NIS 2 — Poland
NIS 2 IN POLAND
Projekt ustawy o krajowym systemie cyberbezpieczeństwa (zmiana ustawy KSC) — the national act transposing Directive (EU) 2022/2555 in Poland. Supervised by Ministerstwo Cyfryzacji (MC).
DRAFT PUBLISHED
Key facts
In force
Not yet in force
Primary supervisor
Max fine — essential entities
Up to EUR 10 million or 2% of global annual turnover, whichever is higher
Max fine — important entities
Up to EUR 7 million or 1.4% of global annual turnover, whichever is higher
Registration deadline
Final registration mechanics depend on the amended KSC's entry into force; entities should monitor CSIRT NASK's covered-entity portal.
Scope and national nuance
Poland's transposition extends the existing Ustawa o krajowym systemie cyberbezpieczeństwa (KSC) rather than introducing a separate act. The Ministry of Digital Affairs (Ministerstwo Cyfryzacji) is the policy lead; operational supervision is split across three CSIRTs of national reference.
Sector supervisors
| Sector | Authority | Acronym |
|---|---|---|
| National CSIRT — general | CSIRT NASK | CSIRT NASK |
| National CSIRT — military | CSIRT MON | CSIRT MON |
| National CSIRT — government | CSIRT GOV | CSIRT GOV |
| Telecommunications | Urząd Komunikacji Elektronicznej | UKE |
What is specific to Poland
- Poland already had a comprehensive cybersecurity act (KSC) covering operators of essential services — the NIS 2 transposition amends and broadens KSC rather than replacing it.
- Three CSIRTs of national reference share supervisory and incident-handling duties: CSIRT NASK for the broader economy, CSIRT MON for the defence sector, CSIRT GOV for central government.
- Polish public administration has its own track of obligations under KSC, layered on top of the directive's general scope, creating cumulative obligations for state entities.
- Documentation and registration are bilingual (Polish and English) on the CSIRT NASK portal, easing the burden on multinational operators.
DSI Advisory — NIS 2 Programme
Move from reading the law to evidencing compliance
Start with the free NIS 2 Scorecard to score your organisation across the twelve Article 21 security domains and receive a paragraph-cited PDF report. Then book a structured NIS 2 scope and gap assessment tailored to MC’s supervisory expectations.