ith-plain-white

Do you need to implement NIS-2 in your company?

What consequences might a company face for failing to implement the NIS-2 Directive?If you're not sure whether your company will be affected by the NIS-2 Directive, please fill out the survey we've prepared for you

The Sejm passed an amendment to the Act on the National Cybersecurity System

The Sejm passed an amendment to the Act on the National Cybersecurity System (KSC), which aims to strengthen the protection of digital systems and services in Poland. The new regulations transpose the EU’s NIS2 Directive into Polish law, which is intended to increase resilience to cyber threats and better protect citizens, businesses, and public institutions.

Legal and Financial Consequences of Failure to Implement the NIS2 Directive

ith-nis2-icon-6

Non-compliance with NIS2

Failure to comply with the directive’s requirements exposes the company to serious legal and financial consequences that affect its operational stability and market position.

ith-nis2-icon-5

Heavy administrative fines

Potential fines can reach up to 10 million euros or 2% of global annual revenue, even in the absence of an actual cybersecurity incident.

ith-nis2-icon-1

Inadequate Procedures and Risk Management

The absence of formal mechanisms, policies, and organizational oversight in and of itself constitutes grounds for imposing penalties.

ith-nis2-icon-4

Inspections and Interventions by Supervisory Authorities

Audits, inspections, and binding administrative decisions can result in additional costs, mandatory investments, and disruptions to operations.

ith-nis2-icon-3

Personal Responsibility of Management

The Board of Directors and key managers are individually responsible for overseeing cybersecurity, which may result in administrative sanctions.

ith-nis2-icon-2

Business Disruption and Indirect Losses

In extreme cases, this could result in a ban on providing services, as well as the loss of contracts, problems in bidding processes, and increased costs for insurance and legal services.

You can read more about the consequences at: gov.pl
niko-nis2-cytat
"NIS2 isn't a compliance cost—it's an investment in trust, business continuity, and the ability to continue selling."
Niko Bałazy - CEO of ITH

Does the NIS-2 Directive Apply to Your Company?

Please fill out the survey below

    Expand This offer does not constitute an offer within the meaning of the Civil Code. The offer is addressed to business customers only. All prices given are net prices. * Hereby, pursuant to Art. 23 of the Act of 23 August 1997 on the Protection of Personal Data (Journal of Laws of 2016, No. 922 of 28 June 2016, consolidated text), I consent to the processing of my personal data provided in the form above (i.e.: Tax ID (NIP), telephone number, e-mail address) by ITH Sp. z o.o. with its registered office in Warsaw, ul. Nowogrodzka 31, 00-511 Warszawa, entered in the register of entrepreneurs of the National Court Register under KRS number 0000469801, NIP: 7010389026, REGON: 146777630, for the purpose of presenting and fulfilling a commercial offer. I have been informed of my right to access the data I have provided, of the possibility of modifying it, and of objecting to its further processing. The controller of the personal data is ITH Sp. z o.o. with its registered office in Warsaw, ul. Nowogrodzka 31, 00-511 Warszawa, entered in the register of entrepreneurs of the National Court Register under KRS number 0000469801, NIP: 7010389026, REGON: 146777630.

    They trusted us

    ITH
    ITH
    ITH
    ITH
    ITH

    Let's talk about your company's needs

    Check out what else we have for you!

    Write to us

    Support
    Maintenance

    ITH NOC
    Management Center
    Infrastructure ITH
    Open all week, 24 hours a day

    Solutions
    for you

    ITH sales team
    Open Monday through Friday from 9:00 a.m. to 8:00 p.m.

      Expand This offer does not constitute an offer within the meaning of the Civil Code. This offer is intended solely for business customers. All prices listed are net prices. * Pursuant to Article 23 of the Act of August 23, 1997, on the Protection of Personal Data (Journal of Laws of 2016, No. 922 of June 28, 2016, consolidated text), I hereby consent to the processing of my personal data provided in the form above (i.e., Tax Identification Number (NIP), phone number, email address) by ITH Sp. z o.o., with its registered office in Warsaw, ul. Nowogrodzka 31, 00-511 Warsaw, registered in the Register of Entrepreneurs of the National Court Register under KRS number 0000469801, Tax ID (NIP): 7010389026, REGON: 146777630, for the purpose of presenting and fulfilling a commercial offer. I have been informed of my right to access the data I have provided, to modify it, and to object to its further processing. The controller of personal data is ITH Sp. z o.o., with its registered office in Warsaw, at ul. Nowogrodzka 31, 00-511 Warsaw, registered in the Register of Entrepreneurs of the National Court Register under KRS number 0000469801, NIP: 7010389026, REGON: 146777630.
      _DSC6603

      FAQ

      Yes—the NIS2 Directive (EU 2022/2555) explicitly classifies providers of public electronic communications networks and services as critical entities in the digital infrastructure sector. If you provide internet access, voice services, or data transmission to external customers and employ 50 or more employees or have a turnover of 10 million euros or more—you are a critical entity without exception. Smaller ISPs may be designated as such by a decision of the national regulatory authority if they provide critical services. Contact us—we’ll conduct a free assessment.

      Key entities (which include ISPs) are subject to a stricter supervisory regime than important entities. The differences are significant: higher financial penalty thresholds (€10 million vs. €7 million), active and proactive oversight by authorities (not merely reactive after an incident), and an obligation to register and report regularly. For key entities, supervisory authorities may conduct unannounced inspections, require external audits, and issue orders to immediately cease operations. For important entities, supervision is reactive—it occurs primarily after an incident.

      Business continuity management at an ISP is a formal, documented system that ensures the operator is able to maintain or quickly restore services following a failure or attack. NIS2 specifically requires: a business continuity plan (BCP) describing procedures for maintaining services under various failure scenarios, a disaster recovery plan (DRP) with measurable RTO and RPO objectives, regular testing of both plans (at least once a year), and documentation of the test results. ITH develops and tests both plans as part of the NIS2 implementation for ISPs.

      NIS2 imposes a three-stage obligation on ISPs, as key entities, to report serious incidents: (1) an early warning within 24 hours of detection—basic information about the nature of the incident, (2) a full incident report within 72 hours—a detailed assessment, scope, and potential impacts, (3) a final report within 30 days—a description of the corrective actions taken and lessons learned. CSIRT Polska is the primary body responsible for receiving reports. Our 24/7 SOC automates this entire process—from detection and classification to submitting the required report on behalf of your ISP.

      Management liability is one of the most significant elements of NIS2 and is very much a reality. The directive requires Member States’ authorities to implement mechanisms for the personal liability of individuals holding management positions. In Poland, this means that penalties of up to 300% of monthly salary may be imposed, and in extreme cases, a ban on holding management positions. This liability is of a supervisory nature—the board of directors is responsible for implementing and maintaining the security system, even if it does not participate in day-to-day technical operations. Therefore, training for management is a mandatory component of our implementation.

      Yes—ITH is leading the NIS2 implementation as an external team of experts, minimizing the involvement of the internal IT department. We take on the entire administrative, documentation, and legal burden. This includes: auditing, developing policies and procedures, training, technical implementation of security controls, and continuous 24/7 SOC monitoring. For ISPs without a dedicated security team, this is the most effective and fastest implementation model.