Short answer
Not every organization does, but every organization has to check. Three things decide the qualification, in this order: the sector of activity listed in Annex 1 or Annex 2 to the Polish Act on the National Cybersecurity System, the size of the entity calculated together with linked and partner enterprises, and the categories covered regardless of size — for which the Act provides separate lists for essential entities and for important ones. As a rule, the organization carries out the assessment itself and is itself answerable for the result; the authority enters an entity in the register ex officio only where the entity has failed to do so. That is why a negative result also has to be documented.
Why this question arises at all
The question keeps coming back because two of its elements work against intuition.
First: NIS2 is not a rule that applies directly. Directive (EU) 2022/2555 entered into force on January 16, 2023 and set October 17, 2024 as the transposition deadline for Member States, but it binds the state, not the business. An organization’s obligations follow from national law — in Poland, from the Act on the National Cybersecurity System (KSC) as amended by the Act of January 23, 2026 (Journal of Laws 2026, item 252, promulgated on March 2, 2026, in force since April 3, 2026). An analysis based solely on the text of the directive, or on material concerning another Member State, leads to wrong conclusions, because it is the national act that specifies the sectors, the categories of entities and the deadlines.
Second: as a rule, nobody will send a notification. Qualification rests on self-assessment, and the application for entry in the register is filed and signed by the head of the entity or a person authorized by them — under a declaration as to the truthfulness of the data, made subject to criminal liability. There are several exceptions and they are worth knowing, because they change the position of particular organizations. The minister responsible for computerization enters ex officio telecommunications undertakings, trust service providers, public entities and critical entities, and separately — former operators of essential services, which became essential entities by operation of law on the day the amendment entered into force. The authority competent for cybersecurity may in addition enter in the register an entity that meets the criteria but has not filed an application on time, and may recognize by decision as an essential or important entity one that does not meet the criteria. None of these routes, however, releases an organization from the duty to assess itself — they come into play where the assessment has not been carried out, or has produced a result the authority does not share.
Then there is the scale of the change. The previous legal framework covered operators of essential services, digital service providers and the public entities named in the Act — a clearly narrower circle overall. According to estimates by the Ministry of Digitization, the new rules apply to roughly 38,000 entities, including some 27,000 public ones — that is, mostly organizations with no established assessment practice.
What must be determined before the decision
Self-identification has three steps. The order matters: skipping the first one leads to calculating the size of an entity that does not fall within any sector anyway.
Does the activity fall within the sectors in Annex 1 or Annex 2
Annex 1 covers the essential sectors: energy (including mineral extraction, electricity, heat, oil and fuels, gas, nuclear energy and hydrogen), air, rail, water and road transport, banking and financial market infrastructure, health care together with the manufacture and distribution of medicinal products and medical devices, drinking water supply, collective wastewater treatment, digital infrastructure and electronic communications, ICT service management, space, and public entities.
Annex 2 covers the important sectors: postal services, nuclear energy investments, waste management, the manufacture and distribution of chemicals, the production and distribution of food, the manufacture of medical devices, computers and electronics, electrical equipment, machinery, motor vehicles and other transport equipment, digital service providers, scientific research, and public entities.
What decides is the actual nature of the activity, not the business classification code. The code is a pointer and a starting point, but an organization with a broad profile often runs one business line that falls within an annex and several that stay outside it. A machinery manufacturer that also provides control system maintenance services to customers should assess both activities separately and only then establish how they affect the qualification of the entity as a whole.
It is also worth checking whether the entry in the annex is conditional. A municipal office is an example: it falls within the public entities sector, but only where, as at January 1 of a given year, it employs at least 50 people in full-time equivalents under employment contracts.
What is the size of the entity — calculated together with the group
Size is established under Annex I to Commission Regulation (EU) No 651/2014 — the same method organizations know from State aid law. The data is taken as at the date on which the financial statements are drawn up.
| Category | Headcount | Financial condition |
|---|---|---|
| Micro-enterprise | fewer than 10 people | annual turnover or balance sheet total up to EUR 2 million |
| Small enterprise | fewer than 50 people | annual turnover or balance sheet total up to EUR 10 million |
| Medium-sized enterprise | fewer than 250 people | annual turnover up to EUR 50 million or balance sheet total up to EUR 43 million |
The construction of this definition matters more than it looks. The headcount condition and the financial condition apply jointly, but the financial condition itself is an alternative — meeting one of the two criteria is enough. From this follows what it takes to exceed the medium-sized enterprise category, on which essential entity status depends: an organization exceeds those requirements if it employs at least 250 people or exceeds both financial thresholds at the same time. A company with 120 employees, turnover of EUR 70 million and a balance sheet total of EUR 60 million exceeds the medium-sized category despite its modest headcount. Conversely, at 300 employees the financial figures no longer matter.
