**The six-year saga surrounding key legislation for the country’s cyber security is nearing its finale. The Council of Ministers has adopted a draft amendment to the NSC Act, implementing the NIS2 Directive. Deputy Prime Minister Gawkowski is counting on swift parliamentary proceedings and the president’s signature later this year. **
After six years of legislative saga, work on one of the most important pieces of legislation for Poland’s cyber security is finally gaining momentum. The Council of Ministers adopted a draft amendment to the National Cyber Security System (KSC) Act on Tuesday, October 21. This is a key moment that the industry has been waiting for for years, as the legislation implements the EU’s NIS2 directive into Polish law. Deputy Prime Minister and Minister of Digitization Krzysztof Gawkowski is determined to see the legislative process in parliament completed later this year, as he has emphasized in recent weeks.
The importance of the project was emphatically stated by Prime Minister Donald Tusk, who said during the public part of the government meeting that “cyber security is crucial from the perspective of internal and external security.” He also pointed to the need to ensure full control over equipment used by state institutions. The bill will now go on the parliamentary track, where it will be processed by the Sejm and the Senate.
The adoption of the draft by the Council of Ministers is a watershed moment for Polish cyber resilience. Experts have been pointing out for years that delays in the implementation of the NIS2 directive could not only lead to sanctions from the European Union, but above all expose Polish companies and institutions to growing cyber threats. With attacks from hostile states and organized crime groups on the rise, the lack of adequate regulation has been a major gap in national security.
Shortcuts
- What is the amendment to the National Cyber Security System Act and why should Polish companies and institutions take an urgent interest in it?
- Why did it take as long as six years to work on the amendment to the NSC law, and what was the main reason for the delays in implementing the NIS2 directive?
- Does Deputy Prime Minister Krzysztof Gawkowski ensure rapid implementation of the KSC law, and what will he do to ensure that the legislative process is completed later this year?
- When exactly did the Council of Ministers adopt the draft amendment to the KSC law, and what does this mean for the legislative process going forward?
- Why does Prime Minister Donald Tusk consider cyber-security to be an absolute state priority, and how important is it to Poland’s national security?
- What specific requirements for the control of IT equipment and the replacement of devices in state institutions will the new KSC Law introduce?
- When will the bill on the KSC go to the Diet and the Senate, and what is the timetable for the amendment to be processed in parliament?
- Will the president sign the amendment to the KSC law, and what steps will Minister Gawkowski take to secure the support of the head of state?
What is the amendment to the National Cyber Security System Act and why should Polish companies and institutions take an urgent interest in it?
The amendment to the Law on the National Cyber Security System (NSC) is a fundamental legal change, the main purpose of which is to implement the European NIS2 Directive in Poland. The directive significantly expands the catalog of entities that will be considered crucial to the functioning of the state and the economy, imposing a number of stringent cyber security obligations on them. Among other things, the draft provides for the creation of sectoral incident response teams (sectoral CSIRTs) and a significant expansion of the list of entities covered by the NSC system, which will include thousands of new companies from more than a dozen industries.
The previous law on the KSC, in effect since 2018, covered a relatively narrow group of entities, mainly in the energy, transportation, banking or health care sectors. The new regulation radically changes this situation, expanding the list to include additional sectors, including ICT service management, postal and courier service providers, waste management, production and distribution of chemicals, food production, and the digital sector including cloud service providers and data centers.
The key change is the introduction of two categories of entities: key entities and important entities. Each of these categories will have specific responsibilities, with key entities subject to more stringent requirements. Companies will have to implement comprehensive information security management systems, conduct regular security audits, train employees, and immediately report serious security incidents to competent authorities.
For entrepreneurs, this means the need to prepare for the new legal requirements. Experts estimate that up to a dozen thousand Polish companies that have not been covered by the KSC system so far may fall under the new regulations. They will have to conduct audits of their IT infrastructure, implement appropriate security procedures and allocate budgets for training and system upgrades. Ignoring these obligations could result in severe financial penalties, which, according to the NIS2 directive, could reach up to €10 million or 2% of a company’s global annual turnover.
It is also worth noting that the new regulations impose personal liability on corporate executives. Boards of directors and supervisory boards will be required to actively supervise the implementation of cyber-security measures, and their negligence could result in legal consequences. This is a significant change in the approach to cyber security, which is expected to raise the profile of these issues at the highest decision-making level in companies.
📚 Read the complete guide: IAM / Zero Trust: Zarządzanie tożsamością i dostępem - od podstaw do Zero Trust
Why did it take as long as six years to work on the amendment to the NSC law, and what was the main reason for the delays in implementing the NIS2 directive?
The legislative saga surrounding the amendment of the NSC has been going on for six years, even though the deadline for implementation of the NIS2 directive passed on October 17, 2024. Throughout this time, successive versions of the draft and proposed amendments have appeared, and the process has been significantly delayed. The delays were explained in various ways. On the one hand, the high degree of complexity of the matter was pointed out, especially in the context of the much debated regulations on high-risk suppliers. On the other hand, there was no shortage of voices pointing to protracted legislative processes at the EU level as the reason for the delay.
The history of the amendment has been a string of controversies and political disputes. The first version of the draft appeared as early as 2019, when work began on adapting Polish law to EU requirements. However, the following years brought a series of changes and revisions, and the draft was repeatedly returned to the drawer. One of the most contentious elements was the legislation on so-called “high-risk suppliers,” which was supposed to restrict the use of hardware and software from countries considered a potential threat to national security.
