However, group relationships may affect both the company’s size and the classification of managed services provided within the corporate group.
Table of contents
- Pitfall 1. Can services provided exclusively within a corporate group fall within the scope of NIS2?
- Pitfall 2. Can ancillary ICT services bring a company within the scope of NIS2?
- Pitfall 3. Is the size of a group company determined solely on the basis of its own data?
- Pitfall 4. When are the data of partner and linked enterprises disregarded?
- Pitfall 5. Does every form of cooperation between companies constitute joint service provision, and how can the independence of network and information systems be determined?
- Pitfall 6. Is the Polish branch of a foreign undertaking subject to the Polish Act on the National Cybersecurity System?
- Pitfall 7. Can a corporate group implement NIS2 jointly?
Pitfall 1. Can services provided exclusively within a corporate group fall within the scope of NIS2?
A common mistake when assessing the application of NIS2 within a corporate group is to disregard services provided exclusively within the group. This applies in particular where one company provides other group entities with IT support, systems administration, helpdesk services, and account and access management.
The fact that services are provided exclusively to linked entities does not, in itself, exclude the application of the Polish Act on the National Cybersecurity System. What matters is whether the services are provided between separate legal entities and whether their actual scope corresponds to the definition of managed services. If so, the company providing those services may need to be assessed as a potential managed service provider operating in a highly critical sector.
Pitfall 2. Can ancillary ICT services bring a company within the scope of NIS2?
ICT services do not need to constitute a company’s principal or predominant activity to be taken into account when assessing whether the Polish Act on the National Cybersecurity System applies. If, alongside its main business activity, a company also provides services that meet the definition of managed services, the ancillary nature of those services does not preclude the company from qualifying as a managed service provider.
This may apply in particular to a shared services centre established primarily to perform financial, accounting or administrative functions, while also providing other group companies with ongoing IT support, operating a helpdesk, managing accounts and access rights, administering network and information systems, or being responsible for updating and maintaining them.
Ważny fragment
The classification of these activities does not depend on their share in the company’s overall business activity or on the proportion of the company’s revenue that they generate.
Pitfall 3. Is the size of a group company determined solely on the basis of its own data?
For the purpose of assessing whether the Polish Act on the National Cybersecurity System applies, a company’s size is generally not determined solely on the basis of its own staff headcount, annual turnover and annual balance sheet total. If the company belongs to a corporate group or has relationships with other enterprises that may result in those enterprises being classified as partner enterprises or linked enterprises, the nature of those relationships must be determined.
The data of such enterprises must be taken into account in accordance with the rules set out in Annex I to Commission Regulation (EU) No 651/2014. This means that a company which, on the basis of its own data, would qualify as a microenterprise or small enterprise may, after the data of its partner enterprises or linked enterprises are taken into account, reach the size threshold required for the Polish Act on the National Cybersecurity System to apply.
Pitfall 4. When are the data of partner and linked enterprises disregarded?
As a general rule, the data of partner enterprises and linked enterprises must be taken into account when determining the size of an enterprise. However, the Polish Act on the National Cybersecurity System provides for a specific exemption. Where an enterprise reaches the applicable size threshold solely as a result of the inclusion of such data, it will not be classified on that basis as an important or essential entity if its network and information systems are independent of those of the relevant enterprises or if it does not provide services falling within the scope of the Act jointly with those enterprises.
Ważny fragment
The use of the conjunction “or” in these provisions is significant. For the exemption to apply, it is not necessary to demonstrate both the independence of the network and information systems and the absence of joint service provision. It is sufficient for either of these conditions to be met.
Pitfall 5. Does every form of cooperation between companies constitute joint service provision, and how can the independence of network and information systems be determined?
The Polish Act on the National Cybersecurity System does not specify what constitutes joint service provision or when network and information systems should be regarded as independent. The guidance issued by the Ministry of Digital Affairs is helpful in this respect. According to that guidance, network and information systems may be considered independent where the provision of services by a given entity does not require the involvement of a partner or linked enterprise. Independence may also mean that the networks and information systems used are substitutable, meaning that they can be replaced, within an acceptable timeframe and at an acceptable cost, by solutions provided by other entities with equivalent or better functional and technical parameters.
The Ministry also indicates that where an entity and its partner or linked enterprise do not provide the same service falling within the scope of the national cybersecurity system, the data of that enterprise should, as a general rule, not be taken into account when determining the size of the entity. By contrast, joint provision of the same service may occur where the entities have divided between themselves the responsibilities connected with the provision of that service. Such an operating model should be properly documented.
Pitfall 6. Is the Polish branch of a foreign undertaking subject to the Polish Act on the National Cybersecurity System?
Pursuant to Article 5a of the Polish Act on the National Cybersecurity System, an important or essential entity is subject to the obligations laid down in the Act if the entity has its place of residence or registered office in the Republic of Poland, or conducts business activities in Poland through a registered office or branch, or on a cross-border basis.
Where a foreign undertaking operates in Poland through a branch, it should be remembered that the branch is not a separate legal person. It is an organisationally separate part of the foreign undertaking. Therefore, when determining the size of the entity, the assessment should not be limited to the staff headcount or financial data attributed to the Polish branch. The foreign undertaking as a whole should be the relevant point of reference.
A more complex situation arises where a foreign company carries out an activity falling within the scope of NIS2 in another country, while its Polish branch carries out an activity that does not fall within the scope of the Polish Act on the National Cybersecurity System. The Act does not expressly determine whether, in such circumstances, the mere existence of a branch in Poland is sufficient for the foreign undertaking to become subject to the obligations laid down in the Polish Act.
In our view, the application of the Polish Act on the National Cybersecurity System should be linked to the activity carried out in Poland. This means that a foreign undertaking should, in principle, be subject to the obligations under Polish law where its Polish branch also carries out an activity falling within a sector covered by the Act. However, this issue is not conclusively resolved by the applicable provisions and should therefore be assessed carefully on a case-by-case basis.
Pitfall 7. Can a corporate group implement NIS2 jointly?
Companies belonging to the same corporate group may prepare jointly for compliance with the Polish Act on the National Cybersecurity System. The group may implement uniform security policies and procedures, use shared technical tools, and centrally organise training, infrastructure monitoring or incident handling. This approach may streamline NIS2 implementation, particularly where group companies use shared network and information systems or are supported by a single IT department.
A group-wide implementation does not, however, change the fact that the obligations under the Polish Act on the National Cybersecurity System apply to specific important and essential entities, rather than to the corporate group as a whole. Each company must therefore be assessed individually and must ensure proper compliance with the obligations applicable to that company as a separate entity.
The obligations arising from NIS2 and the Polish Act on the National Cybersecurity System should be assessed separately for each company, as it is a specific entity rather than the corporate group as a whole that may qualify as an essential or important entity. However, membership of a corporate group is not irrelevant. In practice, it may have a significant impact both on the assessment of an enterprise’s size and on the classification of managed services provided within the group.