Polish companies caught by the NIS2 cybersecurity law have until 3 October 2026 to self-identify and register in the national registry, or face a fine before any incident even happens.
Why It Matters
Unlike GDPR, NIS2 registration is self-assessed: a company decides for itself whether it counts as a key or important entity based on its sector and size, then must file through the Ministry of Digital Affairs' online registry. Energy is one of the sectors pulled in directly, alongside transport, healthcare, and digital infrastructure, and missing the 3 October deadline is a violation in its own right, worth up to EUR 10 million for key entities, independent of whether any cyber incident ever happens.
What To Do About It
If your business sits in energy, transport, healthcare, water, digital infrastructure, or one of the other listed sectors and has more than a handful of staff, get a NIS2 applicability check done before October. Self-registering when unsure of your classification is safer than being found unregistered after the deadline.
Sources
Related Signals
Od 7 września 2026 operatorzy sieci dostają prawo zdalnie ograniczać moc mikroinstalacji 0,8-50 kW albo je odłączać, jeśli zagrażają sieci albo właściciel nie zainstaluje wymaganego urządzenia sterującego.
25 Aug 2026A partir de 1 de outubro de 2026 entra em vigor o Decreto-Lei 108/2026: a comunicação prévia deixa de ter fase de saneamento e a obra pode arrancar logo após o pagamento das taxas.
25 Aug 2026Od 7 stycznia 2026 obiekty do 200 m² na dwóch kondygnacjach powstają na zgłoszenie, nie pozwolenie na budowę, a nadzór budowlany dostał nowe narzędzie: 60 dni na poprawki zamiast wstrzymania robót.
25 Aug 2026