731 901 601
The NIS 2 Directive – what is it and who does it apply to? A comprehensive guide for businesses

The NIS 2 Directive – what is it and who does it apply to? A comprehensive guide for businesses

Introduction

Cybersecurity is no longer the sole preserve of IT departments. With the entry into force of the NIS 2 Directive, it has become a legal obligation for many organisations – including private companies. If you run a business, there is a strong likelihood that the new regulations apply to you too. In this article, we explain what the NIS 2 Directive is, who it covers and what changes it introduces.

What is the NIS 2 Directive?

The NIS 2 Directive is a set of EU regulations on cybersecurity, aimed at ensuring a high level of protection for information systems across the EU. In practice, this means an obligation to implement specific security measures and to report incidents. The new regulation replaces the previous NIS Directive and significantly expands its scope – both in terms of the number of entities covered and the requirements. 

The Directive came into force at EU level in 2023, whilst Member States were given time to transpose it into national law. In Poland, the regulations implementing NIS 2 came into force in April 2026 through an amendment to the Act on the National Cybersecurity System.

Who is covered by the NIS 2 Directive?

NIS 2 covers two main groups of organisations:

1. Critical entities

  • energy 
  • transport 
  • banking and financial infrastructure 
  • healthcare 
  • public administration 
  • digital infrastructure 

2. Important entities

  • food production and distribution 
  • waste management 
  • courier and postal services 
  • chemical industry 
  • digital service providers

Importantly, whether an organisation is covered by the regulations is also determined by its size (number of employees and turnover), and not just by the sector in which it operates.

Key requirements for organisations covered by the NIS 2 Directive

The NIS 2 Directive imposes specific obligations on organisations, which must be effectively implemented and applied in day-to-day operations. A key element is risk management, which involves identifying threats, assessing their impact on the organisation’s operations, and implementing appropriate security measures.

Companies are also required to detect and report cybersecurity incidents promptly to the relevant authorities. In practice, this means having clearly defined procedures and the capability to monitor systems.

Another key obligation is to adequately secure IT systems and data – including, amongst other things, access control, regular backups and the implementation of threat detection mechanisms. The Directive also extends liability to the supply chain, which means that risks associated with suppliers and business partners must be taken into account.

Another new feature is the explicit involvement of the board of directors, which is responsible for overseeing cybersecurity and making decisions in this area. Consequently, compliance with NIS2 requirements is not a one-off exercise, but a process requiring continuous monitoring, updating and improvement.

 

Read other posts

Counterfeit medicines in the supply chain – how does the DPD system protect patients?

Counterfeit medicines in the supply chain – how does the DPD system protect patients?

Counterfeit medicinal products are one of the most serious problems facing the modern pharmaceutical industry. A medicine lacking an active ingredient, containing it in the wrong concentration, or manufactured under uncontrolled conditions may not only fail to treat – it may kill. read more
Who is ISO 42001 aimed at, and what benefits does it offer an organisation?

Who is ISO 42001 aimed at, and what benefits does it offer an organisation?

Artificial intelligence is becoming an increasingly integral part of the day-to-day operations of businesses. AI tools are now used not only in the IT sector, but also in marketing, logistics, HR, finance, e-commerce and customer service. read more
How much does not having ISO 27001 cost? A bill that makes an impression

How much does not having ISO 27001 cost? A bill that makes an impression

Most companies that do not have ISO 27001 do not have it for one reason: the cost of implementation seems too high. read more
More posts