NIS2 Incident Reporting in Poland: Deadlines and Notification Duty Under the uKSC
Who Must Report and What Counts as a Major Incident
Poland implements NIS2 through the Ustawa o krajowym systemie cyberbezpieczeństwa (uKSC) (as amended, Dz.U. 2026 poz. 252). The reporting duty applies to two categories of regulated organisations:
- podmiot kluczowy (essential entity)
- podmiot ważny (important entity)
The classification depends on your sector (Annex 1 or Annex 2 to the Act) and your company size measured against the thresholds in Regulation (EU) No 651/2014 (art. 5 ust. 1 and art. 5 ust. 2 uKSC). Some entities qualify regardless of size — for example DNS service providers, qualified trust service providers and critical entities (art. 5 ust. 1 pkt 4).
The trigger for reporting is a incydent poważny (major incident). Under art. 2 pkt 7 uKSC, this is an incident that causes or may cause a serious degradation of service quality or an interruption in service continuity, financial loss to the entity, or serious material or non-material damage to other persons.
If you are unsure whether your organisation is a podmiot kluczowy or podmiot ważny, a free scoping check can help you map your obligations before an incident ever happens.
The Three Reporting Deadlines Under the uKSC
Polish law sets a staged reporting process in art. 11 ust. 1 pkt 4, 4a–4c uKSC. The deadlines are precise — do not rely on generic assumptions.
| Stage | Deadline | Legal basis |
|---|---|---|
| Early warning (wczesne ostrzeżenie) | Without delay, no later than 24 hours from detection | art. 11 ust. 1 pkt 4 |
| Incident notification (zgłoszenie incydentu poważnego) | Without delay, no later than 72 hours from detection | art. 11 ust. 1 pkt 4a |
| Interim report (sprawozdanie okresowe) | On request of the competent sectoral CSIRT | art. 11 ust. 1 pkt 4b |
| Final report (sprawozdanie końcowe) | No later than one month from the notification made under pkt 4a | art. 11 ust. 1 pkt 4c |
Key points to remember:
- The 24-hour and 72-hour clocks both run from the moment of detection of the incident.
- The one-month deadline for the final report is counted from the 72-hour notification, not from the early warning.
- The interim (periodic) report is only required if the competent sectoral CSIRT specifically asks for it.
Which Authority and CSIRT Receives Your Report
Under the uKSC, the early warning, the incident notification and the final report all go to the competent sectoral CSIRT (właściwy CSIRT sektorowy) — see art. 11 ust. 1 pkt 4, 4a and 4c.
Poland operates a multi-authority model. The bodies named in the Act include:
- CSIRT MON
- CSIRT NASK
- CSIRT GOV
- CSIRT sektorowe (sectoral CSIRTs)
- the organ właściwy do spraw cyberbezpieczeństwa (competent authority for cybersecurity)
- the minister właściwy do spraw informatyzacji (minister responsible for digitalisation)
Which specific competent authority applies to your organisation — and whether any registration obligation attaches — depends on your sector under this multi-authority structure. This point should be confirmed for your situation: [TÄPSUSTAB PARTNER-JURIST].
Because reports flow to the correct sectoral CSIRT, it is essential to identify your channel before an incident occurs. Setting this up under time pressure during a live incident wastes hours you do not have against a 24-hour clock.
Penalties for Failing to Report on Time
Missing your reporting obligations exposes your organisation to administrative fines set by the competent authority for cybersecurity.
- Podmiot kluczowy (essential entity): up to EUR 10 000 000 or 2% of the entity's revenue from business activity in the preceding financial year, whichever is higher, and not less than 20 000 zł (art. 73 ust. 3 uKSC).
- Podmiot ważny (important entity): up to EUR 7 000 000 or 1.4% of revenue, and not less than 15 000 zł (art. 73 ust. 4 uKSC).
- Where a breach causes a direct and serious cyber threat to defence, state or public security, public order, or human life and health — or a risk of serious material damage or serious disruption to services — the authority may impose a fine of up to 100 000 000 zł (art. 73 ust. 5 uKSC).
These figures underline why a clean, tested incident-reporting workflow is not just a compliance formality but a genuine financial safeguard.
Next step: Use our free scoping and gap tool to confirm whether you are a podmiot kluczowy or podmiot ważny, and to check your incident-reporting readiness against the uKSC deadlines.
Frequently asked questions
How quickly must I report a major incident in Poland?
You must send an early warning without delay and no later than 24 hours from detection of the major incident (art. 11 ust. 1 pkt 4 uKSC), followed by a full incident notification no later than 72 hours from detection (art. 11 ust. 1 pkt 4a uKSC).
When is the final report due?
The final report (sprawozdanie końcowe) must be submitted to the competent sectoral CSIRT no later than one month from the 72-hour notification made under art. 11 ust. 1 pkt 4a (art. 11 ust. 1 pkt 4c uKSC). An interim report is required only if the sectoral CSIRT requests it.
Who do I report a major incident to?
Reports go to the competent sectoral CSIRT (właściwy CSIRT sektorowy) under art. 11 uKSC. Poland uses a multi-authority model including CSIRT MON, CSIRT NASK, CSIRT GOV and sectoral CSIRTs. The exact competent authority for your sector should be confirmed by a partner lawyer: [TÄPSUSTAB PARTNER-JURIST].
What are the fines for not reporting on time?
An essential entity (podmiot kluczowy) can face up to EUR 10 000 000 or 2% of annual revenue, whichever is higher (art. 73 ust. 3 uKSC). An important entity (podmiot ważny) can face up to EUR 7 000 000 or 1.4% of revenue (art. 73 ust. 4 uKSC). Serious cases may reach up to 100 000 000 zł (art. 73 ust. 5 uKSC).
Check your NIS2 compliance
This article is general information, not legal advice. A partner lawyer confirms your specific situation.