Foreign owners of Polish energy assets keep treating this as a group IT matter. It is a Polish registry entry with a six-month statutory clock running from 3 April 2026, and the deadline is 3 October 2026. Self-registration only opened on 7 May, once the state finished entering the categories it enters on its own, so the practical filing window has been under five months. Two things make this different from a routine compliance date. The supervisor here is the President of URE, the same regulator that issued your licence, and the sanction available before 2028 is not a fine.
What actually falls due on 3 October
The amendment implementing NIS2 into Polish law, the act of 23 January 2026 (Dz.U. 2026 item 252), entered into force on 3 April 2026. That was roughly eighteen months after the EU transposition deadline of 17 October 2024, and ten months after the Commission sent Poland a reasoned opinion on 7 May 2025 for failing to notify full transposition. Nineteen member states got that letter. If your group sits in Germany, the Netherlands or Ireland, its own jurisdiction was very likely among them.
The obligation the act creates is self-identification. Every entity that meets the sector and size test determines its own status and files for entry in the Register of Essential and Important Entities (Wykaz podmiotów kluczowych i ważnych), the register of key and important entities, through the application at wykaz-ksc.gov.pl. Nobody writes to tell you.
Between 13 April and 6 May 2026 the Minister of Digital Affairs made entries on his own initiative for four categories: operators of essential services under the old law, trust service providers, telecoms undertakings, and public bodies. If your entity was entered that way, registration is closed and the rest of the timetable still runs. Everyone else files.
Registration confirms a status that already exists. The duties attach by operation of law on the date the test is met, whether or not anything has been filed. A company that never files remains obligated, simply without an entry on record.
The chain that follows the registration date
By 3 April 2027, twelve months after entry into force, key and important entities have to have the Chapter 3 security management measures in place and be using the S46 system, which has been open to new entities since 12 June 2026. By 3 April 2028, key entities that were not previously operators of essential services face their first security audit. One detail gets lost in most summaries: an entity that was an operator of essential services keeps its existing three-year audit cycle with no deferral, and where an audit falls due before 4 April 2027 it is carried out against the pre-amendment requirements.
Why the parent company’s NIS2 programme does not cover the Polish subsidiary
Article 5a of the amended act ties the obligation to a Polish footprint: a seat, a branch, or cross-border activity carried out on Polish territory. It says nothing about where group cybersecurity policy is written or which transposition the corporate compliance function treats as primary. A Dutch fund’s Polish wind portfolio runs its own clock. So does a German utility’s Polish grid-services subsidiary and a UK infrastructure fund’s Polish BESS vehicle, whatever programme exists at group level in Amsterdam, Frankfurt or London. Three seats, three clocks.
Parents often assume coverage because their own jurisdiction transposed NIS2 earlier and group security policy already meets the directive’s substance. The policies may well meet it. Somebody still has to file in Poland, by the Polish entity, under the Polish act.
Where energy sits, and where size stops being a shield
Annex 1 places energy among the key sectors: electricity, gas, oil, district heating, and two subsectors that are new in this act, nuclear and hydrogen. Within electricity the annex reaches beyond generation, transmission, distribution and supply to aggregation, demand response, energy storage, electric vehicle charging point operators, and nominated electricity market operators.
Classification then runs on size, and the two tiers matter more than most English-language summaries suggest. An entity in Annex 1 that exceeds the medium-enterprise threshold, broadly 250 employees or turnover above EUR 50 million, is a key entity. Below that, from 50 employees or turnover above EUR 10 million, the same annex produces an important entity. The difference is not cosmetic. Key entities are supervised both preventively and after the fact, so the authority can inspect without any incident or suspicion of breach. Important entities are supervised after the fact, in particular where a breach is reasonably suspected. Classifying upward to be safe buys a permanent exposure to inspection on the regulator’s initiative.
Size is not always decisive either. Article 5(1) lists categories that are key entities regardless of headcount or turnover. A small technical operator running SCADA system for a distribution asset is exactly the profile where the assumption of being too small to matter gets tested by an inspector first and a penalty second.
The exemption most group structures never check
Employee and turnover figures are calculated across the capital group, which is why a three-person Polish SPV under a large fund can find itself in scope. Article 5(6) provides a way out. An entity that crosses the threshold only because related enterprises are counted in does not become a key entity if its information system is independent of theirs, or if it does not provide services jointly with them. Article 5(7) applies the same rule to important entities. The provision is drafted as an alternative, so one of the two conditions is enough.
That is an engineering question. A wind farm with its own separated control system gives a different answer from fifteen farms run from one control room on shared infrastructure, and the burden of demonstrating that independence sits with the company. For a fund holding a Polish portfolio through SPVs, this single test can decide whether one entity files or fifteen do.
