NIS-2 Directive – check whether you are subject to the requirements

NOTE: The questionnaire has been updated following the publication on 7 października 2024 r. of the new draft Cyber Security Act

Is my company subject to NIS-2 and the draft amendment to the National Cyber Security System Act?

We have prepared a short questionnaire for you to identify whether, and to what extent, your company will be subject to the requirements of the Directive on measures for a high common level of cyber security throughout the European Union (NIS2 Directive).

NIS-2 – from when and what penalties?

The implementation of the NIS2 Directive, which is likely to come into force as early as 2025, will introduce significant changes for Polish entities: liability of governing bodies and penalties of up to EUR 10,000,000 or as much as 2% of a company’s annual turnover.

Learn more:  Dyrektywa NIS-2: Czym jest, kogo dotyczy i kiedy wchodzi w życie? (this article is in Polish)

Is my company subject to NIS-2 Directive?

We have prepared a short survey to help you determine whether and to what extent your company will be subject to the requirements of the Directive on measures for a high common level of cybersecurity across the Union (the NIS-2 Directive). The NIS-2 Directive will be transposed into Polish law through an amendment to the Polish National Cybersecurity System (NCS) Act, which is expected to enter into force in 2025. The new regulations will bring significant changes for Polish entities: liability of management bodies and financial penalties reaching up to EUR 10,000,000 or 2% of the company’s global annual revenue. We are here to help you prepare for the new requirements. We have prepared some questions to help you make a preliminary assessment of your potential new responsibilities in this area. After answering the questions, you will receive a score reflecting the likelihood that you will be affected by the new obligations imposed by the Directive and the draft amendment to the NCS Act.

1

About your business

2

Questionnaire

3

Result

Does your company operate in one of the following sectors?

  • Energy
  • Transport
  • Banking and financial market infrastructures
  • Healthcare
  • Drinking water supply and distribution
  • Digital infrastructure
  • ICT service management
  • Space
  • Manufacture, production and distribution of chemicals
  • Production, processing and distribution of food
  • Manufacturing
  • Postal services
  • Waste management
  • Digital providers
  • Research
  • DNS service providers
  • Qualified or non-qualified trust service providers
  • Critical entities
  • Public entities
  • Top-level domain (TLD) name registries
  • Electronic communications providers
  • OTHER

    Including but not limited to::

  • Mineral extraction
  • Electricity – distribution system operators, transmission system operators, generators or participants in the storage and aggregation market, charging point operators responsible for the management and operation of a charging point, providing a charging service to end users, including for and on behalf of a mobility service provider
  • District heating or cooling – operators of district heating or cooling
  • Oil – operators of oil transmission pipelines, operators of oil production, refining and treatment facilities, storage and transmission, as well as a central stockholding entities
  • Gas – supply undertakings, distribution system operators, transmission system operators, storage system operators, LNG system operators, as well as natural gas undertakings or operators of a natural gas refining and treatment facilities; entities engaged in the extraction of natural gas under licence
  • Nuclear power – nuclear power plant operators, nuclear power plant investors
  • Hydrogen – operators of hydrogen production, storage and transmission
  • Air – air carriers, airport managing body operators or entities operating ancillary installations contained within airports; traffic management control operators providing air traffic control (ATC) services
  • Rail – infrastructure managers or railway undertakings, including operators of service facilities
  • Water – inland, sea and coastal passenger and freight water transport companies, as well as managing bodies of a port, including port facilities and entities operating works and equipment contained within ports; operators of vessel traffic services
  • Road – road authorities responsible for traffic management control, excluding public entities for which traffic management or the operation of intelligent transport systems is a non-essential part of their general activity
  • Including but not limited to::

  • credit institutions
  • operators of trading venues
  • central counterparties (CCPs)
  • SKOK credit unions
  • brokerage firms
  • Including but not limited to::

