NIS2 Incident Reporting in Poland: Deadlines and Notification Duty Under the uKSC

Published: · AIPOS OÜ · nis2europe.eu

Who Must Report and What Counts as a Major Incident

Poland implements NIS2 through the Ustawa o krajowym systemie cyberbezpieczeństwa (uKSC) (as amended, Dz.U. 2026 poz. 252). The reporting duty applies to two categories of regulated organisations:

The classification depends on your sector (Annex 1 or Annex 2 to the Act) and your company size measured against the thresholds in Regulation (EU) No 651/2014 (art. 5 ust. 1 and art. 5 ust. 2 uKSC). Some entities qualify regardless of size — for example DNS service providers, qualified trust service providers and critical entities (art. 5 ust. 1 pkt 4).

The trigger for reporting is a incydent poważny (major incident). Under art. 2 pkt 7 uKSC, this is an incident that causes or may cause a serious degradation of service quality or an interruption in service continuity, financial loss to the entity, or serious material or non-material damage to other persons.

If you are unsure whether your organisation is a podmiot kluczowy or podmiot ważny, a free scoping check can help you map your obligations before an incident ever happens.

The Three Reporting Deadlines Under the uKSC

Polish law sets a staged reporting process in art. 11 ust. 1 pkt 4, 4a–4c uKSC. The deadlines are precise — do not rely on generic assumptions.

StageDeadlineLegal basis
Early warning (wczesne ostrzeżenie)Without delay, no later than 24 hours from detectionart. 11 ust. 1 pkt 4
Incident notification (zgłoszenie incydentu poważnego)Without delay, no later than 72 hours from detectionart. 11 ust. 1 pkt 4a
Interim report (sprawozdanie okresowe)On request of the competent sectoral CSIRTart. 11 ust. 1 pkt 4b
Final report (sprawozdanie końcowe)No later than one month from the notification made under pkt 4aart. 11 ust. 1 pkt 4c

Key points to remember:

Which Authority and CSIRT Receives Your Report

Under the uKSC, the early warning, the incident notification and the final report all go to the competent sectoral CSIRT (właściwy CSIRT sektorowy) — see art. 11 ust. 1 pkt 4, 4a and 4c.

Poland operates a multi-authority model. The bodies named in the Act include:

Which specific competent authority applies to your organisation — and whether any registration obligation attaches — depends on your sector under this multi-authority structure. This point should be confirmed for your situation: [TÄPSUSTAB PARTNER-JURIST].

Because reports flow to the correct sectoral CSIRT, it is essential to identify your channel before an incident occurs. Setting this up under time pressure during a live incident wastes hours you do not have against a 24-hour clock.

Penalties for Failing to Report on Time

Missing your reporting obligations exposes your organisation to administrative fines set by the competent authority for cybersecurity.

These figures underline why a clean, tested incident-reporting workflow is not just a compliance formality but a genuine financial safeguard.

Next step: Use our free scoping and gap tool to confirm whether you are a podmiot kluczowy or podmiot ważny, and to check your incident-reporting readiness against the uKSC deadlines.

Frequently asked questions

How quickly must I report a major incident in Poland?

You must send an early warning without delay and no later than 24 hours from detection of the major incident (art. 11 ust. 1 pkt 4 uKSC), followed by a full incident notification no later than 72 hours from detection (art. 11 ust. 1 pkt 4a uKSC).

When is the final report due?

The final report (sprawozdanie końcowe) must be submitted to the competent sectoral CSIRT no later than one month from the 72-hour notification made under art. 11 ust. 1 pkt 4a (art. 11 ust. 1 pkt 4c uKSC). An interim report is required only if the sectoral CSIRT requests it.

Who do I report a major incident to?

Reports go to the competent sectoral CSIRT (właściwy CSIRT sektorowy) under art. 11 uKSC. Poland uses a multi-authority model including CSIRT MON, CSIRT NASK, CSIRT GOV and sectoral CSIRTs. The exact competent authority for your sector should be confirmed by a partner lawyer: [TÄPSUSTAB PARTNER-JURIST].

What are the fines for not reporting on time?

An essential entity (podmiot kluczowy) can face up to EUR 10 000 000 or 2% of annual revenue, whichever is higher (art. 73 ust. 3 uKSC). An important entity (podmiot ważny) can face up to EUR 7 000 000 or 1.4% of revenue (art. 73 ust. 4 uKSC). Serious cases may reach up to 100 000 000 zł (art. 73 ust. 5 uKSC).

Check your NIS2 compliance

Start the free scoping test

Run the free gap analysis Run the free surface scan

This article is general information, not legal advice. A partner lawyer confirms your specific situation.

Back to home