of Directive (EU) 2022/2557 (CER)
public entities listed in Annex 1
managed security service providers - from small enterprise size upwards
electronic communications undertakings - from medium-sized enterprise size upwards (smaller ones are important entities)
entities designated by a decision of the authority, e.g. the sole provider of a service essential for societal or economic activity
The authority may also, by decision, designate a small entity listed in an annex as an essential or important entity - for example, if it is the sole provider of an essential service or is of significant importance for its region (voivodeship) or for the country as a whole (Art. 7l).
Exclusions and special cases
Special services and entities subordinate to or supervised by the Minister of National Defence are not essential or important entities; the minister designates, by a decision that is not published, the units that are considered to be such entities (Art. 5(10)-(11)).
The Act does not apply to entities performing medical activities that are established by the Head of the Internal Security Agency (ABW) or the Head of the Foreign Intelligence Agency (AW) (Art. 1(2)(3)).
The provisions on the information security management system and incident reporting do not apply to essential and important entities in the banking and financial market infrastructure sector (DORA replaces them), but obligations such as registration, contact persons and training for the head of the entity still apply (Art. 8i).
A critical entity is a critical infrastructure operator entered in the register of critical entities kept by the Director of the Government Centre for Security; the authority informs the operator of the entry within 30 days (Art. 2(11c) of the KSC Act; Art. 3(1a), Art. 6zo(1) and Art. 6zr(3) of the Crisis Management Act).
Until critical entities are identified under the Crisis Management Act, no entity is entered in the register as a critical entity; the Government Centre for Security will provide the Minister of Digital Affairs with the list of identified entities (Ministry of Digital Affairs, Q&A of 1 October 2026, questions 2.37-2.38).
DNS service providers, TLD name registries, domain name registrars and providers of cloud computing services, data centre services, content delivery networks, managed services (including managed security services), online marketplaces, online search engines and social networking platforms are subject to the Polish Act where their main establishment is in Poland - that is, where the head of the entity who takes decisions on the information security management system is based (Art. 5a(3)-(4)).
06-Rules
Decision tree: how the scope checker determines your status
The same logic the checker uses - step by step, with the legal provisions. It also works without JavaScript.
Exclusions
First, we check whether the organisation can be an essential or important entity at all.
Special services and entities subordinate to or supervised by the Minister of National Defence are not essential or important entities - unless the minister designates them by decision (Art. 5(10)-(11)).
The Minister of National Defence may, by decision, designate subordinate units as essential or important entities (Art. 5(11)).
Status determined by the authority
A decision of the authority or entry in the register as a critical entity determines the status regardless of your other answers.
The competent authority may, by decision, recognise an entity listed in an annex as an essential entity (Annex 1) or an important entity (Annex 2); the Minister of Digital Affairs may recognise a state legal person as an essential entity (Art. 7l(1)-(2), Art. 7m(1)).
A critical entity is an essential entity regardless of size (Art. 5(1)(4)(c)).
Sector listed in an annex
The rules in Art. 5 apply to the types of entities listed in Annexes 1 and 2.
The activity is not listed in Annex 1 or 2, so the rules in Art. 5 do not apply to it - unless the organisation is a critical entity (Art. 5(1)-(2), Annexes 1 and 2).
Types of entities covered regardless of size
Some entities are subject to the Act regardless of their headcount and turnover.
A DNS service provider (other than operators of root name servers) is an essential entity regardless of size (Art. 5(1)(4)(a), Art. 2(4g)).
A top-level domain (TLD) name registry is an essential entity regardless of size (Art. 5(1)(4)(i)).
An entity providing domain name registration services is an essential entity regardless of size (Art. 5(1)(4)(j)).
A qualified trust service provider is an essential entity regardless of size (Art. 5(1)(4)(b)).
An operator of a nuclear power facility is an essential entity regardless of size (Art. 5(1)(4)(h)).
A public entity listed in Annex 1 (including government administration, specified public finance sector units, regional governments and district offices) is an essential entity regardless of size (Art. 5(1)(4)(d)).
A municipal office that, on 1 January of a given year, employs at least 50 people under employment contracts in full-time equivalents is a public entity listed in Annex 1 and therefore an essential entity (Annex 1, Public entities sector, point 4; Art. 5(1)(4)(d)).
An entity that is not a business and is listed in Annex 1 by name or by type is an essential entity regardless of size (Art. 5(1)(4)(g)).
An entity that is not a business and is listed in Annex 2 by name or by type is an important entity (Art. 5(2)(7)).
An investor in a nuclear power facility that has obtained a decision in principle is an important entity regardless of size (Art. 5(2)(5)).