Equally important is what this method does not allow: it does not allow a company to be looked at in isolation from its group. Linked and partner enterprises are taken into account when calculating the thresholds, so a special purpose vehicle employing a dozen or so people and belonging to a large capital group usually ceases to be a small enterprise once the group’s figures are added. This is the most common source of faulty self-assessment in organizations with complex ownership structures.
The Act does, however, provide an explicit exception to that rule, and it settles part of the cases in capital groups. Where an entity exceeds the thresholds solely because the data of linked or partner enterprises has been added, but its information system is independent of their systems or it does not provide services jointly with them — it is neither an essential nor an important entity. Assessing the independence of systems therefore stops being a technical matter and becomes an element of legal qualification, to be documented as carefully as the threshold calculation itself.
Status is established separately for each entity — a group is not subject to the Act as a whole.
Does the entity belong to a category covered regardless of size
This step tends to be skipped, and it settles the largest number of borderline cases. It is worth remembering that the Act provides two separate lists: one on the essential entities side, the other on the important entities side.
Regardless of size, essential entities include, among others, DNS service providers, top-level domain name registries and entities providing domain name registration services, qualified trust service providers, critical entities, operators of nuclear facilities, the public entities named in Annex 1 in the public entities sector, and non-business entities identified in that annex by name or by type.
Regardless of size, important entities include, among others, non-qualified trust service providers that are micro, small or medium-sized enterprises, electronic communications undertakings that are micro or small enterprises, investors in nuclear facilities that have obtained a decision in principle, non-business entities named in Annex 2, and also local government budgetary units, local government budgetary establishments, local government cultural institutions and companies performing public utility tasks, where they perform a public task using information systems. That last point covers a very large group of local government units and is the one most often overlooked in self-assessments.
Separately, the Act lowers the size threshold for two types of activity. An electronic communications undertaking is an essential entity from the medium-sized enterprise level up. A provider of managed services in the field of cybersecurity — from the small enterprise level. This distinction should be read literally: the lowered threshold applies to a provider of managed security services, not to every managed service provider. Annex 1 lists both types separately and attaches different consequences to them.
Non-business healthcare providers have their own rule: with 50 to 249 employees they are important entities, and with at least 250 — essential ones.
Is the entity essential or important
Qualification does not end with the answer “we are covered”. An essential entity is an organization from a sector in Annex 1 that exceeds the requirements for a medium-sized enterprise, plus every category on the essential list. An important entity is an organization from a sector in Annex 1 that meets those requirements without exceeding them, an organization from a sector in Annex 2 from the medium-sized level up, and the categories on the important list. Where an entity meets the requirements for both categories, it is an essential entity.
The catalogue of basic obligations is similar in both categories: entry in the register, an information security management system, incident handling and reporting, use of the S46 system, the appointment of at least two contact persons for the entities of the national cybersecurity system, and the responsibility of the head of the entity. There are three differences, and all of them have a financial or organizational dimension.
The first is the audit. A periodic security audit of the information system, carried out at least once every three years counting from the signature of the previous report, is borne by essential entities only. An important entity may be ordered by the authority to undergo an external audit, but only in the event of a significant incident or another breach of the rules.
The second is supervision. Essential entities are subject to both preventive and follow-up supervision; important entities — to follow-up supervision only, and the range of supervisory measures available against them is narrower.
The third is penalties. An essential entity is liable up to EUR 10 million or 2% of its revenue from business activity for the previous financial year, whichever is higher, and not less than PLN 20,000. An important entity — up to EUR 7 million or 1.4% of revenue, not less than PLN 15,000. Regardless of category, the Act provides for a penalty of up to PLN 100 million where the breach causes a direct and serious threat to defence, state security, public order or human life and health.
For the board the conclusion is practical: the category determines the scale of the work, the audit cycle and the level of financial exposure. That is why qualification is settled before the budget is set, not after.
