Poland NIS2 Energy Compliance: Who Regulates You — URE, PSE, or the Ministry — After Orlen Absorbed Lotos and PGNiG
Poland’s amended Act on the National Cybersecurity System (KSC) took effect on 3 April 2026, and it did something most “NIS2 in Poland” coverage has missed: multiple Polish-language legal analyses of the amendment report that it moved cybersecurity supervision of the entire energy sector off a general ministry’s desk and onto a market regulator’s — the President of the Energy Regulatory Office (Prezes URE). If you run cybersecurity, compliance, or board reporting for an electricity, gas, oil, district heating, or hydrogen business with Polish operations, that single change affects who audits you, who you notify after an incident, and who can suspend your activity. This guide maps Poland’s energy-sector scope under Annex I of the NIS2 Directive, names the authority you actually answer to, and works through two entities most generic Poland guides skip entirely: PSE, the state-owned transmission operator now facing two separate cyber regimes at once, and PKN Orlen, which absorbed Grupa Lotos and PGNiG and now straddles two Annex I subsectors under one roof. For the broader picture of how Poland structures NIS2 supervision — registration, CSIRTs, and cross-sector authorities — see our NIS2 in Poland overview; this guide narrows in on energy specifically.
This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.
Does This Apply to You? Poland’s Energy-Sector Scope Under the Amended KSC Act
In plain terms: if your organisation generates, transmits, distributes, stores, or supplies electricity, oil, gas, district heat, or hydrogen in Poland — and you’re a medium or large enterprise — you’re almost certainly in scope. NIS2’s Annex I treats the entire energy value chain as a sector of high criticality, which means most energy businesses default to essential-entity status once they cross the large-enterprise threshold, not the lighter important-entity tier most other sectors get [1][3].
| Subsector | Annex I entity types | Polish scope examples |
|---|---|---|
| Electricity | Generation facilities above threshold, TSOs, DSOs, supply undertakings, aggregators/demand response/storage operators | PSE (sole TSO), regional distribution operators, electricity suppliers |
| Oil | Transmission pipeline operators, production/refining/processing, storage, central stockholding entities | PKN Orlen refining and storage assets (including former Lotos sites) |
| Gas | Supply undertakings, DSOs, TSOs, storage system operators, LNG system operators | Poland’s gas TSO, PKN Orlen’s former PGNiG upstream and supply business |
| District heating/cooling | Network operators | Municipal and industrial heat network operators |
| Hydrogen | Producers, distributors, suppliers | New subsector under NIS2 — did not exist under NIS1 |
Poland uses the EU’s standard self-identification test rather than a case-by-case administrative decision: a large enterprise (roughly 250+ staff, or turnover above €50M and balance sheet above €43M) in an Annex I sector defaults to essential-entity (“podmiot kluczowy”) status; a medium enterprise defaults to important-entity (“podmiot ważny”) status [1][8]. A handful of energy entities land in scope regardless of size — sole providers of a given service in Poland, and anything separately designated critical infrastructure under the EU’s Critical Entities Resilience Directive [1]. If you want the EU-wide version of this scope test rather than Poland’s specific application of it, our NIS2 Energy Sector Compliance guide covers Article 21 controls and enforcement deadlines across all member states.
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
Who Regulates You in Poland — URE, PSE, or the Ministry?
Before the 2026 amendment, Poland’s general answer to “who regulates energy cybersecurity” was the minister responsible for energy — a framing several international law-firm summaries of Poland’s NIS2 transposition still use [6]. That’s no longer the full picture. Multiple Polish-language legal analyses of the amended KSC Act report that Article 41 now names the President of the Energy Regulatory Office — Prezes URE — as the competent cybersecurity authority (“organ właściwy”) for the entire energy sector [8][9].
We want to be precise about how solid that finding is: we could not independently pull the consolidated Article 41 text this session — Poland’s official legislative database blocks automated retrieval — so treat the URE designation as strongly corroborated (two independent, mutually consistent Polish-language legal sources) rather than primary-text-verified. Confirm directly with URE or a Polish compliance advisor before relying on it for a filing.
