GrantThornton - regions

NIS2 in a corporate group: seven pitfalls that may bring a company within its Scope

Get in touch

Magdalena Bilicka

Counsel, Attorney-at-law

Key words

The obligations under the Polish Act on the National Cybersecurity System apply to a specific entity rather than to the corporate group as a whole. Each company should independently determine whether it qualifies as an important or essential entity.

However, group relationships may affect both the company’s size and the classification of managed services provided within the corporate group.

Pitfall 1. Can services provided exclusively within a corporate group fall within the scope of NIS2?

A common mistake when assessing the application of NIS2 within a corporate group is to disregard services provided exclusively within the group. This applies in particular where one company provides other group entities with IT support, systems administration, helpdesk services, and account and access management.

The fact that services are provided exclusively to linked entities does not, in itself, exclude the application of the Polish Act on the National Cybersecurity System. What matters is whether the services are provided between separate legal entities and whether their actual scope corresponds to the definition of managed services. If so, the company providing those services may need to be assessed as a potential managed service provider operating in a highly critical sector.

Pitfall 2. Can ancillary ICT services bring a company within the scope of NIS2?

ICT services do not need to constitute a company’s principal or predominant activity to be taken into account when assessing whether the Polish Act on the National Cybersecurity System applies. If, alongside its main business activity, a company also provides services that meet the definition of managed services, the ancillary nature of those services does not preclude the company from qualifying as a managed service provider.

This may apply in particular to a shared services centre established primarily to perform financial, accounting or administrative functions, while also providing other group companies with ongoing IT support, operating a helpdesk, managing accounts and access rights, administering network and information systems, or being responsible for updating and maintaining them.

Ważny fragment

The classification of these activities does not depend on their share in the company’s overall business activity or on the proportion of the company’s revenue that they generate.

Pitfall 3. Is the size of a group company determined solely on the basis of its own data?

For the purpose of assessing whether the Polish Act on the National Cybersecurity System applies, a company’s size is generally not determined solely on the basis of its own staff headcount, annual turnover and annual balance sheet total. If the company belongs to a corporate group or has relationships with other enterprises that may result in those enterprises being classified as partner enterprises or linked enterprises, the nature of those relationships must be determined.

The data of such enterprises must be taken into account in accordance with the rules set out in Annex I to Commission Regulation (EU) No 651/2014. This means that a company which, on the basis of its own data, would qualify as a microenterprise or small enterprise may, after the data of its partner enterprises or linked enterprises are taken into account, reach the size threshold required for the Polish Act on the National Cybersecurity System to apply.

Pitfall 4. When are the data of partner and linked enterprises disregarded?

As a general rule, the data of partner enterprises and linked enterprises must be taken into account when determining the size of an enterprise. However, the Polish Act on the National Cybersecurity System provides for a specific exemption. Where an enterprise reaches the applicable size threshold solely as a result of the inclusion of such data, it will not be classified on that basis as an important or essential entity if its network and information systems are independent of those of the relevant enterprises or if it does not provide services falling within the scope of the Act jointly with those enterprises.

Ważny fragment

The use of the conjunction “or” in these provisions is significant. For the exemption to apply, it is not necessary to demonstrate both the independence of the network and information systems and the absence of joint service provision. It is sufficient for either of these conditions to be met.

Pitfall 5. Does every form of cooperation between companies constitute joint service provision, and how can the independence of network and information systems be determined?

The Polish Act on the National Cybersecurity System does not specify what constitutes joint service provision or when network and information systems should be regarded as independent. The guidance issued by the Ministry of Digital Affairs is helpful in this respect. According to that guidance, network and information systems may be considered independent where the provision of services by a given entity does not require the involvement of a partner or linked enterprise. Independence may also mean that the networks and information systems used are substitutable, meaning that they can be replaced, within an acceptable timeframe and at an acceptable cost, by solutions provided by other entities with equivalent or better functional and technical parameters.

The Ministry also indicates that where an entity and its partner or linked enterprise do not provide the same service falling within the scope of the national cybersecurity system, the data of that enterprise should, as a general rule, not be taken into account when determining the size of the entity. By contrast, joint provision of the same service may occur where the entities have divided between themselves the responsibilities connected with the provision of that service. Such an operating model should be properly documented.

More services related to: Legal Advisory
Find out more

Pitfall 6. Is the Polish branch of a foreign undertaking subject to the Polish Act on the National Cybersecurity System?

Pursuant to Article 5a of the Polish Act on the National Cybersecurity System, an important or essential entity is subject to the obligations laid down in the Act if the entity has its place of residence or registered office in the Republic of Poland, or conducts business activities in Poland through a registered office or branch, or on a cross-border basis.

