Abstract cybersecurity network nodes over a factory silhouette representing NIS2 manufacturing compliance in Poland

Poland’s NIS2 Manufacturing Scope Test: Why It Catches Volkswagen Poznań But Not KGHM’s Copper Smelters

Plain-language summary: if your factory in Poland makes chemicals, medical devices, electronics, electrical equipment, machinery, or motor vehicles and employs 50 or more people, or turns over €10 million or more, you are an important entity under the amended KSC Act — register in System S46 by 3 October 2026, whether or not you supply Volkswagen, a German Tier 1, or the Polish state. What most guidance skips is that "manufacturing" is not one undifferentiated bucket. Poland’s own scope test, applied to real facilities, catches an automotive assembly plant like Volkswagen Poznań immediately but leaves a copper smelter like KGHM’s Głogów works outside the manufacturing gate entirely — a distinction with real consequences for who registers, and under which sector code. This guide covers the scope test, the S46/Wykaz KSC mechanics, what Article 21 means for a factory floor running 20-year-old PLCs, the supply-chain cascade already reaching Polish automotive suppliers through TISAX, Poland’s distinctive high-risk-vendor power, and the penalty and timeline calendar you’re now working against.

Does Your Facility Actually Fall Under Poland’s Manufacturing Scope?

The amended ustawa o Krajowym Systemie Cyberbezpieczeństwa (KSC Act) folds manufacturing into Załącznik nr 2 (Annex 2, important entities) using language lifted almost directly from NIS2’s own Annex II, Section 5: production and distribution of chemicals, machinery and devices, including electronic and transport equipment [2]. In NACE terms, that means computer, electronic and optical products (C26), electrical equipment (C27), machinery n.e.c. (C28), motor vehicles and trailers (C29), other transport equipment (C30), medical devices, and chemical substance manufacture under REACH [5]. Three conditions have to hold at once: you’re established in Poland, your activity sits in one of those categories, and you clear 50 employees or €10 million in annual turnover [4].

Manufacturing subsector NACE / legal basis Real Polish example
Motor vehicles, trailers & semi-trailers NACE C29 Volkswagen Poznań (4 plants, ~9,000 staff)
Chemicals (REACH substance manufacture) Reg. (EC) 1907/2006 Downstream petrochemical output, e.g. the Płock complex
Computer, electronic & optical products NACE C26
Electrical equipment NACE C27
Machinery n.e.c. NACE C28
Other transport equipment NACE C30
Medical devices & IVD Reg. (EU) 2017/745
Not covered by this gate Mining (Section B), basic metals (NACE C24) KGHM ore mining & copper smelting/refining

Applied to three real Polish operations, the test produces genuinely different answers. Volkswagen Poznań — four plants, roughly 9,000 employees, over 100,000 Crafter vans a year from the Września site alone [14] — is squarely NACE C29: an easy, unambiguous important entity. PKN Orlen’s Płock site processes up to 17.8 million tonnes of crude oil annually across 71 installations [13], but most of that output is refining and fuel supply — an Annex I energy activity, not manufacturing. Only the downstream petrochemical output that meets REACH’s substance-manufacture definition tests against the chemicals gate at all, and Poland’s cross-sector rule means Orlen registers once, under its principal activity, almost certainly energy rather than manufacturing [1]. KGHM’s Głogów and Legnica copper smelters [12] are the harder case: ore mining and copper smelting/refining sit in NACE’s mining (Section B) and basic-metals (Division 24) categories, neither of which appears anywhere in Annex II’s manufacturing list — and Poland’s own sectoral expansion added coal mining to the energy sector, not copper metallurgy to manufacturing [7]. By the manufacturing scope test specifically, KGHM’s core smelting activity doesn’t register as a manufacturing entity at all — a reminder that headcount and industrial scale don’t substitute for matching the actual NACE gate. (A group KGHM’s size may still carry separate obligations through other business lines or a specific national designation; the point here is narrowly about the manufacturing sector code.)

S46, the Wykaz KSC Registry, and Poland’s Registration Clock

Once you clear the scope test, registration runs through System S46, the Ministry of Digital Affairs’ IT platform, feeding the public Wykaz KSC registry at wykaz-ksc.gov.pl, live since 13 April 2026 [1]. Registration isn’t uniform. Telecoms operators, trust-service providers, and already-designated critical-infrastructure operators were entered automatically by the ministry using existing registry data by early May 2026. Everyone else — where the great majority of manufacturers sit — falls into the self-registration window: 7 May to 3 October 2026, with the head of the entity or an authorised representative responsible for filing [1][2]. Miss the window and you’re still obligated; you’re just registering late, against a clock that’s already running for the substantive requirements.

