NIS2 and the uKSC in Poland: How EU Rules Become National Law
From EU directive to Polish law
The EU NIS2 directive — Directive (EU) 2022/2555 — is not directly binding on your company. Like every EU directive, it must be transposed into national law by each Member State. In Poland, that national law is the Ustawa o krajowym systemie cyberbezpieczeństwa (uKSC).
This distinction matters for compliance planning. The directive sets the framework and minimum requirements; the uKSC is the text your organisation is actually held to. When you assess obligations, deadlines and penalties, the Polish statute is the binding source.
In practice, the two work together:
- NIS2 (Directive (EU) 2022/2555) — defines the objectives: cybersecurity risk-management measures (art 21(1) and art 21(2)) and incident reporting obligations (art 23).
- uKSC — implements these in Polish law and adds national specifics, including who supervises, how you classify, and additional national regimes.
Because the uKSC transposes NIS2, many concepts line up closely. For example, the directive's incident reporting timeline — a 24-hour early warning and a 72-hour notification (art 23(4)) — is mirrored in the uKSC through a 24-hour early warning (art. 11 ust. 1 pkt 4) and a 72-hour notification (art. 11 ust. 1 pkt 4a).
Who supervises: the competent authority in Poland
NIS2 requires each Member State to designate competent authorities and CSIRTs. Poland uses a multi-authority (sector-based) model.
Under the uKSC (Dz.U. 2026 poz. 252), the key roles include:
- Organ właściwy do spraw cyberbezpieczeństwa — the competent authority for cybersecurity (which also imposes financial penalties under the law).
- Minister właściwy do spraw informatyzacji — the minister responsible for computerisation, with specific powers described below.
- CSIRT MON, CSIRT NASK, CSIRT GOV and the CSIRT sektorowe (sector CSIRTs) — the response teams that receive incident reports.
For most entities, major incidents are reported to the właściwy CSIRT sektorowy (the relevant sector CSIRT). Note that which competent authority applies — and any registration duty — depends on your sector under this multi-authority model, and should be confirmed for your specific case. [TÄPSUSTAB PARTNER-JURIST]
Classification: podmiot kluczowy vs podmiot ważny
NIS2 distinguishes between essential and important entities. The uKSC transposes these as two statutory categories:
- podmiot kluczowy (essential entity) — defined in art. 5 ust. 1
- podmiot ważny (important entity) — defined in art. 5 ust. 2
The uKSC ties classification to the sectors listed in its załącznik nr 1 and załącznik nr 2, and to size thresholds referencing the medium-enterprise definition under rozporządzenie 651/2014/UE.
A few examples from the statute:
- A podmiot kluczowy includes an entity in załącznik nr 1 that exceeds the medium-enterprise thresholds, and — regardless of size — DNS service providers, qualified trust service providers, critical entities, and certain public bodies (art. 5 ust. 1).
- A podmiot ważny includes an entity in załącznik nr 1 meeting the medium-enterprise thresholds that is not a podmiot kluczowy, and entities in załącznik nr 2 (art. 5 ust. 2).
Getting this classification right is the starting point of any gap assessment, because it drives your obligations and your penalty exposure.
What the uKSC adds on top of NIS2
Beyond straightforward transposition, the Polish law introduces national elements that go further than the directive text itself.
1. The high-risk supplier regime ("dostawca wysokiego ryzyka" / 5G Toolbox)
Under uKSC art. 67b ust. 15, the Minister właściwy do spraw informatyzacji may issue a decision recognising a supplier of hardware or software — and entities within its capital group (within the meaning of the accounting law) — as a dostawca wysokiego ryzyka (high-risk supplier), where that supplier constitutes a threat to the fundamental interest of state security.
This is a distinctly national instrument aligned with the EU 5G Toolbox approach and layered onto the NIS2 framework. *Note: high-risk-supplier provisions are subject to constitutional review and their content may change — confirm the current status with a partner lawyer before relying on them.* [TÄPSUSTAB PARTNER-JURIST]
2. National penalty ceilings
The uKSC sets its own financial penalty amounts:
| Entity type | Maximum penalty |
|---|---|
| podmiot kluczowy | up to 10 000 000 EUR or 2% of annual turnover, whichever is higher (art. 73 ust. 3) |
| podmiot ważny | up to 7 000 000 EUR or 1,4% of annual turnover (art. 73 ust. 4) |
There is also a specific penalty of up to 100 000 000 zł where a podmiot kluczowy or podmiot ważny causes a direct and serious cyber threat to defence, state security, public order, or life and health (art. 73 ust. 5).
3. Concrete reporting deadlines and final report
The uKSC operationalises reporting: a 24-hour early warning (art. 11 ust. 1 pkt 4), a 72-hour incident notification (art. 11 ust. 1 pkt 4a), interim reports on request (art. 11 ust. 1 pkt 4b), and a final report within one month of the notification (art. 11 ust. 1 pkt 4c).
Want to know where you stand? A free scoping and gap tool can help you check likely classification and readiness before you engage legal counsel.
Frequently asked questions
What is the Polish law that transposes NIS2?
The NIS2 directive (Directive (EU) 2022/2555) is transposed into Polish law by the Ustawa o krajowym systemie cyberbezpieczeństwa (uKSC). The uKSC is the binding national text for your obligations, deadlines and penalties.
Who is the competent authority for cybersecurity in Poland?
Poland uses a multi-authority model. It includes the organ właściwy do spraw cyberbezpieczeństwa (competent cybersecurity authority), the minister właściwy do spraw informatyzacji, and the response teams CSIRT MON, CSIRT NASK, CSIRT GOV and the CSIRT sektorowe. The exact authority for you depends on your sector and should be confirmed with a partner lawyer.
What does the uKSC add compared to NIS2?
Among other things, the uKSC introduces the national high-risk supplier regime (dostawca wysokiego ryzyka / 5G Toolbox) under art. 67b ust. 15, sets national penalty ceilings (art. 73 ust. 3-5), and lays down concrete incident reporting deadlines (art. 11).
How are entities classified under the uKSC?
The uKSC defines a podmiot kluczowy (essential entity) in art. 5 ust. 1 and a podmiot ważny (important entity) in art. 5 ust. 2, based on the sectors in załącznik nr 1 and nr 2 and size thresholds referencing rozporządzenie 651/2014/UE.
Check your NIS2 compliance
This article is general information, not legal advice. A partner lawyer confirms your specific situation.