NIS2 Country Guide

NIS2 Poland: KSC Amendment, Deadlines & Registration

Poland transposed NIS2 by amending the Act on the National Cybersecurity System (KSC). The amendment has applied since 3 April 2026 and brings roughly 42,000 organisations into scope. Registration in the S46 system closes on 3 October 2026.

Poland In force: 3 Apr 2026 Register by: 3 Oct 2026 Law: KSC amendment (Dz.U. 2026 poz. 252) Last updated: 1 Aug 2026

Introduction: NIS2 Directive & the Polish context

Poland implemented the original NIS Directive through the Act on the National Cybersecurity System (KSC) adopted in July 2018, which created a decentralised national cybersecurity system built around three national CSIRTs (CSIRT NASK, CSIRT MON and CSIRT GOV) and operators of essential services and digital service providers.

The NIS2 amendment broadened that regime substantially. It shifts the focus from individual services to whole entities, widens the list of sectors, and adds stronger enforcement including personal liability for the head of the entity and a high-risk supplier regime. Roughly 42,000 organisations are now in scope, making Poland one of the largest NIS2 populations in the EU.

Quick link: New to NIS2? Start with our general guides “What is NIS2?” and “NIS vs NIS2”.

What you must do in Poland

The Polish law phases obligations in over two years. These are the dates that bind you, in order.

  1. Self-identify. The Act applies automatically to entities meeting the criteria in Annexes 1 and 2. Nobody designates you, and the duty to assess yourself started on 3 April 2026.
  2. Register in the S46 system by 3 October 2026. Six months from entry into force. The system has been live since 12 June 2026. See Registration.
  3. Implement the security measures by 3 April 2027. An information security management system, security policies and supply-chain risk management.
  4. Complete your first security audit by 3 April 2028, then at least once every three years.
  5. Report incidents from day one. The reporting duty is already live, and which CSIRT you report to depends on what kind of entity you are. See Incident reporting.
The nearest deadline is 3 October 2026. Registration is the one obligation with a hard date in the next few months, and it is also the one the regulator can check without visiting you.

NIS2 implementation in Poland

Poland transposed NIS2 by amending the Act on the National Cybersecurity System (KSC) rather than adopting a standalone law. Multiple drafts were published between 2023 and 2025, reflecting long political and industry debate.

The amendment was adopted by the Sejm in January 2026, approved by the Senate, published in the Journal of Laws on 2 March 2026 as Dz.U. 2026 poz. 252, and entered into force on 3 April 2026.

The amendment keeps the KSC as the backbone of the national regime while introducing NIS2 concepts: key and important entities, stricter incident reporting, a central register of regulated entities, the high-risk supplier procedure, and a much stronger sanctioning framework that reaches the head of the entity personally.

Status

In force since 3 April 2026. Published in the Journal of Laws on 2 March 2026 as Dz.U. 2026 poz. 252.

Legal structure

An amendment to the 2018 Act on the National Cybersecurity System, supported by secondary legislation and sectoral regulations. The KSC remains the single national framework.

Scale

Roughly 42,000 entities are in scope across public and private sectors, phased in through registration by October 2026, security measures by April 2027 and a first audit by April 2028.

NIS2 Poland: what you need to know about compliance

Even without a final act in force, the Polish drafts closely follow the NIS2 model of essential and important entities and give a clear picture of the obligations organisations will face once the amendment is adopted.

Who is likely in scope?

  • Entities operating in NIS2 Annex I sectors (energy, transport, health, drinking water, digital infrastructure, public administration, etc.).
  • Entities in NIS2 Annex II sectors (postal and courier services, waste management, food, manufacturing of critical products, research, etc.).
  • Medium and large organisations meeting NIS2 size or turnover thresholds.
  • Entities covered regardless of size, such as DNS and TLD operators, trust-service providers, major cloud and data-centre operators.

