
Cybersecurity is no longer the sole preserve of IT departments. With the entry into force of the NIS 2 Directive, it has become a legal obligation for many organisations – including private companies. If you run a business, there is a strong likelihood that the new regulations apply to you too. In this article, we explain what the NIS 2 Directive is, who it covers and what changes it introduces.
The NIS 2 Directive is a set of EU regulations on cybersecurity, aimed at ensuring a high level of protection for information systems across the EU. In practice, this means an obligation to implement specific security measures and to report incidents. The new regulation replaces the previous NIS Directive and significantly expands its scope – both in terms of the number of entities covered and the requirements.
The Directive came into force at EU level in 2023, whilst Member States were given time to transpose it into national law. In Poland, the regulations implementing NIS 2 came into force in April 2026 through an amendment to the Act on the National Cybersecurity System.
NIS 2 covers two main groups of organisations:
1. Critical entities
2. Important entities
Importantly, whether an organisation is covered by the regulations is also determined by its size (number of employees and turnover), and not just by the sector in which it operates.

The NIS 2 Directive imposes specific obligations on organisations, which must be effectively implemented and applied in day-to-day operations. A key element is risk management, which involves identifying threats, assessing their impact on the organisation’s operations, and implementing appropriate security measures.
Companies are also required to detect and report cybersecurity incidents promptly to the relevant authorities. In practice, this means having clearly defined procedures and the capability to monitor systems.
Another key obligation is to adequately secure IT systems and data – including, amongst other things, access control, regular backups and the implementation of threat detection mechanisms. The Directive also extends liability to the supply chain, which means that risks associated with suppliers and business partners must be taken into account.
Another new feature is the explicit involvement of the board of directors, which is responsible for overseeing cybersecurity and making decisions in this area. Consequently, compliance with NIS2 requirements is not a one-off exercise, but a process requiring continuous monitoring, updating and improvement.