Where a foreign undertaking operates in Poland through a branch, it should be remembered that the branch is not a separate legal person. It is an organisationally separate part of the foreign undertaking. Therefore, when determining the size of the entity, the assessment should not be limited to the staff headcount or financial data attributed to the Polish branch. The foreign undertaking as a whole should be the relevant point of reference.

A more complex situation arises where a foreign company carries out an activity falling within the scope of NIS2 in another country, while its Polish branch carries out an activity that does not fall within the scope of the Polish Act on the National Cybersecurity System. The Act does not expressly determine whether, in such circumstances, the mere existence of a branch in Poland is sufficient for the foreign undertaking to become subject to the obligations laid down in the Polish Act.

In our view, the application of the Polish Act on the National Cybersecurity System should be linked to the activity carried out in Poland. This means that a foreign undertaking should, in principle, be subject to the obligations under Polish law where its Polish branch also carries out an activity falling within a sector covered by the Act. However, this issue is not conclusively resolved by the applicable provisions and should therefore be assessed carefully on a case-by-case basis.

Pitfall 7. Can a corporate group implement NIS2 jointly?

Companies belonging to the same corporate group may prepare jointly for compliance with the Polish Act on the National Cybersecurity System. The group may implement uniform security policies and procedures, use shared technical tools, and centrally organise training, infrastructure monitoring or incident handling. This approach may streamline NIS2 implementation, particularly where group companies use shared network and information systems or are supported by a single IT department.

A group-wide implementation does not, however, change the fact that the obligations under the Polish Act on the National Cybersecurity System apply to specific important and essential entities, rather than to the corporate group as a whole. Each company must therefore be assessed individually and must ensure proper compliance with the obligations applicable to that company as a separate entity.

 

The obligations arising from NIS2 and the Polish Act on the National Cybersecurity System should be assessed separately for each company, as it is a specific entity rather than the corporate group as a whole that may qualify as an essential or important entity. However, membership of a corporate group is not irrelevant. In practice, it may have a significant impact both on the assessment of an enterprise’s size and on the classification of managed services provided within the group.

Also worth checking out: NIS-2 Directive – check whether you are subject to the requirements [short survey]>>

FAQ: NIS2 Directive and corporate groups

Does NIS2 apply to the entire corporate group?

No. The application of the Polish Act on the National Cybersecurity System must be assessed separately for each company.

Do managed services provided exclusively within a corporate group fall within the scope of NIS2?

They may. The intra-group nature of the services does not preclude the application of the Act. What matters is whether the services are provided between separate legal entities and whether they meet the statutory definition of managed services.

Can ancillary IT activities bring a company within the scope of NIS2?

Yes. ICT services do not need to constitute the company’s main business activity. What matters is the actual scope of the activities performed, rather than the proportion of revenue generated by IT services, the company’s Polish Classification of Activities (PKD) code or the name given to the service in the relevant agreement.

Does an entity always fall within the scope of NIS2 after the data of partner or linked enterprises are taken into account?

No. If the applicable size threshold is reached only after taking into account the data of partner enterprises or linked enterprises, the specific exemption under Article 5(6) or Article 5(7) of the Polish Act on the National Cybersecurity System must also be considered.

Let's talk your business

We provide services related to Legal Advisory

We will contact you next working day to identify your needs and tailor our sevices to suit them.

Check again! Some characters you used are not allowed.

Invalid format. Write youraddress@domain.com or phone number +XX XXXXXXXXX.

Get in touch

Magdalena Bilicka

Counsel, Attorney-at-law

Key words

Get in touch

Magdalena Bilicka

Counsel, Attorney-at-law

Key words

Request contact

Magdalena Bilicka

Counsel, Attorney-at-law

CONTACT_US_ADDITIONAL_TEXT
Information about cookies

1. As part of the website, the Administrator uses cookies to provide services at the highest level, including in a manner tailored to individual needs.
2. Using the website without changing the cookie settings means that cookies will be stored on your terminal device. You can change your cookie settings in your browser at any time.
3. The Administrator uses cookies to identify the website users, to keep statistics for marketing purposes, and to correctly provide other services offered by the website.
4. Cookies, including session cookies, may also provide information about your terminal equipment and the version of the browser you are using. These tasks are carried out for the correct display of content within the Administrator's website.
3. Cookies are short text files. Cookies do not, under any circumstances, allow the personal identification of a website visitor and no information is stored in them that could allow such identification.
A complete list of the cookies we use and information about their purposes is available in our Privacy Policy.