Core obligations (based on draft)

  • Implement risk-management measures for networks and information systems aligned with NIS2 Article 21.
  • Introduce governance structures and policies, including management-approved cybersecurity strategies.
  • Detect, handle and report significant incidents and certain cyber threats within strict deadlines.
  • Manage supply-chain and vendor risk, with special rules for “high-risk vendors” in sensitive sectors.
  • Ensure that management bodies are directly responsible for overseeing and approving cybersecurity measures.

Register of entities

Drafts foresee a central register of essential and important entities maintained at national level. Entities will either be identified by the authority or required to submit information to be included in the register and keep their data up to date.

Key message: although the law is delayed, the direction is clear. Polish organisations in NIS2-relevant sectors are expected to prepare on the basis of the Directive and the published drafts, rather than wait for the final act.

Competent authorities & CSIRTs

Poland operates a decentralised national cybersecurity system anchored in three national CSIRTs and coordinated through the KSC. The NIS2 amendment builds on this structure and clarifies roles for supervision and incident handling.

Role Authority Notes
National cybersecurity authorities Authorities designated under the KSC (e.g. Government Plenipotentiary for Cybersecurity, sectoral authorities) Oversee implementation of the KSC, coordinate NIS2 transposition and supervise operators of essential services, digital service providers and future essential/important entities.
National CSIRTs CSIRT NASK, CSIRT MON, CSIRT GOV Three national CSIRTs share responsibility for incident handling: CSIRT NASK (civilian and commercial sector), CSIRT MON (defence) and CSIRT GOV (government and public administration).
Sectoral CSIRTs Sector-specific CSIRTs (planned) The draft amendment provides for sector and subsector CSIRTs to support essential and important entities in particular sectors and to relay incidents to the national CSIRTs.

Registration: who, where, by when

Registration means applying for entry in the national register of key and important entities. It is a self-assessment: you decide whether you qualify, and you carry the consequences of getting it wrong.

Where

The S46 system, the national ICT platform for the cybersecurity system, live since 12 June 2026.

When

By 3 October 2026, six months after the Act entered into force. New entities register once they begin the qualifying activity.

Who

Key entities (podmioty kluczowe) and important entities (podmioty ważne) in the sectors listed in Annexes 1 and 2 to the Act.

Failure to register carries the full penalty ceiling, and unlike most obligations it is trivially verifiable. If you are unsure whether you qualify, resolve it well before October.

Incident reporting in Poland

Poland does not have a single national CSIRT. Which team you report to depends on what kind of entity you are, and getting the routing wrong costs time you do not have inside a 24-hour window.

CSIRTRun byReceives reports from
CSIRT NASKNASK (Research and Academic Computer Network)The general case: most private-sector key and important entities, local government, and citizens.
CSIRT GOVHead of the Internal Security Agency (ABW)Government administration and critical infrastructure operators.
CSIRT MONMinister of National DefenceDefence entities and organisations subordinate to or supervised by the MoD.
Sectoral CSIRTs (CSIRT sektorowy)Appointed by the competent authority for each sectorSectors where a dedicated team has been established. A sectoral CSIRT sits alongside the three national teams rather than replacing them: it handles first-line reports for its sector and coordinates upward.
Within 24 hours — early warning, from the moment you become aware of a significant incident.
Within 72 hours — incident notification with an initial assessment of severity and impact.
Within one month — final report covering root cause, mitigations applied and cross-border impact.
Confirm your CSIRT in writing before an incident. The routing follows the type of entity, not the type of incident, so it can be settled once and documented in your response plan.

