15 September 2026
Share Print

Poland’s NIS2 implementation – 3 October deadline for self-registration

To The Point
(4 min read)

Poland’s implementation of the NIS2 Directive significantly expands the number of organisations subject to cybersecurity obligations and introduces a key deadline of 3 October 2026 for the self-registration of essential and important entities. Businesses should not assume they are out of scope simply because they have not been contacted by a regulator, as qualification requires a detailed self-assessment of activities, sector classification, size thresholds and group structures. Registration is only the first step, with wider compliance obligations, including cybersecurity risk management, incident reporting, business continuity and supply chain security, applying from 3 April 2027. Read our overview of who must register, common qualification pitfalls, and the practical steps organisations should take now to prepare for NIS2 compliance in Poland.

Entities falling within the scope of Poland’s amended NIS2 cybersecurity framework should check whether they fall within the new regime and are subject to the upcoming registration deadline. Most businesses in scope will need to self-register, and the deadline for submitting an application for registration is 3 October 2026. Qualification as an important or essential entity is not always clear-cut and raises many practical issues. Registration should be only the first step towards NIS2 compliance.

The amended Act on the National Cybersecurity System (the “UKSC”), implementing the NIS2 Directive into Polish law, entered into force on 3 April 2026. 

The new regime significantly expanded the number of organisations subject to cybersecurity requirements in Poland (from a few hundred under NIS1 to tens of thousands under NIS2) and introduced the distinction between essential entities and important entities.

The rules apply across a broad range of sectors, including energy, transport, healthcare, digital infrastructure, manufacturing and certain digital services. However, operating within a sector listed in the UKSC does not necessarily mean that an organisation is automatically in scope. The assessment depends on the type of activity carried out by the relevant entity and, in many cases, its size, determined by its headcount and financial data.

Registration deadline: 3 October 2026
Self-assessment
Traps to avoid
Registration process
Registration as a first step in the NIS2 compliance journey
What should you do now?
How can we help?

NIS2 applicability self-assessment


Does your business fall under the NIS2 Directive? Find out using our self-assessment tool.

Assess your obligations  

Next steps

If you have a query that you would like to discuss, please get in touch with one of our specialists.

To the Point


Subscribe to receive legal insights and industry updates directly into your inbox

Sign up now