New obligations for Polish entrepreneurs, imposed by the government, are the consequences of adopting the EU NIS2 directive. This law aims to strengthen cybersecurity. The regulations cover a total of 18 key economic sectors, including, among others: energy, transport, health, banking, and digital services.
Entrepreneurs have six months to register
The possibility for entrepreneurs from the 18 strategic sectors listed in the law to register with the National Cybersecurity System became available on May 7. They have until October 3 to join the register. This must be done through the platform wykaz-ksc.gov.pl. After this period, they may face huge financial penalties, up to 10 million euros.
Registration is just one of many obligations that will be imposed on entrepreneurs due to the new regulations. Others include implementing an information security management system and procedures for data breach incidents. Companies will also be required to report all cybersecurity incidents and mitigate their effects.
Communication with the bodies responsible for implementing the directive will be simplified by the S46 Cyber Hub platform, which entrepreneurs can use for daily reporting and communication with the relevant authority responsible for cybersecurity, as well as the Ministry of Digital Affairs. According to estimates, the cybersecurity system is expected to cover nearly 38,000 entities, including 27,000 public institutions.
Not everyone has to register themselves
Some companies are exempt from the obligation to register independently. These are the largest entities that are of special importance to the economy. In their case, the application will be processed automatically. Such entrepreneurs must wait for information from the Ministry of Digital Affairs that their application has been submitted. They will then only be asked to complete data that will be entered into the government database.
The entire process aims to increase cybersecurity, accelerate the flow of threat information, and enable faster systemic responses to cyber attacks.
The Ministry of Digital Affairs provides a detailed division of key and important sectors:
- Energy:
- mining
- electricity
- heat
- oil and fuels
- gas
- nuclear energy
- hydrogen
- Transport:
- Banking and financial market infrastructure
- Health protection:
- providing health services and public health
- production and distribution of active substances, medicinal products and medical devices
- Drinking water supply and distribution
- Collective sewage disposal
- Digital infrastructure:
- digital infrastructure excluding electronic communication
- electronic communication
- ICT service management
- Space sector
- Public entities
Important sectors (Appendix 2 to the law)
- Postal services
- Nuclear energy investments
- Waste management:
- waste collection
- waste transport
- waste processing, including sorting, with oversight of the mentioned activities, and subsequent handling of waste disposal sites
- activities performed as a waste seller or intermediary in waste trade
- Production, manufacturing and distribution of chemicals
- Production, manufacturing and distribution of food
- Production:
- medical devices and in‑vitro diagnostic medical devices
- computers, electronic and optical devices
- electrical equipment
- machines and equipment, elsewhere unclassified
- motor vehicles, trailers and semi‑trailers
- other transport equipment
- Digital service providers
- Scientific research
- Public entities.