What doesn’t change regardless of which framing is current: URE was already energy’s economic regulator — tariffs, licensing, market oversight — under the Energy Law. What the amendment adds is a cybersecurity supervisory toolkit layered on top of that existing relationship: the competent authority can now issue warnings, order security assessments and audits, and — at the top of the ladder — suspend a key entity’s activity [8]. Either way, your incident reports and audit evidence go to a Poland-specific authority, not to Brussels or ENISA directly — for the CSIRT you’ll actually be reporting incidents to, see our Poland NIS2 Competent Authority breakdown of the three-CSIRT model.
PSE’s Double Exposure: KSC Critical Infrastructure Status Plus the EU’s NCCS
PSE — Polskie Sieci Elektroenergetyczne — is Poland’s only electricity transmission system operator, 100% owned by the State Treasury, and it runs the entire 220/400 kV backbone that keeps the country’s grid frequency stable [10]. That combination — sole operator, state-owned, physically irreplaceable — is functionally the same profile Germany’s KRITIS regime uses to flag critical-infrastructure operators for its strictest cybersecurity tier. Poland doesn’t use the KRITIS label, but PSE’s own designation as critical infrastructure under Polish law does comparable work — think of PSE as Poland’s KRITIS-equivalent energy operator, even though the two frameworks aren’t formally linked.
What makes PSE’s position genuinely unusual is that it doesn’t answer to just one cyber regime. NIS2/KSC is the general-purpose layer every essential entity in Poland’s energy sector carries. Sitting on top of that, the EU’s Network Code on Cybersecurity — Commission Delegated Regulation (EU) 2024/1366, in force since 13 June 2024 — adds a second, electricity-specific layer that applies only to entities a competent authority designates as “high-impact” or “critical-impact” for cross-border electricity flows [4]. A transmission operator running the interconnectors that keep Poland’s grid synchronised with its neighbours is exactly the kind of entity the NCCS was written for. PSE has separately proposed taking on the role of managing entity for a dedicated energy-sector CSIRT — a proposal, not yet law, but one that would put PSE at the centre of both incident response and its own compliance obligations [10].
Practical read for anyone downstream of PSE — distribution operators, large industrial consumers, energy traders: don’t assume NCCS is someone else’s problem just because you’re not a TSO. NCCS designation criteria run on grid impact, not corporate size — a large distribution operator or a market participant providing balancing services can be pulled in too, on a schedule set independently of the KSC registration deadline below.
PKN Orlen After Lotos and PGNiG: One Group, Two Annex I Subsectors
PKN Orlen closed its merger with Grupa Lotos in 2022, and its merger with PGNiG was registered in Poland’s National Court Register on 2 November 2022 [11]. The combined group now runs refining, fuel retail, and petrochemicals — the Orlen and former-Lotos businesses — alongside upstream gas production and gas supply — the former PGNiG business — under one corporate structure.
For NIS2 scope purposes, that merger didn’t create one energy entity; it created one corporate group operating across two separate Annex I subsectors at once. Orlen’s refining and storage assets sit in the Oil subsector (production, refining, processing, storage); the former PGNiG upstream and supply operations sit in the Gas subsector (supply undertakings, storage system operators) [3]. Each subsector carries its own entity-type list and, in principle, its own essential/important classification exercise. A group this size clears the large-enterprise threshold everywhere it operates, so the practical effect is essential-entity status across both — but the compliance obligation doesn’t collapse into a single filing just because the corporate ownership did. When we mapped this scenario against our own Energy Pack’s classification workbook, it became clear a gap analysis for a group like this has to run subsector by subsector, not company-wide.
This is also a preview of a problem other Polish energy consolidations will hit: when M&A activity crosses Annex I subsector lines, NIS2 scope follows the operating entity’s activity, not the parent’s registered business line.