An investor without a decision in principle is not an entity listed in Annex 2 - its status changes once it obtains one (Art. 5(2)(5), Annex 2).
A local government budgetary unit or establishment (including a municipal office employing fewer than 50 people in full-time equivalents), a local government cultural institution or a municipal company performing public utility tasks is an important entity if it performs a public task using information systems (Art. 5(2)(8), Annex 2; Ministry of Digital Affairs, Q&A of 1 October 2026, question 1.8).
A local government public entity that does not perform public tasks using information systems does not meet the criterion for an important entity (Art. 5(2)(8)).
Special thresholds
For some types of entities, the Act sets its own size thresholds.
An electronic communications undertaking that is at least a medium-sized enterprise is an essential entity (Art. 5(1)(2)).
An electronic communications undertaking that is a micro or small enterprise is an important entity (Art. 5(2)(4)).
A managed security service provider (e.g. incident handling, security testing, audits, consultancy) is an essential entity even as a small enterprise (Art. 2(4j) and Art. 5(1)(3)).
A managed security service provider that is a microenterprise does not meet the threshold for an essential entity (Art. 5(1)(3)).
A non-qualified trust service provider that is a micro, small or medium-sized enterprise is an important entity; a large one is an essential entity under the general rule (Art. 5(2)(3) and (1)(1)).
A healthcare provider that is not a business (e.g. an independent public healthcare institution, SP ZOZ) is an essential entity if it employs at least 250 people (Art. 5(8)(2)).
A healthcare provider that is not a business is an important entity if it employs between 50 and 249 people (Art. 5(8)(1)).
A healthcare provider that is not a business and employs fewer than 50 people does not meet the thresholds of the Act - according to the Ministry of Digital Affairs, such an SP ZOZ is not subject to the Act (Art. 5(8); Ministry of Digital Affairs, Q&A of 1 October 2026, question 3.20).
General rule: sector and size
All other entities are classified by the sector listed in an annex and the size of the enterprise.
Essential or important entity - the general rule (Art. 5(1)(1) and (2)(1)-(2) of the KSC Act)
Sector
Large enterprise
Medium-sized enterprise
Small and micro
Annex 1 - sectors of high criticality
Essential entity
Important entity
Outside the Act unless an exception applies
Annex 2 - other critical sectors
Important entity
Important entity
Outside the Act unless an exception applies
An enterprise in a sector listed in Annex 1 that exceeds the thresholds for a medium-sized enterprise (a large enterprise) is an essential entity (Art. 5(1)(1)).
A medium-sized enterprise in a sector listed in Annex 1 is an important entity (Art. 5(2)(1)).
Micro and small enterprises in sectors listed in Annex 1 are not covered by the general rule (Art. 5(1)(1) and (2)(1)).
A medium-sized or large enterprise in a sector listed in Annex 2 is an important entity (Art. 5(2)(2)).
Micro and small enterprises in sectors listed in Annex 2 are not covered by the general rule (Art. 5(2)(2)).
Groups of companies
Size is calculated together with linked and partner enterprises - with one exception.
Size is calculated together with linked and partner enterprises where the information system is shared with them or services are provided jointly (Art. 5(6)-(7), Art. 6 of Annex I to Regulation (EU) No 651/2014).
Exception: an entity that exceeds a threshold only because of its linked or partner enterprises is not, on that basis, an essential or important entity if its information system is independent of theirs or it does not provide services jointly with them - in that case only the size of the company itself counts (Art. 5(6)-(7)).
The provision on an independent information system refers expressly to the medium-sized enterprise thresholds. Where special thresholds apply (electronic communications, managed security services, trust services), the effect has to be assessed case by case (Art. 5(6)-(7)).
Small entities of particular importance
Where the thresholds are not met, the authority may still designate an entity by decision.
An entity listed in an annex that does not meet the thresholds may be recognised by a decision of the authority as essential or important if, for example, it is the sole provider of a service essential for societal or economic activity, or its service is of significant importance at regional (voivodeship) or national level (Art. 7l(1)(2)).
If you don't know the answer
Answering “I don't know” does not stop the checker: we calculate every variant. If they all lead to the same status, the result is certain. If they differ, the result is “further analysis needed”, with a list of the questions on which the status depends, for example:
Whether the organisation is a business (carries out economic activity).
Number of staff.
Annual turnover.
Annual balance sheet total.
Whether the organisation has linked or partner enterprises.
The size of the organisation alone, without linked and partner enterprises.
Whether the information system is independent of the other enterprises in the group.
Whether the trust services are qualified.
