(4 min read)
Poland’s implementation of the NIS2 Directive significantly expands the number of organisations subject to cybersecurity obligations and introduces a key deadline of 3 October 2026 for the self-registration of essential and important entities. Businesses should not assume they are out of scope simply because they have not been contacted by a regulator, as qualification requires a detailed self-assessment of activities, sector classification, size thresholds and group structures. Registration is only the first step, with wider compliance obligations, including cybersecurity risk management, incident reporting, business continuity and supply chain security, applying from 3 April 2027. Read our overview of who must register, common qualification pitfalls, and the practical steps organisations should take now to prepare for NIS2 compliance in Poland.
Entities falling within the scope of Poland’s amended NIS2 cybersecurity framework should check whether they fall within the new regime and are subject to the upcoming registration deadline. Most businesses in scope will need to self-register, and the deadline for submitting an application for registration is 3 October 2026. Qualification as an important or essential entity is not always clear-cut and raises many practical issues. Registration should be only the first step towards NIS2 compliance.
The amended Act on the National Cybersecurity System (the “UKSC”), implementing the NIS2 Directive into Polish law, entered into force on 3 April 2026.
The new regime significantly expanded the number of organisations subject to cybersecurity requirements in Poland (from a few hundred under NIS1 to tens of thousands under NIS2) and introduced the distinction between essential entities and important entities.
The rules apply across a broad range of sectors, including energy, transport, healthcare, digital infrastructure, manufacturing and certain digital services. However, operating within a sector listed in the UKSC does not necessarily mean that an organisation is automatically in scope. The assessment depends on the type of activity carried out by the relevant entity and, in many cases, its size, determined by its headcount and financial data.
Registration deadline: 3 October 2026
Entities that meet the criteria for qualification as an essential or important entity and are not subject to automatic registration must submit an application for entry in the register of important and essential entities by 3 October 2026.
Registration is carried out electronically through the register forming part of Poland’s national cybersecurity system (S46 system). The application is submitted by the entity’s management or by a duly authorised person (e.g. proxy).
Different rules apply to certain categories of entities which are entered in the register ex officio, including certain public entities, telecommunications undertakings, trust service providers and existing operators of essential services. The authorities started sending requests to affected organisations earlier this year.
Most businesses need to assess whether they meet the criteria to qualify as essential or important entities under the UKSC. As a rule, an application must then be submitted within six months of the date on which the relevant criteria are met. If a business already met the criteria on 3 April 2026, it will need to register by 3 October 2026. The lack of a notification from the relevant authority does not automatically mean that the business is not subject to the UKSC.
Self-assessment
The starting point should be a self-assessment by the business to determine whether it qualifies as an essential or important entity within the meaning of the UKSC. This assessment may be complex and require an analysis of sector classification, size thresholds (employees, balance sheet total, annual turnover), and the nature of the services provided. Businesses operating as part of capital groups need to analyse their interconnections within the group and the independence of their IT systems.
Traps to avoid
The entire activity of the business needs to be analysed, not only its main one. In many cases, an entity operating in a sector that does not itself fall within the scope of the UKSC may nevertheless be regarded as an essential or important entity because it meets one of the relevant criteria (for example, a company in the real estate sector that holds a licence for electricity generation or trading in fuels).
Another case worth noting is the provision of IT and cybersecurity services to companies within the group. Such activity may constitute a separate and independent basis for bringing the company within the scope of UKSC, even if the capital group operates in a sector not indicated in Annex 1 or 2 to the UKSC.
Registration process
Preparing the registration file requires cooperation between the business, the legal team and the IT department. It will be necessary to gather information from several areas of the business. To prepare the notification, the organisation must provide its core identification and classification details (entity data and sector/activity under the UKSC), key contact and address information (including details of the S46 account administrator), and essential technical and structural information (public IP addresses and domains, details of any representative, and information about any managed cybersecurity service providers). Organisations should therefore identify and collect the required information and any supporting documents sufficiently in advance.
Registration as a first step in the NIS2 compliance journey
The 3 October deadline relates only to registration. Organisations within the scope of the new cybersecurity framework will still have a few months to align their operations with the new material requirements under the UKSC. In principle, entities in scope are required to comply with the obligations under the new regime by 3 April 2027. These include requirements relating to cybersecurity risk management, incident handling and reporting, business continuity, supply chain security and governance.
Registration should therefore not be viewed as a standalone administrative exercise. It is one of the first steps in a broader compliance process under the new Polish cybersecurity framework.
What should you do now?
Businesses should:
- confirm whether they qualify as an essential or important entity, including the relevant sector and subsector;
- where self-registration applies, prepare the required information and submit the application by 3 October 2026; and
- once the registration process is completed, assess their readiness to comply with the wider UKSC requirements and plan their compliance roadmap ahead of April 2027 deadline.
How can we help?
We advise businesses on mapping and implementing obligations arising under the NIS2 Directive at EU level and under the UKSC in Poland. In particular, we support our clients by:
- assessing whether the new NIS2 Directive/UKSC obligations apply to an organisation;
- supporting with registration in the register of important and essential entities;
- assessing NIS2/UKSC compliance readiness;
- implementing cybersecurity policies, procedures and documentation;
- advising on the legal aspects of cybersecurity incident management and reporting;
- reviewing agreements with ICT product and service providers;
- delivering training for management boards and IT teams on the new regulatory requirements.