NIS2 Directive in Poland – who does it apply to and what obligations does it impose on companies?

The NIS2 Directive extends cybersecurity requirements to numerous sectors of the economy. In Poland, the new regulations may apply to manufacturers of electronic products, electrical equipment, machinery, medical devices and transport equipment, among others.

What does NIS2 mean for businesses? Which companies are covered by the regulations, and how do the new requirements affect the selection of devices and network infrastructure?

What is the NIS2 Directive?

The NIS2 Directive is an EU legal act establishing a common cybersecurity framework for the Member States of the European Union. Its official designation is Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022.

NIS2 replaced the previous NIS Directive and extended the scope of the regulations to additional sectors and groups of companies. Its purpose is to increase the resilience of organisations to cyberattacks, failures and other events that may disrupt important services or processes. (Directive (EU) 2022/2555 – EUR-Lex)

The new regulations were introduced in response to factors including:

  • the ongoing digitalisation of industry and services,
  • the growing dependence of companies on information systems,
  • the integration of IT infrastructure with industrial automation,
  • the increasing importance of cloud services and network communication,
  • dependencies between companies and their suppliers.

In manufacturing companies, information systems are often connected to routers, industrial computers, measuring equipment and control systems. An incident may therefore lead not only to data loss, but also to production stoppages, communication disruptions or reduced service availability.

NIS2 is not a technical standard or a certification scheme for devices. A router, industrial computer or switch cannot therefore automatically be described as “NIS2-certified”. The regulations primarily concern how an organisation manages the cybersecurity of its systems, processes and services.

Who does NIS2 apply to in Poland?

The NIS2 Directive was implemented in Poland through an amendment to the Act on the National Cybersecurity System. The new regulations entered into force on 3 April 2026 and divided organisations covered by the Act into:

  • essential entities,
  • important entities.

(official information from the Polish Ministry of Digital Affairs – in Polish)

To determine whether a company is covered by the Act, it is necessary to analyse:

  1. the actual scope of its business activities,
  2. the sector or subsector specified in the Act,
  3. the size of the company,
  4. the specific rules set out in Article 5 of the Act on the National Cybersecurity System.

The Polish Classification of Activities code, known as the PKD code, may support the assessment, but the actual nature of the company’s operations is decisive, rather than the information entered in the register alone. Partner and linked enterprises must also be taken into account when determining the size of a company. (official self-identification guidance from the Polish Ministry of Digital Affairs – in Polish)

The regulations primarily apply to medium-sized and large organisations operating in sectors listed in the Act. In certain cases, the regulations apply regardless of the size of the company.

Areas that are particularly relevant to companies operating in the electronics and industrial sectors include:

  • energy,
  • transport,
  • healthcare,
  • digital infrastructure,
  • electronic communications,
  • the manufacture of electronic products and electrical equipment,
  • the manufacture of machinery,
  • the manufacture of vehicles and transport equipment.

The complete list of activities is provided in Annexes 1 and 2 to the Act on the National Cybersecurity System. (official scope information from the Polish Ministry of Digital Affairs – in Polish)

Does NIS2 apply to electronics manufacturers?

Yes, electronics manufacturers may be subject to the NIS2 regulations. Important sectors include the manufacture of:

  • computers, electronic and optical products,
  • electrical equipment,
  • machinery and equipment,
  • motor vehicles,
  • other transport equipment,
  • medical devices and in vitro diagnostic medical devices.

NIS2 may therefore apply to manufacturers of industrial automation equipment, measuring instruments, automotive electronics, embedded systems, communication devices and selected medical devices.

Operating in the electronics industry alone does not automatically mean that a company is covered by the Act. The exact scope of its activities, the size of the company and any exceptions provided for in the regulations must also be considered.

Does NIS2 apply to suppliers?

A supplier does not automatically become an essential or important entity simply because it works with a company covered by the Act.

However, it may be indirectly affected by the customer’s requirements. Organisations covered by the regulations must consider risks associated with suppliers of products, software and services. In practice, they may therefore request information concerning:

  • the product support period,
  • the availability of updates,
  • vulnerability management procedures,
  • security documentation,
  • the end of the device’s life cycle,
  • the process for reporting technical issues.

Such requirements may appear in requests for quotations, contracts and purchasing specifications.

What obligations does NIS2 impose on companies?

Companies covered by the Act must implement technical, operational and organisational measures appropriate to the level of risk. This does not mean purchasing a single program or device, but establishing a consistent cybersecurity management system. (official guidance from the Polish Ministry of Digital Affairs – in Polish)

Risk management

An organisation should determine which systems, information and processes are most important to its operations. It must then identify potential threats and select appropriate safeguards.

The measures may include:

  • access and permissions management,
  • software updates,
  • vulnerability management,
  • communication security,
  • system monitoring,
  • supplier security,
  • employee training.

