NIS2 and the uKSC in Poland: How EU Rules Become National Law

Published: · AIPOS OÜ · nis2europe.eu

From EU directive to Polish law

The EU NIS2 directive — Directive (EU) 2022/2555 — is not directly binding on your company. Like every EU directive, it must be transposed into national law by each Member State. In Poland, that national law is the Ustawa o krajowym systemie cyberbezpieczeństwa (uKSC).

This distinction matters for compliance planning. The directive sets the framework and minimum requirements; the uKSC is the text your organisation is actually held to. When you assess obligations, deadlines and penalties, the Polish statute is the binding source.

In practice, the two work together:

Because the uKSC transposes NIS2, many concepts line up closely. For example, the directive's incident reporting timeline — a 24-hour early warning and a 72-hour notification (art 23(4)) — is mirrored in the uKSC through a 24-hour early warning (art. 11 ust. 1 pkt 4) and a 72-hour notification (art. 11 ust. 1 pkt 4a).

Who supervises: the competent authority in Poland

NIS2 requires each Member State to designate competent authorities and CSIRTs. Poland uses a multi-authority (sector-based) model.

Under the uKSC (Dz.U. 2026 poz. 252), the key roles include:

For most entities, major incidents are reported to the właściwy CSIRT sektorowy (the relevant sector CSIRT). Note that which competent authority applies — and any registration duty — depends on your sector under this multi-authority model, and should be confirmed for your specific case. [TÄPSUSTAB PARTNER-JURIST]

Classification: podmiot kluczowy vs podmiot ważny

NIS2 distinguishes between essential and important entities. The uKSC transposes these as two statutory categories:

The uKSC ties classification to the sectors listed in its załącznik nr 1 and załącznik nr 2, and to size thresholds referencing the medium-enterprise definition under rozporządzenie 651/2014/UE.

A few examples from the statute:

Getting this classification right is the starting point of any gap assessment, because it drives your obligations and your penalty exposure.

What the uKSC adds on top of NIS2

Beyond straightforward transposition, the Polish law introduces national elements that go further than the directive text itself.

1. The high-risk supplier regime ("dostawca wysokiego ryzyka" / 5G Toolbox)

Under uKSC art. 67b ust. 15, the Minister właściwy do spraw informatyzacji may issue a decision recognising a supplier of hardware or software — and entities within its capital group (within the meaning of the accounting law) — as a dostawca wysokiego ryzyka (high-risk supplier), where that supplier constitutes a threat to the fundamental interest of state security.

This is a distinctly national instrument aligned with the EU 5G Toolbox approach and layered onto the NIS2 framework. *Note: high-risk-supplier provisions are subject to constitutional review and their content may change — confirm the current status with a partner lawyer before relying on them.* [TÄPSUSTAB PARTNER-JURIST]

2. National penalty ceilings

The uKSC sets its own financial penalty amounts:

Entity typeMaximum penalty
podmiot kluczowyup to 10 000 000 EUR or 2% of annual turnover, whichever is higher (art. 73 ust. 3)
podmiot ważnyup to 7 000 000 EUR or 1,4% of annual turnover (art. 73 ust. 4)

There is also a specific penalty of up to 100 000 000 zł where a podmiot kluczowy or podmiot ważny causes a direct and serious cyber threat to defence, state security, public order, or life and health (art. 73 ust. 5).

3. Concrete reporting deadlines and final report

The uKSC operationalises reporting: a 24-hour early warning (art. 11 ust. 1 pkt 4), a 72-hour incident notification (art. 11 ust. 1 pkt 4a), interim reports on request (art. 11 ust. 1 pkt 4b), and a final report within one month of the notification (art. 11 ust. 1 pkt 4c).

Want to know where you stand? A free scoping and gap tool can help you check likely classification and readiness before you engage legal counsel.

Frequently asked questions

What is the Polish law that transposes NIS2?

The NIS2 directive (Directive (EU) 2022/2555) is transposed into Polish law by the Ustawa o krajowym systemie cyberbezpieczeństwa (uKSC). The uKSC is the binding national text for your obligations, deadlines and penalties.

Who is the competent authority for cybersecurity in Poland?

Poland uses a multi-authority model. It includes the organ właściwy do spraw cyberbezpieczeństwa (competent cybersecurity authority), the minister właściwy do spraw informatyzacji, and the response teams CSIRT MON, CSIRT NASK, CSIRT GOV and the CSIRT sektorowe. The exact authority for you depends on your sector and should be confirmed with a partner lawyer.

What does the uKSC add compared to NIS2?

Among other things, the uKSC introduces the national high-risk supplier regime (dostawca wysokiego ryzyka / 5G Toolbox) under art. 67b ust. 15, sets national penalty ceilings (art. 73 ust. 3-5), and lays down concrete incident reporting deadlines (art. 11).

How are entities classified under the uKSC?

The uKSC defines a podmiot kluczowy (essential entity) in art. 5 ust. 1 and a podmiot ważny (important entity) in art. 5 ust. 2, based on the sectors in załącznik nr 1 and nr 2 and size thresholds referencing rozporządzenie 651/2014/UE.

Check your NIS2 compliance

Start the free scoping test

Run the free gap analysis Run the free surface scan

This article is general information, not legal advice. A partner lawyer confirms your specific situation.

Back to home