
The Sejm passed an amendment to the Act on the National Cybersecurity System (KSC), which aims to strengthen the protection of digital systems and services in Poland. The new regulations transpose the EU’s NIS2 Directive into Polish law, which is intended to increase resilience to cyber threats and better protect citizens, businesses, and public institutions.
Failure to comply with the directive’s requirements exposes the company to serious legal and financial consequences that affect its operational stability and market position.
Potential fines can reach up to 10 million euros or 2% of global annual revenue, even in the absence of an actual cybersecurity incident.
The absence of formal mechanisms, policies, and organizational oversight in and of itself constitutes grounds for imposing penalties.
Audits, inspections, and binding administrative decisions can result in additional costs, mandatory investments, and disruptions to operations.
The Board of Directors and key managers are individually responsible for overseeing cybersecurity, which may result in administrative sanctions.
In extreme cases, this could result in a ban on providing services, as well as the loss of contracts, problems in bidding processes, and increased costs for insurance and legal services.

Please fill out the survey below

Yes—the NIS2 Directive (EU 2022/2555) explicitly classifies providers of public electronic communications networks and services as critical entities in the digital infrastructure sector. If you provide internet access, voice services, or data transmission to external customers and employ 50 or more employees or have a turnover of 10 million euros or more—you are a critical entity without exception. Smaller ISPs may be designated as such by a decision of the national regulatory authority if they provide critical services. Contact us—we’ll conduct a free assessment.
Key entities (which include ISPs) are subject to a stricter supervisory regime than important entities. The differences are significant: higher financial penalty thresholds (€10 million vs. €7 million), active and proactive oversight by authorities (not merely reactive after an incident), and an obligation to register and report regularly. For key entities, supervisory authorities may conduct unannounced inspections, require external audits, and issue orders to immediately cease operations. For important entities, supervision is reactive—it occurs primarily after an incident.
Business continuity management at an ISP is a formal, documented system that ensures the operator is able to maintain or quickly restore services following a failure or attack. NIS2 specifically requires: a business continuity plan (BCP) describing procedures for maintaining services under various failure scenarios, a disaster recovery plan (DRP) with measurable RTO and RPO objectives, regular testing of both plans (at least once a year), and documentation of the test results. ITH develops and tests both plans as part of the NIS2 implementation for ISPs.
NIS2 imposes a three-stage obligation on ISPs, as key entities, to report serious incidents: (1) an early warning within 24 hours of detection—basic information about the nature of the incident, (2) a full incident report within 72 hours—a detailed assessment, scope, and potential impacts, (3) a final report within 30 days—a description of the corrective actions taken and lessons learned. CSIRT Polska is the primary body responsible for receiving reports. Our 24/7 SOC automates this entire process—from detection and classification to submitting the required report on behalf of your ISP.
Management liability is one of the most significant elements of NIS2 and is very much a reality. The directive requires Member States’ authorities to implement mechanisms for the personal liability of individuals holding management positions. In Poland, this means that penalties of up to 300% of monthly salary may be imposed, and in extreme cases, a ban on holding management positions. This liability is of a supervisory nature—the board of directors is responsible for implementing and maintaining the security system, even if it does not participate in day-to-day technical operations. Therefore, training for management is a mandatory component of our implementation.
Yes—ITH is leading the NIS2 implementation as an external team of experts, minimizing the involvement of the internal IT department. We take on the entire administrative, documentation, and legal burden. This includes: auditing, developing policies and procedures, training, technical implementation of security controls, and continuous 24/7 SOC monitoring. For ISPs without a dedicated security team, this is the most effective and fastest implementation model.