Municipal office headcount in full-time equivalents.
Whether public tasks are performed using information systems.
Whether the investor has obtained a decision in principle.
07-Result
What your result means and what to do next
Essential entity
The organisation meets the criteria for an essential entity. It must implement the obligations under the KSC Act, including an information security management system, and undergo a security audit at least once every 3 years. The authority's supervision is both ex ante and ex post.
Next steps
Apply for entry in the register or - if the Minister of Digital Affairs enters you ex officio - complete your data when requested. The deadline for entities already in scope passed on 3 October 2026, but registration is declaratory, so if you missed it, apply as soon as possible.
Carry out a gap analysis: a comparison of your current state with the requirements of the Act and an implementation plan to meet the 3 April 2027 deadline.
Plan your first Art. 15 security audit (due by 3 April 2028) in a way that preserves auditor independence.
Work through our NIS2/KSC checklist and plan the annual training for the head of the entity.
The organisation meets the criteria for an important entity. Most of its obligations are the same as those of an essential entity, but a security audit is required only when the authority orders one by decision, and supervision is ex post.
Next steps
Apply for entry in the register or - if the Minister of Digital Affairs enters you ex officio - complete your data when requested. The deadline for entities already in scope passed on 3 October 2026, but registration is declaratory, so if you missed it, apply as soon as possible.
Carry out a gap analysis: a comparison of your current state with the requirements of the Act and an implementation plan to meet the 3 April 2027 deadline.
Prepare your documentation so that an audit ordered by the authority does not catch the organisation off guard.
Work through our NIS2/KSC checklist and plan the annual training for the head of the entity.
Based on your answers, the organisation does not meet the criteria for an essential or important entity. This may change if its size or the scope of its activity changes - the criteria are assessed as at the date on which the financial statements are prepared.
Next steps
Save the result and check your status again after the next financial year closes or when your activity changes.
If you supply ICT products or services to essential or important entities, prepare for their requirements for suppliers - e.g. penetration testing before every major release.
The status depends on information that is missing or on an assessment that the law does not settle explicitly. The questions on which the result depends are listed in the reasoning - clarify them, ideally with a lawyer or at the start of a gap analysis.
Next steps
Clarify the questions listed in the reasoning - e.g. the group's financial figures, your legal form or decisions of the authorities.
We will prepare a reasoned classification at the start of a gap analysis.
Application for entry in the register of essential and important entities in the S46 system (the Wykaz KSC application) and notification of changes to the data within 14 days (Art. 7c(1), (3) and (6)).
The Minister of Digital Affairs makes the entry in the register ex officio (including public entities, electronic communications undertakings, trust service providers and critical entities) - the entity completes any missing data when requested (Art. 7a(2), Art. 7b(2)).
Information security management system: risk assessment, policies, technical and organisational measures (including business continuity, supply chain, monitoring, cryptography, access control and staff training) and incident management (Art. 8(1)).
Important entities that are public entities apply the requirements of Annex 4 to the Act instead of Art. 8(1) (Art. 8(3)).
Reporting significant incidents through the S46 system: an early warning within 24 hours, an incident notification within 72 hours and a final report within one month (Art. 11(1)(4)-(4c)).
Reporting significant incidents through the S46 system - without an early warning and without intermediate, progress or final reports (Art. 12c).
Security documentation - normative (management system, business continuity, technical documentation) and operational (records, logs) - retained for at least 2 years after it is withdrawn from use (Art. 10).
The entity designates at least two persons to liaise with the entities of the national cybersecurity system; micro and small enterprises designate at least one (Art. 9(1)-(3)).
The head of the entity is responsible for performing the obligations, including those entrusted to others, and undergoes documented training once every calendar year (Art. 8c, Art. 8e).
An essential entity carries out, at its own expense, a security audit of the information system at least once every 3 years, counting from the signing of the report on the last audit (Art. 15(1); copy of the report to the authority within 3 working days - Art. 15(1a)).
A security audit only when ordered by the authority - after a significant incident or another infringement of the law (Art. 15(1b)).
The provisions on the information security management system and incident reporting do not apply to essential and important entities in the banking and financial market infrastructure sector (DORA replaces them), but obligations such as registration, contact persons and training for the head of the entity still apply (Art. 8i).
Ex ante and ex post supervision by the competent authority (Art. 53(3)(1)).
Ex post supervision by the competent authority, particularly where there are reasonable grounds to suspect an infringement of the law (Art. 53(3)(2)).
A fine of up to EUR 10 million or 2% of revenue from business activity in the previous financial year, whichever is higher; not less than PLN 20,000 (Art. 73(3)).
