As of today, exactly 39 days remain until the October 3 registration deadline under Poland’s amended NIS2 cybersecurity law. The clock is ticking, and many foreign branches may not realize it.

When looking at NIS2 adoption across the European Union, Poland is among the Member States that have already completed transposition. Major EU economies like France, Spain, and Ireland still lack final implementing legislation. In contrast, Poland’s amended Act on the National Cybersecurity System is officially in force. For the Polish tech ecosystem, this regulatory readiness is a positive signal. It demonstrates that Poland provides a highly regulated and secure environment.

The Element of Surprise: Local Branches Are on the Clock

This progress sets a firm deadline. Under the amended law, organizations classified as key or important entities must register in the government S46 system by October 3, 2026. Entities that cross the thresholds later are granted six months from that date to complete registration.

A critical detail is that this obligation applies equally to Polish subsidiaries and branches of foreign companies. If your headquarters is located in a country where national legislation is delayed, your corporate leadership might assume there is no immediate rush. In reality, the Polish deadline is fixed and independent.

Compliance Does Not Equal Resilience: The MyDr Reality Check

While Poland advances its NIS2 regulatory framework, legal compliance alone does not guarantee immunity from cyber threats.

The recent data breach at MyDr, a medical software provider used by more than 12,000 healthcare facilities, serves as a sobering reminder. The company confirmed it was targeted in a cyberattack. Poland’s Ministry of Digital Affairs put the potential reach at close to 19 million people. However, MyDr’s own leadership has since cautioned that notifying that many people through medical facilities does not confirm their data was actually accessed or exposed. Poland’s Central Cybercrime Bureau (CBZC) and the data protection authority (UODO) have both opened investigations, and the full scope is still being determined.

This incident highlights a fundamental truth. Registering in the S46 database fulfills a statutory duty, but it does not stop an active attack. The sectors covered by the amended national law are already under active threat, regardless of their regulatory status.

Securing Your Tech Footprint Before the Deadline

Real cyber resilience requires continuous infrastructure monitoring and qualified technical specialists. As October 3 approaches, companies operating in Poland should confirm their legal status and audit their talent capabilities.

Navigating new EU regulations requires the right technical headcount on the ground. At Winged IT, we specialize in tech recruitment. We help international businesses scale mature, highly qualified IT and cybersecurity teams in Poland, ensuring you have the experts needed to defend your infrastructure.


Cover photo source: Canva