Polish companies caught by the NIS2 cybersecurity law have until 3 October 2026 to self-identify and register in the national registry, or face a fine before any incident even happens.
Why It Matters
Unlike GDPR, NIS2 registration is self-assessed: a company decides for itself whether it counts as a key or important entity based on its sector and size, then must file through the Ministry of Digital Affairs' online registry. Energy is one of the sectors pulled in directly, alongside transport, healthcare, and digital infrastructure, and missing the 3 October deadline is a violation in its own right, worth up to EUR 10 million for key entities, independent of whether any cyber incident ever happens.
What To Do About It
If your business sits in energy, transport, healthcare, water, digital infrastructure, or one of the other listed sectors and has more than a handful of staff, get a NIS2 applicability check done before October. Self-registering when unsure of your classification is safer than being found unregistered after the deadline.
Sources
Related Signals
A hacked vendor account let attackers into Żabka's internal systems for days before anyone noticed; the retailer confirmed the breach on 4 August after the data went up for sale.
5 Aug 2026KSeF carries no administrative penalties until 1 January 2027, but the tax code's separate criminal-fiscal liability for false or missing invoices already applies in full.
5 Aug 2026Poland's grid reform lets a battery share one connection point with solar or wind without counting as a second source, reopening capacity that developers were refused before.
4 Aug 2026