NIS2: essential or important entity — and what it requires
NIS2 — Directive (EU) 2022/2555 — applies to medium and large entities in the Annex I sectors (essential: energy, transport, banking, health, digital infrastructure, ICT service management, public administration, space and others) and the Annex II sectors (important: postal services, waste, chemicals, food, manufacturing, digital providers, research). It requires ten risk management measures (Art. 21), incident reporting within 24 and 72 hours (Art. 23) and management accountability (Art. 20). Poland implements it through the amended National Cybersecurity System Act (KSC).
The size rule
In scope if you have 50+ staff or more than €10m in turnover / balance sheet total and operate in an Annex I or II sector (Art. 2(1)). Some entities are in scope regardless of size — DNS, TLD registries, trust service providers.
Essential vs important
Essential entities: large entities in Annex I sectors and certain named categories; important entities: everyone else in scope. Essential entities face ex-ante supervision and higher penalties (Art. 3, 32–34).
Ten measures, one list
Art. 21(2)(a)–(j): risk policies, incident handling, continuity, supply chain, secure development, effectiveness assessment, cyber hygiene and training, cryptography, HR and access control, MFA and secure communications.
Management is accountable
Art. 20: management bodies approve and oversee the measures, must undergo training and can be held liable.
Which sectors
| Annex | Category | Sectors |
|---|---|---|
| Annex I | High criticality | Energy; transport; banking; financial market infrastructure; health; drinking water; waste water; digital infrastructure (IXPs, DNS, TLDs, cloud, data centres, CDNs, trust services, public networks); ICT service management B2B (managed service and managed security service providers); public administration; space |
| Annex II | Other critical | Postal and courier services; waste management; chemicals; food; manufacturing (medical devices, electronics, machinery, vehicles); digital providers (marketplaces, search engines, social networks); research organisations |
Software houses and SaaS companies most often fall in scope as managed service providers or managed security service providers (Annex I, ICT service management) or as cloud service providers — if they meet the size threshold. Vendors below the threshold are usually affected indirectly, through the supply chain security measure (Art. 21(2)(d)) of their NIS2-covered customers.
The ten measures in Art. 21(2)
- Policies on risk analysis and information system security
- Incident handling
- Business continuity, backup management, disaster recovery and crisis management
- Supply chain security, including relationships with direct suppliers and service providers
- Security in network and information system acquisition, development and maintenance, including vulnerability handling and disclosure
- Policies and procedures to assess the effectiveness of the measures
- Basic cyber hygiene practices and cybersecurity training
- Policies on the use of cryptography and, where appropriate, encryption
- Human resources security, access control policies and asset management
- Multi-factor or continuous authentication, secured voice, video and text communications and secured emergency communication systems
Incident reporting
Art. 23: an early warning within 24 hours of becoming aware of a significant incident, an incident notification within 72 hours and a final report within a month — to the CSIRT or the competent authority. In Poland that means the relevant national CSIRT (CSIRT NASK, CSIRT GOV or CSIRT MON) under the KSC act.
Poland: the KSC act
Poland implements NIS2 through an amendment to the National Cybersecurity System Act. The amendment introduces registration for essential and important entities, the security measures, reporting to the national CSIRTs and a penalty regime. Because the national text goes beyond the directive in places — on high-risk vendors, for example — Polish entities should audit against the KSC act, not only NIS2. Audomate maintains both as versioned frameworks.
Questions we get most often
Updated 7 September 2026 · This page explains the rules in plain language and is not legal advice. What applies to you always depends on your own contracts and services.
Find out where you stand in four weeks
Pick this regulation for a 4-week pilot. Your documents, a cited gap list, remediation drafts — and a verified mark if you pass.