Chors.net
Blog & Insights

Precyzyjna wiedza
o ciemnych systemach.

Ekspercka analiza i studia przypadków dla decydentów. Nawigacja po złożonościach nowoczesnej infrastruktury cyfrowej z niekompromisowymi standardami bezpieczeństwa.

NIS2 penalties in 2026: what you really risk

Short answer

Penalties for non-compliance with NIS2/KSC in Poland: an essential entity up to 10M EUR or 2% of annual turnover (min. PLN 20,000), an important entity up to 7M EUR or 1.4% (min. PLN 15,000). For a breach causing serious cyber threat — up to PLN 100M. Additionally, the entity's manager bears personal liability. "NIS2 certificate" does not exist — compliance is shown by registry entry, an implemented system and reporting.

Key facts

  • Essential entity: up to 10M EUR or 2% of annual turnover, min. PLN 20,000 (Art. 73(1) KSC Act).
  • Important entity: up to 7M EUR or 1.4%, min. PLN 15,000 (Art. 73(2)).
  • Serious breach: up to PLN 100M for direct serious cyber threat (Art. 73(5)).
  • Personal liability of the manager — the penalty may target the managing person, not only the company.
  • Missing registry entry (self-registration by 3.10.2026) is itself a breach of a statutory duty.
  • Incident reporting: early warning 24h, full notification 72h, final report 1 month.

What penalties do NOT mean

  • Penalties are not "automatic" — they require a finding by the supervisory authority.
  • Missing a "NIS2 certificate" is not punishable, because such a certificate does not exist — it is a myth.
  • The amount depends on scale, severity and corrective actions — not merely on being in scope.
  • Penalties are separate from GDPR liability for a data breach — two different regimes.

How to realistically reduce risk

AreaWhat it givesDeadline
KSC registry entryConfirms action; removes registration-breach riskby 3.10.2026
Security management system (SZBI)Evidence of proportional approach; lowers severityby 3.04.2027
Incident reportingClear 24h/72h process; avoids penalty for missing reportfrom 3.04.2026
Cybersecurity auditFind gaps before the supervisor's auditor doesby 3.04.2028
Supply-chain managementAn incident at your vendor is your risk — NIS2 requires vendor assessmentongoing

Engineer Marcin Białczyk's perspective

Penalties are an argument for the boardroom, but not the only driver. I view NIS2/KSC as operational risk management: a registry entry and a working security system are not a "cost of an avoided fine", but a measurable reduction of business-disruption risk. In manufacturing, one stopped process often costs more than a fine. That is why we first measure exposure and map risk — and treat penalties as one signal, not the goal itself.

Boundaries and assumptions

  • This article is informational and technical; it is not legal advice.
  • Penalty amounts come from the KSC Act (Art. 73) and may depend on the circumstances.
  • CHORS.NET does not certify compliance and does not issue legal opinions; it works with law firms on legal matters.
  • Facts reflect the legal state as of 19.08.2026.

Sources

  • Act on the National Cyber Security System, consolidated Dz.U. 2026 item 20 — Art. 73 (penalties), Art. 7c (registration), Art. 16 (audit)
  • Directive (EU) 2022/2555 (NIS2)
  • Consultations: legalgeek.pl, cgolegal.pl, infor.pl (fetched 08.08.2026)

CHORS Cryptogram

Minimalistyczny zapis na miesięczne analizy. Surowe dane, trendy audytowe i analiza zero-day prosto na skrzynkę. Zero marketingowego szumu.

Klucz GPG dostępny na życzenie.