NIS2 Poland: KSC Amendment, Deadlines & Registration
Poland transposed NIS2 by amending the Act on the National Cybersecurity System (KSC). The amendment has applied since 3 April 2026 and brings roughly 42,000 organisations into scope. Registration in the S46 system closes on 3 October 2026.
Introduction: NIS2 Directive & the Polish context
Poland implemented the original NIS Directive through the Act on the National Cybersecurity System (KSC) adopted in July 2018, which created a decentralised national cybersecurity system built around three national CSIRTs (CSIRT NASK, CSIRT MON and CSIRT GOV) and operators of essential services and digital service providers.
The NIS2 amendment broadened that regime substantially. It shifts the focus from individual services to whole entities, widens the list of sectors, and adds stronger enforcement including personal liability for the head of the entity and a high-risk supplier regime. Roughly 42,000 organisations are now in scope, making Poland one of the largest NIS2 populations in the EU.
What you must do in Poland
The Polish law phases obligations in over two years. These are the dates that bind you, in order.
- Self-identify. The Act applies automatically to entities meeting the criteria in Annexes 1 and 2. Nobody designates you, and the duty to assess yourself started on 3 April 2026.
- Register in the S46 system by 3 October 2026. Six months from entry into force. The system has been live since 12 June 2026. See Registration.
- Implement the security measures by 3 April 2027. An information security management system, security policies and supply-chain risk management.
- Complete your first security audit by 3 April 2028, then at least once every three years.
- Report incidents from day one. The reporting duty is already live, and which CSIRT you report to depends on what kind of entity you are. See Incident reporting.
NIS2 implementation in Poland
Poland transposed NIS2 by amending the Act on the National Cybersecurity System (KSC) rather than adopting a standalone law. Multiple drafts were published between 2023 and 2025, reflecting long political and industry debate.
The amendment was adopted by the Sejm in January 2026, approved by the Senate, published in the Journal of Laws on 2 March 2026 as Dz.U. 2026 poz. 252, and entered into force on 3 April 2026.
The amendment keeps the KSC as the backbone of the national regime while introducing NIS2 concepts: key and important entities, stricter incident reporting, a central register of regulated entities, the high-risk supplier procedure, and a much stronger sanctioning framework that reaches the head of the entity personally.
Status
In force since 3 April 2026. Published in the Journal of Laws on 2 March 2026 as Dz.U. 2026 poz. 252.
Legal structure
An amendment to the 2018 Act on the National Cybersecurity System, supported by secondary legislation and sectoral regulations. The KSC remains the single national framework.
Scale
Roughly 42,000 entities are in scope across public and private sectors, phased in through registration by October 2026, security measures by April 2027 and a first audit by April 2028.
NIS2 Poland: what you need to know about compliance
Even without a final act in force, the Polish drafts closely follow the NIS2 model of essential and important entities and give a clear picture of the obligations organisations will face once the amendment is adopted.
Who is likely in scope?
- Entities operating in NIS2 Annex I sectors (energy, transport, health, drinking water, digital infrastructure, public administration, etc.).
- Entities in NIS2 Annex II sectors (postal and courier services, waste management, food, manufacturing of critical products, research, etc.).
- Medium and large organisations meeting NIS2 size or turnover thresholds.
- Entities covered regardless of size, such as DNS and TLD operators, trust-service providers, major cloud and data-centre operators.
Core obligations (based on draft)
- Implement risk-management measures for networks and information systems aligned with NIS2 Article 21.
- Introduce governance structures and policies, including management-approved cybersecurity strategies.
- Detect, handle and report significant incidents and certain cyber threats within strict deadlines.
- Manage supply-chain and vendor risk, with special rules for “high-risk vendors” in sensitive sectors.
- Ensure that management bodies are directly responsible for overseeing and approving cybersecurity measures.
Register of entities
Drafts foresee a central register of essential and important entities maintained at national level. Entities will either be identified by the authority or required to submit information to be included in the register and keep their data up to date.
Registration: who, where, by when
Registration means applying for entry in the national register of key and important entities. It is a self-assessment: you decide whether you qualify, and you carry the consequences of getting it wrong.
Where
The S46 system, the national ICT platform for the cybersecurity system, live since 12 June 2026.
When
By 3 October 2026, six months after the Act entered into force. New entities register once they begin the qualifying activity.
Who
Key entities (podmioty kluczowe) and important entities (podmioty ważne) in the sectors listed in Annexes 1 and 2 to the Act.
Incident reporting in Poland
Poland does not have a single national CSIRT. Which team you report to depends on what kind of entity you are, and getting the routing wrong costs time you do not have inside a 24-hour window.
| CSIRT | Run by | Receives reports from |
|---|---|---|
| CSIRT NASK | NASK (Research and Academic Computer Network) | The general case: most private-sector key and important entities, local government, and citizens. |
| CSIRT GOV | Head of the Internal Security Agency (ABW) | Government administration and critical infrastructure operators. |
| CSIRT MON | Minister of National Defence | Defence entities and organisations subordinate to or supervised by the MoD. |
| Sectoral CSIRTs (CSIRT sektorowy) | Appointed by the competent authority for each sector | Sectors where a dedicated team has been established. A sectoral CSIRT sits alongside the three national teams rather than replacing them: it handles first-line reports for its sector and coordinates upward. |
NIS2 timeline & key dates (Poland)
Sector-specific notes for Poland
- Energy: electricity, gas and other critical energy operators will fall under strict essential-entity obligations once the amendment is in force.
