NIS2 in Poland
What binds you in Poland is the national law transposing NIS2 — not the directive itself. Here is who supervises you, where you register, and where you report.
Reviewed . Verify against the national official journal before relying on this for a filing.
National transposition
Ustawa o krajowym systemie cyberbezpieczeństwa (KSC Act), as amended for NIS2
The Sejm adopted the KSC amendment in January 2026 and the Senate approved it; the President signed it on 19 February 2026, it was published in the Dziennik Ustaw on 2 March 2026 and it entered into force on 3 April 2026. Poland transposed by amending the KSC Act of 5 July 2018 rather than by passing a new law, so the article numbers you need are in the consolidated 2018 act, not in the amending one. Poland had received a reasoned opinion from the Commission on 7 May 2025 for not notifying full transposition.
Narodowe Standardy Cyberbezpieczeństwa — NSC series — NSC 800-53 v2.0 among them
NSC 800-53 v2.0, published 1 September 2021, published by Ministerstwo Cyfryzacji — Departament Cyberbezpieczeństwa. Built on NIST publications, adapted into Polish — NSC 800-53 corresponds to NIST SP 800-53.
Poland publishes the Narodowe Standardy Cyberbezpieczeństwa — more than twenty standards that are the Polish adaptation of the NIST publications and keep their numbering, NSC 800-53 being NIST SP 800-53. They are recommendations rather than binding requirements, which makes Poland the least additional work for an organisation already running NIST. Poland also placed notable weight on supply chain obligations in the KSC amendment, so supplier assurance is the part most likely to be examined.
A label is not compliance
The NSC are recommendations, not binding requirements. Your obligations come from the Ustawa o krajowym systemie cyberbezpieczeństwa as amended for NIS2 — the NSC tell you how the Polish administration expects the work to be structured, and a supervisor will recognise them, but citing an NSC control is not a defence.
Who supervises you
Ministry of Digital Affairs is the competent authority designated by Poland. It holds the article 32 and 33 supervisory powers: inspections and audits, requests for information and evidence, binding instructions, orders to remedy deficiencies, and administrative fines. For essential entities those powers are exercised ex ante — without needing any indication of non-compliance.
Incident notifications under article 23 normally go to CSIRT NASK / GOV / MON, though some member states route them through the competent authority instead. Confirm the channel before you need it: the 24-hour clock is not the moment to discover which portal applies.
What differs from the directive
Because NIS2 is a directive, Poland legislated its own version of it. The security baseline in article 21 is common across the Union and will not differ. What does differ:
- Registration. The portal, the information required and the deadline are national.
- Scope. Several member states extended coverage below the directive's size thresholds, or added sectors of national importance.
- Penalty calibration. The article 34 ceilings are common; how the authority calibrates within them is not.
- Reporting format. Deadlines are fixed by the directive; the form and the language are national.
If you operate in several member states
You have one security programme and several compliance relationships. Registration, supervision and reporting are per-jurisdiction, and a cross-border incident can require filings in each affected member state. Article 26 sets jurisdiction rules — generally the member state of establishment, with specific rules for digital providers.