Skip to content
Knowledge Base

Does My Company Fall Under NIS2/NSC? A Self-Identification Test Step by Step

The Polish model of implementing NIS2 is based on self-identification — it is you who assesses whether your company is subject to it. We guide you through a simple, three-step test (sector, size, role) and explain what to do before the 3 October 2026 deadline.

The most frequent question we hear from companies after the entry into force of the amendment to the NSC Act sounds simple: “Does this even apply to us?”. The problem is that no one will send you a letter with the answer. The Polish model of implementing the NIS2 Directive is based on self-identification — the organization itself must assess its status and register in the list.

This article is a practical test. Go through three steps and you will know whether, and as what type of entity, you most likely fall under it.

What does self-identification mean?

In the previous model, the state individually designated operators of essential services. NIS2 changes this: it automatically covers entire sectors and size categories. In practice, the burden of assessment has been shifted onto companies — and it is they who are responsible for its correctness. That is why self-identification is worth taking seriously and documenting.

Step 1: Check your sector

The first question: does your activity fall within the sectors listed in the act? They include, among others:

  • energy, transport, banking and financial market infrastructure,
  • healthcare, drinking water and wastewater,
  • digital infrastructure, ICT services,
  • postal and courier services, waste management,
  • manufacturing (including medical devices, electronics, machinery), food,
  • scientific research, digital services.

If your industry is not on the list — you most likely do not fall under it. If it is — move on.

Step 2: Check the size of the organization

As a rule, the regulation covers organizations from the level of a medium-sized enterprise upwards. The simplified thresholds are:

  • employment of 50 people or more, or
  • annual turnover / balance sheet total above the threshold for medium-sized companies.

The category also depends on this: larger entities in critical sectors usually end up in the group of essential entities, the rest — important entities. We have described the differences in the article on the essential and important entity.

Step 3: Check your role in the supply chain

Even if you are a smaller company, you may fall under the act if you provide critical services to entities covered by the regulation or to critical infrastructure. For some essential entities, size is irrelevant — what counts is the role.

How to interpret the result of the test?

  • Sector YES + size threshold YES → you most likely fall under it; establish the category and prepare the registration.
  • Sector YES + below the threshold, but a critical role → it is possible that you fall under it despite a small scale.
  • Sector NO → you usually do not fall under it, but it is worth documenting this assessment.

In case of doubt, do not guess — carry out a KSC/NIS2 readiness audit that will unambiguously establish the status.

What to do before 3 October 2026?

This is the first hard deadline: the application for registration in the list of essential and important entities. The recommended order:

  1. Carry out and document the self-identification (this test).
  2. Establish the category (essential/important).
  3. Submit the registration application before the deadline.
  4. Plan the implementation of obligations (deadline: 3 April 2027).

You will find the full schedule in the article on the deadlines of the KSC/NIS2 amendment.

Check out our services

Self-identification is seemingly a formality, but in reality it is the first obligation on which everything else depends. It is better to do it consciously and in advance than under the pressure of a deadline.

What to do if the answer is no

Coming out of the test with “we are not in scope” closes the question only in appearance. Companies that are neither essential nor important entities still receive security requirements — not from the regulator, but from their customers who are. Article 21 of the directive obliges those customers to manage supply chain risk, so the requirements travel downstream as contract clauses, questionnaires and audit rights.

In practice this means a supplier to a regulated entity should know in advance what it will be asked: whether it has a security policy, within what time it would report an incident on its side, who its named contact is, and whether it accepts an audit. Preparing those answers before the first questionnaire arrives costs less than assembling them in the week before a tender — and establishing where the gaps are is what a gap analysis is for.


Share:

Talk to an expert

Have questions about this topic? Get in touch with our specialist.

Sales Representative
Przemysław Widomski

Przemysław Widomski

Sales Representative

Response within 24 hours
Free consultation
Individual approach

Providing your phone number will speed up contact.

Want to Reduce IT Risk and Costs?

Book a free consultation - we respond within 24h

Response in 24h Free quote No obligations

Or download free guide:

Download NIS2 Checklist