Risk analysis should not be a one-off activity. It should be updated following significant infrastructure changes, the implementation of new systems, a change of supplier or an incident.

Incident response

A company must have procedures that enable it to detect, assess and handle a cybersecurity incident.

In the event of a significant incident, an essential or important entity must submit:

  • an early warning within 24 hours of detecting the incident,
  • a notification containing additional information within 72 hours,
  • a final report after the incident has been handled.

(official NIS2 implementation Q&A – in Polish)

The organisation should identify in advance the persons responsible for submitting the notification and establish procedures for internal communication and cooperation with the relevant CSIRT.

Business continuity

Entities covered by the regulations must prepare for situations in which a cyberattack or failure disrupts their operations.

In practice, this requires the development and testing of:

  • backups,
  • system recovery procedures,
  • business continuity plans,
  • crisis communication procedures,
  • alternative methods of carrying out the most important processes.

The purpose is to limit the consequences of an incident and restore the operation of services as quickly as possible.

Management responsibility and documentation

Cybersecurity is not solely the responsibility of the IT department. The management of an essential or important entity is responsible for supervising the performance of the required duties and providing adequate resources. The head of the entity and the person entrusted with the head’s cybersecurity responsibilities are also subject to annual training. (official information from the Polish e-Health Centre – in Polish)

The company should retain documentation confirming the actions it has taken, including:

  • risk analysis results,
  • procedures,
  • test reports,
  • incident registers,
  • training records,
  • change and update documentation.

Key deadlines

Entities that met the relevant criteria on the date the regulations entered into force must:

  • register in the KSC Register by 3 October 2026,
  • connect to the S46 system by 3 April 2027,
  • implement the main obligations by 3 April 2027.

New essential entities that were not previously operators of essential services should carry out their first mandatory audit by 3 April 2028. Subsequent audits must be conducted at least once every three years. (official information on the obligations of essential and important entities – in Polish)

How does NIS2 affect the selection of devices and network infrastructure?

NIS2 does not specify a single mandatory set of device parameters. However, the selected equipment should enable the company to implement the measures resulting from its risk analysis.

This applies to devices and systems including:

  • industrial routers,
  • communication gateways,
  • switches,
  • industrial computers,
  • servers,
  • IoT devices,
  • automation systems.

Before selecting a device, it is worth checking:

  • how long the manufacturer plans to support the model,
  • whether firmware updates are available,
  • how the manufacturer communicates information about vulnerabilities,
  • whether users and permission levels can be managed,
  • whether unused ports and services can be disabled,
  • whether secure authentication and encryption are supported,
  • whether the device records events and can transmit logs,
  • whether the manufacturer provides secure configuration documentation,
  • when the product will reach the end of its life cycle.

A lack of continued support may mean that known vulnerabilities will not be removed. Information about updates and the product life cycle should therefore be reviewed during the purchasing process.

The ability to divide infrastructure into separate segments is also important. Separating office systems, production systems and systems accessible from the internet may reduce the consequences of a compromised device.

ENISA’s technical guidance applies directly to certain entities in the digital infrastructure, ICT service management and digital services sectors. However, it may also serve as a useful reference when assessing updates, configuration, logging and other security measures. (ENISA NIS2 Technical Implementation Guidance)

Selecting an appropriate device does not guarantee that a company complies with NIS2. It may, however, support the implementation of safeguards, infrastructure monitoring and system management throughout the entire operating life of the system.

How should a company prepare for NIS2?

The preparation process can be divided into five basic steps.

1. Determine whether the company is covered by the Act

The company should analyse its actual activities, its size, its links with other entities and the criteria specified in the Act.

2. Appoint responsible persons

Representatives of management, IT, production, purchasing, the legal department and other areas associated with the systems in use should be involved in the process.

3. Define the scope

The company should determine which services, processes, locations and systems are relevant to the activities covered by the regulations. The assessment may include both IT infrastructure and industrial OT systems.

4. Conduct a gap analysis

Existing measures should be compared with the requirements of the Act in order to identify:

  • critical gaps,
  • high-priority tasks,
  • required technical changes,
  • missing procedures and documents.

A plan specifying the tasks, deadlines and responsible persons can then be prepared.

5. Test and update the measures

Procedures should be regularly tested in practice. This includes data recovery, communication during an incident and cooperation between departments.

Preparing for NIS2 is an ongoing process. The measures adopted should be reviewed following organisational changes, the implementation of new technologies, a change of supplier or an incident.

Selecting devices for industrial applications

When selecting a router, industrial computer, switch or communication module, it is worth comparing not only the basic technical parameters, but also the documentation, support terms and device management functions.

Elhurt supports customers in selecting and integrating finished products from reputable manufacturers, including communication devices and industrial computers. The support covers matching the solution to the application parameters, available interfaces, operating environment and project requirements.

This article is for informational purposes only and does not replace an individual legal assessment of a specific organisation’s situation.