Skip to content
Knowledge base Updated: February 5, 2026

National Cybersecurity System Act - Objectives, Definitions, Regulations and Roles

Read about the National Cybersecurity System Act, its objectives, regulations, and roles in protecting IT systems.

The National Cybersecurity System Act is a key legal act in Poland that regulates issues related to cybersecurity and protection of IT systems. This comprehensive regulation introduces a framework for managing cyber threats at the national level and defines the responsibilities of various entities in ensuring digital security. Learn about the main objectives of the act, key definitions, organizational structure of the cybersecurity system, and the roles and obligations of operators of essential services and digital service providers.

Table of Contents

What is the main objective of the National Cybersecurity System Act?

The main objective of the National Cybersecurity System Act is to ensure a high level of cybersecurity at the national level. The act aims to create a coherent and effective system for managing cyber threats, protecting critical infrastructure and IT systems, and coordinating actions of various entities responsible for cybersecurity in Poland.

📚 Read the complete guide: IAM / Zero Trust: Zarządzanie tożsamością i dostępem - od podstaw do Zero Trust

What entities does the National Cybersecurity System cover?

The National Cybersecurity System covers various types of entities, including:

  • Operators of essential services - entities providing services crucial for maintaining key social and economic activities
  • Digital service providers - entities offering digital services such as online marketplaces, cloud computing services, or search engines
  • Authorities responsible for cybersecurity at various levels
  • CSIRT teams (Computer Security Incident Response Teams)
  • Public administration entities

The act precisely defines the criteria for identifying operators of essential services and digital service providers, taking into account the scale of operations, number of users, and significance for the functioning of the economy and society.

What are the key definitions introduced by the act?

The act introduces a number of key definitions that are fundamental to understanding and applying its provisions:

  • Cybersecurity - resistance of IT systems to actions violating the confidentiality, integrity, availability, and authenticity of processed data or related services offered by these systems
  • Incident - an event having or potentially having an adverse impact on cybersecurity
  • Operator of essential services - an entity providing a service crucial for maintaining key social or economic activities
  • Digital service provider - an entity providing digital services
  • CSIRT (Computer Security Incident Response Team) - a team responsible for handling cybersecurity incidents
  • Critical infrastructure - systems and their functionally related facilities serving the provision of essential services

These definitions create a common terminology framework that facilitates communication and cooperation between various entities within the National Cybersecurity System.

How does the act regulate the organization of the National Cybersecurity System?

The act precisely defines the organizational structure of the National Cybersecurity System, which consists of:

  • Government Plenipotentiary for Cybersecurity - coordinates activities within the National Cybersecurity System
  • Single Point of Contact - ensures international cooperation in the field of cybersecurity
  • National-level CSIRT teams - handle cybersecurity incidents in their respective areas
  • Sectoral cybersecurity teams - operate in individual sectors of the economy
  • Authorities responsible for cybersecurity - supervise compliance with act provisions in their areas

This structure ensures effective coordination of actions at various levels and facilitates information flow between individual system elements.

What tasks are assigned to national-level CSIRTs?

National-level CSIRT teams play a key role in the National Cybersecurity System. Their main tasks include:

  • Monitoring cybersecurity threats and incidents
  • Issuing warnings and alerts about current threats
  • Providing support in incident handling to operators of essential services and digital service providers
  • Analyzing incidents and identified threats
  • Cooperating with other CSIRT teams domestically and internationally
  • Conducting activities aimed at increasing public awareness of cybersecurity threats
  • Participating in the development of good practices and standards in the field of cybersecurity

CSIRT teams act as specialized centers of expertise and operational support in the field of cybersecurity.

What role does the Single Point of Contact play?

The Single Point of Contact is a key element ensuring Poland’s international cooperation in the field of cybersecurity. Its main tasks include:

  • Coordinating cooperation with equivalent entities in other European Union Member States
  • Participating in the work of the Cooperation Group established under the NIS Directive
  • Exchanging information on cybersecurity threats and incidents with foreign partners
  • Coordinating Poland’s position in international matters related to cybersecurity
  • Facilitating information flow between Polish entities and international partners

The Single Point of Contact ensures that Poland actively participates in the European cybersecurity cooperation network and can effectively benefit from the exchange of information and experiences with other countries.

