Skip to main content
Compliance

NIS2 in Poland: What Changed in 2026 and New Deadlines

Poland’s UKSC amendment took force on 3 April 2026 and transposed the EU NIS2 Directive. It changed five things: it widened the scope of covered companies, split them into essential and important entities, raised fines to EUR 10 million, added personal liability for management boards, and introduced three-stage incident reporting. The first deadline is registration by 3 October 2026.

Where the change comes from - NIS2 and the 2026 UKSC amendment

Poland transposed the NIS2 Directive (2022/2555) late. The EU deadline fell on 17 October 2024, but the amendment to Poland’s National Cybersecurity System Act (UKSC) only took force on 3 April 2026. That amendment replaced the 2018 regime, which had implemented the original NIS Directive from 2016.

Keep two things separate, because coverage tends to blur them into one label. NIS2 is the directive - the EU-level source of the rules. UKSC is the Polish act that puts those rules into force and names who enforces them. When you read about “NIS2 obligations in Poland”, in practice you are applying UKSC. The supervisory authority is the Ministry of Digital Affairs, and incident reports go to CSIRT NASK, the national team operated by CERT Polska.

Five things the amendment changed

The amendment is not cosmetic. EU-wide, the scope jumped from roughly 1,700 covered entities under the old directive to around 160,000 under NIS2, according to the European Commission. Five changes separate the new regime from the old one.

DimensionNIS1 / old UKSC (2018)2026 amendment (NIS2)
Entities coveredNarrow - operators of essential services designated by administrative decisionBroad - self-identification, two tiers: essential (Annex I) and important (Annex II)
FinesNational administrative penalties, no EU percentage ceilingUp to EUR 10 million or 2% of global turnover (essential); EUR 7 million or 1.4% (important)
Management liabilityNo explicit personal liabilityPersonal liability of board members (Article 20), with possible management bans
Incident reportingReporting duty, no fixed stage structureThree stages to CSIRT NASK: 24h / 72h / 30 days (Article 23)
Security measuresGeneral “appropriate measures”Explicit list of 10 measures (Article 21)

Two of these matter to you even if your company is out of scope. First, Article 20 moves accountability for security failures from the IT team to the people running the company - “the technician handles that” stops being a defence. Second, Article 21 replaces vague “appropriate measures” with a concrete list: risk analysis, incident handling, backups, supply-chain security, cryptography, access control, and multi-factor authentication. That list overlaps heavily with GDPR Article 32, so one set of controls produces evidence for two regulators - a connection we cover in the data security and compliance guide.

The new compliance timeline

The amendment spread obligations across three dates. If your business is in scope, each one counts.

NIS2/UKSC compliance timeline in Poland: 3 April 2026 amendment in force, 3 October 2026 entity registration, 3 April 2027 full Article 21 compliance, 3 April 2028 first mandatory audit for essential entities 3 Apr 2026 Amendment in force 3 Oct 2026 Register entity 3 Apr 2027 Full Article 21 compliance 3 Apr 2028 First audit (essential)

Registration by 3 October 2026 is the nearest deadline - filing in the essential and important entities register run by the Ministry of Digital Affairs, with fines up to EUR 10 million for skipping it. Full compliance with the 10 Article 21 measures applies from 3 April 2027, and the first mandatory audit - essential entities only - falls on 3 April 2028. The full registration procedure and the measures list sit in the NIS2 and UKSC compliance guide.

Does the change affect your business

A business falls under UKSC only when it clears two tests at once: it operates in a sector listed in Annex I or II, and it employs at least 50 people or turns over at least EUR 10 million. Most dental practices, accounting firms, and aesthetic clinics clear neither test and stay out of scope - but self-identification is now the entity’s own duty, so don’t assume your side of the line without checking.

Work it out before 3 October. The two-question test, the supply-chain exception, and three worked scenarios are in does NIS2 apply to my business and the compliance guide’s decision tree. Even out of scope, the 10 Article 21 measures are a sound baseline - and their technical layer is exactly what an external vulnerability assessment verifies.

FAQ

When did the 2026 UKSC amendment take force?

The amendment to Poland’s National Cybersecurity System Act took force on 3 April 2026. It transposed the EU NIS2 Directive into Polish law and replaced the 2018 regime. The first practical deadline for in-scope companies is registration by 3 October 2026.

What exactly did the amendment change compared with the previous act?

It widened the range of covered entities and split them into essential and important, raised fines to EUR 10 million or 2% of turnover, added personal liability for management boards, set three-stage incident reporting (24h / 72h / 30 days), and replaced general measures with a concrete list of ten Article 21 requirements.

Does the amendment create new obligations for a small business?

Usually not. Obligations apply to companies in an Annex I or II sector that also pass the size threshold - 50 employees or EUR 10 million turnover. Most small practices stay out of scope, but the duty to self-assess whether you qualify now sits with the business itself.

What is the nearest NIS2 deadline in Poland?

The nearest deadline is 3 October 2026 - registration in the essential and important entities register run by the Ministry of Digital Affairs. Failing to register when required carries an administrative fine of up to EUR 10 million. Full Article 21 compliance follows on 3 April 2027.

What is the difference between UKSC and NIS2?

NIS2 is an EU directive that sets common cybersecurity rules. UKSC is the Polish act that implements those rules and names the enforcers - in Poland the Ministry of Digital Affairs supervises, and CSIRT NASK receives incident reports. When you talk about NIS2 obligations in Poland, you are applying UKSC.


Want to check whether your company already meets the Article 21 technical baseline - multi-factor authentication, encryption, and up-to-date patches on what is exposed to the internet? Book a free PreScan: a passive external check of your company’s attack surface, with results in 24 hours and no obligation.

Informational material, not legal advice. Legal position as of August 2026. Whether your business falls under UKSC depends on an individual assessment of sector and size - consult Polish counsel or a Data Protection Officer before the 3 October 2026 deadline.