
Poland’s NIS2 Law Brings 38,000 Organisations into the Cybersecurity System
Poland’s amended National Cybersecurity System Act is now in force. Its scale, registration timetable and management duties turn NIS2 into a board-level implementation programme.
Poland’s amendment to the National Cybersecurity System Act took effect on 3 April 2026. The Act of 23 January 2026 transposes NIS2 and replaces the earlier division between operators of essential services and digital-service providers with essential and important entities.
The Ministry of Digital Affairs estimates that the system may cover about 38,000 organisations, including roughly 27,000 public bodies. Sectors include energy, transport, banking, health, water, digital infrastructure, managed ICT services, space and public administration, as well as postal services, waste, chemicals, food, manufacturing, digital providers and research.
The first deadline is scope and registration
Entities that met the criteria when the law entered into force must be entered in the KSC register by 3 October 2026. The Ministry began registering certain previously known operators and public bodies automatically on 13 April. Self-registration for other in-scope organisations opens on 7 May.
Do not assume that an organisation will receive an invitation. Build a legal-entity-level scope record covering sector, services, size, public status and any special inclusion criteria. Groups should assess Polish entities separately even when cybersecurity is managed centrally.
The implementation year has started
Existing in-scope entities have until 3 April 2027 to implement the new duties. These include an information security management system, incident management and reporting, named contacts for the national system and connection to Poland’s S46 information-sharing system.
Essential entities face mandatory audits. For newly covered essential entities that were not previously operators of essential services, the first audit is due by 3 April 2028, followed by audits at least every three years.
The transition period is useful, but it is not a reason to postpone. Supplier changes, logging improvements, identity redesign and recovery tests can require most of a year on their own.
Management accountability needs evidence
The new rules place responsibility on leadership for cybersecurity tasks. Boards and directors should not approve a generic policy and wait for 2027.
A defensible governance rhythm should include:
- a confirmed list of essential services and accountable entities;
- an executive owner and an operational KSC contact;
- regular reporting on material cyber risks and overdue treatment;
- approval of the risk-management and incident-response framework;
- exercises that include legal reporting and service continuity;
- evidence that leaders received appropriate cybersecurity training;
- tracking of registration, S46 connection and audit readiness.
Minutes should record decisions, assumptions and accepted risk. That evidence is useful during supervision and invaluable after an incident.
Localise the incident workflow
Multinational organisations can reuse a common NIS2 control framework, but Poland’s register, competent authorities and CSIRT channels need local ownership. Map each regulated service to the correct reporting route and ensure the response team can produce a technically useful early notification while facts are still changing.
Procurement also needs to identify suppliers that can interrupt or compromise an essential service. Contracts should support incident notification, access to evidence, vulnerability handling and recovery testing rather than merely promising “NIS2 compliance”.
The practical starting point
By the end of the first month, an organisation should know whether it is an essential or important entity, who will register it, which systems support its regulated services and which gaps cannot be closed before April 2027 without immediate work.
Poland has provided a timetable. The quality of the outcome will depend on whether organisations use it to build operational resilience rather than a last-minute compliance file.
Official sources
- Polish Ministry of Digital Affairs: the KSC amendment enters into force
- Polish Ministry of Digital Affairs: who the amended KSC covers
- Official legal text: Act of 23 January 2026
This article is general information, not legal advice. Organisations should obtain advice on their specific status and duties.
Continue the series: European National Cyber & Digital Law Series index