What does the Government Plenipotentiary for Cybersecurity deal with?

The Government Plenipotentiary for Cybersecurity is the central coordinating figure in the National Cybersecurity System. Their main tasks include:

  • Coordinating activities within the National Cybersecurity System
  • Monitoring cybersecurity level in the country
  • Initiating and coordinating activities aimed at improving cybersecurity
  • Preparing analyses and forecasts regarding cybersecurity threats
  • Cooperating with authorities responsible for cybersecurity and other entities
  • Representing Poland in international matters related to cybersecurity
  • Supervising the implementation of the Cybersecurity Strategy of the Republic of Poland
  • Coordinating activities of national-level CSIRT teams

The Plenipotentiary plays a key role in ensuring coherence and effectiveness of actions taken to protect cyberspace in Poland.

What obligations does the act impose on operators of essential services?

Operators of essential services are subject to a number of obligations aimed at ensuring an appropriate level of cybersecurity. The main obligations include:

  • Implementing appropriate technical and organizational measures to manage cybersecurity risks
  • Implementing measures to prevent incidents and minimize their impact
  • Reporting significant incidents to the competent CSIRT team
  • Designating a person or organizational unit responsible for maintaining contact with the competent CSIRT team
  • Conducting regular cybersecurity audits
  • Using systems and IT solutions meeting minimum cybersecurity requirements
  • Documenting the applied security measures and incidents

These obligations aim to ensure that operators of essential services maintain an appropriate level of protection for their IT systems and can effectively respond to cybersecurity threats.

How should operators of essential services manage risk?

Risk management is a key element of ensuring cybersecurity by operators of essential services. The act requires operators to implement a systematic approach to risk management, which includes:

  • Identifying assets requiring protection and potential threats
  • Analyzing and evaluating cybersecurity risks
  • Implementing appropriate technical and organizational security measures
  • Continuously monitoring the effectiveness of implemented measures
  • Regularly reviewing and updating risk management procedures
  • Training staff in cybersecurity
  • Testing security procedures and incident response plans

The risk management process should be adapted to the specifics of the operated service and the scale of potential threats. Operators are required to document the risk management process and be able to present it to supervision authorities.

What does the incident reporting and handling process look like?

The incident reporting and handling process is a key element of the National Cybersecurity System. The act defines precise procedures in this area:

  • Detection and identification - operators of essential services are required to implement mechanisms to detect and identify incidents
  • Initial assessment - after detecting an incident, an initial assessment of its scale and impact on service provision is made
  • Notification - in case of a significant incident, the operator is required to immediately notify the competent CSIRT team
  • Handling - the operator takes actions aimed at minimizing the impact of the incident and restoring normal service provision
  • Analysis - after handling the incident, a detailed analysis of causes and effects is conducted
  • Final report - the operator submits a final report on the incident to the competent CSIRT team
  • Lessons learned - based on incident analysis, security procedures and measures are updated

The CSIRT team provides support at all stages of incident handling and can issue recommendations and good practices.

What requirements does the act set for digital service providers?

Digital service providers, although subject to less restrictive requirements than operators of essential services, are also required to ensure an appropriate level of cybersecurity. The main requirements include:

  • Implementing appropriate technical and organizational measures to manage cybersecurity risks
  • Implementing measures to prevent incidents and minimize their impact
  • Reporting significant incidents to the competent CSIRT team
  • Cooperating with authorities responsible for cybersecurity

Digital service providers are also required to maintain documentation of applied security measures and be able to present it upon request from supervision authorities.

How does the act regulate supervision and control issues?

The act establishes a comprehensive system of supervision and control over compliance with cybersecurity requirements. Authorities responsible for cybersecurity have broad powers, including:

  • Conducting inspections at operators of essential services and digital service providers
  • Requesting information and documentation regarding applied security measures
  • Issuing recommendations and orders to remedy identified deficiencies
  • Imposing administrative penalties for violations of act provisions
  • Ordering audits of IT systems

Inspections can be conducted both planned and ad-hoc, particularly in case of suspected serious violations of act provisions or after significant incidents.

What powers do authorities responsible for cybersecurity have?

