Directive (EU) 2022/2555 replaced the original NIS Directive and widened the scope of EU cybersecurity regulation from a few hundred operators to tens of thousands of entities across 18 sectors. Member States had to transpose it by 17 October 2024, with the obligations applying from 18 October 2024.
A directive is not directly applicable, which is the practical complication. NIS 2 sets the floor; the binding rules are national. Poland transposed it through an amendment to the Act on the National Cybersecurity System, which entered into force on 3 April 2026 — roughly seventeen months after the EU deadline. Entities that met the criteria on that date must apply for entry in the register of key and important entities by 3 October 2026.
The substance sits in two articles. Article 21(2) sets ten minimum risk-management measures, from risk analysis and incident handling through supply-chain security to multi-factor authentication. Article 23 sets the reporting clock: an early warning within 24 hours of becoming aware of a significant incident, a fuller notification within 72 hours, and a final report within one month.
Article 20 is what changes the conversation internally. Management bodies must approve the risk-management measures, oversee their implementation, and can be held liable for failing to do so — and they are required to undertake training themselves. NIS 2 is therefore not a matter the security team can carry alone, which is usually the first structural problem an assessment surfaces.