We encourage you to check whether the new regulations regarding the National Cybersecurity System will also apply to your company.
Many business owners believe that the new cybersecurity regulations do not apply to them. In practice, however, it is not the industry alone that determines this. The type of business, the scope of services, and, in many cases, the size of the company also matter. That is why it is worth verifying whether the new regulations also apply to your organization.
How can you check this?
We encourage you to use the “Pre-verification of Compliance with NIS2 Recommendations” service—this is an important step that will allow your company to prepare for the new requirements well in advance.
If your company is determined to be a critical or important entity, the person authorized to represent the company must submit an application for inclusion in the NCS registry by October 3, 2026. This registry will include critical and important entities, which, once entered into the S46 system, will be required to fulfill a number of new cybersecurity obligations, including:
- implementing cybersecurity risk management measures,
- reporting serious incidents,
- fulfilling organizational and documentation obligations,
- and, in some cases, conducting security audits.
In the near future, the Ministry of Development and Technology will carry out initiatives to support businesses in meeting their new NCS obligations. We will create educational materials that may prove helpful in analyzing the new regulations and preparing for their implementation.
If you have any questions, please contact us at: cyfrowy.biznes@mrit.gov.pl