Authorities responsible for cybersecurity have broad powers enabling effective supervision over compliance with act provisions:

  • Accessing premises and IT systems of controlled entities
  • Reviewing documentation and IT systems
  • Obtaining explanations from employees and representatives of controlled entities
  • Ordering audits and tests of IT systems
  • Imposing administrative penalties
  • Issuing binding recommendations and orders
  • Limiting or suspending the operation of IT systems in case of serious threats

These powers are balanced by procedural safeguards that protect the rights of controlled entities and ensure transparency of supervision.

What penalties does the act provide for violations of its provisions?

The act provides for a system of administrative penalties for violations of its provisions. Penalties can be imposed on:

  • Operators of essential services
  • Digital service providers
  • Other entities subject to act provisions

Penalty amounts depend on the type of violation and can reach up to 1,000,000 PLN. The most serious violations include:

  • Failure to report significant incidents
  • Failure to implement required security measures
  • Obstructing inspections
  • Failure to comply with orders issued by authorities responsible for cybersecurity

Before imposing a penalty, the authority considers the circumstances of the case, including the scale of violation, intentionality of actions, and effects of violation.

How does the act relate to the Cybersecurity Strategy of the Republic of Poland?

The National Cybersecurity System Act creates a legal framework for implementing the Cybersecurity Strategy of the Republic of Poland. The Strategy defines strategic objectives and directions of actions in the field of cybersecurity, while the act provides legal tools and organizational structures for implementing these objectives.

The act requires the Government Plenipotentiary for Cybersecurity to supervise the implementation of the Strategy and prepare reports on progress in its implementation. This ensures coherence between strategic planning and operational actions in the field of cybersecurity.

How does the act implement the NIS Directive?

The National Cybersecurity System Act is the main legal act implementing the provisions of the NIS Directive (Directive (EU) 2016/1148 on measures for a high common level of security of network and information systems across the Union) into Polish law.

The act transposes all key elements of the Directive, including:

  • Identification of operators of essential services
  • Requirements for digital service providers
  • Establishment of CSIRT teams
  • Creation of Single Point of Contact
  • Cooperation mechanisms at national and international levels
  • Incident reporting requirements
  • Supervision and control system

What new economic sectors were covered by the act in the amendment?

Amendments to the National Cybersecurity System Act expanded the list of sectors covered by its provisions. New sectors include:

  • Digital infrastructure
  • Waste management
  • Production and distribution of chemicals
  • Food production, processing, and distribution
  • Manufacturing
  • Digital service providers (expanded definition)
  • Postal and courier services
  • Public administration

Expansion of the sector list reflects the growing digitization of the economy and the need to protect an increasingly wider range of IT systems that are critical for the functioning of the state and society.

The act introduces special regulations regarding the security of 5G networks, reflecting the strategic importance of this technology. Key provisions include:

  • Requirement to conduct security risk assessments for 5G network suppliers
  • Possibility of excluding specific suppliers from participation in building 5G infrastructure
  • Special supervision procedures for 5G network operators
  • Requirements for securing key network components
  • Cooperation with international partners in the field of 5G security

These regulations aim to minimize risks associated with the use of equipment from suppliers who may pose a threat to national security.

What are the deadlines for entities to adapt to new regulations?

The act provides transitional periods allowing entities to adapt to new requirements. Deadlines vary depending on the type of entity and specific obligations:

  • Operators of essential services - generally 6-12 months from the act taking effect
  • Digital service providers - generally 12 months from the act taking effect
  • Specific technical requirements - may have extended deadlines up to 24 months

Deadlines are set to allow entities adequate time to implement necessary changes while ensuring that cybersecurity level is improved as quickly as possible.

Learn key terms related to this article in our cybersecurity glossary:


Learn More

Explore related articles in our knowledge base:


Explore Our Services

Need cybersecurity support? Check out:


See also:

Share:

Talk to an expert

Have questions about this topic? Get in touch with our specialist.

Sales Representative
Łukasz Gil

Łukasz Gil

Sales Representative

Response within 24 hours
Free consultation
Individual approach

Providing your phone number will speed up contact.

Want to Reduce IT Risk and Costs?

Book a free consultation - we respond within 24h

Response in 24h Free quote No obligations

Or download free guide:

Download NIS2 Checklist