FRAMEWORKS

NIS 2 Directive Framework

EU cybersecurity framework establishing security requirements, incident reporting obligations, and enforcement mechanisms for essential and important entities across critical sectors.

Section 01 · The directive

What NIS 2 requires

Directive (EU) 2022/2555 replaced the original NIS Directive and widened the scope of EU cybersecurity regulation from a few hundred operators to tens of thousands of entities across 18 sectors. Member States had to transpose it by 17 October 2024, with the obligations applying from 18 October 2024.

A directive is not directly applicable, which is the practical complication. NIS 2 sets the floor; the binding rules are national. Poland transposed it through an amendment to the Act on the National Cybersecurity System, which entered into force on 3 April 2026 — roughly seventeen months after the EU deadline. Entities that met the criteria on that date must apply for entry in the register of key and important entities by 3 October 2026.

The substance sits in two articles. Article 21(2) sets ten minimum risk-management measures, from risk analysis and incident handling through supply-chain security to multi-factor authentication. Article 23 sets the reporting clock: an early warning within 24 hours of becoming aware of a significant incident, a fuller notification within 72 hours, and a final report within one month.

Article 20 is what changes the conversation internally. Management bodies must approve the risk-management measures, oversee their implementation, and can be held liable for failing to do so — and they are required to undertake training themselves. NIS 2 is therefore not a matter the security team can carry alone, which is usually the first structural problem an assessment surfaces.

2022/2555
Directive, replacing NIS 1
3 Oct 2026
Polish register deadline
24 h
Early warning after a significant incident
10
Minimum measures in Article 21(2)
18
Sectors across Annexes I and II
What the Directive enumerates

Scope and obligations follow the text of the Directive and the national law that implements it. Each cell represents one entry; point at a group to see its contents. Counts are the full published sets.

Minimum risk-management measures

10 of 33
  • (a) Risk analysis and information system security policies
  • (b) Incident handling
  • (c) Business continuity, backup and crisis management
  • (d) Supply chain security
  • (e) Security in acquisition, development and maintenance
  • (f) Assessing the effectiveness of risk-management measures
  • (g) Basic cyber hygiene and cybersecurity training
  • (h) Cryptography and, where appropriate, encryption
  • (i) Human resources security, access control and asset management
  • (j) Multi-factor authentication and secured communications
Section 02 · Readiness drivers

Why NIS 2 arrives as a deadline rather than a project

For most Polish organisations NIS 2 stopped being theoretical on 3 April 2026, when the amended Act on the National Cybersecurity System entered into force. The register deadline of 3 October 2026 forces the first decision — whether the entity is in scope at all — and that decision cannot be deferred, because failing to register is itself a breach. A second group is pulled in indirectly: suppliers who are not in scope themselves but whose customers must satisfy the supply-chain measure in Article 21(2)(d).

  1. 01 Register deadline of 3 October 2026 Entities in scope on 3 April 2026 must apply for entry; omitting to register is itself a breach. Strength 5 of 5
  2. 02 Scope determination Sector, size and service tests decide whether an entity is key, important, or outside the regime entirely. Strength 5 of 5
  3. 03 Management accountability Article 20 requires approval, oversight and training, and exposes management bodies to liability. Strength 4 of 5
  4. 04 Supply-chain pressure Customers in scope push Article 21(2)(d) obligations down to suppliers through contract terms. Strength 3 of 5
  5. 05 Incident reporting readiness The 24-hour early warning is short enough that the escalation path must exist beforehand. Strength 2 of 5
Indicative strength on a 1–5 scale, based on Up Secure engagement patterns.
Key entities

Large organisations in Annex I sectors face proactive supervision and fines reaching EUR 10 million or 2% of worldwide turnover, whichever is higher.

Important entities

Medium-sized Annex I organisations and Annex II sectors are supervised after the fact, with fines reaching EUR 7 million or 1.4% of worldwide turnover.

Suppliers to entities in scope

Article 21(2)(d) makes a customer responsible for its supply chain, so obligations arrive contractually even for organisations outside the regime.

Section 03 · The timeline

Statutory dates, EU and Polish

These are dates fixed by the Directive and by the Polish implementing law, not planning estimates. Select a view to see the EU sequence or the Polish one. Organisations operating in several Member States should expect the national dates and procedures to differ.

