Ustawa o krajowym systemie cyberbezpieczeństwa (KSC), System Zarządzania Bezpieczeństwem Informacji
Art. 8 ustawy z dnia 5 lipca 2018 r. o krajowym systemie cyberbezpieczeństwa (Dz.U. 2026 poz. 20) w brzmieniu nadanym ustawą z dnia 23 stycznia 2026 r. (Dz.U. 2026 poz. 252)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force in 199 days, effective 3 April 2027.
A sector security regimes rule binding public and private bodies.
As of 14 September 2026.
What it requires
- This duty does not yet fully bind: the amending Act entered into force on 3 April 2026, and Article 33(1) gives an entity that already meets the essential-entity or important-entity criteria on that date until 3 April 2027 to carry out Article 8's information security management system duty; an entity already regulated as an operator usługi kluczowej (essential service operator) under the pre-amendment Act continues to apply the prior Article 8 regime until it has deployed the new system.
- This binds an essential entity or important entity classified against the Załącznik nr 1 or Załącznik nr 2 sector lists, which name an online marketplace, an internet search engine and a social-networking-service platform (Załącznik nr 2, Dostawcy usług cyfrowych) among the digital service providers it reaches expressly; the wider sector classes the Załączniki also reach (critical-facility operators, energy, transport, health, finance, telecommunications and digital-infrastructure providers, and public administration) are a designation and sector class no activity in this vocabulary expresses, so they are not separately flagged here.
- Once it applies, implement an information security management system in the information system used in the processes affecting your provision of the service, covering systematic risk assessment and risk management, physical, personnel and supply-chain security, business continuity and disaster-recovery planning, continuous monitoring, effectiveness evaluation, cybersecurity training and basic cyber-hygiene, cryptography, secure communications and multi-factor authentication where appropriate, asset management, and access control.
- Have the entity's management implement and oversee the system, proportionate to the assessed risk, the entity's size, the cost of implementation, and the likelihood and severity of an incident.
- Expect an administrative fine of up to EUR 10,000,000 or 2 percent of worldwide annual turnover, whichever is higher, for an essential entity, or up to EUR 7,000,000 or 1.4 percent of turnover for an important entity, for failing to implement the system or for a system that does not meet these requirements.
If you get it wrong
Criminal exposureNo
Private right of actionNo
Criminal exposure note
The Act's own sanction for an Article 8 infringement is an administrative fine (kara pieniężna) under Article 73; no provision reviewed here makes the infringement itself a criminal offence.
Penalty structure
Article 73(3), as amended: the fine for an essential entity's infringement of, among other duties, Article 8 or Article 11 may not exceed EUR 10,000,000, converted to zloty at the National Bank of Poland's average rate on the preceding 31 December, or 2 percent of the entity's turnover in the preceding financial year, whichever is higher, with a floor of 20,000 zloty (about EUR 4,600). Article 73(4) sets an important entity's cap at EUR 7,000,000 or 1.4 percent of turnover, with a floor of 15,000 zloty.
- Rule
- Higher of
- As of
- 14 September 2026
- Currency
- EUR
- Fixed cap
- 10,000,000
- Turnover percentage cap
- 2
Who enforces it
Enforcement body
The organ właściwy do spraw cyberbezpieczeństwa (competent authority for cybersecurity) designated for the entity's sector, coordinated by the minister właściwy do spraw informatyzacji (minister responsible for computerisation) and backed by CSIRT NASK, CSIRT GOV, CSIRT MON and the sectoral CSIRTs.
Settledness
- As of
- 14 September 2026
- Guidance link
- https://www.gov.pl/web/baza-wiedzy/nowelizacja-ustawy-o-krajowym-systemie-cyberbezpieczenstwa
- Guidance body
- Kancelaria Prezesa Rady Ministrów, portal gov.pl Baza Wiedzy
- Open questions
- Will the Rada Ministrów rozporządzenie under the new Article 8a, setting sector-specific detail for the information security management system, narrow how the fourteen Article 8(1)(2) categories apply to an online marketplace, internet search engine or social-networking-service platform provider specifically?
What it reaches
Obligation class
Security, Governance
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 8 requires an essential entity or an important entity to implement an information security management system in the information system used in the processes affecting its provision of the service, covering fourteen baseline categories of technical and organisational measure: risk-assessment and information-security policy, secure system acquisition and development, physical and environmental security, personnel security, ICT supply-chain security, business continuity and disaster-recovery planning, continuous monitoring, effectiveness evaluation, cybersecurity training, basic cyber-hygiene, cryptography, secure communications and multi-factor authentication, asset management, and access control, transposing NIS2 Article 21.
Załącznik nr 2 names an online-marketplace provider, an internet search-engine provider and a social-networking-service-platform provider among the digital service providers this duty reaches expressly. The Act entered into force on 3 April 2026, but Article 33(1) of the amending Act gives an entity that already meets the essential-entity or important-entity criteria on that date twelve months, until 3 April 2027, to carry out this duty.
An entity already regulated as an operator usługi kluczowej (essential service operator) under the pre-amendment Act continues applying the prior Article 8 regime until it has deployed the new system.
When LexLint raises it
operates_social_platform
Read the law
Dziennik Ustaw text, api.sejm.gov.pl, amending Act of 23 January 2026 (Dz.U. 2026 poz. 252)