Ustawa o krajowym systemie cyberbezpieczeństwa (KSC), Zgłaszanie Incydentów Poważnych
Art. 11 ustawy z dnia 5 lipca 2018 r. o krajowym systemie cyberbezpieczeństwa (Dz.U. 2026 poz. 20) w brzmieniu nadanym ustawą z dnia 23 stycznia 2026 r. (Dz.U. 2026 poz. 252)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force in 199 days, effective 3 April 2027.
A vulnerability and incident reporting rule binding public and private bodies.
As of 14 September 2026.
What it requires
- This duty does not yet fully bind for most entities: the amending Act entered into force on 3 April 2026, and Article 33(1) gives an entity that already meets the essential-entity or important-entity criteria on that date until 3 April 2027 to carry out Article 11's incident-notification duty; an entity already regulated as an operator usługi kluczowej (essential service operator) under the pre-amendment Act has an accelerated deadline of 3 October 2026, six months after entry into force, to begin reporting under this Article.
- This binds an essential entity or important entity classified against the Załącznik nr 1 or Załącznik nr 2 sector lists, which name an online marketplace, an internet search engine and a social-networking-service platform among the digital service providers it reaches expressly; the wider sector classes it also reaches are not separately flagged here, for the reason given on this jurisdiction's companion risk-management row.
- Notify the competent sectoral CSIRT without delay, and in any event within 24 hours of detecting a significant incident, with an early warning.
- Follow with a fuller notification within 72 hours of detection, a periodic report on the CSIRT's request, and a final report no later than one month after the 72-hour notification.
- Where a serious cyber threat arises, inform the users of your services who may be affected of the preventive measures they can take, and inform them of the threat itself unless doing so would increase the risk to information-system security; where a significant incident has an adverse effect on your service, inform the affected users of the incident.
- Expect an administrative fine of up to EUR 10,000,000 or 2 percent of worldwide annual turnover, whichever is higher, for an essential entity, or up to EUR 7,000,000 or 1.4 percent of turnover for an important entity, for failing to report as required.
If you get it wrong
Criminal exposureNo
Private right of actionNo
Criminal exposure note
The Act's own sanction for an Article 11 infringement is an administrative fine (kara pieniężna) under Article 73; no provision reviewed here makes a failure to report itself a criminal offence.
Penalty structure
Article 73(4), as amended: the fine for an important entity's infringement of, among other duties, Article 8 or Article 11 may not exceed EUR 7,000,000, converted to zloty at the National Bank of Poland's average rate on the preceding 31 December, or 1.4 percent of the entity's turnover in the preceding financial year, whichever is higher, with a floor of 15,000 zloty. Article 73(3) sets an essential entity's cap at EUR 10,000,000 or 2 percent of turnover, with a floor of 20,000 zloty.
- Rule
- Higher of
- As of
- 14 September 2026
- Currency
- EUR
- Fixed cap
- 7,000,000
- Turnover percentage cap
- 1.4
Who enforces it
Enforcement body
The organ właściwy do spraw cyberbezpieczeństwa (competent authority for cybersecurity) designated for the entity's sector, coordinated by the minister właściwy do spraw informatyzacji (minister responsible for computerisation) and backed by CSIRT NASK, CSIRT GOV, CSIRT MON and the sectoral CSIRTs.
Settledness
- As of
- 14 September 2026
- Guidance link
- https://www.gov.pl/web/baza-wiedzy/sejm-uchwalil-nowelizacje-ustawy-o-krajowym-systemie-cyberbezpieczenstwa
- Guidance body
- Kancelaria Prezesa Rady Ministrów, portal gov.pl Baza Wiedzy
- Open questions
- Will the Rada Ministrów rozporządzenie under Article 11(4), setting the thresholds for classifying an incident as significant by sector and subsector, narrow when an online marketplace, internet search engine or social-networking-service platform provider specifically must report?
What it reaches
Obligation class
Reporting, Security
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 11 requires an essential entity or an important entity to notify the competent sectoral CSIRT of a significant incident on a graduated clock, transposing NIS2 Article 23. It requires an early warning without delay and no later than 24 hours after detection. It requires a fuller notification within 72 hours of detection, and a periodic report on the CSIRT's request. It requires a final report no later than one month after the 72-hour notification.
New Article 11(2a) requires the entity to inform affected users of a serious cyber threat and of the preventive measures they can take, and new Article 11(2b) requires informing users of a significant incident that adversely affects the service.
The Act entered into force on 3 April 2026, but Article 33(1) of the amending Act gives an entity that already meets the essential-entity or important-entity criteria on that date twelve months, until 3 April 2027, to carry out this duty; Article 33(4) accelerates that clock to six months, until 3 October 2026, for an entity already regulated as an operator usługi kluczowej (essential service operator) under the pre-amendment Act.
When LexLint raises it
operates_social_platform
Read the law
Dziennik Ustaw text, api.sejm.gov.pl, amending Act of 23 January 2026 (Dz.U. 2026 poz. 252)