NIS2 timeline & key dates (Poland)

July 2018 — Original Act on the National Cybersecurity System (KSC) enters into force, implementing NIS1 in Poland.
17 Oct 2024 — EU deadline for NIS2 transposition passes; Poland has not yet adopted the amendment.
7 May 2025 — European Commission issues a reasoned opinion to Poland for failure to notify full transposition.
Jan 2026 — The Sejm adopts the amendment and the Senate approves it.
2 Mar 2026 — Published in the Journal of Laws as Dz.U. 2026 poz. 252.
3 Apr 2026 — The amendment enters into force. Self-identification and incident-reporting duties begin.
12 Jun 2026 — The S46 registration system goes live.
3 Oct 2026 — Deadline to apply for entry in the register of key and important entities.
3 Apr 2027 — Deadline to implement the technical and organisational security measures.
3 Apr 2028 — Deadline for the first mandatory security audit, then at least every three years. Administrative fines become available for most breaches.

Sector-specific notes for Poland

  • Energy: electricity, gas and other critical energy operators will fall under strict essential-entity obligations once the amendment is in force.
  • Digital infrastructure: data centres, electronic communications networks and cloud providers are a major focus, with specific vendor-risk rules.
  • Public administration: ministries, key central authorities and selected local government entities will be included as essential or important entities.
  • Industry & manufacturing: manufacturers of critical products and key industrial players will be captured as important entities in line with NIS2.
  • Finance & health: banks, financial market infrastructures and healthcare providers will face combined obligations from NIS2 and sector-specific EU rules.

How Polish law differs from the NIS2 Directive

Poland did not simply copy the Directive. Four choices go beyond it, and two have no equivalent anywhere else in the EU.

AreaWhat Poland does
Three national CSIRTsMost member states run one. Poland splits reporting between CSIRT NASK, CSIRT GOV and CSIRT MON, plus sectoral teams. Your reporting path depends on what you are.
High-Risk Supplier procedureThe Dostawca Wysokiego Ryzyka mechanism lets a supplier be formally designated high risk. Two consequences follow: key entities may not introduce any new products from that supplier, and existing equipment must be withdrawn. The withdrawal window is 4 years for equipment performing critical network functions (5G/3GPP core elements such as AMF, AUSF and UPF) and 7 years for all other ICT hardware and software, counted from publication of the decision in Monitor Polski. Neither the Directive nor ISO 27001 has an equivalent.
Extraordinary penaltyA fine of up to PLN 100 million where a breach creates a direct and serious threat to national defence or security, public order, human life and health, or the continuity of essential services. This sits above the NIS2 ceilings.
Personal fines for the head of the entityPoland fines the individual, not only the organisation, and does it by reference to their own pay. Under Art. 73a(4) the head of a private entity faces up to 300% of their remuneration, calculated using the holiday-pay equivalent rules. For a public entity the ceiling is 100%, unless that body is also in scope through another Annex sector, in which case 300% applies again. A municipal water utility is the standard example. The fine is separate from any penalty on the entity itself.
Enforcement is phased too. For most administrative breaches, including the personal fine on the head of the entity, penalties can only be imposed from 3 April 2028, two years after entry into force. That is a runway, not an exemption: the obligations are already binding, and the registration deadline is unaffected.

Operating in more than one EU country?

Registering in Poland does not necessarily cover you elsewhere, and registering elsewhere does not necessarily cover Poland.

Register once

DNS providers, TLD registries, cloud computing providers, data centre providers, CDNs, managed service providers and managed security service providers register only in the member state of their main establishment, and are supervised there.

Register in each country

Every other entity type registers separately in each member state where it provides in-scope services. A Polish manufacturer with operations in three countries may face three registrations.

Rules that are identical everywhere

Implementing Regulation (EU) 2024/2690 sets the technical requirements for the digital and ICT entity types above. It is not transposed, so Polish and German obligations read the same.

Also in scope elsewhere? See our guides for Germany, Czechia and the Netherlands, or the full country index.

Penalties for non-compliance

Poland runs one of the strictest sanctions models in the EU. It goes beyond the NIS2 ceilings and adds national mechanisms, including a fine levied on the head of the entity personally.