- Digital infrastructure: data centres, electronic communications networks and cloud providers are a major focus, with specific vendor-risk rules.
- Public administration: ministries, key central authorities and selected local government entities will be included as essential or important entities.
- Industry & manufacturing: manufacturers of critical products and key industrial players will be captured as important entities in line with NIS2.
- Finance & health: banks, financial market infrastructures and healthcare providers will face combined obligations from NIS2 and sector-specific EU rules.
How Polish law differs from the NIS2 Directive
Poland did not simply copy the Directive. Four choices go beyond it, and two have no equivalent anywhere else in the EU.
| Area | What Poland does |
|---|---|
| Three national CSIRTs | Most member states run one. Poland splits reporting between CSIRT NASK, CSIRT GOV and CSIRT MON, plus sectoral teams. Your reporting path depends on what you are. |
| High-Risk Supplier procedure | The Dostawca Wysokiego Ryzyka mechanism lets a supplier be formally designated high risk. Two consequences follow: key entities may not introduce any new products from that supplier, and existing equipment must be withdrawn. The withdrawal window is 4 years for equipment performing critical network functions (5G/3GPP core elements such as AMF, AUSF and UPF) and 7 years for all other ICT hardware and software, counted from publication of the decision in Monitor Polski. Neither the Directive nor ISO 27001 has an equivalent. |
| Extraordinary penalty | A fine of up to PLN 100 million where a breach creates a direct and serious threat to national defence or security, public order, human life and health, or the continuity of essential services. This sits above the NIS2 ceilings. |
| Personal fines for the head of the entity | Poland fines the individual, not only the organisation, and does it by reference to their own pay. Under Art. 73a(4) the head of a private entity faces up to 300% of their remuneration, calculated using the holiday-pay equivalent rules. For a public entity the ceiling is 100%, unless that body is also in scope through another Annex sector, in which case 300% applies again. A municipal water utility is the standard example. The fine is separate from any penalty on the entity itself. |
Operating in more than one EU country?
Registering in Poland does not necessarily cover you elsewhere, and registering elsewhere does not necessarily cover Poland.
Register once
DNS providers, TLD registries, cloud computing providers, data centre providers, CDNs, managed service providers and managed security service providers register only in the member state of their main establishment, and are supervised there.
Register in each country
Every other entity type registers separately in each member state where it provides in-scope services. A Polish manufacturer with operations in three countries may face three registrations.
Rules that are identical everywhere
Implementing Regulation (EU) 2024/2690 sets the technical requirements for the digital and ICT entity types above. It is not transposed, so Polish and German obligations read the same.
Penalties for non-compliance
Poland runs one of the strictest sanctions models in the EU. It goes beyond the NIS2 ceilings and adds national mechanisms, including a fine levied on the head of the entity personally.
- Key entities: up to €10 million or 2% of worldwide annual turnover, whichever is higher.
- Important entities: up to €7 million or 1.4% of worldwide annual turnover, whichever is higher.
- Extraordinary penalty: up to PLN 100 million where the breach creates a direct and serious threat to national defence or security, public order, human life and health, or the continuity of essential services.
- The head of the entity, personally: up to 300% of their remuneration in the private sector and 100% in the public sector, under Art. 73a(4). Separate from any fine on the entity.
- Corrective measures: orders to remedy deficiencies, enhanced supervision, follow-up audits, and in the most serious cases suspension of a key entity's activity.
- Timing: most administrative fines can only be imposed from 3 April 2028.
How to prepare for NIS2 in Poland
- Assess whether you are likely in scope: map your organisation against NIS2 Annex I & II sectors and size thresholds; assume that the Polish law will broadly follow them.
- Monitor the legislative process: follow official publications and legal updates on the amendment to the KSC so you know when the law is finally adopted and when it enters into force.
- Run a NIS2 gap assessment now: compare your current cybersecurity posture against NIS2 Article 21 requirements (governance, technical controls, processes, documentation).
- Plan for registration: prepare internal data (services, systems, dependencies, key contacts) that you will need to provide once the register of entities goes live.
- Strengthen incident management: design monitoring, triage and reporting workflows that can support 24-hour early warning and follow-up reports required by NIS2.
- Review supply-chain and vendor risk: identify high-impact suppliers and plan contractual updates, mindful of possible “high-risk vendor” restrictions in Poland.
- Align with recognised frameworks: build or refine an ISMS aligned with ISO/IEC 27001 or similar to make NIS2 implementation structured and auditable.
- Engage the board: brief senior management on upcoming personal liability and ensure cybersecurity is treated as a strategic, not just technical, topic.