What public entity status changes
Public entities enter the system by two routes — as essential entities under Annex 1 or as important entities from the local government list — but they have their own, simplified set of requirements. An important entity that is a public entity does not apply the general provision on the information security management system; it implements a system under a separate annex to the Act, which names specific measures, including training for people involved in processing information, rules for using publicly available cloud services and publicly available large generative artificial intelligence models, and a review of the system at least once a year. The same entity is also exempt from part of the reporting obligations for incidents.
This matters for local government units, which in market communications are sometimes treated exactly like large enterprises — the scope of work for them is different and follows from a different provision.
What DORA changes in the financial sector
Banking and financial market infrastructure appear in Annex 1, so entities from that sector are subject to the KSC Act. The scope of their obligations is different, however, and the basis is national and expressly stated: the Act excludes, for that sector, the provisions on the information security management system and on reporting significant incidents, while retaining the provisions on qualification, entry in the register, the responsibility of the head of the entity, contact persons and the deadlines for performing obligations. In practice a financial institution meets the requirements of the DORA Regulation while still having to demonstrate correct qualification and registration in the national register.
The annex is worth reading literally. The sector covers credit institutions, domestic banks, branches of foreign banks, credit unions, entities operating a regulated market, a multilateral trading facility and an organized trading facility, and administrators of critical benchmarks. It does not list payment institutions, insurance undertakings, investment fund companies or investment firms — these are not essential or important entities on that basis, although the Act does provide separate obligations and a separate financial penalty for financial entities outside that circle.
By when the qualification must be ready
The registration schedule does not follow directly from the Act — the Act delegates it to a communication of the minister responsible for computerization and allows that communication to be changed if entries prove impossible for technical or organizational reasons. The communication in force, of April 8, 2026, sets out:
| Deadline | What happens |
|---|---|
| April 3, 2026 | The amendment to the KSC Act entered into force |
| May 7 – October 3, 2026 | Filing of applications for entry by essential and important entities, excluding those entered ex officio |
| April 8, 2026 – April 3, 2027 | Start of use of the S46 system by entities that were parties to earlier agreements |
| June 12, 2026 – April 3, 2027 | Start of use of the S46 system by the remaining entities |
| April 3, 2027 | End of the twelve-month period for performing obligations by entities that met the criteria on April 3, 2026 |
| April 3, 2028 | Expiry of the twenty-four-month period for the first audit of essential entities; after that date financial penalties may also be imposed for the first time |
For the qualification itself, the binding date is October 3, 2026 — the last day of the self-registration period. At the time of this update, around six weeks remain. Two caveats matter here. That deadline applies to entities that met the criteria on the day the Act entered into force; an entity that meets them later has six months from that moment to file its application. For entities entered ex officio the deadline is individual and runs from service of the request to complete the data.
The deferral of penalties also has a limit worth knowing about: it does not cover the extraordinary penalty of up to PLN 100 million. That one may be imposed from the moment the Act starts to apply.
Four possible qualification outcomes
| Outcome | When it applies | What to do by October 3, 2026 | What follows |
|---|---|---|---|
| Essential entity | A sector from Annex 1 above the medium-sized enterprise thresholds, the lowered threshold for electronic communications and managed security services, or a category from the essential list | Entry in the register together with documented qualification | Full scope of obligations, audit cycle, preventive and follow-up supervision, higher penalty ceiling |
| Important entity | A sector from Annex 1 at the medium-sized enterprise level, a sector from Annex 2 from the medium-sized level up, or a category from the important list — including local government units | Entry in the register together with documented qualification | A similar scope of obligations without the periodic audit, follow-up supervision only, lower penalty ceiling; public entities — a simplified system under the annex |
| Outside the scope, but a supplier to covered entities | No qualifying sector or no threshold met, while serving essential and important entities | A qualification note; a review of security requirements in customer contracts | Requirements arrive by contract, not by statute — questionnaires, contractual clauses, audit rights |
| Outside the scope | No sector, no threshold, no special category — or exclusion on the ground of system independence within the group | A qualification note and an indication of who repeats the assessment when things change | Reassessment on growth, acquisition, joining a group or a new service line |
The third row applies to more organizations than the scope of the Act alone would suggest. Essential and important entities are required to manage supply chain risk, and the only practical tool available to them is contractual requirements and verification. Providers of IT, maintenance, logistics or technical service therefore receive questions about safeguards, incident response times, remote access rights and audit rights — regardless of their own status. For such an organization, putting the basics in order usually turns out to be cheaper than answering yet another security questionnaire from each customer separately.
