731 901 601
The NIS 2 Directive – what is it and who does it apply to? A comprehensive guide for businesses

The NIS 2 Directive – what is it and who does it apply to? A comprehensive guide for businesses

Introduction

Cybersecurity is no longer the sole preserve of IT departments. With the entry into force of the NIS 2 Directive, it has become a legal obligation for many organisations – including private companies. If you run a business, there is a strong likelihood that the new regulations apply to you too. In this article, we explain what the NIS 2 Directive is, who it covers and what changes it introduces.

What is the NIS 2 Directive?

The NIS 2 Directive is a set of EU regulations on cybersecurity, aimed at ensuring a high level of protection for information systems across the EU. In practice, this means an obligation to implement specific security measures and to report incidents. The new regulation replaces the previous NIS Directive and significantly expands its scope – both in terms of the number of entities covered and the requirements. 

The Directive came into force at EU level in 2023, whilst Member States were given time to transpose it into national law. In Poland, the regulations implementing NIS 2 came into force in April 2026 through an amendment to the Act on the National Cybersecurity System.

Who is covered by the NIS 2 Directive?

NIS 2 covers two main groups of organisations:

1. Critical entities

  • energy 
  • transport 
  • banking and financial infrastructure 
  • healthcare 
  • public administration 
  • digital infrastructure 

2. Important entities

  • food production and distribution 
  • waste management 
  • courier and postal services 
  • chemical industry 
  • digital service providers

Importantly, whether an organisation is covered by the regulations is also determined by its size (number of employees and turnover), and not just by the sector in which it operates.

Key requirements for organisations covered by the NIS 2 Directive

The NIS 2 Directive imposes specific obligations on organisations, which must be effectively implemented and applied in day-to-day operations. A key element is risk management, which involves identifying threats, assessing their impact on the organisation’s operations, and implementing appropriate security measures.

Companies are also required to detect and report cybersecurity incidents promptly to the relevant authorities. In practice, this means having clearly defined procedures and the capability to monitor systems.

Another key obligation is to adequately secure IT systems and data – including, amongst other things, access control, regular backups and the implementation of threat detection mechanisms. The Directive also extends liability to the supply chain, which means that risks associated with suppliers and business partners must be taken into account.

Another new feature is the explicit involvement of the board of directors, which is responsible for overseeing cybersecurity and making decisions in this area. Consequently, compliance with NIS2 requirements is not a one-off exercise, but a process requiring continuous monitoring, updating and improvement.

 

Read other posts

KZR as a ticket to stable relationships with major clients: why it’s worth investing in certification

KZR as a ticket to stable relationships with major clients: why it’s worth investing in certification

In the biofuels, biomass, waste and recycled materials sectors, KZR is more often seen as a necessary formal requirement than as a practical tool for building client relationships. read more
Knowledge management in ISO 9001:2026 – a new requirement not present in the 2015 version

Knowledge management in ISO 9001:2026 – a new requirement not present in the 2015 version

When comparing ISO 9001:2015 with the forthcoming version of the standard, the most attention is usually paid to the organisational climate, risks and opportunities, or quality culture. read more
IFS PACsecure – what do retail chains require from food packaging manufacturers?

IFS PACsecure – what do retail chains require from food packaging manufacturers?

Manufacturers of food-contact packaging operate at a specific point in the supply chain: their product never reaches the consumer directly, but it does come into direct contact with what the consumer eats. read more
More posts