731 901 601
The NIS 2 Directive – what is it and who does it apply to? A comprehensive guide for businesses

The NIS 2 Directive – what is it and who does it apply to? A comprehensive guide for businesses

Introduction

Cybersecurity is no longer the sole preserve of IT departments. With the entry into force of the NIS 2 Directive, it has become a legal obligation for many organisations – including private companies. If you run a business, there is a strong likelihood that the new regulations apply to you too. In this article, we explain what the NIS 2 Directive is, who it covers and what changes it introduces.

What is the NIS 2 Directive?

The NIS 2 Directive is a set of EU regulations on cybersecurity, aimed at ensuring a high level of protection for information systems across the EU. In practice, this means an obligation to implement specific security measures and to report incidents. The new regulation replaces the previous NIS Directive and significantly expands its scope – both in terms of the number of entities covered and the requirements. 

The Directive came into force at EU level in 2023, whilst Member States were given time to transpose it into national law. In Poland, the regulations implementing NIS 2 came into force in April 2026 through an amendment to the Act on the National Cybersecurity System.

Who is covered by the NIS 2 Directive?

NIS 2 covers two main groups of organisations:

1. Critical entities

  • energy 
  • transport 
  • banking and financial infrastructure 
  • healthcare 
  • public administration 
  • digital infrastructure 

2. Important entities

  • food production and distribution 
  • waste management 
  • courier and postal services 
  • chemical industry 
  • digital service providers

Importantly, whether an organisation is covered by the regulations is also determined by its size (number of employees and turnover), and not just by the sector in which it operates.

Key requirements for organisations covered by the NIS 2 Directive

The NIS 2 Directive imposes specific obligations on organisations, which must be effectively implemented and applied in day-to-day operations. A key element is risk management, which involves identifying threats, assessing their impact on the organisation’s operations, and implementing appropriate security measures.

Companies are also required to detect and report cybersecurity incidents promptly to the relevant authorities. In practice, this means having clearly defined procedures and the capability to monitor systems.

Another key obligation is to adequately secure IT systems and data – including, amongst other things, access control, regular backups and the implementation of threat detection mechanisms. The Directive also extends liability to the supply chain, which means that risks associated with suppliers and business partners must be taken into account.

Another new feature is the explicit involvement of the board of directors, which is responsible for overseeing cybersecurity and making decisions in this area. Consequently, compliance with NIS2 requirements is not a one-off exercise, but a process requiring continuous monitoring, updating and improvement.

 

Read other posts

NIS2 and ISO 27001 – differences, similarities and what is actually required

NIS2 and ISO 27001 – differences, similarities and what is actually required

Many organisations that are beginning to grapple with the requirements of NIS2 immediately look to ISO 27001 as a ‘ready-made solution’. read more
ISO 22000 – the cornerstone of food safety management worldwide

ISO 22000 – the cornerstone of food safety management worldwide

Among all food safety management systems, ISO 22000 holds a special place – as the only standard with a truly global scope, developed by the International Organisation for Standardisation, it covers the entire food chain from raw material producers to distributors. read more
The EU Regulation on Packaging and Packaging Waste – how to prepare your business for the new obligations

The EU Regulation on Packaging and Packaging Waste – how to prepare your business for the new obligations

For many businesses, the entry into force of the PPWR Regulation represents not only a change in legislation but also the need to reorganise operational processes. read more
More posts