NIS2 in Poland
Poland's amended Act on the National Cybersecurity System (KSC) entered into force on 3 April 2026, roughly 17 months late. It covers about 42,000 entities across 18 sectors, with registration running to October 2026.
Key Deadlines
Competent Authority
The amended KSC designates sector-specific competent authorities and runs multiple national CSIRTs in parallel. CERT Polska (CSIRT NASK) covers the private sector, CSIRT GOV covers public administration and CSIRT MON the military. Obligations phase in over the first 12 to 24 months.
Registration Process
Entities in scope on 3 April 2026 have six months โ until early October 2026 โ to register in the national register. Registration runs through the sector competent authority; monitor cert.pl and gov.pl/cyfryzacja for sector-specific routing.
Find out if your company is in scope
Does your organisation fall under Annex I (Essential) or Annex II (Important) entities?
Key Requirements
- 1Incident notification to the appropriate CSIRT within 24 hours (early warning) and 72 hours
- 2Implementation of Article 21 security measures as specified in the UKSC amendment
- 3Annual risk assessment (Ocena Ryzyka) mandatory for kluczowe and waลผne podmioty
- 4Registration with sector supervisor once designated
- 5Management accountability provisions similar to NIS2 Article 20
- 6Polish public administration entities are explicitly included
National Additions
FAQ: NIS2 in Poland
What are the key Polish KSC deadlines now that the law is in force?
What is Poland's CSIRT GOV vs CERT Polska?
Ready to assess your NIS2 compliance?
Use our free tools to check your NIS2 scope and run a gap assessment.
Currency and sources
The legal details on this page were last checked on 25 July 2026.