Short answer
Penalties for non-compliance with NIS2/KSC in Poland: an essential entity up to 10M EUR or 2% of annual turnover (min. PLN 20,000), an important entity up to 7M EUR or 1.4% (min. PLN 15,000). For a breach causing serious cyber threat — up to PLN 100M. Additionally, the entity's manager bears personal liability. "NIS2 certificate" does not exist — compliance is shown by registry entry, an implemented system and reporting.
Key facts
- Essential entity: up to 10M EUR or 2% of annual turnover, min. PLN 20,000 (Art. 73(1) KSC Act).
- Important entity: up to 7M EUR or 1.4%, min. PLN 15,000 (Art. 73(2)).
- Serious breach: up to PLN 100M for direct serious cyber threat (Art. 73(5)).
- Personal liability of the manager — the penalty may target the managing person, not only the company.
- Missing registry entry (self-registration by 3.10.2026) is itself a breach of a statutory duty.
- Incident reporting: early warning 24h, full notification 72h, final report 1 month.
What penalties do NOT mean
- Penalties are not "automatic" — they require a finding by the supervisory authority.
- Missing a "NIS2 certificate" is not punishable, because such a certificate does not exist — it is a myth.
- The amount depends on scale, severity and corrective actions — not merely on being in scope.
- Penalties are separate from GDPR liability for a data breach — two different regimes.
How to realistically reduce risk
| Area | What it gives | Deadline |
|---|---|---|
| KSC registry entry | Confirms action; removes registration-breach risk | by 3.10.2026 |
| Security management system (SZBI) | Evidence of proportional approach; lowers severity | by 3.04.2027 |
| Incident reporting | Clear 24h/72h process; avoids penalty for missing report | from 3.04.2026 |
| Cybersecurity audit | Find gaps before the supervisor's auditor does | by 3.04.2028 |
| Supply-chain management | An incident at your vendor is your risk — NIS2 requires vendor assessment | ongoing |
Engineer Marcin Białczyk's perspective
Penalties are an argument for the boardroom, but not the only driver. I view NIS2/KSC as operational risk management: a registry entry and a working security system are not a "cost of an avoided fine", but a measurable reduction of business-disruption risk. In manufacturing, one stopped process often costs more than a fine. That is why we first measure exposure and map risk — and treat penalties as one signal, not the goal itself.
Boundaries and assumptions
- This article is informational and technical; it is not legal advice.
- Penalty amounts come from the KSC Act (Art. 73) and may depend on the circumstances.
- CHORS.NET does not certify compliance and does not issue legal opinions; it works with law firms on legal matters.
- Facts reflect the legal state as of 19.08.2026.
Sources
- Act on the National Cyber Security System, consolidated Dz.U. 2026 item 20 — Art. 73 (penalties), Art. 7c (registration), Art. 16 (audit)
- Directive (EU) 2022/2555 (NIS2)
- Consultations: legalgeek.pl, cgolegal.pl, infor.pl (fetched 08.08.2026)
