Skip to main content
In forceNIS2

NIS2 in Poland

Poland's amended Act on the National Cybersecurity System (KSC) entered into force on 3 April 2026, roughly 17 months late. It covers about 42,000 entities across 18 sectors, with registration running to October 2026.

Transposition law
Nowelizacja ustawy o krajowym systemie cyberbezpieczeล„stwa (ustawa KSC)
In force since
3 April 2026
Competent authority
CERT Polska / CSIRT GOV
Max fine (Essential)
PLN 15 million (~โ‚ฌ3.5 million) or 2% of global annual turnover
Max fine (Important)
PLN 8 million (~โ‚ฌ1.9 million) or 1.4% of global annual turnover
Law adopted
19 February 2026

Key Deadlines

Sejm passes the KSC amendment
22 January 2026
Signed by the President
19 February 2026
KSC amendment in force
3 April 2026
Registration window closes
3 October 2026
Chapter 3 security obligations apply
3 April 2027

Competent Authority

CERT Polska / CSIRT GOV
National CSIRT; sector supervisors to be designated by UKSC amendment
https://www.cert.pl โ†—

The amended KSC designates sector-specific competent authorities and runs multiple national CSIRTs in parallel. CERT Polska (CSIRT NASK) covers the private sector, CSIRT GOV covers public administration and CSIRT MON the military. Obligations phase in over the first 12 to 24 months.

Registration Process

Entities in scope on 3 April 2026 have six months โ€” until early October 2026 โ€” to register in the national register. Registration runs through the sector competent authority; monitor cert.pl and gov.pl/cyfryzacja for sector-specific routing.

๐Ÿ“Š Quick Test

Find out if your company is in scope

Does your organisation fall under Annex I (Essential) or Annex II (Important) entities?

Check NIS2 Scope โ†’

Key Requirements

  • 1Incident notification to the appropriate CSIRT within 24 hours (early warning) and 72 hours
  • 2Implementation of Article 21 security measures as specified in the UKSC amendment
  • 3Annual risk assessment (Ocena Ryzyka) mandatory for kluczowe and waลผne podmioty
  • 4Registration with sector supervisor once designated
  • 5Management accountability provisions similar to NIS2 Article 20
  • 6Polish public administration entities are explicitly included

National Additions

โ˜…Poland is proposing national cybersecurity certification requirements for high-risk ICT products used by Essential Entities
โ˜…The UKSC amendment includes provisions for a national cybersecurity incident response centre (CSIRT level 3)
โ˜…Polish defence sector entities have additional obligations under separate cybersecurity legislation

FAQ: NIS2 in Poland

What are the key Polish KSC deadlines now that the law is in force?
The amendment took effect on 3 April 2026. Entities already in scope on that date have six months to register (to early October 2026), twelve months to meet the Chapter 3 security obligations (to 3 April 2027), and key entities have twenty-four months before their first mandatory audit (to 3 April 2028).
What is Poland's CSIRT GOV vs CERT Polska?
CERT Polska (CSIRT NASK) handles cybersecurity for the commercial/private sector. CSIRT GOV (handled by ABW, the internal security agency) covers government and public administration. CSIRT MON covers the military. Under NIS2, each handles incident notifications for its respective constituency.

Ready to assess your NIS2 compliance?

Use our free tools to check your NIS2 scope and run a gap assessment.

Currency and sources

The legal details on this page were last checked on 25 July 2026.