Most common mistakes
- Qualifying by business classification code. What decides is the actual activity. Multi-sector organizations have to assess each significant line separately.
- Calculating size without the capital group — and, conversely, adding the group without checking the exception. Leaving out linked and partner enterprises understates the result. But adding their data automatically, without examining the independence of information systems, overstates it and can pull into the system an entity that is not subject to the Act.
- Looking for size-independent categories only on the essential entities side. The second list, on the important entities side, covers among others local government budgetary units and municipal companies. Overlooking it excludes hundreds of units that are in fact covered.
- Confusing a managed service provider with a provider of managed services in the field of cybersecurity. The lowered threshold applies only to the latter.
- Treating qualification as a one-off exercise. Headcount growth, crossing a turnover threshold, joining a group, a new service line or acquiring a company all change the result. The duty to file an application is tied to the moment the criteria are met, not to the first registration deadline.
- No record of the assessment. A note setting out what data was taken into account, which activity was assigned to which annex, how size was calculated and who approved the application is evidence of due diligence. Where the result is negative, it is the only trace that a decision was made at all.
Conclusions and next steps
The answer to the question in the title is settled in three steps, always in the same order: sector, size calculated together with the group and with the exception for independent systems taken into account, and categories covered regardless of size — on both sides of the divide. Only then is the entity’s category assigned, because it determines the scope of work, the audit cycle and the level of financial exposure.
A sensible order of work is the same across industries. First establish which activities correspond to the sectors in the annexes and whether any unit in the group falls within either of the size-independent lists. Then calculate size separately for each entity, taking linked and partner enterprises into account — and where it is precisely those enterprises that push the entity over the threshold, examine and describe the independence of the information systems. Then assign the category, document the conclusions and decide on entry in the register. Finally, name the person who will repeat the assessment when the data changes materially.
The output of this work is short: a list of the entities that are covered, their categories, the reasoning and a named responsibility for the next steps. That is enough material for the board to decide on the scope of implementation, and enough evidence that the qualification was carried out deliberately. What follows from it for the board itself — who the head of the entity is and where to start the work — I have described in Where should the board begin preparing for NIS2?. An organization that has established that it is not covered finishes its work on the same document — with the difference that this document is the only trace of the analysis it carried out.
Related materials
- Where should the board begin preparing for NIS2? — the next stage: what to do once the qualification is settled and responsibility and the starting point have to be established.
- What to do after detecting an incident? — the sequence of the first day and the reporting deadlines that start to apply once the entity’s status is established.
- Does every data breach need to be reported? — the obligations towards the supervisory authority that, for entities covered by the KSC Act, run in parallel with reports to the CSIRT.
- When and how to apply for entry in the register of essential and important entities — deadlines, the data required and the declaration of the head of the entity.
Sources
- Act of July 5, 2018 on the National Cybersecurity System, consolidated text — Chancellery of the Sejm, ISAP: isap.sejm.gov.pl (accessed: August 18, 2026) (in Polish)
- Act of January 23, 2026 amending the Act on the National Cybersecurity System and certain other acts (Journal of Laws 2026, item 252) — transitional provisions, Journal of Laws: dziennikustaw.gov.pl (accessed: August 18, 2026) (in Polish)
- Commission Regulation (EU) No 651/2014, Annex I — definition of micro, small and medium-sized enterprises — EUR-Lex: eur-lex.europa.eu (accessed: August 18, 2026)
- Communication of the Minister of Digitization of April 8, 2026 on the schedule for filing applications for entry in the register of essential and important entities (Official Journal of the Ministry of Digitization, item 7) — Ministry of Digitization: gov.pl (accessed: August 18, 2026) (in Polish)
- Directive (EU) 2022/2555 of the European Parliament and of the Council (NIS2) — EUR-Lex: eur-lex.europa.eu (accessed: August 18, 2026)
- Amendment to the KSC Act — how to carry out self-identification? — Ministry of Digitization: gov.pl (accessed: August 18, 2026) (in Polish)
Settle the qualification before you set the scope of implementation
If your organization’s status is still open to doubt — because of the group structure, several business lines or the question of information system independence — it is worth settling before the work starts. Support in preparing for NIS2 and KSC covers entity qualification, gap analysis and a plan of actions that can be sustained and demonstrated during an audit.
This material is general and educational in nature. It does not constitute individual legal advice or a recommendation for a specific organization. The scope of obligations should be assessed taking into account its situation.
Legal status: August 2026.