NIS2 Requirements and the Amended UKSC. How to Build Real Cyber Resilience and Avoid Management Liability?

The growing number of digital security incidents—many of which affect medium-sized and large enterprises—has prompted the European legislator to comprehensively reform the legal framework for cybersecurity. The result is the NIS2 Directive, which is being implemented in Poland through the amendment of the National Cybersecurity System Act (UKSC), establishing April 3, 2026, as the date from which the regulations become fully enforceable.

The new regulation significantly expands the scope of entities subject to legal obligations and redefines responsibility for cybersecurity. It is no longer solely the domain of IT departments but has become one of the key areas of operational and legal risk for executive management. Implementing the requirements of NIS2 is not merely a formal compliance exercise but a necessity for ensuring Business Continuity in the event of digital infrastructure disruption.

Essential and Important Entities – Qualification Criteria and the Supply Chain Revolution

The NIS2 Directive replaces the previous discretionary designation of Operators of Essential Services with an automatic qualification system based on company size thresholds and sector classification. The new legal framework applies to medium-sized and large organizations operating across as many as 15 critical sectors of the economy, including energy, transport, banking, digital infrastructure, postal services, manufacturing, waste management, and food distribution.

The classification divides organizations into two main categories:

Essential entities: covering large enterprises (employing more than 250 employees or generating annual revenue exceeding EUR 50 million) operating in high-priority sectors.
Important entities: covering medium-sized enterprises (with at least 50 employees or annual revenue of at least EUR 10 million) operating in designated strategic industries.

Of particular importance from a legal advisory perspective is that the impact of the NIS2 regulations cannot be avoided by claiming the absence of direct sector qualification. The Directive directly requires essential and important entities to assess and secure their entire supply chain. This means that subcontractors, software providers, logistics companies, and technology agencies working with organizations covered by NIS2 will also be required to meet stringent security standards or risk losing commercial contracts.

The New Incident Reporting Regime and Organizational & Technical Obligations

Meeting the requirements of NIS2 requires organizations to implement appropriate and proportionate technical and organizational measures to manage risks affecting network and information systems. Among the highest priorities are continuous risk assessment, data encryption, supply continuity, and a continuous identity verification policy based on the Zero Trust model.

The regulation also introduces a highly stringent three-stage reporting timeline for significant cybersecurity incidents to the relevant CSIRT teams:

Early warning (within 24 hours): from the moment the organization becomes aware of the incident, indicating whether it was caused by unlawful activity and whether it may have cross-border implications.
Incident notification (within 72 hours): including a preliminary assessment of the scope of the breach, its impact, and indicators of compromise (IoCs).
Final report (within 1 month): providing a detailed description of the incident, the root cause, and the corrective measures implemented.

Personal Management Liability and Significant Financial Penalties

The key systemic change introduced by NIS2 and the UKSC is the transfer of direct personal responsibility for regulatory compliance to the management body (company boards of directors). Individuals managing the organization are required to approve cybersecurity risk management measures and participate in regular mandatory cybersecurity training. Failure to fulfill these legal obligations may authorize the supervisory authority to impose financial penalties on board members of up to 300% of their monthly remuneration and, in severe cases, temporarily suspend them from performing management functions.

Administrative financial penalties imposed directly on organizations are equally severe. Regulatory breaches may result in fines of:

For essential entities: up to EUR 10 million or 2% of the organization's total worldwide annual turnover in the preceding financial year.
For important entities: up to EUR 7 million or 1.4% of the organization's total worldwide annual turnover in the preceding financial year.

Under the principle of applying the higher penalty, supervisory authorities are required to impose whichever amount is greater, clearly demonstrating that cybersecurity has become one of the highest legal and financial risk areas for modern businesses.

The NIS2 Compliance Process with Rulity Consulting

Aligning an organization with the requirements of NIS2 and the amended National Cybersecurity System Act (UKSC) is a multi-stage process that combines legal and organizational auditing with advanced IT implementations and the establishment of continuous operational oversight.

At Rulity Consulting, we support executive boards and operations directors in safely guiding their organizations through the digital compliance transformation process. We provide comprehensive Gap Analysis, review contractual structures with suppliers throughout the supply chain, prepare the required legal documentation and incident management procedures, and implement continuous 24/7 Security Operations Center (SOC) monitoring. Reduce management risk and protect the operational stability of your business before the new regulations begin to be enforced.

NIS2 and UKSC Requirements – Frequently Asked Questions

When do the NIS2 requirements officially become enforceable in Poland?

The EU Directive has already entered into force, while its direct enforceability within the Polish legal framework begins under the amended National Cybersecurity System Act (UKSC) on April 3, 2026. However, organizations should conduct audits and implement compliance measures well in advance to achieve full operational readiness.

Does my company fall under NIS2 if I am not directly part of a critical sector?

Possibly, for two reasons. First, your industry may fall within the list of important sectors (such as manufacturing, postal and courier services, or digital infrastructure). Second, even if your organization is not directly covered due to its size, the requirements of NIS2 may still apply indirectly if you provide services or products to essential entities. Under the Directive, these organizations are legally required to audit and enforce cybersecurity standards throughout their entire supply chain.

What does personal management liability under NIS2 mean?

Members of management bodies can no longer delegate full responsibility for IT security to external providers or internal technical departments. They are personally responsible for approving cybersecurity risk management measures, completing mandatory training, and may face financial and disciplinary liability for failing to implement the required measures, including individual penalties of up to 300% of their remuneration.