Narodowe Standardy Cyberbezpieczeństwa
NIS2 says what you must achieve, never how you demonstrate it. Poland answers with NSC. If you operate there, this is what your regulator reads.
Reviewed . Verify against the scheme owner before relying on this for a certification decision.
This framework is not compliance
The NSC are recommendations, not binding requirements. Your obligations come from the Ustawa o krajowym systemie cyberbezpieczeństwa as amended for NIS2 — the NSC tell you how the Polish administration expects the work to be structured, and a supervisor will recognise them, but citing an NSC control is not a defence.
We put that first because it is the most expensive misunderstanding about any national framework. ISO/IEC 27001 is equally accepted. The NSC are the natural choice for an entity that already works to NIST, since the numbering is the same.
What it is built on
NSC does not invent its own taxonomy. It sits on NIST publications, adapted into Polish — NSC 800-53 corresponds to NIST SP 800-53.
A series of more than twenty standards, each mirroring a NIST publication: NSC 199 and NSC 200 (categorisation and minimum requirements), NSC 800-53 (controls), NSC 800-61 (incident handling), NSC 800-207 (zero trust).
How it covers article 21(2)
Resolved by reference to NIST SP 800-53, because NSC 800-53 is that publication adapted into Polish and keeps its family identifiers. Holding one mapping for both is the only way they cannot drift apart.
Family level, inherited from the NIST mapping. And the NSC are recommendations: a family match locates your evidence, it does not discharge the Polish statute.
| Art. 21(2) | Measure | NSC — NIST SP 800-53 Rev. 5 control family |
|---|---|---|
| (a) | Risk analysis and security policies | RA PL PM |
| (b) | Incident handling | IR AU SI |
| (c) | Business continuity | CP PE |
| (d) | Supply chain security | SR SA |
| (e) | Security in acquisition, development and maintenance | SA CM MA RA SI |
| (f) | Assessing the effectiveness of the measures | CA PM |
| (g) | Basic cyber hygiene and cybersecurity training | AT SI CM |
| (h) | Cryptography and encryption | SC |
| (i) | Human resources security, access control and asset management | PS AC IA CM MP PE |
| (j) | Multi-factor authentication and secured communications | IA AC SC |
20 NIST SP 800-53 Rev. 5 control family units, in full
- AC — Access Control
- AT — Awareness and Training
- AU — Audit and Accountability
- CA — Assessment, Authorization and Monitoring
- CM — Configuration Management
- CP — Contingency Planning
- IA — Identification and Authentication
- IR — Incident Response
- MA — Maintenance
- MP — Media Protection
- PE — Physical and Environmental Protection
- PL — Planning
- PM — Program Management
- PS — Personnel Security
- PT — PII Processing and Transparency
- RA — Risk Assessment
- SA — System and Services Acquisition
- SC — System and Communications Protection
- SI — System and Information Integrity
- SR — Supply Chain Risk Management
What you already have, for the same measure
Nobody in scope starts from nothing. NSC is what your supervisor reads; ISO 27001 is what most organisations already run. Read a row across and you have the whole path, from the article to the control you can point at today.
NIST 800-53 is not repeated here: NSC publishes no identifiers of its own and its mapping above is the NIST 800-53 one. Showing it twice would make a duplication look like independent confirmation.
| Art. 21(2) | NSC | ISO 27001 ISO/IEC 27001:2022 Annex A control |
|---|---|---|
| (a) Risk analysis | RA PL PM | 5.1 5.2 5.3 5.4 5.7 5.31 5.35 5.36 |
| (b) Incident handling | IR AU SI | 5.5 5.6 5.7 5.24 5.25 5.26 5.27 5.28 6.8 8.15 8.16 |
| (c) Continuity | CP PE | 5.29 5.30 7.5 7.11 7.12 8.13 8.14 |
| (d) Supply chain | SR SA | 5.19 5.20 5.21 5.22 5.23 |
| (e) Secure development | SA CM MA RA SI | 5.8 8.8 8.9 8.25 8.26 8.27 8.28 8.29 8.30 8.31 8.32 8.33 8.34 |
| (f) Effectiveness | CA PM | 5.33 5.35 5.36 8.16 |
| (g) Hygiene and training | AT SI CM | 5.37 6.3 8.7 |
| (h) Cryptography | SC | 8.24 |
| (i) HR, access, assets | PS AC IA CM MP PE | 5.9 5.10 5.11 5.12 5.13 5.15 5.16 5.17 5.18 6.1 6.2 6.4 6.5 6.6 6.7 7.1 7.2 7.3 7.4 7.6 7.7 7.8 7.9 7.10 7.13 7.14 8.1 8.2 8.3 8.4 8.10 8.11 8.12 8.18 8.19 |
| (j) MFA and comms | IA AC SC | 5.14 8.5 8.6 8.17 8.20 8.21 8.22 8.23 |
A crosswalk is not an equivalence
Holding the controls in a row does not discharge the measure. Each framework words its requirement differently, and each mapping has a stated limit:
- ISO 27001 — Mapping a control does not make it applicable: applicability comes from your risk assessment and your Statement of Applicability. Note also that the risk-assessment obligation of article 21(2)(a) is carried by clause 6.1 of the standard, not by Annex A — a control-only reading misses it.
Use a row to find the evidence you already hold, then read the requirement itself.
We are not affiliated with Ministerstwo Cyfryzacji — Departament Cyberbezpieczeństwa. NSC and related marks belong to their owners.