The part that reaches past the compliance department
The 2018 predecessor act treated cybersecurity as an operational IT function. The 2026 amendment identifies the entity’s manager (kierownik podmiotu), with the governing body itself under Article 8c. Where that body has more than one member and no specific person has been designated as responsible, responsibility falls on every member of it. Delegating the work to a CISO or an external provider does not move the liability off the people who delegated it.
At entity level the exposure is real but deferred. Key entities face administrative fines up to EUR 10 million or 2 percent of revenue from the preceding financial year, whichever is higher, and not less than PLN 20,000 (Article 73(3)). Important entities face EUR 7 million or 1.4 percent, not less than PLN 15,000 (Article 73(4)). Where an entity has traded for less than twelve months the calculation base is EUR 500,000 and EUR 250,000 respectively (Article 73(3a)), which is the situation of a newly incorporated project company. The manager carries a separate personal fine. Up to 300 percent of remuneration (Article 73a(4)), imposable independently of the fine on the entity.
What can actually happen before April 2028
Article 35 of the amending act defers the fines under Article 73(1) to (4) and Articles 73a to 73c by two years, to 3 April 2028. That covers the personal fine on the manager as well. Most commentary stops there and concludes that nothing can happen until 2028. Two things sit outside the deferral.
The first is the extraordinary penalty of up to PLN 100 million under Article 73(5), which Article 35 does not list. Its triggers repay reading in full, because they extend past threats to state security and human life to the risk of causing serious material damage or serious disruption to the provision of services. For a distribution or generation business that bar sits lower than the shorthand suggests. It remains an exceptional instrument requiring a direct and serious cyber threat, so it is not the base case.
The second is the supervisory toolkit. It consists of measures, which Article 35 leaves alone. Article 53(4) requires the authority to open with a written warning setting out what to do and by when. Article 53(5) then provides eight measures, among them appointing a monitoring official for up to a month with the right to enter the premises and inspect documents, and ordering breaches to be made public. At the end of that path stands Article 53(9), which for a key entity allows the authority to suspend a licence or narrow its scope, suspend activity entered in the commercial register, and bar the entity’s manager from performing management functions until the deficiencies are removed.
For a licensed energy business, that is the sentence in this article that matters most. In the energy sector those powers sit with the President of URE, the same office that issued the licence, approves tariffs, and assesses compliance with the grid codes. The cybersecurity file lands on a desk that already holds the group’s regulatory history in Poland.
What to have ready before you file
A current KRS extract and NIP, matched to the exact entity that holds the Polish grid connection or the licence.
An inventory of the systems supporting the regulated activity: SCADA system, metering, remote control links to the DSO or TSO. Not the corporate network.
Group headcount and turnover, plus evidence on whether the Polish entity’s systems are independent of the rest of the group under Article 5(6).
A board resolution naming the person accountable, which is what stops responsibility resting on every member of the governing body.
A contact point for incident reporting once the entity is live in S46.
Everything on that list stays under NDA from the first call.
Where GridStaff Compliance fits
GridLink’s engineers work inside the systems this act is written to cover: SCADA at substation level, protection and automation architecture, the operational interface with the DSO and TSO. The engineering side is led by Staff, whose team has over 800 MVA of connected capacity behind it. That matters here for one specific reason. The Article 5(6) independence test is answered by how the control systems are actually built and operated, not by an organisational chart, and it has to be evidenced.
GridStaff Compliance takes an asset through the sector and size classification against Annexes 1 and 2, tests the group exemption, prepares the registration filing, and maps the gap between what the entity already documents for grid-code purposes and what Chapter 3 requires by April 2027. The work is advisory. The classification and the filing remain the entity’s own decision, made on our analysis, and we do not act as security contractor, systems integrator, or certifying body.
One caveat that works against us. If your Polish entity was an operator of essential services under the old act, it was entered in the register on the state’s initiative in April or May and there is nothing to file. What remains is the SZBI deadline and the audit cycle, which is a different scope and a different budget.
Send us the entity’s ownership structure and the jurisdiction it reports into, and we will confirm in writing whether it falls in scope and at which tier. No documents needed for that first answer.
The registration window closes on 3 October 2026. Book a scoping call this week if the filing has not been made, because the 2026 entry is the first line of the record an inspector reads at the 2028 audit.
Sources: Act of 5 July 2018 on the national cybersecurity system, consolidated text Dz.U. 2026 item 20; Act of 23 January 2026 amending it, Dz.U. 2026 item 252, including Article 35; Ministry of Digital Affairs timetable of April 2026; European Commission reasoned opinion of 7 May 2025 on NIS2 transposition; Directive (EU) 2022/2555.






