Regulation · NIS2

NIS2: essential or important entity — and what it requires

NIS2 — Directive (EU) 2022/2555 — applies to medium and large entities in the Annex I sectors (essential: energy, transport, banking, health, digital infrastructure, ICT service management, public administration, space and others) and the Annex II sectors (important: postal services, waste, chemicals, food, manufacturing, digital providers, research). It requires ten risk management measures (Art. 21), incident reporting within 24 and 72 hours (Art. 23) and management accountability (Art. 20). Poland implements it through the amended National Cybersecurity System Act (KSC).

01

The size rule

In scope if you have 50+ staff or more than €10m in turnover / balance sheet total and operate in an Annex I or II sector (Art. 2(1)). Some entities are in scope regardless of size — DNS, TLD registries, trust service providers.

02

Essential vs important

Essential entities: large entities in Annex I sectors and certain named categories; important entities: everyone else in scope. Essential entities face ex-ante supervision and higher penalties (Art. 3, 32–34).

03

Ten measures, one list

Art. 21(2)(a)–(j): risk policies, incident handling, continuity, supply chain, secure development, effectiveness assessment, cyber hygiene and training, cryptography, HR and access control, MFA and secure communications.

04

Management is accountable

Art. 20: management bodies approve and oversee the measures, must undergo training and can be held liable.

Which sectors

AnnexCategorySectors
Annex IHigh criticalityEnergy; transport; banking; financial market infrastructure; health; drinking water; waste water; digital infrastructure (IXPs, DNS, TLDs, cloud, data centres, CDNs, trust services, public networks); ICT service management B2B (managed service and managed security service providers); public administration; space
Annex IIOther criticalPostal and courier services; waste management; chemicals; food; manufacturing (medical devices, electronics, machinery, vehicles); digital providers (marketplaces, search engines, social networks); research organisations

Software houses and SaaS companies most often fall in scope as managed service providers or managed security service providers (Annex I, ICT service management) or as cloud service providers — if they meet the size threshold. Vendors below the threshold are usually affected indirectly, through the supply chain security measure (Art. 21(2)(d)) of their NIS2-covered customers.

The ten measures in Art. 21(2)

  1. Policies on risk analysis and information system security
  2. Incident handling
  3. Business continuity, backup management, disaster recovery and crisis management
  4. Supply chain security, including relationships with direct suppliers and service providers
  5. Security in network and information system acquisition, development and maintenance, including vulnerability handling and disclosure
  6. Policies and procedures to assess the effectiveness of the measures
  7. Basic cyber hygiene practices and cybersecurity training
  8. Policies on the use of cryptography and, where appropriate, encryption
  9. Human resources security, access control policies and asset management
  10. Multi-factor or continuous authentication, secured voice, video and text communications and secured emergency communication systems

Incident reporting

Art. 23: an early warning within 24 hours of becoming aware of a significant incident, an incident notification within 72 hours and a final report within a month — to the CSIRT or the competent authority. In Poland that means the relevant national CSIRT (CSIRT NASK, CSIRT GOV or CSIRT MON) under the KSC act.

Poland: the KSC act

Poland implements NIS2 through an amendment to the National Cybersecurity System Act. The amendment introduces registration for essential and important entities, the security measures, reporting to the national CSIRTs and a penalty regime. Because the national text goes beyond the directive in places — on high-risk vendors, for example — Polish entities should audit against the KSC act, not only NIS2. Audomate maintains both as versioned frameworks.

Talk to us about NIS2 and the KSC act

Questions we get most often

Below the size threshold you are generally not in scope directly, unless you fall into one of the size-independent categories (Art. 2(2)) — a trust service or DNS provider, say — or a member state designates you. You will still receive supply chain requirements from your NIS2-covered customers.
Supervision and penalties. Essential entities face ex-ante supervision (audits, inspections) and fines of up to €10m or 2% of turnover; important entities are supervised ex-post and face up to €7m or 1.4%. The Art. 21 security measures are the same for both.
DORA takes precedence (Art. 4 NIS2): financial entities apply DORA's ICT risk and incident rules instead of the NIS2 ones. A bank sits in Annex I of NIS2, but its cybersecurity obligations come from DORA.

Updated 7 September 2026 · This page explains the rules in plain language and is not legal advice. What applies to you always depends on your own contracts and services.

Find out where you stand in four weeks

Pick this regulation for a 4-week pilot. Your documents, a cited gap list, remediation drafts — and a verified mark if you pass.