NIS2 Directive – how to address the challenges?

A brief overview of the NIS2 Directive

The NIS2 Directive represents a significant step towards strengthening cybersecurity across the European Union. Its implementation introduces new requirements and obligations for a broad range of organisations. In Poland, the transposition of NIS2 presents businesses with a number of challenges that require careful planning and well‑considered strategies.

NIS2 Directive – who is in scope?

Entities subject to the NIS2 Directive are not limited to large organisations. They also include smaller businesses operating, among others, in the following sectors:

  • manufacture of motor vehicles (excluding motorcycles),
  • manufacture of trailers and semi‑trailers,
  • production of parts and accessories for motor vehicles.

These entities must prepare for new regulatory obligations and operational challenges.

NIS2 Directive – new challenges for businesses

The new framework expands the number of entities subject to regulation, many of which will need to address complex compliance requirements. Key challenges for essential and important entities include:

  1. Understanding the regulations: the complexity of the NIS2 framework may be particularly challenging for smaller organisations. Adequate training and support are essential to minimise the risk of implementation errors.
  2. Risk assessment: entities must conduct systematic risk assessments and implement appropriate and proportionate technical and organisational measures, taking into account the state of the art, implementation costs, the size of the entity, the likelihood of incidents, exposure to risk, and potential social and economic impact.
  3. IT infrastructure readiness: many organisations will need to invest in advanced cybersecurity technologies to ensure adequate protection against cyber threats.
  4. Documentation requirements: essential and important entities must establish both normative and operational documentation, covering everything from information security management systems to sector‑specific requirements.
  5. Incident response: rapid and effective incident response is critical to maintaining business continuity. The Directive imposes specific obligations regarding incident reporting and handling, aimed at minimising the impact of cyber incidents.

NIS2 Directive – new opportunities

Despite the challenges, the implementation of NIS2 also presents significant opportunities for organisations:

  1. Enhanced customer trust: organisations that effectively implement NIS2 standards can strengthen trust among clients and business partners.
  2. Improved security posture: investments in cybersecurity technologies and risk management processes contribute to overall organisational resilience and help prevent incidents that may result in substantial financial losses.
  3. Increased competitiveness: compliance with NIS2 may offer a competitive advantage by enabling organisations to provide more secure products and services.

NIS2 Directive – why act now?

The implementation of NIS2 in Poland is not only about meeting regulatory requirements, but also about creating a more secure digital environment. Understanding the legal framework, preparing IT infrastructure and implementing effective risk management processes will deliver long‑term value.

The NIS2 Directive entered into force on January 16 2023 and will be implemented into Polish law on April 3 2026 through amendments to the Act on the National Cybersecurity System. From that date, deadlines for self‑identification and the implementation of required changes will begin to run.

Entities classified as essential or important that fail to comply with the new obligations may face significant financial and non‑financial sanctions. In the case of important entities (including qualifying manufacturers), financial penalties may reach up to EUR 7 million or 1.4% of the entity’s total worldwide annual turnover for the preceding financial year, whichever is higher.

NIS2 Directive – legal support

We provide comprehensive cybersecurity advisory services, including specialised training. We support clients in the self‑identification process and assist in adapting contractual frameworks to meet new regulatory requirements. In the event of cyber incidents, we also advise on litigation strategy and assist in pursuing claims. Please feel free to contact us to learn how we can support your organisation in achieving compliance with the NIS2 Directive and responding effectively to cybersecurity incidents.

Back to