A fine of up to EUR 7 million or 1.4% of revenue from business activity in the previous financial year; not less than PLN 15,000 (Art. 73(4)).
Deadlines
Entities that met the criteria on 3 April 2026 applied for registration from 7 May to 3 October 2026 - that deadline has passed. Registration is declaratory and the obligations arise from the Act, so you should apply without delay - self-registration is available at all times, and the authority may also enter an entity ex officio. Entities that come within scope later must apply within 6 months from meeting the criteria (Art. 33(3) of the amending act, announcement of the Minister of Digital Affairs (Dz.Urz. MC 2026 item 7); Art. 7c(1), Art. 7d(5), Art. 7j of the KSC Act; Ministry of Digital Affairs, Q&A of 1 October 2026, question 2.32).
The Minister of Digital Affairs enters these entities in the register ex officio; after being requested to do so, an entity has 6 months to complete any missing data (Art. 7a(2), Art. 7b(2)).
Obligations under Chapter 3 of the Act (management system, incidents, documentation, contact persons): by 3 April 2027 for entities that met the criteria on 3 April 2026; for others - within 12 months from meeting the criteria (Art. 33(1) of the amending act, Art. 16(1) of the KSC Act).
First security audit: by 3 April 2028 (entities that were essential on 3 April 2026) or within 24 months from meeting the criteria; then at least once every 3 years (Art. 33(2) of the amending act, Art. 16(2) and Art. 15(1) of the KSC Act).
After a decision of the authority: 12 months for the obligations under Chapter 3 and 24 months for the first audit of an essential entity - counted from delivery of the decision (Art. 7l(7), Art. 7m(6)).
Fines under Art. 73(1)-(4), Arts. 73a-73c and Art. 76b may be imposed for the first time 2 years after the amendment entered into force (according to the Ministry of Digital Affairs - after 3 April 2028). The moratorium does not cover the fine of up to PLN 100 million (Art. 35 of the amending act).
Special situations
Digital providers (including cloud computing, data centre and DNS service providers, managed service providers and managed security service providers) apply the measures set out in Commission Implementing Regulation (EU) 2024/2690 (Art. 8b(1)).
An important entity that is a public entity designates at least one contact person, and the fine for the head of a public entity is up to 100% of their remuneration (Art. 9(3), Art. 73a(5)).
If the organisation is a municipal company or a local government budgetary unit or establishment, also check the “Local government budgetary units, cultural institutions and municipal companies” option - performing public tasks using information systems gives it the status of an important entity (Art. 5(2)(8)).
Essential and important entities assess the security of their suppliers of ICT products and services - so customers covered by the Act may impose security requirements on you in their contracts (Art. 8(1)(2)(e) and Art. 8(2)).
The authority may also, by decision, recognise as essential or important an entity listed in an annex that does not meet the thresholds - e.g. where it is the sole provider of an essential service or its service is of significant regional (voivodeship) or national importance (Art. 7l(1)).
A critical entity is an essential entity regardless of size. A critical entity is a critical infrastructure operator entered in the register of critical entities kept by the Director of the Government Centre for Security; the authority informs the operator of the entry within 30 days. The authorities carry out the first identification of critical entities and their entry in the register within 9 months of the entry into force of the Act of 29 May 2026 (4 July 2026), i.e. by 4 April 2027 (Art. 5(1)(4)(c); Art. 2(11c) of the KSC Act; Art. 3(1a), Art. 6zo(1) and Art. 6zr(3) of the Crisis Management Act; Art. 34 of the Act of 29 May 2026 (Dz.U. 2026 item 815)).
08-Next steps
What to do once you know your status
Entry in the register
Who has to be in the KSC register? All essential and important entities. Each entity applies itself through the S46 system, unless the Minister of Digital Affairs enters it ex officio. According to the Ministry of Digital Affairs, self-registration in the register is available at all times; 3 October 2026 was the last day for entities that met the criteria on the date the amendment entered into force (Ministry of Digital Affairs, Q&A of 1 October 2026, question 2.32). Registration is declaratory - the obligations arise from the Act, not from the entry in the register (Art. 7d(5)). If you have missed the deadline, apply as soon as possible.
Security management system
Entities that were already in scope when the amendment entered into force must implement the obligations in Chapter 3 of the Act - an information security management system, incident reporting, documentation and contact persons - by 3 April 2027. A NIS2 gap analysis shows where to start, and our NIS2 implementation page sets out the work plan.
