Audit · NIS2

NIS2: Will Your Company Be Fined? 5 Steps to Sleep Soundly

Remote Admin Audit Team·April 24, 2026·6 min read

Imagine waking up one morning to find an official letter waiting on your desk. But this isn’t ordinary correspondence. It’s a decision from a supervisory authority imposing a financial penalty on your company, one large enough to shake its liquidity. The reason? Non-compliance with the NIS2 directive.

A nightmare? Unfortunately, since spring 2026 it has become a painful reality for many Polish companies. The transition period is over, and state authorities have stopped merely threatening and moved on to concrete action. The question is no longer whether you should deal with this, but how to do it quickly and effectively to avoid trouble.

That’s why we put together this guide. We’ll walk you through the process step by step, so you can sleep soundly.

How massive can the consequences be?

Before we get into concrete actions, it’s worth knowing what’s at stake. Many business owners still downplay the threat, not realizing the scale of the financial risk. The new regulations show no leniency – the fines are severe enough to threaten the existence of even a stable, well-run business.

The maximum fine depends on which category your company falls into. Essential entities face sanctions of up to EUR 10 million or 2% of annual global turnover – whichever is higher is always applied. For important entities, the lawmakers set fines of up to EUR 7 million or 1.4% of turnover. Worse still, the amendment to the Polish National Cybersecurity System Act (KSC), which took effect on April 3, 2026, also introduces personal financial liability for management boards.

Bearing in mind these risks, and the fact that since 2026 personal board liability for IT security is now a fact, it’s time to move on to a concrete remediation plan.

Step 1: Determine whether and how NIS2 applies to your company

A critical mistake is assuming NIS2 only applies to large corporations. The new directive significantly expands the range of entities covered by the regulations, and in practice touches more than a dozen sectors of the economy that are critical to the functioning of the state and the internal market – from energy and transport, through healthcare and wastewater management, to digital infrastructure and postal services.

To determine your status:

  1. Check your sector and company size. Whether you fall into the essential or important entity category depends on your industry, headcount, and annual turnover.
  2. Don’t ignore the supply chain. Even if your company isn’t directly named in the law, you may still be subject to NIS2 as a key supplier to a regulated entity. Large companies, in order to meet their own requirements, are now forcing compliance on their business partners.

If you need a solid foundation of knowledge, start by reading: Does my company fall under NIS2?. Then check exactly which obligations apply to you by reviewing the list of obligations for companies in Poland.

Step 2: Conduct a comprehensive IT security audit

Once you know the regulations apply to you, you need to precisely diagnose your current state. Without that, you can’t determine what needs to improve. An audit is the only way to establish a baseline and prove to supervisory authorities that you’re taking the matter seriously.

Such an audit is far more than an inventory of your equipment. It covers an analysis of your actual state of compliance with NIS2 requirements.

  • Access and identity management: Who has access to sensitive data and systems? Is the process of granting and revoking permissions controlled? Have you implemented phishing-resistant multi-factor authentication (MFA), which is now the absolute standard?
  • Business continuity: Does your company have tested business continuity plans (BCP) and disaster recovery plans (DRP)? NIS2 places enormous emphasis on the ability to quickly restore critical functions after an incident. How do you measure up against these requirements?
  • Supply chain security: Do you vet your IT subcontractors for cyber resilience? A gap at your supplier is now your gap and your liability.

A professional audit doesn’t have to be a nightmare. If you want to learn how to prepare for one and what gets assessed, read our detailed guide: IT security audit step by step.

Step 3: Implement the right technical and organizational measures

The audit will show you where to improve. Now comes the most important stage – implementing concrete, measurable safeguards to close the gaps you found. NIS2 isn’t just “paperwork” – it’s primarily about real, technical cybersecurity.

Focus on the fundamentals that build genuine resilience:

  • Server infrastructure security: Make sure your servers are patched on an ongoing basis (patch management), properly configured (hardening), and isolated where necessary (network segmentation). Without this foundation, every other measure is ineffective.
  • Real-time monitoring: Deploying SIEM (Security Information and Event Management) systems lets you continuously analyze server logs and detect anomalies instantly, cutting attack response time from hours to minutes. Without it, you may not even know an incident is underway.
  • Employee training: The human factor is the weakest link. Regular, hands-on training in recognizing phishing and social engineering is now mandatory and required by NIS2.

Our checklist is a practical guide through this process: Implementing NIS2 in the server room – From audit to cyber resilience. If you’re interested in the key business-continuity aspect, check out how to implement log monitoring and respond to incidents.

Step 4: Prepare the mandatory documentation

Supervisory authorities no longer take your word for it. They demand hard evidence. If you can’t prove you’ve implemented a given security measure, then legally speaking it’s as if you hadn’t. In the event of an incident, missing documentation is a direct path to a fine.

What documents are we talking about?

  • Information Security Policy (ISP): A document defining the company’s approach to cybersecurity.
  • Audit and penetration test reports: Evidence that you regularly and proactively verify the state of your defenses.
  • Incident response procedures: A detailed, step-by-step playbook for an attack.
  • Supplier contracts: Must include cybersecurity clauses and meet NIS2 requirements.

Need a ready-made template to work from? Use our plan: NIS2 in practice for SMEs – a 90-day implementation checklist. You’ll also find key information on documentation requirements in our guide for the board.

Step 5: Ensure continuous monitoring and improvement

NIS2 compliance isn’t a one-off project that ends with the first audit. It’s an ongoing process. It’s about building a culture of continuous monitoring and adaptation to an evolving threat landscape within your organization. The law is unforgiving on this point: a lack of ongoing oversight is a straight path to a fine.

In practice, this means:

  • Continuous log monitoring: Systems must not only collect logs but also automatically analyze them, correlate events, and alert on potential threats. Without this piece, quickly detecting and responding to an attack is impossible.
  • Regular penetration testing: At least once a year, your IT environment should be tested by external specialists who will attempt to break in and find weak points.
  • Updating documentation and procedures: The IT world changes fast, and your procedures need to change with it. They must be “living documents,” subject to regular review and updates.

Without this, the system doesn’t work. To make technology work in your favor, start by understanding the basics: how to read server logs and draw conclusions from them.

Don’t wait for the first letter from the authorities

Investing time in these 5 steps is an investment in your peace of mind and that of your business partners. You’ll avoid the stress of an inspection, eliminate the risk of massive fines, and – most importantly – genuinely protect your business against cyberattacks.

If this process feels overwhelming, you’re not alone. We’ve already helped dozens of companies get through it safely and painlessly.

👉 Book a free consultation and find out how we can help.

See how we secure infrastructure for other companies: Explore our IT cybersecurity services | Hosting and VPS for demanding businesses