  • healthcare providers
  • EU reference laboratories
  • entities carrying out research and development activities of medicinal products
  • entities providing healthcare services subcontracted to key or important players in the healthcare sector
  • manufacturers/importers of basic pharmaceutical products and preparations
  • manufacturers/importers of basic pharmaceutical products and preparations, and other medical devices
  • public pharmacies
  • pharmaceutical wholesalers
  • suppliers and distributors of water intended for human consumption
  • Waste water disposal Water and sewerage companies
  • Including but not limited to::

  • Internet exchange point providers
  • cloud computing service providers
  • data centre service providers
  • content delivery network providers
  • domain name system service providers
  • managed service providers
  • managed cybersecurity service providers
  • operators of ground-based infrastructures owned, managed and operated by Member States or private parties that support the provision of space-based services, excluding providers of public electronic communications networks
  • Including but not limited to undertakings carrying out the manufacture of substances and the production and distribution of substances or mixtures, and enterprises carrying out the production of articles from substances or mixtures
  • Food businesses engaged in wholesale distribution and industrial production and processing
  • manufacture of medical devices and in vitro diagnostic medical devices
  • manufacture of computer, electronic and optical products
  • manufacture of electrical equipment
  • manufacture of machinery and equipment n.e.c.
  • manufacture of motor vehicles, trailers and semi-trailers
  • manufacture of other transport equipment
  • postal service providers
  • Waste collection
  • Waste transport
  • Treatment of waste, including sorting, together with supervision of such activities and subsequent management of waste disposal sites.
  • Activities performed as a waste dealer or waste broker
  • Supplies and services for the waste management sector
  • Waste collection
  • providers of online marketplaces
  • providers of online search engines
  • providers of social networking services platforms
  • research organisations
  • universities and higher education providers
  • federations of higher education and science institutions
  • scientific institutes of the Polish Academy of Sciences (PAN)
  • international scientific institutes
  • Łukasiewicz Research Network
  • institutes operating within the Łukasiewicz Research Network
  • Polish Academy of Arts and Sciences (PAU)
  • Including but not limited to::

  • public authorities, including government administration, state control and defence of rights bodies
  • courts and tribunals
  • local authorities and their associations
  • metropolitan associations
  • public finance units
  • self-financing local public finance entities
  • executive agencies
  • public finance institutions
  • Social Insurance Institution (ZUS) and funds managed by it and Agricultural Social Insurance Fund (KRUS) and funds managed by the President of the Agricultural Social Insurance Fund (KRUS)
  • public universities and higher education providers
  • Polish Academy of Sciences (PAN) and its organisational units
  • state and local government cultural institutions
  • Research institutes
  • National Bank of Poland (NBP)
  • Bank Gospodarstwa Krajowego
  • Office of Technical Inspection (UDT)
  • Polish Air Navigation Services Agency (PAŻP)
  • Polish Centre for Accreditation (PCA)
  • Polish Financial Supervision Authority (KNF)
  • National Health Fund (NFZ)
  • Polish Press Agency (PAP)
  • The State Water Holding Wody Polskie, referred to in Water Law of 20 July 2017 (Journal of Laws of 2024 items 1087 and 1087)
  • The Polish Development Fund (PFR) and other development institutions referred to in the Development Institutions System Act of 4 July 2019 (Article 2 para. 1 points 1 and 3-6)
  • National Fund for Environmental Protection and Water Management (NFOŚiGW)
  • Regional funds for Environmental Protection and Water Management
  • State Fund for the Rehabilitation of the Disabled (PFRON)
  • Radioactive Waste Disposal Facility in Otwock-Świerk
  • Commercial law companies performing public utility tasks within the meaning of Article 1 para. 2 of the Municipal Management Act of 20 December 1996 (Journal of Laws of 2021 item 679)

Tell us about your business

  • Less than 50
  • Between 50 and 250
  • More than 250
  • Less than EUR 10 million
  • Between EUR 10 and 50 million
  • More than EUR 50 million

Your result:

Your answers
Company size 0 - 10 pracowników Change

Adam Woźniak

Executive Director

Get in touch with Adam Woźniak, to consult your result.

*Required consent
Information about personal data processing can be found in Privacy policy and Information clause.