5 key takeaways
- Key and important entities have 12 months from the date they qualify to implement all cybersecurity obligations — for entities that qualified on 3 April 2026, the deadline is 3 April 2027
- The law requires 10 specific measures covering: risk assessment, incident handling, business continuity, supply chain security, secure development, effectiveness testing, cyber hygiene, cryptography, access control, and preventive measures
- All 10 measures must be delivered through a formal SZBI (information security management system) — documented, implemented, reviewed and audited on an ongoing basis
- The head of the entity is personally liable for SZBI implementation, incident reporting and cooperation with audits — up to 300% of annual leave allowance remuneration
- Key entities must complete an independent security audit at least once every 3 years, at their own cost, and submit the report to the competent authority within 3 working days
The NIS2 cybersecurity measures Poland requires key and important entities to implement must be fully in place by 3 April 2027. If your organisation registered in the Wykaz KSC before 3 October 2026, the question has changed. It is no longer “do we qualify?” — it is “what exactly do we now have to build, and by when?”
This post walks through all 10 measures, explains what implementing an SZBI actually means in practice, sets out what personal board liability looks like under the new regime, and gives you a realistic timeline to April 2027.
NIS2 Cybersecurity Measures Poland: The Legal Starting Point: NIS2 Poland Cybersecurity Measures Under Article 8 KSC
The amended Act on the National Cybersecurity System (KSC Act), which transposes Directive (EU) 2022/2555 (NIS2) into Polish law, requires key and important entities to implement “appropriate and proportionate technical, operational and organisational measures” to manage cybersecurity risk. These measures must be calibrated to the entity’s size, exposure and the state of the art. Specifically, Article 8(1)(2) of the amended KSC Act mirrors the ten domains of Article 21(2) of the NIS2 Directive. Consequently, every key and important entity must implement all ten. Moreover, entities have 12 months from the date they first meet the qualifying criteria to do so. For organisations that already qualified on 3 April 2026, the deadline is 3 April 2027.
The 10 NIS2 Poland Cybersecurity Measures in Practice
Measure 1: Risk Assessment and Information Security Policies
Build a documented, systematic process for assessing and managing incident risk. Additionally, prepare a written information security policy and topic-specific sub-policies.
In practice: a risk register reviewed on a defined cycle, a board-approved security policy, and evidence that the policy drives real decisions — not a document that sits in a drawer.
Measure 2: Incident Handling
Document your incident management process end to end: detection, triage, containment, eradication, recovery, and lessons learned. Furthermore, connect this process directly to your statutory reporting obligations — early warning within 24 hours, notification within 72 hours, and a final report.
In practice: an incident response plan with clear roles, an on-call rotation, and rehearsed escalation paths to the sectoral CSIRT.
Measure 3: Business Continuity and Crisis Management
Test your business continuity plans, backup management, disaster recovery, and crisis management procedures. Specifically, these must be capable of restoring your information system after an event that exceeds ordinary recovery capacity.
In practice: backups tested for actual restorability, a documented recovery time objective, and a crisis communication plan.
Measure 4: Supply Chain Security
Address security in your relationships with direct suppliers and service providers. In particular, assess each supplier’s vulnerabilities and the quality of ICT products, services and processes they provide.
In practice: security clauses in supplier contracts, vendor risk assessments before onboarding critical suppliers, and a register of critical third-party dependencies.
Measure 5: Security in System Acquisition, Development and Maintenance
Build security into the acquisition, development and maintenance of your network and information systems. Additionally, implement a vulnerability handling and disclosure policy.
In practice: secure development lifecycle controls, mandatory security testing before go-live, and a documented process for receiving and triaging vulnerability reports.
Measure 6: Policies to Assess the Effectiveness of Measures
Evaluate whether your cybersecurity measures are actually working. This goes beyond the statutory audit — it is an internal, ongoing assessment process.
In practice: internal audits, penetration testing, and periodic management review of security metrics.
Measure 7: Cyber Hygiene and Staff Training
Implement basic cyber hygiene practices and cybersecurity training for all personnel. Moreover, the head of the entity and anyone with delegated cybersecurity responsibilities must complete dedicated annual training.
In practice: mandatory phishing-awareness and hygiene training for all staff, and a documented board-level training record.
Measure 8: Cryptography and Encryption
Prepare policies and procedures on the use of cryptography, including encryption where appropriate.
In practice: a data classification scheme paired with encryption standards for data at rest and in transit — for anything above the lowest sensitivity tier.
Measure 9: Access Control, Asset Management and Secure Communications
Implement role-based access control, asset management, human resources security, and secure voice, video and text communications. Furthermore, apply multi-factor authentication where appropriate — both within the organisation and across the national cybersecurity system.
In practice: a current asset inventory, offboarding procedures that revoke access on the day employment ends, and MFA on privileged and remote-access accounts.
Measure 10: Preventive and Mitigating Measures
Ensure the confidentiality, integrity, availability and authenticity of processed data. Additionally, implement a patch management process that accounts for the criticality of each update. Finally, build the ability to act immediately on detected vulnerabilities — including temporarily restricting inbound network traffic to contain an incident.
A Note on Sector-Specific Requirements
DNS providers, TLD registries, cloud providers, data centres, content delivery networks, managed service providers, managed security service providers, online marketplaces, search engines, social networks, and trust service providers apply the more granular requirements of Commission Implementing Regulation (EU) 2024/2690 rather than the general Article 8 list. If your organisation falls into one of those categories, check the Regulation specifically.
