Cybersecurity · 7 min

NIS2 — obligations for companies in Poland

NIS2 is coming hard. Check whether it applies to you.

29 October 2025

Cyberattacks on Polish businesses are no longer a problem for large corporations only. In 2026 the primary targets are small and mid-sized companies, because they have data, money and weaker defences. Below we show exactly what NIS2 — obligations for companies in Poland means and which decisions are worth making this quarter.

NIS2 is coming hard. Check whether it applies to you.

Who NIS2 covers

Regulatory compliance is not optional — it is a condition for operating. For Polish companies in 2026 the three sets of requirements that matter most are: GDPR, NIS2 and (in selected industries) sectoral rules (e.g. KNF).

The minimum you need

  • A record of processing activities and a risk analysis.
  • Data Processing Agreements (DPA) with every provider processing personal data.
  • An incident reporting procedure (72 hours to the DPA in case of a breach).
  • A security policy and regular employee training.
  • Backups with restore tests (proof that the backup works).

GDPR fines in Poland reach up to 4% of global turnover. NIS2 adds reporting duties and personal liability of the management. The cost of preparation is incomparably lower than the cost of being unprepared.

Key requirements

This section frames the topic "Key requirements" in the context of NIS2 — obligations for companies in Poland. We approach it from the business side — what concrete value or risk it brings to the company.

What you gain

  • Significantly reduced risk of ransomware and customer data leaks.
  • Compliance with GDPR, NIS2 and cyber insurers' requirements.
  • Trust from partners in procurement processes and security audits.

Most common mistakes

  • Relying only on antivirus instead of layered protection (EDR + MFA + backup).
  • A backup that was never tested — in practice equivalent to no backup at all.
  • No anti-phishing training — 90% of incidents start with a click on a link.

Implementation timeline

A smooth rollout of an IT solution is not a one-off action — it is a project in 4 phases. Cutting them short "to go faster" is the shortest path to an outage.

Phase 1: Audit and dependency map

We inventory systems, integrations, licences, accounts and users. The output is a list of what can be moved as is, what needs a refactor and what should be sunset.

Phase 2: Pilot

We pick one team (5–15 people), migrate them under controlled conditions and collect feedback. Findings feed back into the main plan.

Phase 3: Main migration

Rolled out in waves (typically 30–50 people per week), always with a helpdesk on standby on day one after cutover. Data, mail and permissions migrate before the users, not with them.

Phase 4: Reinforcement

Training, documentation, procedures and handover to steady-state operations. Without this phase the investment quickly loses value, because the knowledge stays in the heads of 2–3 people.

Penalties

This section frames the topic "Penalties" in the context of NIS2 — obligations for companies in Poland. We approach it from the business side — what concrete value or risk it brings to the company.

What you gain

  • Significantly reduced risk of ransomware and customer data leaks.
  • Compliance with GDPR, NIS2 and cyber insurers' requirements.
  • Trust from partners in procurement processes and security audits.

Most common mistakes

  • Relying only on antivirus instead of layered protection (EDR + MFA + backup).
  • A backup that was never tested — in practice equivalent to no backup at all.
  • No anti-phishing training — 90% of incidents start with a click on a link.

Key takeaways

  • Significantly reduced risk of ransomware and customer data leaks.
  • Relying only on antivirus instead of layered protection (EDR + MFA + backup).
  • Treat the topic of "NIS2 — obligations for companies in Poland" as a project, not a one-off purchase — the best results come from a step-by-step approach.

Frequently asked questions

Check your company's security level

We invite you to a free cybersecurity consultation. We will walk through a checklist of 30 key areas (MFA, backup, EDR, training) and point out priorities for the next quarter.