Scope European Union Span Jan 2023 – Jun 2027
  1. 01 Directive enters into force Directive (EU) 2022/2555 replaces NIS 1
    16 Jan 2023
  2. 02 Transposition deadline Member States had to adopt implementing law
    17 Oct 2024
  3. 03 Obligations apply Article 21 measures and Article 23 reporting
    18 Oct 2024
  4. 04 National regimes diverge Procedures, registers and sector rules set per Member State
    from Oct 2024
Directive adopted EU obligations National transposition Polish deadlines
Scope Poland Span Jan 2023 – Jun 2027
  1. 01 EU obligations apply Binding on Member States, not yet on Polish entities
    18 Oct 2024
  2. 02 Transposition gap Poland legislated roughly seventeen months after the deadline
    Oct 2024 – Apr 2026
  3. 03 Amended KSC Act in force Published 2 March 2026, effective 3 April 2026
    3 Apr 2026
  4. 04 Self-registration opens Register of key and important entities
    7 May 2026
  5. 05 Registration deadline Entities in scope on 3 April 2026 must apply for entry
    3 Oct 2026
Directive adopted EU obligations National transposition Polish deadlines
Section 04 · How Up Secure helps

Where you will get supported

The areas we work in, and where each one falls across a NIS 2 programme. The services that deliver them are listed further down.

Areas of support across a NIS 2 programme
NIS 2 support by programme stage
Area of support ScopeAssessImplementOperate
Advisory & leadership
Scope and entity classification Covered during Scope Covered during Assess Not covered during Implement Not covered during Operate
Management oversight and reporting Covered during Scope Covered during Assess Covered during Implement Covered during Operate
Security leadership (vCISO) Covered during Scope Covered during Assess Covered during Implement Covered during Operate
Assessment & assurance
Gap analysis against Article 21 Covered during Scope Covered during Assess Not covered during Implement Not covered during Operate
Risk assessment and treatment Covered during Scope Covered during Assess Covered during Implement Covered during Operate
Supplier and supply-chain review Not covered during Scope Covered during Assess Covered during Implement Covered during Operate
Technical testing of controls Not covered during Scope Covered during Assess Covered during Implement Covered during Operate
Resilience
Incident handling and reporting readiness Not covered during Scope Covered during Assess Covered during Implement Covered during Operate
Business continuity and crisis exercises Not covered during Scope Covered during Assess Covered during Implement Covered during Operate
Enablement & tooling
Cyber hygiene and management training Not covered during Scope Covered during Assess Covered during Implement Covered during Operate
Section 05 · Related services

Services supporting NIS 2 readiness

The catalogue below is selected from the live service graph and grouped by area of expertise. Where the register deadline is the immediate concern, scope determination comes first — the rest of the programme can be sequenced once it is clear whether the entity is key, important, or outside the regime.

Audits and Assessments

Systematic compliance audits, security assessments, and maturity evaluations across GDPR, ISO 27001, NIS 2, SOC 2, and AI Act frameworks for organizations in regulated industries.

Secure Source Code Review

SAST and manual code review for Python/Django apps. Findings mapped to OWASP Top 10 and CWE with fix guidance.

NIS 2 DirectiveISO 27001
Read more

Web Application Penetration Testing

Web app penetration testing with OWASP methodology. Severity-scored findings and remediation guidance for Python/Django.

NIS 2 DirectiveISO 27001SOC 2
Read more

Consultancy and Advisory

Strategic consultancy and implementation advisory across GDPR, AI Act, ISO 27001, NIS 2, and cybersecurity for organizations building compliance programs or making security architecture decisions.

Secure Source Code Review

SAST and manual code review for Python/Django apps. Findings mapped to OWASP Top 10 and CWE with fix guidance.

NIS 2 DirectiveISO 27001
Read more

Security and Privacy Architecture Review

Security and privacy architecture review for SaaS applications — threat modeling, data flow analysis, and design recommendations.

NIS 2 DirectiveGDPRISO 27001
Read more

Cybersecurity and Data Protection Risk Assessment

Combined cybersecurity and data protection risk assessment with risk register, treatment plan, and DPIA support.

NIS 2 DirectiveGDPRISO 27001SOC 2
Read more

US Software Review for EU Regulatory Compliance

Review of US-built software against EU privacy and cybersecurity regulations — GDPR, NIS 2, and AI Act compliance.

AI ActNIS 2 DirectiveGDPR
Read more

ISO 27001 Consulting

ISO 27001 consulting — gap analysis, ISMS design, risk assessment, and certification readiness for SaaS companies.

NIS 2 DirectiveISO 27001
Read more

NIS2 Compliance Consulting

NIS2 compliance consulting — gap analysis, governance framework, incident response, and supply chain security.

