Companies covered by Poland's NIS2 cybersecurity law have until 3 October 2026 to self-assess and register in the government's S46 system, with fines up to EUR 10 million for getting it wrong.
Why It Matters
The amended Act on the National Cybersecurity System took effect on 3 April 2026 and pulled in a wide new set of sectors, energy and renewables among the first, alongside manufacturing, chemicals, food production and waste management. Every entity meeting the size and sector criteria has a six-month window from that date to decide whether it counts as a key or important entity and register through the S46 portal. Skipping the self-assessment is itself a violation, separate from the security work that follows, and critical entities face fines up to EUR 10 million or 2% of global turnover.
What To Do About It
If you run a business in energy, manufacturing, food, waste or one of the other newly covered sectors, do the NIS2 size and sector self-assessment now rather than in September: confirm whether you meet the thresholds, and if you do, register through system-s46 on gov.pl before 3 October 2026 so the registration itself is not the first thing that goes wrong.
Sources
Related Signals
The Ministry of Finance confirmed KSeF invoicing errors can be fined up to 100% of VAT once penalties start on 1 January 2027, and rejected business calls to soften the regime further.
10 Aug 2026UOKiK fined food producer Bunge Polska 4.29 million zloty for supplier contracts that dumped weather risk onto growers while still penalising them for missed deliveries.
10 Aug 2026Poland's KSeF e-invoicing exemption for sales under 10,000 zloty a month has no grace period: the invoice that pushes you over the line must go through KSeF immediately.
7 Aug 2026