# NIS2

Source: https://ordergroup.co/glossary/nis2/
Last updated: 2026-10-10

> What the NIS2 Directive and Poland's KSC act mean for energy companies, and which security requirements end up in the software they buy.

[Energy](https://ordergroup.co/glossary/energy/)
4 min read

# NIS2

NIS2 Directive
Also known as: NIS 2 directive, KSC

Definition

NIS2 is the EU cybersecurity directive (EU) 2022/2555. It requires essential and important entities, including electricity suppliers, grid operators, producers, aggregators, storage and charge point operators, to manage cyber risk and send an early warning of significant incidents within 24 hours.

Cite this entry

Text
"NIS2". Order Group, Software glossary, 10 October 2026. https://ordergroup.co/glossary/nis2/
HTML
`<a href="https://ordergroup.co/glossary/nis2/">NIS2</a> - Order Group`

Reviewed by [Michał Dżaman](https://ordergroup.co/authors/michal-dzaman/), Co-founder & Head of Backend
Last reviewed 10 October 2026

## How NIS2 works

Directive (EU) 2022/2555, known as NIS2, was adopted on December 14, 2022 and replaced the first NIS directive (2016/1148). Member States had to transpose it by October 17, 2024 and apply it from October 18, 2024. As a directive it does not bind companies directly. Each country writes its own law, and in Poland that law is the act on the national cybersecurity system (ustawa o krajowym systemie cyberbezpieczeństwa, KSC).

NIS2 covers medium-sized and larger organizations in the sectors listed in its annexes and sorts them into essential and important entities, which differ mainly in how closely they are supervised and how high the fines can go. Energy is in Annex I. For electricity the list covers electricity undertakings that supply power, distribution and transmission system operators, producers, nominated electricity market operators, market participants providing aggregation, demand response or energy storage services, and operators of recharging points.

The obligations sit in three articles. Article 20 makes the management body approve the cybersecurity risk-management measures, oversee them and take part in training. Article 21 lists the minimum measures, from risk analysis and incident handling to supply chain security, cryptography and multi-factor authentication. Article 23 sets the reporting clock for significant incidents.

NIS2 obligations in numbers (Directive (EU) 2022/2555)
ObligationArticleRequirement

Early warning23(4)(a)Within 24 hours of becoming aware of a significant incidentIncident notification23(4)(b)Within 72 hoursFinal report23(4)(d)Within one month of the notificationFines, essential entities34(4)Maximum of at least EUR 10 million or 2% of worldwide annual turnover, whichever is higherFines, important entities34(5)Maximum of at least EUR 7 million or 1.4% of worldwide annual turnover, whichever is higher

## What NIS2 means for your software

NIS2 regulates the organization, but most of Article 21 lands on its systems, and much of it on whoever builds them. Point (d) requires supply chain security and point (e) security in "network and information systems acquisition, development and maintenance," including vulnerability handling. Article 21(3) tells entities to consider the vulnerabilities of each direct supplier and the quality of its products and cybersecurity practices. A grid operator, aggregator or charge point operator buying software will therefore write these requirements into the contract and ask its supplier to prove them.

In practice the requirements that reach the software are fairly predictable. Encryption of data in transit and, where appropriate, at rest follows from point (h), and multi-factor authentication for users and administrators from point (j). Access control and an asset inventory come from point (i), backups and a tested recovery procedure from point (c). The 24-hour early warning sets a design target: the system has to produce security logs and alerts that let someone notice an incident within hours of it starting. Device fleets add their own work, because every meter, gateway or inverter connection is a supplier link and an entry point.

NIS2 does not certify products. Connected devices are covered by separate EU rules, the Cyber Resilience Act (CRA) and the delegated act under the Radio Equipment Directive (RED DA), so for energy devices the hardware maker answers to CRA and RED DA, and the operator to NIS2.

Writing the specification?

Add NIS2 to your requirements checklist

Collect the terms your project touches and get their system requirements in one e-mail, ready for an RFP.

Article 21(2) measures and what they mean for a system you buy
Measure (Art. 21(2))What to expect in the software

(b) Incident handlingCentral logs, alerting, a runbook that supports the 24-hour warning(c) Business continuityBackups, restore tests, documented recovery time(d) Supply chain securitySupplier inventory, dependency and component tracking(e) Secure development and maintenanceCode review, vulnerability handling and patch process(h) CryptographyTLS for device and user traffic, encryption of stored data(i) Access control and asset managementRoles, the least-privilege principle and a list of devices and services(j) Multi-factor authenticationMFA for administrators and remote access

## Rules and standards

Poland transposed NIS2 through the act of January 23, 2026 amending the KSC act (Dz.U. 2026 poz. 252), published on March 2, 2026 and in force since April 3, 2026. According to the Ministry of Digital Affairs, key entities (the Polish act's name for essential entities) and important entities had to apply for entry in the register by October 3, 2026 and must implement the new obligations by April 3, 2027. Key entities have to complete their first security audit by April 3, 2028 and repeat it at least every three years. For most obligations, administrative fines can be imposed only after April 3, 2028. The amendment also makes the heads of entities responsible for carrying out cybersecurity tasks.

