NIS2 is the EU Directive 2022/2555 that replaced the original NIS Directive on 18 October 2024 and broadened cybersecurity obligations to 18 sectors (energy, transport, health, manufacturing, ICT-B2B, public administration, postal/courier, waste management, medical-device manufacturing, etc.). In Poland, the directive is transposed by the Act on the National Cybersecurity System (KSC) — consolidated text Dz.U. 2026 item 20, which entered into force on 3 April 2026. Self-registration in the KSC registry opened on 7 May 2026, and the statutory deadline for filing falls on 3 October 2026 (Article 7c(1)). There is no “NIS2 certificate.” Compliance is demonstrated by the registry entry, an implemented information-security management system, and incident reporting — not by a third-party seal.
Key facts
- NIS2 is not a certification scheme. Obligations derive directly from the statute; their fulfilment is evidenced by the KSC registry entry, an operational ISMS, and incident reporting.
- Directive 2022/2555 has applied in the EU since 18.10.2024; in Poland it is transposed by the KSC Act (Dz.U. 2026 item 20), which entered into force on 3.04.2026.
- Sectoral scope covers 18 areas (energy, transport, banking, financial-market infrastructure, health, drinking water, wastewater, digital infrastructure, public administration, space, post, waste, chemicals, food, medical devices, motor vehicles, ICT-B2B suppliers, and B2C providers of essential services).
- Entity classification: essential entities (energy, transport, health, water, digital infrastructure, public administration) and important entities (Annex II sectors). They differ by size thresholds and supervisory regime.
- Polish deadlines: KSC self-registration from 7.05.2026 to 3.10.2026; operational duties to be implemented by 3.04.2027; first cybersecurity audit by 3.04.2028 (Article 16 KSC).
Decision table — what it means for a B2B / manufacturing company
| Area | What we know | What it means for a B2B / manufacturing company | Recommended action (30 / 90 days) |
|---|---|---|---|
| Entity qualification | Annex I/II sector + size threshold (general rule: medium-sized enterprise ~50 staff / EUR 10m turnover) | Even below the general threshold, MSSPs in Annex II sectors may be captured from ~10 staff / EUR 2m | 30 days: PKD-vs-actual-activity mapping; 90 days: legal counsel on qualification |
| KSC registry entry | Self-registration live from 7.05.2026; missing the 3.10.2026 deadline = statutory breach | Each day of delay is legal and reputational risk; the authority may enter a record ex officio | 30 days: document collection; 90 days: submission via the KSC portal |
| ISMS | Article 8 KSC requires an ISMS proportional to scale and risk | For manufacturing: IT and OT security, segmentation, access management for the line | 30 days: gap audit; 90 days: implementation plan with process owners |
| Incident reporting | Early warning 24h, notification 72h, final report 30 days | OT (line stoppage) and IT (data leak) incidents must share one procedure | 30 days: escalation playbook; 90 days: tabletop exercise |
| Cybersecurity audit | First audit by 3.04.2028 (Article 16); auditor from the MC list | This is not a “pentest”; it is a compliance audit against statutory requirements | 90 days: choose the form (internal vs external auditor) and scope |
| Penalties | Article 73 KSC — up to EUR 10m or 2% of annual turnover for essential entities, up to EUR 7m / 1.4% for important entities | Plausible scenario: fine + loss of tender eligibility + legal-handling cost | 30 days: budget reserve; 90 days: legal-risk mitigation plan |
Perspective from Marcin Białczyk (CHORS.NET)
I work with operators of manufacturing companies and ICT suppliers going back to the NIS1 era and the 2018 KSC Act. The most common mistake I see is treating NIS2 as a project to tick off before the audit rather than as part of an ongoing business-continuity system. In practice, the KSC Act requires a system that works on an ordinary Tuesday morning — when the line stops, the cloud vendor has an outage, or someone clicks a phishing link. The 2028 audit merely verifies what should already be running.
The second trap is conflating concepts: ISO 27001 ≠ NIS2 compliance. ISO 27001 organises an information-security management system, but does not cover CSIRT reporting duties, registry entries, or the sectoral specifics of the Annexes. In one engagement I plan to return to that distinction in detail — for now I leave it as a contrast, not as a case study.
The third thing I flag with operators: NIS2 also creates duties regarding ICT suppliers (B2B). If you are an essential entity, your suppliers become part of your risk chain. In CHORS.NET, every P3_NIS2_READINESS audit starts with a supplier map and questions about their readiness, before we touch our own controls.
Frequently asked questions
Is there an “NIS2 certificate”?
No. Compliance is evidenced by the KSC registry entry, an implemented ISMS, incident reporting, and the cybersecurity audit under Article 16 KSC. Legal interpretation requires consultation with a law firm.
Can a small company (< 50 staff) fall under NIS2?
Yes — in Annex II sectors (important entities) and certain MSSPs, lower thresholds apply (~10 staff / EUR 2m turnover). See Articles 5–6 KSC.
What is the first step for a company hearing about NIS2 now?
Identify the sector you actually operate in (PKD does not always reflect real activity), confirm the size threshold, then register in the KSC registry via the self-registration portal before 3.10.2026.
What happens if I miss the 3.10.2026 deadline?
Lack of registration is a statutory breach. The authority may enter a record ex officio, and the entity faces administrative sanctions (Article 73 KSC). Legal interpretation requires consultation with a law firm.
Does NIS2 require a “pentest”?
No — the statute requires a cybersecurity audit under Article 16, which is a compliance assessment against statutory requirements, not a penetration test.
How CHORS.NET helps
If your company is assessing whether NIS2/KSC applies to you, see our services or contact us. Related cluster articles: How to report NIS2 — self-registration step by step · NIS2 certification — myth vs fact.
Scope and limitations
- We are not a 24/7 SOC and we do not guarantee detection of every incident. Our model is P0_PASSIVE_SNAPSHOT and P1_AUTH_VA — not continuous monitoring with a coverage promise.
- We do not certify NIS2/KSC compliance and we do not issue standalone legal opinions. Compliance is demonstrated by the KSC registry entry and incident reporting, not by a “certificate”.
- The results and deadlines in this article reflect the state as of 9 August 2026 and may require updates after subsequent statutory changes or implementing acts.
- For interpretation of the KSC provisions, CHORS.NET works with partner law firms.
- This material is informational and technical; it does not constitute legal advice.
Sources
- Directive (EU) 2022/2555 of 14.12.2022 (NIS2)
- ENISA — NIS Directive implementation
- KSC Act — consolidated text Dz.U. 2026 item 20
- CGO Legal — NIS2 Poland 2026 (legal analysis)
- LegalGeek — NIS2/KSC 2026 introduction
- Infor.pl — KSC registry self-registration from 7.05.2026
- NASK PIB — national cybersecurity system