Cybersecurity after self‑identification – first steps following the entry into force of NIS2. Article by Krystian Tomasik
The new provisions implementing the NIS2 Directive, which entered into force on April 3 2026, significantly reshape the landscape of cybersecurity obligations for businesses operating across multiple sectors of the economy. In the second article of the series dedicated to these issues, Krystian Tomasik, Legal Counsel and Associate at SSW, explains the steps that should be taken following the self‑identification process.
The article was published on the Rzeczpospolita website and serves as a practical continuation of the first instalment in the series, which addressed the scope of application of the new regulations.
What should be done after self‑identification? Key takeaways
The author demonstrates, step by step, that further actions depend primarily on whether a company qualifies as an essential or important entity within the meaning of the new provisions.
Entities outside the scope of essential and important categories
The article highlights that even entities not directly subject to the NIS2 regime should not disregard the new standards. In practice:
- essential and important entities may require their contractors to implement specific cybersecurity standards,
- the security of ICT supply chains is becoming increasingly important,
- the absence of appropriate procedures may result in both commercial and contractual risks.
Essential and Important Entities – Obligations and Deadlines
For companies that meet the criteria of essential or important entities, the author discusses, among other things:
- the obligation to submit an application for entry into the relevant register,
- statutory deadlines arising from the new provisions,
- the scope of information that must be provided as part of the application,
- the role of the S46 system as a central tool for fulfilling regulatory obligations.
Particular attention is also given to the possibility of ex officio entry into the register and the risks associated with a failure to act on the part of the entity.
Why is it worth reading the full article?
Krystian Tomasik’s article serves as a practical guide that:
- organises the obligations arising after self‑identification,
- highlights differences in the legal position of companies,
- identifies potential consequences of failing to meet statutory deadlines,
- helps organisations better prepare for the implementation of NIS2 requirements.
Full article
Cybersecurity – First Steps Following Self‑Identification (published on the Rzeczpospolita website)
Contact
If you have any questions regarding NIS2, the self‑identification process or subsequent cybersecurity obligations, please do not hesitate to contact the SSW Cybersecurity team.