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Registration is the floor, not the finish line. Entities that met the criteria on 3 April 2026, the amendment’s entry-into-force date, have 12 months — until 3 April 2027 — to have a working information security management system in place covering Article 21’s measures [2]. The first statutory audit follows within 24 months of entry into force, by 3 April 2028, then every three years after that [2]. For a manufacturer starting from a generic IT security posture, that’s a tight runway to extend a policy framework across OT systems that were never designed with NIS2’s ten measures in mind. The three-gate scope test, CSIRT routing, and registration mechanics common to every Polish NIS2 entity are covered in full in our Poland NIS2 hub.

What Article 21 Actually Requires on the Factory Floor

Article 21(2) sets ten measures under an all-hazards approach, proportionate to the entity’s size, exposure, and the severity of likely incidents [3]. For a Polish assembly or process plant, the friction concentrates in a handful of places: business continuity planning that treats a halted production line as the primary failure mode, not just data loss; supply chain security under (d), covering direct suppliers and service providers; and access control and asset management under (i), which assumes you can actually inventory every PLC, HMI, and remote-access point on the shop floor — a nontrivial task on equipment installed a decade before "asset inventory" was a compliance term. Poland’s own trade press has flagged network segmentation, backup discipline, and access control on OT/IT networks as the areas manufacturers most often have to build from close to zero [8], and the September 2025 Jaguar Land Rover ransomware attack — six weeks of halted production and roughly £1.5 billion in impact — is the reference case Polish industrial cybersecurity commentary keeps returning to for what an unmanaged OT incident actually costs [8]. Our manufacturing compliance hub maps all ten Article 21(2) measures against OT-specific interpretations in full; this guide focuses on what’s distinctly Polish rather than repeating that mapping.

One correction worth making explicitly: Commission Implementing Regulation (EU) 2024/2690, which sets detailed binding technical requirements across 13 sections, applies only to eleven named digital-infrastructure and ICT-service-provider categories — DNS providers, cloud and data-centre operators, managed service providers, and similar [6]. A Polish factory is not on that list. Article 21 governs your OT systems directly, in its general, outcome-based form, not the CIR’s granular technical annex — see our CIR 2024/2690 guide for the full scope breakdown.

The Supply Chain Cascade: How Volkswagen Poznań Pulls Suppliers Into Compliance They Don’t Legally Owe

Article 21(2)(d) requires in-scope entities to manage risk from their direct suppliers, and the KSC Act’s own guidance frames this as an ongoing, risk-based supplier-security policy rather than a one-time checkbox: selection criteria that weigh a supplier’s cybersecurity maturity, contractual audit rights, subcontractor rules, and incident-reporting terms, reassessed over the life of the relationship rather than just at signing [9]. For Volkswagen Poznań’s roughly 9,000 direct jobs [14], that obligation flows downstream to every Tier 2 and Tier 3 component supplier in its network — most of which are far too small to independently meet NIS2’s 50-employee or €10 million threshold, and so carry no direct KSC obligation of their own. They get pulled in anyway, contractually, because their customer’s own compliance depends on assessing them.

Polish automotive suppliers have a head start most manufacturing subsectors don’t: TISAX, the VDA-developed, ISO/IEC 27001-based information-security standard, is already close to a mandatory ticket to supply German-linked OEMs, and it substantively overlaps with NIS2’s own requirements [10]. The gap is narrow but real — TISAX is a private assessment standard with no statutory reporting channel, so it doesn’t establish the official contact point a competent authority expects, and it doesn’t enforce NIS2’s specific 24-hour early-warning and 72-hour incident-notification clock [10]. A TISAX-certified Tier 1 supplier is most of the way to Article 21 readiness on substance; it still needs the KSC-specific registration, the CSIRT NASK reporting line, and statutory notification timing layered on top.

Poland’s High-Risk Vendor Power — and What It Could Mean for OT Equipment

The amended KSC Act gives Poland’s Minister of Digital Affairs a mechanism most NIS2 transpositions don’t include in this form: after consultation, the minister can formally designate a specific ICT vendor as a high-risk supplier if its products or services pose a serious threat to state security [11]. Once designated, key and important entities using that vendor’s equipment or software must withdraw and replace it, on a phased timeline reported at four to seven years, at their own cost — telecoms-sector estimates for a full replacement cycle already run into the billions of złoty [11]. The mechanism was built with 5G network equipment in mind, and it hasn’t been tested against an industrial-automation or SCADA/PLC vendor to date. But the statutory power isn’t sector-limited: a manufacturer running control-system hardware or software from a vendor a future designation targets would face the same forced-replacement clock as a telecoms operator, on capital equipment that’s far more expensive and disruptive to swap than a server rack. Building vendor diversity and documented fallback options into OT procurement now is cheaper than discovering the exposure after a designation lands.

