The amendment to the National Cybersecurity System Act (NSC), which entered into force on 3 April 2026, changes the way the state classifies organizations covered by the regulation. Instead of the former “essential service operator”, two categories known from the NIS2 Directive appear: the essential entity and the important entity. This is not cosmetics — the assigned category determines the supervision model, the frequency of audits and the upper limits of penalties.
In this article we organize the differences and show how to establish which group your organization belongs to.
Where did the categories of essential entity and important entity come from?
The NIS2 Directive moved away from the individual designation of operators in favour of the automatic coverage of entire sectors and size categories. The Polish amendment transfers this model into the NSC Act. In practice, this means that the organization itself must assess whether it is subject to the regulations and as what type of entity — this is the so-called self-identification.
What is an essential entity?
An essential entity is usually a large organization operating in a sector of the highest criticality. This group includes, among others:
- energy,
- transport,
- banking and financial market infrastructure,
- healthcare,
- drinking water and wastewater,
- digital infrastructure.
Essential entities are subject to the highest requirements and the strictest supervision. More in the entry on essential entity.
What is an important entity?
An important entity is an organization in the remaining sectors covered by the act or a smaller organization in critical sectors. Example sectors include, among others, postal and courier services, waste management, manufacturing, digital service providers and scientific research. Details in the entry on important entity.
What is the key difference — the supervision model
This is the most important distinction in practice:
- Essential entity → proactive supervision. The authority may conduct regular inspections, audits and verification activities regardless of whether an incident has occurred.
- Important entity → reactive supervision. Inspection usually takes place after an incident occurs or a signal of a breach of obligations.
Do the security obligations differ?
The basic catalogue of risk management measures is similar for both categories and includes, among others:
- risk analysis and security policies,
- incident handling and reporting,
- business continuity and crisis management,
- supply chain security,
- cyber hygiene and training,
- the use of cryptography.
The difference lies not so much in what needs to be addressed, but in the intensity of supervision, the frequency of audits and the upper limits of penalties.
What do the penalties look like for both categories?
In accordance with the NIS2 Directive, essential entities are subject to higher maximum administrative penalties than important entities. What is important for Polish companies: in the NSC Act, administrative financial penalties for the majority of obligations will be able to be imposed only after 3 April 2028 (two years from the entry into force of the amendment). This transitional period is meant to give time for thorough implementation, rather than for acting under the pressure of an immediate sanction.
Comparison at a glance
| Feature | Essential entity | Important entity |
|---|---|---|
| Sectors | Highest criticality | Remaining sectors covered by the act |
| Supervision | Proactive (regular) | Reactive (after an incident) |
| Upper limits of penalties | Higher | Lower |
| Catalogue of measures | Similar | Similar |
| Obligation to register in the list | Yes (by 3.10.2026) | Yes (by 3.10.2026) |
How to establish your category?
- Sector — check whether and in which annex to the act your activity falls.
- Size — verify the employment and turnover thresholds.
- Role — assess whether you provide services critical to other covered entities.
If you have doubts, the best first step is a KSC/NIS2 readiness audit that will unambiguously establish the status and the gap to be closed. Remember the deadline — you will find the full calendar in the article on the deadlines of the KSC/NIS2 amendment.
Related concepts
Check out our services
- KSC/NIS2 audit and consulting — establishing the category and a compliance roadmap
- SOC 24/7 — readiness for incident handling and reporting
- vCISO — oversight of the security program
Establishing whether you are an essential or an important entity is the foundation — it determines the scope and order of all further compliance activities.
