The amendment to Poland's Act on the National Cybersecurity System (Ustawa o krajowym systemie cyberbezpieczeństwa, KSC), transposing the EU NIS2 Directive (EU) 2022/2555, was adopted by the Sejm on 23 January 2026, signed by the President on 19 February 2026, published in the Journal of Laws on 2 March 2026, and entered into force on 3 April 2026. It expands the categories of 'key' and 'important' entities subject to cybersecurity risk-management and incident-reporting duties.
Vem som berörs
Medium and large entities in NIS2 sectors (energy, transport, finance, health, digital infrastructure/software, manufacturing, food/agri, and others designated by the Act), plus smaller entities the authorities designate as critical or sole providers of a service.
Storlekar: medelstort företag, stort företag · Branscher: Energi, Transport / logistik, Finans / försäkring, Hälso- och sjukvård, Programvara / SaaS, Tillverkning, Jordbruk / livsmedel, Konsult- och tjänsteföretag · Gäller om: Vi är verksamma i en kritisk sektor (NIS2); Vi är beroende av molntjänster
Vad du ska göra
Assess whether your organisation meets the new 'key entity' or 'important entity' criteria under the amended KSC. If in scope, prepare to register within 6 months of entry into force and to implement cybersecurity risk-management measures and incident-reporting procedures within 12 months.
Sanktion
Administrative fines apply under the Act, but may only be imposed for the first time from 2 years after entry into force (from 3 April 2028); key entities that repeatedly fail to comply can also face suspension of managers pending remediation.
6 months from the amended KSC's entry into force on 2026-04-03; this deadline was extended from an originally proposed 3 months during the Sejm's second reading. Entities that qualify later must still register within 6 months of first meeting the criteria - an ongoing rule, not only a one-off deadline for this initial batch.
Medium and large companies in NIS2 sectors that are or become in scope of the amended KSC, plus smaller entities designated as critical or sole providers of a service.