Skip to main content
Compliance

Does NIS2 Apply to My Business? A Two-Question Test

This is the question we hear most often from Polish clients: “does NIS2 actually apply to us?” The honest answer surprises people in both directions. Some owners assume a new EU cybersecurity law must mean new paperwork for everyone - it doesn’t. Others assume they’re too small to matter, then realize their biggest client is a public hospital, and suddenly the question isn’t abstract anymore.

NIS2 applies only if your business clears two separate tests at once: a sector test and a size test. Miss either one, and you’re out of scope. This post walks through both tests and three real scenarios - a dental practice, an accounting firm, and an aesthetic medicine clinic - so you can see how the test actually plays out, not just read it in the abstract. For the full compliance picture once you know you’re in scope, see our NIS2 and UKSC compliance guide.

The two-question test

Poland’s National Cybersecurity System Act (UKSC) transposes the EU’s NIS2 Directive into Polish law. It applies to a business only when both of the following are true.

Question 1: Is your business in a sector listed in UKSC Annex I or II? Annex I covers essential entities: energy, transport, banking, healthcare providers above a size threshold, digital infrastructure, public administration, and a handful of others. Annex II covers important entities: postal and courier services, waste management, chemicals, food production, manufacturing, and digital service providers such as marketplaces and search engines. Most small professional practices - dental offices, accounting firms, aesthetic clinics - simply aren’t on either list.

Question 2: Does your business meet the EU size threshold? NIS2 Article 3(1) sets the bar at 50 employees or EUR 10 million in annual turnover - one condition is enough to clear it. A ten-person practice fails this test even if it somehow landed in a listed sector.

Both questions have to come back “yes” for NIS2 to apply. Our compliance guide has the full decision tree and the supply-chain exception that trips up more businesses than the two questions above - it’s worth reading before you conclude either way.

Three real scenarios

An eight-person dental practice

A solo dentist with two hygienists and support staff, no hospital contracts, no digital infrastructure business on the side. This practice fails both tests: general dental care isn’t a listed Annex I healthcare activity on its own, and eight employees is nowhere near the 50-person threshold. Out of scope, cleanly. See our dental practice security guide for what protecting patient data looks like regardless of NIS2.

A fifteen-person accounting firm with one hospital client

Bookkeeping and tax services for local businesses, fifteen staff, well under the size threshold - and accounting itself isn’t a listed sector. On its own, this firm is out of scope. But one of its clients is a public hospital, which is an essential entity under Annex I. That doesn’t pull the accounting firm into NIS2 directly. What it can do is pull cybersecurity requirements into the contract: the hospital, as the party actually in scope, may require its suppliers to meet baseline security standards under NIS2 Article 21(2)(d)‘s supply-chain provisions. Read your service contract before assuming this doesn’t touch you. More on this exact situation in our compliance guide’s supply-chain FAQ. For general security practices this kind of firm needs anyway, see our accounting firm security guide.

A twelve-person aesthetic medicine clinic

Injectables, laser treatments, and skin procedures performed by licensed staff. Aesthetic procedures generally don’t qualify as “health services” under Polish medical-activity law the way hospital or GP care does, so this clinic sits outside the healthcare sector definition NIS2 uses - and twelve employees is far below the size threshold regardless. The one edge case: a clinic offering borderline medical procedures with certified medical staff could, in rare setups, drift toward a healthcare-sector classification - at which point the size test becomes the deciding factor again. See our aesthetic medicine security guide for what to protect either way, starting with patient photos and booking data.

What if you’re out of scope?

Being outside NIS2 doesn’t mean doing nothing. The ten security measures NIS2 Article 21 requires for in-scope entities - MFA, tested backups, incident response procedures, staff training - are a sound baseline for any business handling client or patient data, formal obligation or not. And GDPR still applies regardless of NIS2 status: if you hold personal data, you have breach-notification duties either way. A practical starting point that has nothing to do with NIS2 paperwork is closing the entry points attackers actually use - our guides to phishing and ransomware cover the two that hit small practices hardest.

If you are in scope: the nearest deadline

Entities that clear both tests need to register in the Ministry of Digital Affairs’ entity register by October 3, 2026. Full Article 21 technical compliance follows on April 3, 2027, and the first mandatory audit for essential entities on April 3, 2028. The registration procedure, required documents, and penalties for missing it are covered in detail in the compliance guide - this post is only about determining whether you need to file at all.

FAQ

Does NIS2 apply to a sole proprietor?

Only if the same two-question test says yes: a listed Annex I or II sector, and 50+ employees or EUR 10 million+ turnover. A sole proprietor almost never clears the size threshold, so in practice the sector question rarely matters - solo practices are out of scope on size alone.

What if my only client is a hospital?

Your business isn’t automatically in NIS2 scope because a client is. What can happen is contractual: the hospital, as an essential entity, may require security clauses from its suppliers under NIS2’s supply-chain provisions. Check your contract rather than your own sector classification.

Does NIS2 apply to businesses outside Poland?

NIS2 is an EU directive that every member state transposes into national law - Poland’s version is UKSC. A business physically outside the EU generally isn’t captured unless it offers services inside the EU in a way that brings it under a member state’s implementation. This guide covers the Polish UKSC test specifically.

What happens if I assumed I was out of scope and I was wrong?

Missing a registration deadline you were legally required to meet carries administrative fines - up to EUR 10 million for essential entities. If your sector or size is genuinely ambiguous rather than clearly out, get a second opinion from Polish counsel before the October 2026 deadline rather than after it.

Not sure where your business stands on the security side, NIS2 aside? Book a free PreScan - a passive external check of what your business exposes online, results in 24 hours, no obligation.


Informational material, not legal advice. Consult Polish counsel or a Data Protection Officer to confirm your specific scope determination. Information date: August 3, 2026.