Skip to content

NIS 2 IN POLAND

Projekt ustawy o krajowym systemie cyberbezpieczeństwa (zmiana ustawy KSC) — the national act transposing Directive (EU) 2022/2555 in Poland. Supervised by Ministerstwo Cyfryzacji (MC).

DRAFT PUBLISHED

Key facts

In force
Not yet in force
National law
Projekt ustawy o krajowym systemie cyberbezpieczeństwa (zmiana ustawy KSC)
Primary supervisor
Ministerstwo Cyfryzacji (MC)
Max fine — essential entities
Up to EUR 10 million or 2% of global annual turnover, whichever is higher
Max fine — important entities
Up to EUR 7 million or 1.4% of global annual turnover, whichever is higher
Registration deadline
Final registration mechanics depend on the amended KSC's entry into force; entities should monitor CSIRT NASK's covered-entity portal.

Scope and national nuance

Poland's transposition extends the existing Ustawa o krajowym systemie cyberbezpieczeństwa (KSC) rather than introducing a separate act. The Ministry of Digital Affairs (Ministerstwo Cyfryzacji) is the policy lead; operational supervision is split across three CSIRTs of national reference.

Sector supervisors

SectorAuthorityAcronym
National CSIRT — generalCSIRT NASKCSIRT NASK
National CSIRT — militaryCSIRT MONCSIRT MON
National CSIRT — governmentCSIRT GOVCSIRT GOV
TelecommunicationsUrząd Komunikacji ElektronicznejUKE

What is specific to Poland

DSI Advisory — NIS 2 Programme

Move from reading the law to evidencing compliance

Start with the free NIS 2 Scorecard to score your organisation across the twelve Article 21 security domains and receive a paragraph-cited PDF report. Then book a structured NIS 2 scope and gap assessment tailored to MC’s supervisory expectations.

NIS 2 Scorecard →Scope & gap assessment →NIS 2 reference page →