Audit · NIS2

Does My Company Fall Under NIS2? A Simple Guide for the Board and IT

Remote Admin Audit Team·March 19, 2026·4 min read

It’s 2026. The time to prepare for the EU’s NIS2 directive and the amended Polish National Cybersecurity System Act (KSC) has long passed. The transition period is now history, and the compliance and audit machinery is running at full speed. Even so, many mid-sized and large companies are still asking themselves one basic question: “Do these regulations even apply to us?”

If you’re a board member, you care about minimizing financial risk and legal liability. If you run the IT department, you’re worried about budget, staffing shortages, and technical debt. This guide was written to reconcile both perspectives and give you a clear, yes-or-no answer along with a concrete action plan.

Who is subject to NIS2? Sectors and company size

The NIS2 directive doesn’t apply to absolutely every company on the market, but its scope is far broader than its predecessor (NIS1). It was designed to cover supply chains and key sectors of the economy.

To check whether you’re subject to the directive, you need to analyze two main criteria: company size and sector of activity.

1. The size criterion (the cap-size rule)

As a rule, the directive covers:

  • Medium-sized enterprises: 50 to 249 employees AND annual turnover not exceeding EUR 50 million (or a total annual balance sheet of up to EUR 43 million).
  • Large enterprises: more than 250 employees OR annual turnover exceeding EUR 50 million (or a balance sheet exceeding EUR 43 million).

Note: In certain critical cases (e.g., trust service providers, telecommunications), the regulations may also cover micro and small enterprises.

2. The sector criterion

Entities are divided into two categories with different levels of regulatory oversight. It’s important to fully understand the obligations imposed by the classification of essential vs. important entities under NIS2.

Essential sectors (Essential Entities):

  • Energy, transport, banking, financial markets (often overlapping here with DORA).

  • Healthcare, pharmaceutical manufacturing.

  • Drinking water and wastewater.

  • Digital infrastructure (cloud providers, data centers, DNS) and B2B ICT service providers.

  • Public administration and space.

Important sectors (Important Entities):

  • Postal and courier services.

  • Waste management.

  • Manufacturing, production, and distribution of chemicals.

  • Production, processing, and distribution of food.

  • Manufacturing broadly defined (including medical devices, computers, electronics, vehicles, machinery).

  • Digital service providers (search engines, social networking platforms, online marketplaces).

The consequences of ignoring NIS2 in 2026

For the board, the most important change is direct personal liability. Penalties are no longer limited to a percentage of global turnover (which can reach EUR 7 to 10 million, or 1.4%–2% of global turnover, depending on the entity’s status). Under the new guidelines, board members can be held liable for negligence and, in extreme cases, temporarily suspended from their management roles.

For IT, this means the “we don’t have the budget for it” argument no longer holds. Cybersecurity has become a legal requirement, not an option.

My company is subject to the directive — where do I start?

If the analysis above shows that you’re covered by the regulations, you need to act quickly, methodically, and based on hard data.

  1. Map your environment: you can’t secure what you don’t know about. The first step is to take inventory of assets, accounts, systems, and applications.

  2. Identify the gaps: instead of guessing, run a professional NIS2 audit. It will show exactly where your infrastructure and procedures (or the lack thereof) fall short of the letter of the law.

  3. Build an implementation plan: if you’re a smaller organization, our proven 90-day NIS2 implementation checklist for SMEs will help you organize the process over the coming months without bringing your company’s work to a halt.

IT staffing shortages? Why a vCISO is the optimal solution

The biggest challenge in 2026 isn’t buying the right tools, but finding competent people to run them. The requirements imposed by NIS2 (including risk assessment, supply chain security, business continuity plans, and incident reporting) call for expertise at the CISO (Chief Information Security Officer) level.

Hiring such a specialist full-time costs tens of thousands of PLN a month — assuming you can even recruit one. That’s why, for most companies, the optimal solution is a vCISO (Virtual Chief Information Security Officer) service.

What do you gain by working with a vCISO?

  • Legal compliance: the expert takes responsibility for building policies compliant with NIS2, KSC, and, where needed, DORA or MiCA as well.
  • A bridge between business and IT: a vCISO can translate technical IT jargon into a business risk assessment the board can act on.
  • Savings and flexibility: you pay only for the hours actually worked, gaining access to senior-level expertise without the risk of recruitment or leave coverage.

Don’t want to take the risk? Leave NIS2 to the professionals

Managing security under NIS2 is an ongoing process, not a one-time project. If your company qualifies as an essential or important entity, missing documented incident response procedures, untrained staff, or gaps in your network architecture are like a ticking time bomb.

To the board: protecting your business and your personal liability starts with knowing the actual state of your infrastructure.

To the IT department: stop fighting windmills on your own — get hard evidence to back up conversations about budgets and tools.

Want to find out where your organization actually stands on cybersecurity and legal requirements right now? Get in touch with our team — we’ll set up a free technical consultation and plan an audit that gives you certainty, not more promises.