The new National Cybersecurity System

11 March 2026 | Knowledge, News, The Right Focus

The amendment to the Act on the National Cybersecurity System (UKSC) is one of the most significant regulatory reforms in recent years. Its main objective is to align Polish law with Directive (EU) 2022/2555 of the European Parliament and of the Council. The directive, also known as NIS2, substantially raises digital security requirements across the Union.

The Polish Act on the National Cybersecurity System has undergone a thorough overhaul, covering more organisations (with estimates suggesting nearly 40,000 entities)[1], introducing more demanding obligations, statutory personal liability for management board members, and even more stringent rules for imposing financial penalties. In the case of the most serious violations, these penalties can reach 100 million PLN.

Essential and important entities. And even more companies subject to new obligations

One of the amendment’s key features is the expansion of the list of entities subject to cybersecurity obligations. The previous distinction between operators of essential services and digital service providers has been replaced by a broader classification covering essential entities and important entities.

The amended UKSC now covers 18 sectors and industries, all of which must prepare to meet the new requirements. These include energy, transport, healthcare, postal services, waste management, the chemical industry, the space sector, the manufacture of equipment and machinery, digital infrastructure, and the production and distribution of food.

The amendment requires businesses to conduct a thorough analysis of their activities to determine whether they meet the criteria for classification into one of the entity categories. Rather than passively awaiting individual decisions from state authorities, companies should assess for themselves whether they meet the criteria and prepare for mandatory entry into the list.

For many organisations, especially SMEs, this will be their first experience of formal cybersecurity procedures. Consequently, it may be necessary for them to develop policies, implement manuals and procedures, conduct audits, and ensure that these activities are properly documented.

The obligation to create a comprehensive information security management system

One of the most important aspects of the amendment is the obligation to establish a comprehensive information security management system. This system must be proportionate to the level of risk assessed and must, first and foremost, include:

  • Risk analysis and assessment
  • Technical and organisational measures (including encryption, multi-factor authentication (MFA), access control, and physical protection of systems)
  • Ensuring business continuity and crisis management, including disaster recovery plans and backup testing
  • Monitoring, reporting and responding to incidents
  • Supply chain security management

Computer Security Incident Response Teams (CSIRTs) are to play a key role in responding to threats, gathering knowledge and educating entities within specific sectors.

The personal responsibility of board members for implementing cybersecurity requirements

One significant change that could impact the management of organisations is the introduction of personal responsibility of board members for ensuring that the company’s activities comply with the UKSC.

This means that, in the event of serious violations or omissions relating to cybersecurity, the legal and financial consequences could affect not only the company itself, but also the members of its management bodies. It is important to note that responsibility for oversight in this area cannot be fully delegated to lower organisational levels or specialised technical units.

If an organisation fails to clearly allocate responsibilities and designate individuals accountable for specific tasks, all members of the management board will be held jointly and severally liable for any negligence. This signals to the market that cybersecurity management is becoming a fundamental corporate governance responsibility.

Strengthening the country’s entire protection system

The ministers responsible for specific sectors, the Financial Supervision Authority (KNF) and the President of the Office of Electronic Communications (UKE) have been given the tools to oversee and penalise certain services, and even to issue decisions ordering their discontinuation. They can also request audits, issue warnings, monitor compliance, and take preventive action both before and after a breach occurs.

From a market perspective, the new regulations mark the next stage in the development of national cyber resilience. Rather than merely imposing formal requirements on businesses, the Act aims to foster a mature security culture within organisations. Consequently, the amendment is set to become one of the most important tools for modernising the Polish digital economy.

It should be noted that when signing the Act, the President decided to refer certain provisions concerning, among other things, the rules for assessing and approving high-risk suppliers to the Constitutional Tribunal for an a posteriori review. However, this means that the Act has been promulgated and will enter into force in its entirety, so businesses must comply with the obligations it imposes.