  • Key entities: up to €10 million or 2% of worldwide annual turnover, whichever is higher.
  • Important entities: up to €7 million or 1.4% of worldwide annual turnover, whichever is higher.
  • Extraordinary penalty: up to PLN 100 million where the breach creates a direct and serious threat to national defence or security, public order, human life and health, or the continuity of essential services.
  • The head of the entity, personally: up to 300% of their remuneration in the private sector and 100% in the public sector, under Art. 73a(4). Separate from any fine on the entity.
  • Corrective measures: orders to remedy deficiencies, enhanced supervision, follow-up audits, and in the most serious cases suspension of a key entity's activity.
  • Timing: most administrative fines can only be imposed from 3 April 2028.

How to prepare for NIS2 in Poland

  1. Assess whether you are likely in scope: map your organisation against NIS2 Annex I & II sectors and size thresholds; assume that the Polish law will broadly follow them.
  2. Monitor the legislative process: follow official publications and legal updates on the amendment to the KSC so you know when the law is finally adopted and when it enters into force.
  3. Run a NIS2 gap assessment now: compare your current cybersecurity posture against NIS2 Article 21 requirements (governance, technical controls, processes, documentation).
  4. Plan for registration: prepare internal data (services, systems, dependencies, key contacts) that you will need to provide once the register of entities goes live.
  5. Strengthen incident management: design monitoring, triage and reporting workflows that can support 24-hour early warning and follow-up reports required by NIS2.
  6. Review supply-chain and vendor risk: identify high-impact suppliers and plan contractual updates, mindful of possible “high-risk vendor” restrictions in Poland.
  7. Align with recognised frameworks: build or refine an ISMS aligned with ISO/IEC 27001 or similar to make NIS2 implementation structured and auditable.
  8. Engage the board: brief senior management on upcoming personal liability and ensure cybersecurity is treated as a strategic, not just technical, topic.

Official links & resources

Looking for the Act in English? There is no official English translation. The authoritative text is the Polish original: ustawa o krajowym systemie cyberbezpieczeństwa (Act on the National Cybersecurity System), as amended by Dz.U. 2026 poz. 252. English-language summaries, including this page, are guidance only. Where an obligation matters, work from the Polish text or a certified translation.

FAQ: NIS2 in Poland

Has Poland fully transposed NIS2?
Yes. The amending Act was published on 2 March 2026 as Dz.U. 2026 poz. 252 and entered into force on 3 April 2026. Poland missed the October 2024 deadline and received a reasoned opinion from the European Commission in May 2025 before completing transposition.
Which law will implement NIS2 in Poland?
An amendment to the existing Act on the National Cybersecurity System (KSC), which remains the backbone of the Polish regime. The amending Act is Dz.U. 2026 poz. 252.
Should we wait until the law is adopted to start preparing?
The law is already in force, so there is nothing left to wait for. The nearest hard deadline is registration in the S46 system by 3 October 2026.
Who are the main NIS2 players in Poland?
The amendment will continue to rely on the national CSIRTs (CSIRT NASK, CSIRT MON, CSIRT GOV) and the national cybersecurity authorities designated under the KSC, with an extended role in supervising essential and important entities.
Is ISO 27001 mandatory?
The Act does not mandate a single certification such as ISO/IEC 27001, but aligning with recognised standards remains one of the most effective ways to structure and evidence compliance in Poland.
When exactly must we register, and where?
By 3 October 2026, in the S46 system, which has been live since 12 June 2026. Registration is a self-assessment: you decide whether you meet the criteria in Annexes 1 and 2 to the Act.
Which CSIRT do we report incidents to?
It depends on what kind of entity you are. CSIRT NASK covers the general case, CSIRT GOV covers government administration and critical infrastructure, and CSIRT MON covers defence. Some sectors also have a sectoral CSIRT. Confirm your route before an incident, not during one.
Information provided for general guidance; always consult the final Polish NIS2 legislation, official publications on the Act on the National Cybersecurity System and legal counsel for definitive compliance requirements in Poland.