Law / Poland

Ustawa o krajowym systemie cyberbezpieczeństwa (KSC), System Zarządzania Bezpieczeństwem Informacji

Art. 8 ustawy z dnia 5 lipca 2018 r. o krajowym systemie cyberbezpieczeństwa (Dz.U. 2026 poz. 20) w brzmieniu nadanym ustawą z dnia 23 stycznia 2026 r. (Dz.U. 2026 poz. 252)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force in 199 days, effective 3 April 2027.

A sector security regimes rule binding public and private bodies.

As of 14 September 2026.

What it requires

  • This duty does not yet fully bind: the amending Act entered into force on 3 April 2026, and Article 33(1) gives an entity that already meets the essential-entity or important-entity criteria on that date until 3 April 2027 to carry out Article 8's information security management system duty; an entity already regulated as an operator usługi kluczowej (essential service operator) under the pre-amendment Act continues to apply the prior Article 8 regime until it has deployed the new system.
  • This binds an essential entity or important entity classified against the Załącznik nr 1 or Załącznik nr 2 sector lists, which name an online marketplace, an internet search engine and a social-networking-service platform (Załącznik nr 2, Dostawcy usług cyfrowych) among the digital service providers it reaches expressly; the wider sector classes the Załączniki also reach (critical-facility operators, energy, transport, health, finance, telecommunications and digital-infrastructure providers, and public administration) are a designation and sector class no activity in this vocabulary expresses, so they are not separately flagged here.
  • Once it applies, implement an information security management system in the information system used in the processes affecting your provision of the service, covering systematic risk assessment and risk management, physical, personnel and supply-chain security, business continuity and disaster-recovery planning, continuous monitoring, effectiveness evaluation, cybersecurity training and basic cyber-hygiene, cryptography, secure communications and multi-factor authentication where appropriate, asset management, and access control.
  • Have the entity's management implement and oversee the system, proportionate to the assessed risk, the entity's size, the cost of implementation, and the likelihood and severity of an incident.
  • Expect an administrative fine of up to EUR 10,000,000 or 2 percent of worldwide annual turnover, whichever is higher, for an essential entity, or up to EUR 7,000,000 or 1.4 percent of turnover for an important entity, for failing to implement the system or for a system that does not meet these requirements.

If you get it wrong

Criminal exposureNo

Private right of actionNo

Criminal exposure note

The Act's own sanction for an Article 8 infringement is an administrative fine (kara pieniężna) under Article 73; no provision reviewed here makes the infringement itself a criminal offence.

Penalty structure

Article 73(3), as amended: the fine for an essential entity's infringement of, among other duties, Article 8 or Article 11 may not exceed EUR 10,000,000, converted to zloty at the National Bank of Poland's average rate on the preceding 31 December, or 2 percent of the entity's turnover in the preceding financial year, whichever is higher, with a floor of 20,000 zloty (about EUR 4,600). Article 73(4) sets an important entity's cap at EUR 7,000,000 or 1.4 percent of turnover, with a floor of 15,000 zloty.

Rule
Higher of
As of
14 September 2026
Currency
EUR
Fixed cap
10,000,000
Turnover percentage cap
2

Who enforces it

Enforcement body

The organ właściwy do spraw cyberbezpieczeństwa (competent authority for cybersecurity) designated for the entity's sector, coordinated by the minister właściwy do spraw informatyzacji (minister responsible for computerisation) and backed by CSIRT NASK, CSIRT GOV, CSIRT MON and the sectoral CSIRTs.

Settledness

As of
14 September 2026
Guidance link
https://www.gov.pl/web/baza-wiedzy/nowelizacja-ustawy-o-krajowym-systemie-cyberbezpieczenstwa
Guidance body
Kancelaria Prezesa Rady Ministrów, portal gov.pl Baza Wiedzy
Open questions
Will the Rada Ministrów rozporządzenie under the new Article 8a, setting sector-specific detail for the information security management system, narrow how the fourteen Article 8(1)(2) categories apply to an online marketplace, internet search engine or social-networking-service platform provider specifically?

What it reaches

Obligation class

Security, Governance

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 8 requires an essential entity or an important entity to implement an information security management system in the information system used in the processes affecting its provision of the service, covering fourteen baseline categories of technical and organisational measure: risk-assessment and information-security policy, secure system acquisition and development, physical and environmental security, personnel security, ICT supply-chain security, business continuity and disaster-recovery planning, continuous monitoring, effectiveness evaluation, cybersecurity training, basic cyber-hygiene, cryptography, secure communications and multi-factor authentication, asset management, and access control, transposing NIS2 Article 21.

Załącznik nr 2 names an online-marketplace provider, an internet search-engine provider and a social-networking-service-platform provider among the digital service providers this duty reaches expressly. The Act entered into force on 3 April 2026, but Article 33(1) of the amending Act gives an entity that already meets the essential-entity or important-entity criteria on that date twelve months, until 3 April 2027, to carry out this duty.

An entity already regulated as an operator usługi kluczowej (essential service operator) under the pre-amendment Act continues applying the prior Article 8 regime until it has deployed the new system.

When LexLint raises it

  • operates_social_platform

Read the law

Dziennik Ustaw text, api.sejm.gov.pl, amending Act of 23 January 2026 (Dz.U. 2026 poz. 252)

Back to the example  ·  Lint your app