Any questions? Contact us

 

[1] https://edgp.gazetaprawna.pl/prawo/prawo-internetu-i-ochrony-danych/artykuly/10594833,czy-uksc-obejmie-najwieksza-liczbe-podmiotow-w-ue.html

Latest Knowledge

Banking sector overview | Banking today and tomorrow | July 2026

Under the draft legislation, banks will be required to offer existing borrowers a switch from WIBOR-based to POLSTR-based interest rates, a mechanism intended to speed up the voluntary transition of financial instruments to the new benchmark. The banking sector has responded positively to the proposal, according to Tadeusz Białek, President of the Polish Bank Association.

“Withdraw from contract here” – what next for the new button in online shops, on trading platforms and in mobile apps?

From 19 June, national legislation was to require businesses in the European Union entering into distance contracts with consumers via an online interface to provide consumers with the option to withdraw from the contract via a dedicated function/button. However, due to Poland’s delay in transposing Directive 2023/2673, which requires the use of such a button, this obligation has been postponed in our country. We look at what remote contract withdrawal entails and which transactions the new feature will apply to.

Municipal master plans – new deadline, same old challenges

On 11 June 2026, the President signed into law a bill extending the deadline for municipalities to adopt their master plans (plany ogólne). The key deadline for adopting master plans was moved from 30 June to 31 August 2026. We examine the reasons behind this change and consider what the absence of a master plan might mean for potential investors and their future projects.

Record fines and the upcoming 21st sanctions package – what should businesses expect?

The past year has brought a series of enforcement actions that clearly signal a tightening approach by the Polish customs and revenue authorities towards breaches of the sanctions regime. Importantly, businesses should already be preparing for further changes, as the European Union has announced its 21st sanctions package and updated the list of designated persons and entities. We examine the key developments and offer guidance on how to minimise the risk of non-compliance.

A sea change in the rules governing board members’ liability for a company’s tax arrears

The bill amending the General Tax Code (No. UC138) fundamentally overhauls the rules governing the tax liability of third parties for capital companies’ tax arrears.  It comes in response to recent CJEU judgments, the Ombudsman’s February statement and the post-audit report of the Supreme Chamber of Audit (NIK) of December 2025. We examine what’s changing, who will be affected by the new rules and what steps are worth taking right now.

Partner in name, but only if male: the linguistic trap in Polish corporate law

One of the structures available under Polish law is the ‘spółka partnerska’ (professional partnership), modelled on the Anglo-Saxon Limited Liability Partnership. As defined in the Polish Commercial Companies Code, this is a vehicle for individuals practising liberal professions, such as doctors, architects and accountants. And yet, the provisions governing professional partnerships make no mention of their applicability to women. We therefore examine whether there is no room for female partners, feminine-gendered forms, or simply linguistic empathy.

Can you sue over words aimed at an entire community?

A damaging public statement does not necessarily refer to a specific individual. Sometimes, the author attributes negative characteristics to a whole group of people, portrays them as a threat or uses language that could be seen as demeaning. Statements of this kind frequently concern LGBTQ+ people. This raises the question: can a member of the targeted community bring a lawsuit seeking compensation or an apology, even if they were not named directly? We decided to look into this.

Banking sector overview | Banking today and tomorrow | June 2026

According to a statement published by GPW Benchmark, the reference rate administrator, and the Polish Financial Supervision Authority (KNF), which oversees the administrator, 31 December 2036 will be the last day on which the WIBID and WIBOR rates will be provided for all key fixing periods: 1 month (1M), 3 months (3M) and 6 months (6M).

How to correctly calculate length of service from 1 May 2026

New rules for calculating length of service have applied to private sector employers since the beginning of May 2026. With companies continuing to express concerns about the new framework, the Ministry of Family, Labour and Social Policy has addressed the most common questions. We look at the issues that are (still) troubling employers and how we can help.

Contact us:

Robert Brodzik

Robert Brodzik

Advocate / Counsel / NewTech / Data Protection and Cybersecurity

+48 532 206 479

r.brodzik@kochanski.pl