NIS2 · National implementation
NIS2 in Poland
Poland transposed NIS2 by amending the Ustawa o krajowym systemie cyberbezpieczeństwa (KSC Act), published as Dz.U. 2026 poz. 252.
- National law
- Ustawa o krajowym systemie cyberbezpieczeństwa (amended)
- National Cybersecurity System Act, as amended
- Status
- In force
- In force
- 2026
- Authority
- Minister of Digital Affairs and sector authorities
Supervision
The Minister of Digital Affairs leads the system, with three national CSIRTs (CSIRT NASK, CSIRT GOV, CSIRT MON) splitting constituencies and sector authorities supervising their domains. Entities register in the national entity register and report through the national system.
What is specific to Poland
The Polish amendment carried significant national debate about provisions beyond the directive — notably high-risk vendor (dostawca wysokiego ryzyka) assessments allowing exclusion of specific suppliers' equipment, with telecom-sector implications. Transition periods stagger the duties from entry into force, so Polish entities work against a national countdown rather than the directive's dates.
Official sources
Primary references: the national statute book at dziennikustaw.gov.pl and the national cybersecurity authority at www.gov.pl.
NIS2 in Poland: frequently asked questions
Last reviewed:
Related reading
Definitions