What “Implementing an SZBI” Actually Means
The amended KSC Act does not ask entities to tick off the ten measures in isolation. Instead, it requires delivery through a formal information security management system — an SZBI (system zarządzania bezpieczeństwem informacji) — implemented, applied, reviewed and supervised on an ongoing basis.
Documentation is a statutory deliverable
The Act requires entities to prepare, apply and keep current two categories of documentation:
- Normative documentation: the SZBI itself, infrastructure protection documentation including a risk assessment and risk treatment plan, business continuity documentation, and technical documentation
- Operational documentation: records — including automatically generated system logs — that evidence the normative documentation is actually being followed
All documentation must be kept under controlled access, version-tracked, and retained for at least two years after the relevant system or service is withdrawn.
The SZBI must be independently audited
Key entities must carry out a security audit of their information system at least once every three years, at their own cost. Furthermore, they must submit a copy of the audit report to the competent cybersecurity authority within three working days of receiving it. The competent authority can also order an external audit at any time for key entities, or for important entities following a serious incident.
Operational obligations run alongside the SZBI
Beyond the ten measures, entities must designate at least two contact persons for the national cybersecurity system, give service users access to information about cyber threats, and either build an internal cybersecurity structure or contract a managed cybersecurity service provider.
Board Liability: Why the SZBI Cannot Be Delegated to IT
One of the most significant changes the amended KSC Act introduces is that cybersecurity compliance is now also a personal liability for the head of the entity — not only a corporate risk.
Who is “the head of the entity”?
In practice, this means the management board, CEO, or equivalent governing body — defined by reference to the head of the accounting unit under the Accounting Act. Where no individual has been designated as responsible within a collective body, every member of that body is personally liable.
Personal, non-delegable duties
The head of the entity is personally responsible for deciding on the preparation, implementation, application, review and supervision of the SZBI. Additionally, they must plan adequate financial resources for cybersecurity compliance, assign and supervise cybersecurity tasks, and ensure staff know their obligations. Importantly, delegating tasks to another person does not relieve the head of the entity of this responsibility.
Mandatory annual training
The head of the entity — and anyone with delegated cybersecurity responsibilities — must complete cybersecurity training once every calendar year. Furthermore, attendance must be documented.
Personal financial penalties
Independently of any fine on the entity itself, the head of a key or important entity can be personally fined up to 300% of their statutory annual leave allowance remuneration (up to 100% for heads of public-sector entities). This personal exposure covers missed SZBI implementation, incident reporting failures, missed staff training, and non-cooperation with audits.
In short: the board needs to show, personally, that it decided to implement the SZBI, resourced it adequately, and actively supervises it. That is precisely what the Act requires.
Realistic Timeline: NIS2 Cybersecurity Measures Poland by April 2027
Now to Q4 2026 — Gap Assessment and Governance
Start with a gap assessment across all ten Article 8 measures. Subsequently, get board-level sign-off on the remediation plan and budget. Additionally, designate your statutory contact persons, decide whether to run cybersecurity operations in-house or through a managed provider, and book the head of the entity onto mandatory annual training.
Q4 2026 to Q1 2027 — Build the SZBI
Draft and approve normative documentation: security policy, risk assessment and treatment plan, business continuity plan, technical documentation. Furthermore, build the incident detection and reporting workflow so it is ready to meet the 24-hour and 72-hour statutory clocks. Roll out access control, asset management and encryption controls, and begin supply chain due diligence on critical vendors.
Q1 to Q2 2027 — Training, Testing and Evidence
Deliver cyber hygiene training to all staff. Additionally, run an incident response tabletop exercise, test backup restoration, and start generating operational documentation — logs and records — that evidence the SZBI is functioning, not just documented.
By 3 April 2027 — Full Implementation
All Chapter 3 obligations, including the SZBI, must be fully implemented, applied and monitored. Key entities should already be scheduling their first statutory audit, due within 24 months of qualifying — by 3 April 2028 for entities whose obligations began on 3 April 2026. Build in enough lead time to select an eligible auditor and remediate any findings before that deadline.
One Important Note on Enforcement Timing
The amended Act limits enforcement of financial penalties until two years after the Act’s entry into force. In practice, active enforcement of fines starts around April 2028. Nevertheless, this transitional relief covers only the timing of penalties. It does not extend the 12-month SZBI implementation deadline. In other words, the obligation to implement NIS2 Poland cybersecurity measures by 3 April 2027 applies now — regardless of when fines can first be levied.
Where to Start This Week
For most organisations, the starting point is a gap assessment: map the current state of each of the ten Article 8 domains against what the SZBI documentation requires. Then prioritise the gaps that carry the highest incident or enforcement risk, and build a remediation plan with named owners and dates. That plan — and evidence of its execution — is exactly what the competent authority and the first statutory audit will look for.
If you have questions about NIS2 cybersecurity obligations or SZBI implementation in Poland, get in touch.
Katarzyna Szczudlik is a Partner at Schoenherr in Warsaw, advising technology companies, financial institutions and international businesses on NIS2, DORA, cybersecurity law and EU regulatory compliance. She is ranked by Chambers & Partners and Legal 500 EMEA. If NIS2 compliance is on your agenda, let’s talk.