Poland's NIS2 transposition is enacted and in force after a nearly seven-year legislative process: the Ustawa z dnia 23 stycznia 2026 r. o zmianie ustawy o krajowym systemie cyberbezpieczeństwa oraz niektórych innych ustaw (Dz.U. 2026 poz. 252) was published on 2 March 2026 and, under its own Article 49, entered into force on 3 April 2026, one month after publication. It rewrites large parts of the 2018 Ustawa o krajowym systemie cyberbezpieczeństwa (KSC), the base act it amends.
Article 8 requires a podmiot kluczowy (essential entity) or podmiot ważny (important entity), classified against the Załącznik nr 1 (key sectors) and Załącznik nr 2 (important sectors) sector lists, to implement an information security management system covering fourteen baseline categories of technical and organisational measure, transposing NIS2 Article 21.
Załącznik nr 2 names an online-marketplace provider, an internet search-engine provider and a social-networking-service-platform provider among the digital service providers this duty reaches expressly, alongside critical-facility operators, large telecommunications and digital-infrastructure providers (DNS, top-level domain (TLD) registries, domain registration services, cloud computing, data centres, content delivery networks, managed services and managed security services), and public administration.
Article 11 sets a graduated incident-notification clock to the competent sectoral CSIRT: an early warning within 24 hours of detecting a significant incident, a fuller notification within 72 hours, a periodic report on the CSIRT's request, and a final report within one month of the 72-hour notification, transposing NIS2 Article 23; new Article 11(2a)-(2b) duties also require notifying affected users of a serious cyber threat and of a significant incident with an adverse effect on the service.
Both duties phase in rather than binding immediately: Article 33(1) of the amending Act gives an entity that already meets the essential-entity or important-entity criteria on 3 April 2026 twelve months, until 3 April 2027, to carry out the Chapter 3 duties (Articles 8 and 11 among them), with the essential entity's first Article 15 audit due within 24 months; an entity that was already regulated as an operator usługi kluczowej (essential service operator) under the pre-amendment Act has an accelerated six-month deadline, 3 October 2026, to begin reporting incidents under the new Article 11-12b regime, and continues applying the prior Article 8 regime until it has deployed the new system.
Article 73 arms the organ właściwy do spraw cyberbezpieczeństwa (the sector-specific competent cybersecurity authority) to impose an administrative fine for an Article 8 or Article 11 infringement: up to EUR 10,000,000 or 2 percent of turnover, whichever is higher, for an essential entity, and up to EUR 7,000,000 or 1.4 percent of turnover for an important entity, both enforced through the same procedure as the authority's supervisory powers over essential entities.
No instrument reviewed here imposes a mandatory product-security or market-placement duty on a manufacturer independent of the directly applicable Cyber Resilience Act, which is documented at the European Union level and is not restated here.
Poland has no general reasonable-security or information-security-programme statute with no sector gate; the closest general duty is General Data Protection Regulation (GDPR) Article 32's security-of-processing obligation, and personal-data breach notification under GDPR Articles 33-34 and the Polish Act of 10 May 2018 to the President of the Personal Data Protection Office (UODO) sits in the privacy topic rather than here.
Only the digital-provider slice of the essential-and-important-entity class (an online marketplace, an internet search engine, and a social-networking-service platform) is flagged on this jurisdiction's rows; the wider sector classes Article 8 and Article 11 also reach (critical-facility operators, energy, transport, health, finance, digital-infrastructure providers and public administration) are recorded here as law the lint does not yet reach rather than flagged on an unrelated activity.