NIS 2 DirectiveISO 27001
Read more

Secure SDLC Consulting

Secure SDLC consulting — embedding security gates, threat modeling, and DevSecOps practices into your development pipeline.

NIS 2 DirectiveGDPRISO 27001
Read more

Role Outsourcing

Dedicated specialist roles including DPO, Privacy Engineer, Security Engineer, vCISO, and AI Compliance Officer available on a fractional or full-time outsourced basis.

Virtual CISO (vCISO) Services

Fractional vCISO providing security strategy, risk management, and compliance oversight for growing SaaS teams.

NIS 2 DirectiveISO 27001SOC 2
Read more

Security Engineer Role Outsourcing

Outsourced Security Engineer embedding secure coding, DevSecOps, and vulnerability management into your team.

NIS 2 Directive
Read more

Process Outsourcing and Managed Services

Ongoing risk assessments, vendor due diligence programs, and compliance monitoring delivered as managed services with defined service levels and regular reporting cadences.

Cybersecurity and Data Protection Risk Assessment

Combined cybersecurity and data protection risk assessment with risk register, treatment plan, and DPIA support.

NIS 2 DirectiveGDPRISO 27001SOC 2
Read more

Vendor Risk Assessment

Third-party vendor risk assessment for cybersecurity, data protection, and supply chain security compliance.

NIS 2 DirectiveGDPRISO 27001SOC 2
Read more
Start the conversation

Scope a NIS 2 engagement against Polish law, not only the Directive.

The first conversation establishes whether you are a key entity, an important entity, or outside the regime entirely — the determination the register application and every later obligation depends on. Where the 3 October 2026 deadline applies, that comes first and the rest of the programme is sequenced behind it.

Why Up Secure
Scope before spend Entity classification decides the supervisory regime and the fine ceiling. It is cheap to establish and expensive to assume.
The binding rules are national Obligations come from the amended KSC Act in force since 3 April 2026, and the procedures differ from the EU text.
Evidence that carries The ten Article 21 measures map closely onto ISO 27001 Annex A, so one control set can serve both.
Section 06 · Frequently asked

NIS 2 questions for management and security teams

Frequently asked questions

What is the deadline in Poland?
The amended Act on the National Cybersecurity System was published on 2 March 2026 and entered into force on 3 April 2026. Self-registration in the register of key and important entities opened on 7 May 2026, and entities that met the criteria on 3 April 2026 must submit an application for entry by 3 October 2026. Some entities are entered by the Minister of Digital Affairs ex officio and are then asked to complete their registration. Failing to register is a breach in its own right, separate from any shortcoming in the security measures.
How does an organisation determine whether it is in scope?
Three tests combine: the sector, drawn from Annexes I and II; the size of the entity; and the services actually provided. Large entities in Annex I sectors are generally key entities; medium entities in Annex I and the Annex II sectors are generally important entities. Certain entities are covered regardless of size. The assessment should record its sources and assumptions, because a sector label alone rarely settles the question and the classification determines the supervisory regime and the fine ceiling.
What is the difference between key and important entities?
Mainly supervision and penalty exposure. Key entities are subject to proactive supervision — inspections and audits can happen without a triggering incident — with fines reaching EUR 10 million or 2% of total worldwide annual turnover, whichever is higher. Important entities are supervised after the fact, when evidence of non-compliance appears, with fines reaching EUR 7 million or 1.4%. The underlying risk-management obligations in Article 21 are substantially the same for both.
What does the reporting clock actually require?
Article 23 sets a staged sequence for significant incidents: an early warning within 24 hours of becoming aware, a fuller incident notification within 72 hours including an initial assessment and any cross-border impact, an intermediate report if the CSIRT asks for one, and a final report within one month. Where the incident is still ongoing at that point, a progress report replaces the final one. The binding constraint is rarely technical — it is knowing who is authorised to decide that an incident is significant, at three in the morning.
Does an ISO 27001 certificate prove NIS 2 compliance?
No, but it covers much of the ground. The ten measures in Article 21(2) map closely onto Annex A controls, and a certified ISMS produces most of the evidence a supervisor would ask for. What it does not do is answer the scope question, satisfy the registration obligation, meet the incident reporting deadlines, or discharge the management accountability duty in Article 20. Treat certification as a substantial head start rather than a substitute.
We are not in scope, but our customers are. What follows?
Article 21(2)(d) makes entities in scope responsible for the security of their supply chain, including the security practices of direct suppliers. In practice that obligation arrives as contract terms: security requirements, audit rights, incident notification duties, and evidence requests. Suppliers who can answer those questions with existing evidence retain the relationship more easily than those who negotiate each clause from scratch.