Penalties, Personal Liability, and the Compliance Calendar

NIS2’s own floor for important entities — manufacturing’s default classification — sets fines at up to €7 million or 1.4% of worldwide annual turnover, whichever is higher [3][4]. Poland layers a national supplement on top: a domestic-security-threat tier reaching PLN 100 million (roughly €23-24 million), with daily penalties up to PLN 100,000 for continuing violations, alongside personal liability for board and management-body members that can reach 300% of monthly remuneration — a figure our Poland penalties guide breaks down in full. None of that requires the entity to have already suffered an incident; it attaches to the underlying failure to implement Article 21’s measures, or to register at all.

Date What happens
3 April 2026 KSC amendment enters into force; kluczowy/ważny classification applies
13 April 2026 Wykaz KSC registry live at wykaz-ksc.gov.pl
7 May – 3 October 2026 Self-registration window for manufacturers via System S46
3 April 2027 SZBI (information security management system) covering Article 21 must be operational
3 April 2028 First statutory audit deadline; 3-yearly cycle begins

For a manufacturer reading this in the second half of 2026, the practical order is: confirm your NACE match and headcount or turnover position against the scope test above, register within the S46 window if you haven’t already, and use the roughly eleven months between registration and the SZBI deadline to close the gap between whatever IT security policy you currently have and an OT-extended one that actually covers Article 21(2)’s ten measures.

Frequently Asked Questions

Does a 60-employee Polish auto-parts supplier have to register in S46? Yes. If its activity falls within NACE C26-C30 or chemical or medical-device manufacture and it exceeds 50 employees or €10 million in annual turnover, it’s an important entity and must self-register within the 7 May-3 October 2026 window, regardless of whether it directly supplies an OEM.

Is copper mining and smelting covered by Poland’s manufacturing scope? Not by the manufacturing gate specifically. NACE’s mining and basic-metals categories don’t appear in NIS2 Annex II’s manufacturing list, and Poland’s own sectoral expansion added coal mining to energy, not metals mining or smelting to manufacturing. A large mining and metals group could still face separate obligations through other business lines or a specific national designation.

Does CIR 2024/2690 set technical requirements for my factory’s OT network? No. The CIR binds only eleven named digital-infrastructure and ICT-service-provider categories. Manufacturing entities are governed by Article 21 directly, in its general form.

Does TISAX certification satisfy NIS2 for an automotive supplier? It covers most of the substance — risk management, access control, incident handling — but not the statutory registration in S46, the CSIRT NASK reporting line, or NIS2’s specific 24-hour/72-hour notification timing. Treat TISAX as a strong head start, not a substitute.

Can a manufacturer be designated an essential rather than important entity? Only through a specific national determination; Annex II sectors, including manufacturing, default to important-entity status under both the EU directive and the amended KSC Act.

This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.

Sources

  1. "Zmiany w Systemie S46 po nowelizacji i uruchomienie Wykazu podmiotów kluczowych i podmiotów ważnych" — gov.pl (Ministry of Digital Affairs)
  2. "Nowelizacja ustawy o krajowym systemie cyberbezpieczeństwa" — gov.pl Baza Wiedzy
  3. NIS2 Directive, Article 21: Cybersecurity risk-management measures — nis-2-directive.com
  4. NIS2 Directive, Article 3: Essential and important entities — nis-2-directive.com
  5. NIS2 Directive, Annex II — Other Critical Sectors — Luxgap
  6. NIS2 Implementing Regulation (CIR 2024/2690), scope of applicable entities — Advisera
  7. "Poland’s KSC Act Is Now in Force: Why NIS2 Compliance Starts with Infrastructure Automation" — Puppet
  8. "Nowelizacja KSC zmienia zasady gry. Sektor przemysłowy w obliczu NIS2" — cyberdefence24.pl
  9. "Cybersecurity in the supply chain: what NIS2 changes in Poland" — CMS Law
  10. "TISAX jako przepustka do NIS2" — All for One Poland
  11. "Minister wskaże dostawców wysokiego ryzyka" — wnp.pl
  12. KGHM Polska Miedź — Smelting and Refining — kghm.com
  13. PKN Orlen — Zakład Produkcyjny w Płocku (orlen.pl, live but blocks automated fetch checks)
  14. Volkswagen Poznań — Fabryki — volkswagen-poznan.pl
Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Don't miss: