The most frequent question we hear from companies after the entry into force of the amendment to the NSC Act sounds simple: “Does this even apply to us?”. The problem is that no one will send you a letter with the answer. The Polish model of implementing the NIS2 Directive is based on self-identification — the organization itself must assess its status and register in the list.
This article is a practical test. Go through three steps and you will know whether, and as what type of entity, you most likely fall under it.
What does self-identification mean?
In the previous model, the state individually designated operators of essential services. NIS2 changes this: it automatically covers entire sectors and size categories. In practice, the burden of assessment has been shifted onto companies — and it is they who are responsible for its correctness. That is why self-identification is worth taking seriously and documenting.
Step 1: Check your sector
The first question: does your activity fall within the sectors listed in the act? They include, among others:
- energy, transport, banking and financial market infrastructure,
- healthcare, drinking water and wastewater,
- digital infrastructure, ICT services,
- postal and courier services, waste management,
- manufacturing (including medical devices, electronics, machinery), food,
- scientific research, digital services.
If your industry is not on the list — you most likely do not fall under it. If it is — move on.
Step 2: Check the size of the organization
As a rule, the regulation covers organizations from the level of a medium-sized enterprise upwards. The simplified thresholds are:
- employment of 50 people or more, or
- annual turnover / balance sheet total above the threshold for medium-sized companies.
The category also depends on this: larger entities in critical sectors usually end up in the group of essential entities, the rest — important entities. We have described the differences in the article on the essential and important entity.
Step 3: Check your role in the supply chain
Even if you are a smaller company, you may fall under the act if you provide critical services to entities covered by the regulation or to critical infrastructure. For some essential entities, size is irrelevant — what counts is the role.
How to interpret the result of the test?
- Sector YES + size threshold YES → you most likely fall under it; establish the category and prepare the registration.
- Sector YES + below the threshold, but a critical role → it is possible that you fall under it despite a small scale.
- Sector NO → you usually do not fall under it, but it is worth documenting this assessment.
In case of doubt, do not guess — carry out a KSC/NIS2 readiness audit that will unambiguously establish the status.
What to do before 3 October 2026?
This is the first hard deadline: the application for registration in the list of essential and important entities. The recommended order:
- Carry out and document the self-identification (this test).
- Establish the category (essential/important).
- Submit the registration application before the deadline.
- Plan the implementation of obligations (deadline: 3 April 2027).
You will find the full schedule in the article on the deadlines of the KSC/NIS2 amendment.
Related concepts
Check out our services
- KSC/NIS2 audit and consulting — establishing the status and a roadmap
- vCISO — managerial support in the compliance process
- SOC 24/7 — operational readiness for NIS2 obligations
Self-identification is seemingly a formality, but in reality it is the first obligation on which everything else depends. It is better to do it consciously and in advance than under the pressure of a deadline.
What to do if the answer is no
Coming out of the test with “we are not in scope” closes the question only in appearance. Companies that are neither essential nor important entities still receive security requirements — not from the regulator, but from their customers who are. Article 21 of the directive obliges those customers to manage supply chain risk, so the requirements travel downstream as contract clauses, questionnaires and audit rights.
In practice this means a supplier to a regulated entity should know in advance what it will be asked: whether it has a security policy, within what time it would report an incident on its side, who its named contact is, and whether it accepts an audit. Preparing those answers before the first questionnaire arrives costs less than assembling them in the week before a tender — and establishing where the gaps are is what a gap analysis is for.