Security audit
An essential entity carries out a security audit at least once every 3 years, with the first one due by 3 April 2028. We carry out the Art. 15 audit in cooperation with a partner whose auditors meet the requirements of the Act - and we do not audit organisations that we helped to implement their security management system in the year before the audit (Art. 15(2a)).
Checklist
For working through the obligations with your team, use our NIS2/KSC checklist - questions on registration, the head of the entity, the management system, incidents and suppliers, ready to print or save as a PDF, with no email address required.
Frequently asked questions
Who does NIS2 apply to in Poland?
The NIS2 Directive (Directive (EU) 2022/2555) is implemented in Poland by the amendment to the National Cybersecurity System Act (Dz.U. 2026 item 252), in force since 3 April 2026. The Act covers essential and important entities: as a rule, medium-sized and large organisations in the sectors listed in Annexes 1 and 2, plus some groups that are covered regardless of size - e.g. DNS service providers, qualified trust service providers and the public entities listed in Annex 1. Organisations determine their status themselves and apply for entry in the register.
Does NIS2 apply to small companies?
In principle, no - the general rule only applies from medium-sized enterprises upwards. There are exceptions, however: DNS service providers, TLD registries, domain name registrars and qualified trust service providers are covered regardless of size, a managed security service provider is an essential entity even as a small enterprise, and micro and small electronic communications undertakings are important entities (Art. 5 of the Act). The authority may also designate a small entity listed in an annex by decision (Art. 7l).
How is size calculated for a company that belongs to a group?
Using the SME definition in Annex I to Regulation 651/2014: the figures of linked enterprises are added in full, and those of partner enterprises (a holding of at least 25%) in proportion to the holding. There is an exception in Art. 5(6)-(7) of the Act: if a company exceeds a threshold only because of its group, and its information system is independent of the systems of the other group companies or it does not provide services jointly with them, it is not an essential or important entity on that basis. According to the Ministry of Digital Affairs, a change in size only counts once it has occurred in two consecutive financial years.
Who has to be in the KSC register, and who has to apply?
All entities covered by the Act are entered in the register of essential and important entities. Entities normally apply themselves through the S46 system, but the Minister of Digital Affairs enters some entities ex officio, including public entities, electronic communications undertakings, trust service providers and critical entities - these complete their data when requested. The deadline for entities that were in scope on 3 April 2026 passed on 3 October 2026, but registration is declaratory and self-registration remains available at all times, so if you missed the deadline, apply as soon as possible.
Is a municipality, a school or a hospital subject to the KSC Act?
A municipal office employing at least 50 people in full-time equivalents and a district (powiat) office are essential entities regardless of size. According to the Ministry of Digital Affairs, a smaller municipal office and a public school run by a municipality are important entities as local government budgetary units. A hospital run as an independent public healthcare institution (SP ZOZ) is an important entity with 50-249 staff and an essential entity with 250 or more (Art. 5(8)), while a hospital run as a company falls under the general rule for the health sector. More details: NIS2 in local government and NIS2 in hospitals.
Does the scope checker store or send my answers?
No. The checker calculates the result in your browser and does not send your answers to any server - they do not appear in the page address either. Our site statistics (Matomo, without cookies) record only that a result was shown and its type, e.g. “important entity”. You can print the result or save it as a PDF.
Is the result of the scope checker binding?
No - it is indicative and does not constitute legal advice. The checker reproduces the rules in Art. 5 of the Act, but the final classification depends on the details of your activity and on decisions of the authorities: an authority may enter an entity in the register ex officio or designate it as an essential or important entity by decision. We prepare a reasoned classification at the start of a gap analysis.
What should we do if we are an essential or important entity?
Apply for entry in the register (or complete your data when requested, if the minister enters you ex officio), assess your security against the requirements of the Act and plan to implement the obligations by 3 April 2027. An essential entity must also carry out its first security audit by 3 April 2028. Our NIS2/KSC checklist will help, and a gap analysis gives you a prioritised implementation plan.
NIS2 gap analysis against the Polish KSC Act: scope, method, gap report, compliance matrix and an implementation plan to meet the 3 April 2027 deadline.
NIS2 implementation step by step: registration, risk analysis, policies, technical measures, incidents, suppliers and audit, with a timeline to 3 April 2027.
NIS2 checklist for the Polish KSC Act: 40 questions on registration, management, the ISMS, incidents and the audit, each with its legal basis. No email needed.
NIS2 audit under the Polish KSC Act: who is in scope, deadlines 3 April 2027 and 3 April 2028, duties, the Art. 15 audit and fines. Gap analysis, pentests.
Details
Let's talk about your project or audit
Tell us briefly what you need - we will come back with proposed next steps. We work in English and Polish.