Registration Deadlines and Penalties
| Date | Milestone |
|---|---|
| 7 May – 3 October 2026 | Self-identification and KSC registration window (S46 system live from 12 June 2026) |
| 3 April 2027 | Deadline to implement required cybersecurity measures and organisational structures |
| 3 April 2028 | First cybersecurity audits begin for essential entities; administrative enforcement can follow |
Miss the registration window and you’re already non-compliant before the ink dries on your risk assessment — registration is Poland’s first, hardest deadline, not implementation [5][7].
| Entity type | EU-baseline ceiling (Article 34) | Notes |
|---|---|---|
| Essential (“podmiot kluczowy”) | EUR 10,000,000 or 2% of worldwide annual turnover, whichever is higher | Applies to breaches of the Article 21 security measures or Article 23 incident-notification duties |
| Important (“podmiot ważny”) | EUR 7,000,000 or 1.4% of worldwide annual turnover, whichever is higher | Same trigger conditions, lower ceiling |
| Registration/administrative failures | Separate KSC-specific administrative fines, plus board-level personal liability provisions | Poland layers PLN-denominated penalties on top of the Article 34 ceilings — see our full breakdown in Poland NIS2 Enforcement for exact figures |
What to Do Next, by Role
| Role | What to do | Effort |
|---|---|---|
| CISO / IT Security Manager | Confirm which Annex I subsector(s) your operating entities fall into, map current controls against Article 21(2), and flag whether any asset could trigger an NCCS high/critical-impact review | High |
| Compliance Officer / Legal | Run the self-identification test, register in the KSC system inside the 7 May–3 Oct 2026 window, and diarise the 3 Apr 2027 and 3 Apr 2028 deadlines | Medium |
| SME Owner (non-technical) | Confirm whether you’re a medium or large enterprise under the EU thresholds — that single fact decides essential vs important status and which penalty ceiling applies | Low |
| Board / C-Suite | Note the personal liability provisions attached to the amended Act, and budget for both the URE/ministry supervisory relationship and, if relevant, a separate NCCS compliance track | Medium |
Frequently Asked Questions
Is URE the same authority for every Polish energy company, or does it vary by subsector?
The sources available this session describe URE’s Article 41 designation as covering the energy sector broadly — electricity, oil, gas, district heating, hydrogen — rather than split subsector by subsector. Since the primary legislative text wasn’t independently fetchable this session, confirm your specific subsector’s authority directly with URE or a Polish compliance advisor before relying on it for a filing.
Does the NCCS apply to my company even if I’m not PSE?
Possibly. NCCS designation runs on cross-border electricity-flow impact, not company size or ownership — large distribution operators, balancing-service providers, and major generators can all be designated high-impact or critical-impact, separately from KSC essential/important classification.
If PKN Orlen’s Oil and Gas operations get classified differently, what happens?
Nothing prevents a single corporate group from carrying different compliance obligations across its business lines. Each operating entity is assessed against its own Annex I subsector, and a group spanning two subsectors should expect two parallel Article 21 gap analyses, not one combined filing.
We already register with URE for energy-market purposes — is KSC registration separate?
Yes. URE’s existing market and licensing registrations under the Energy Law are a different regime from KSC’s cybersecurity entity registration, which runs through the S46 system inside the 7 May–3 October 2026 window.
Sources
- NIS2 Directive, Article 2 (scope by entity size) — nis-2-directive.com
- NIS2 Directive, Article 34 (administrative fines) — nis-2-directive.com
- NIS2 Directive Annex I, Energy sector scope — see our own Who Must Comply guide (linked above)
- Commission Delegated Regulation (EU) 2024/1366 (Network Code on Cybersecurity) — “First Network Code on Cybersecurity for the electricity sector has been published,” ENTSO-E (entsoe.eu)
- “The NIS2 Directive Implemented in Poland — New Cybersecurity Obligations for Entrepreneurs,” KPMG Poland (kpmg.com/pl)
- “Poland — EU NIS2 Directive,” Eversheds Sutherland (ezine.eversheds-sutherland.com)
- “Sejm uchwalił nowelizację ustawy o KSC,” ITwiz (itwiz.pl)
- “KSC 2026 — Energy sector requirements,” KSC.expert (ksc.expert)
- Polish-language legal commentary on Article 41 of the amended KSC Act (URE designation) — cross-confirmed via two independent sources; primary legislative text not independently fetchable this session
- PSE (Polskie Sieci Elektroenergetyczne) company and industry reporting — wnp.pl, cyberdefence24.pl
- PKN Orlen investor relations — merger announcements, orlen.pl
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
