As of 3 April 2026, Poland’s amended Act on the National Cybersecurity System (NCS Act), implementing the EU NIS2 Directive, has been in force. It is one of the most significant regulatory changes of recent years for companies operating in critical infrastructure sectors – and, as the first months of its application have shown, one for which many organisations are still not fully prepared.
The scale of the change is unprecedented
The previous NCS Act, in force since 2018, applied to a relatively narrow group of several hundred of the largest critical infrastructure operators. Following the amendment, the number of entities subject to the regulation has increased – according to estimates from the Polish Ministry of Digital Affairs and consulting firms – to approximately 38,000–42,000 organisations. This represents roughly a hundredfold increase compared with the previous legal framework.
In addition to telecommunications operators, the new rules cover companies in the energy, banking and transport sectors – precisely the industries in which Suntech has been active for many years.
Poland implemented the Directive more than a year after the EU transposition deadline, which even resulted in proceedings before the Court of Justice of the European Union. However, this delay also meant that companies were given relatively little time to adapt to the new requirements. The first key deadline – registration in the S46 system as an essential or important entity – falls on 3 October 2026.
Market readiness is still far below expectations
Data emerging during the first months following the entry into force of the new regulations shows that the pace at which companies are adapting to the new obligations is significantly behind the timeline envisaged by the legislation.
According to industry reports from July 2026, of an estimated 11,000 private entities covered by the regulation, only around 200 companies had registered in the NCS register at that stage. This means that the vast majority of organisations already formally subject to the new regulations are only beginning – or are still postponing – the compliance process.
The stakes are high. The Act provides for penalties of up to EUR 10 million or 2% of annual turnover, while responsibility for non-compliance may also be imposed personally on an organisation’s management.
This represents a major shift from the previous model, in which cybersecurity was often treated primarily as a technical matter rather than a management responsibility.
What NIS2 means in practice
The new regulations place strong emphasis on systematic risk management, incident response procedures within strictly defined timeframes, and the ability to demonstrate – rather than merely declare – that infrastructure is properly secured and monitored.
Essential entities will be required to conduct their first formal security audit, while the auditability of activities and decisions is becoming one of the key pillars of compliance.
It is no longer enough to know that the network is operating correctly. Organisations must be able to document this at any time and upon request from the relevant authorities.
Why everything starts with inventory
Current discussions around NIS2 are dominated by formal issues – deadlines, penalties and reporting procedures. Much less attention is paid to what, in practice, is a prerequisite for meeting these requirements: accurate and up-to-date knowledge of an organisation’s own infrastructure.
It is impossible to manage risk in a network that is not fully understood. Organisations cannot assess which elements are critical, identify vulnerabilities or respond quickly to an incident if information about network resources is fragmented, outdated or does not exist in a structured form at all.
Network inventory and asset management systems such as SunVizion should therefore not be viewed merely as an additional component supporting NIS2 compliance – they are part of its foundation.
An accurate map of infrastructure, configuration change tracking and a complete history of network events provide exactly the type of information required by the Directive. At the same time, these are data that organisations should maintain regardless of regulatory requirements.
Compliance as a by-product of good infrastructure management
Considering how few companies have so far formally registered in the relevant system, the coming months of 2026 are likely to be a period of accelerated activity for many organisations.
However, NIS2 should not be viewed solely as an additional regulatory burden. It can also serve as an opportunity to bring structure and discipline to areas that should already be properly managed.
Organisations that have invested for years in reliable network inventory and infrastructure management now have a natural advantage. For them, compliance with the Directive becomes a by-product of good practices rather than the starting point for a major transformation.