For other EU countries check the national transposition act, since scope details, registration and supervisors differ.

## From our projects

We have not run NIS2 compliance programs for clients. We meet NIS2 as a requirement on the systems we build. The clearest case is Zeronest, an energy management platform for solar and battery installations that we have built since January 2024. The platform has to meet cybersecurity requirements under NIS2, CRA, RED DA and Poland's KSC act. Devices talk to the cloud over MQTT encrypted with TLS 1.2 behind AWS IoT Core, and client data stays in the EU. Each installation reads the inverter through Zeronest's own device with its own SIM card and LTE link, so the data path does not depend on the inverter maker's cloud or the homeowner's Wi-Fi. The platform also has a demand-side response module for aggregators, the kind of customer listed in Annex I, which is one reason these requirements flow down to the software.

From our projects

[Zeronest - Solar Panel Monitoring App with Automated Battery Management
How Order Group built Zeronest's solar panel monitoring app: an EMS that charges, discharges or sells power based on live prices and weather.](https://ordergroup.co/case-studies/zeronest-solar-panel-monitoring-app/)

## Related terms

- [EMS](https://ordergroup.co/glossary/ems/)

Energy management system
An energy management system (EMS) is software that reads the meters, inverters and batteries on a site and sends them setpoints, deciding when to charge, discharge, curtail or trade within grid, contract and safety limits.
- [Modbus](https://ordergroup.co/glossary/modbus/)

Modbus is an open request-response protocol for reading and writing 16-bit registers and single bits in field devices. Inverters, batteries and energy meters use it over serial lines (Modbus RTU) or Ethernet (Modbus TCP).
- [Smart meter](https://ordergroup.co/glossary/smart-meter/)

A smart meter is an electricity meter that communicates both ways with the network operator's remote reading system, recording interval data such as 15-minute load profiles and accepting commands such as a power limit or disconnection.

## Sources

1. [Directive (EU) 2022/2555 (NIS 2 Directive)](https://eur-lex.europa.eu/eli/dir/2022/2555/oj/eng) - EUR-Lex
2. [Ustawa z dnia 23 stycznia 2026 r. o zmianie ustawy o krajowym systemie cyberbezpieczeństwa oraz niektórych innych ustaw (Dz.U. 2026 poz. 252)](https://eli.gov.pl/eli/DU/2026/252/ogl) - Dziennik Ustaw RP
3. [Nowelizacja ustawy o krajowym systemie cyberbezpieczeństwa zaczyna obowiązywać](https://www.gov.pl/web/cyfryzacja/nowelizacja-ustawy-o-krajowym-systemie-cyberbezpieczenstwa-zaczyna-obowiazywac) - Ministerstwo Cyfryzacji

Michał Dżaman reviewed this entry. Ask how it applies to your project.

[Ask an engineer](https://ordergroup.co/contact-us/)

## FAQ

![Michał Dżaman](https://ordergroup.co/media/images/T02DHCC1Z-USU629221-c8b7d6d66b56-512.format-webp.webp)

Michał Dżaman

Co-founder & Head of Backend

[Talk to an engineer](https://ordergroup.co/contact-us/)

### Does NIS2 apply to my energy company?

It applies if you operate in a sector listed in the directive, for example electricity supply, distribution, generation, aggregation, demand response, energy storage or charging, and you are at least a medium-sized enterprise. Some smaller entities can be included by national authorities. Check the national act, in Poland the amended KSC act, for the exact criteria.

### What are the NIS2 incident reporting deadlines?

An early warning within 24 hours of becoming aware of a significant incident, an incident notification within 72 hours and a final report within one month of the notification (Article 23(4)).

### Is my software supplier covered by NIS2?

A supplier may not be an essential or important entity itself, but Article 21 requires covered entities to manage supply chain security and secure development. Expect contract clauses on vulnerability handling, encryption, MFA, logging and incident cooperation.

### When does NIS2 apply in Poland?

The amended KSC act has been in force since April 3, 2026. Entities had until October 3, 2026 to apply for registration and have until April 3, 2027 to implement the obligations. Key entities must complete their first audit by April 3, 2028.

Building a system that depends on NIS2?

See how we build software for this domain, with case studies and the stack we use.

[See Energy Hub](https://ordergroup.co/energy-hub/)

Requirements checklist

For each term we send the definition and what it requires from your software. Free, no sales call needed.
Your checklist is empty. Use the plus next to a term to add it.
