NIS2 · National implementation

NIS2 in Poland

Poland transposed NIS2 by amending the Ustawa o krajowym systemie cyberbezpieczeństwa (KSC Act), published as Dz.U. 2026 poz. 252.

National law
Ustawa o krajowym systemie cyberbezpieczeństwa (amended)
National Cybersecurity System Act, as amended
Status
In force
In force
2026
Authority
Minister of Digital Affairs and sector authorities

Supervision

The Minister of Digital Affairs leads the system, with three national CSIRTs (CSIRT NASK, CSIRT GOV, CSIRT MON) splitting constituencies and sector authorities supervising their domains. Entities register in the national entity register and report through the national system.

What is specific to Poland

The Polish amendment carried significant national debate about provisions beyond the directive — notably high-risk vendor (dostawca wysokiego ryzyka) assessments allowing exclusion of specific suppliers' equipment, with telecom-sector implications. Transition periods stagger the duties from entry into force, so Polish entities work against a national countdown rather than the directive's dates.

Official sources

Primary references: the national statute book at dziennikustaw.gov.pl and the national cybersecurity authority at www.gov.pl.

NIS2 in Poland: frequently asked questions

Last reviewed:

Related reading

All 27 EU member states