The issue of high-risk providers has become the subject of intense lobbying efforts by both domestic and foreign players. Telecommunications operators argued that overly restrictive regulations could lead to costly infrastructure replacement and delays in the development of 5G networks. Representatives of the security sector, on the other hand, stressed that without stringent restrictions, Poland would remain vulnerable to industrial espionage and hybrid activities by hostile states.
Further complicating the work were changes in the political scene. The legislative process went through the terms of different governments, each of which had slightly different cyber security priorities. The change of power in 2023 brought a new approach to the subject, but also the need to re-examine the draft and make further modifications. Each change of government team also meant a reorganization of legislative priorities, which translated into months of delays.
Changes to the NIS2 Directive itself at the European level were also not insignificant. Work on the EU legislation also dragged on, and the final version of the directive was not adopted until December 2022. This, in turn, required updating the Polish draft to ensure full compliance with EU requirements. Experts point out that Poland is not an isolated case - many member states are also struggling with delays in implementing the NIS2 directive, although few have missed the implementation deadline in such a spectacular way.
Also problematic was the extensive public consultations, which revealed numerous discrepancies between the positions of various industries and institutions. Each sector had its own specific needs and concerns about the new regulations. The energy sector was worried about the cost of upgrading critical infrastructure, the IT industry was concerned about excessive bureaucracy, and health sector players cited insufficient financial and human resources to meet the new requirements. Finding a compromise between these diverse interests took time and numerous negotiations.
Does Deputy Prime Minister Krzysztof Gawkowski ensure rapid implementation of the KSC law, and what will he do to ensure that the legislative process is completed later this year?
Deputy Prime Minister and Minister of Digitization Krzysztof Gawkowski has repeatedly stressed his determination to complete work on the amendment as soon as possible. The minister stressed that he would do his utmost to ensure that the draft is approved by the Council of Ministers and then quickly adopted by parliament. The Deputy Prime Minister stressed that the national cyber security system is one of the main elements of building the country’s resilience, and various forces have tried to block this work for years.
Minister Gawkowski’s position is clear and uncompromising. In his public speeches, he has made no secret of his frustration over years of delays and has made it clear that the new government is prioritizing cyber security. The minister has repeatedly announced that he will personally oversee the legislative process at every stage to avoid further delays.
Gawkowski also outlined a specific timetable for action. Once the draft has been approved by the Council of Ministers, his ministry will work actively with parliamentary committees to ensure that the law proceeds smoothly. The minister also announced a series of meetings with parliamentarians of different political options to build the broadest possible support for the project. He realizes that a bill of such fundamental importance to state security should gain cross-party support.
However, the deputy prime minister is not limited to strictly legislative measures. The Ministry of Digitization has already begun preparatory work to facilitate the implementation of the new regulations. Guidelines and training materials are being prepared for entrepreneurs who will have to adapt to the new requirements. The Ministry is also planning an information campaign to make companies aware of the upcoming changes and give them time to prepare for the new legal reality.
Minister Gawkowski also emphasizes the international context of NIS2 implementation. As a member state of NATO and the European Union, Poland is on the front line in cyberspace. Delays in implementing key regulations not only expose the country to EU sanctions, but more importantly weaken the country’s ability to counter growing cyber threats from hostile states and criminal organizations.
In his speeches, the Deputy Prime Minister repeatedly referred to specific threats facing Poland in cyberspace. He pointed to the growing number of ransomware attacks on Polish companies and institutions, attempts to infiltrate critical infrastructure and disinformation campaigns conducted by hostile states. According to Gawkowski, effective protection against these threats requires not only modern technical tools, but above all a coherent legal framework that defines the duties and responsibilities of all participants in the digital ecosystem.
When exactly did the Council of Ministers adopt the draft amendment to the KSC law, and what does this mean for the legislative process going forward?
As announced, the Council of Ministers dealt with the draft during its Tuesday, October 21 meeting. According to Deputy Minister of Digitization Pawel Olszewski, the government approved the draft amendment to the KSC law. This means that work at the government level has been completed, and the draft is ready to be sent for further work in parliament.
The decision of the Council of Ministers closes an important stage in the legislative process and paves the way for parliamentary work. The draft, which has been repeatedly consulted, revised and agreed upon between various ministries over the years, has finally received the green light from the highest executive body. This is a historic moment that shows that the current government treats the issue of cyber security as one of the key priorities of national security policy.
The approval of the draft by the Council of Ministers means that the document has gone through all the necessary inter-ministerial agreements. The ministries responsible for the key economic sectors that will be covered by the new regulations have expressed their opinions, including the Ministry of Infrastructure, the Ministry of Health, the Ministry of Climate and Environment and the Ministry of State Assets. The project has also received opinions from the Internal Security Agency and the Military Counterintelligence Service, highlighting its national security dimension.
It is worth noting that the timely consideration of the project by the Council of Ministers is a direct result of Deputy Prime Minister Gawkowski’s determination to prevent further delays. The minister personally sought to place the project on the agenda of the cabinet meeting and actively worked with other members of the cabinet to dispel any doubts and ensure unanimous support for the document.
The parliamentary procedure, which will begin in the coming days, will be another test for the bill. The bill will first go to the Sejm, where it will be referred to the relevant committee - most likely to be the Committee on Digitization, Innovation and Modern Technologies. MPs will have the opportunity to submit amendments and comments, although both the government and the ruling coalition declare their willingness to proceed quickly without unnecessary corrections that could further delay the implementation of the NIS2 directive.
Parliamentary experts indicate that with proper coordination and political will, the bill could pass through the Diet and Senate in a matter of weeks. Securing broad political support to avoid prolonged debates and disputes will be key. Minister Gawkowski said he will personally participate in the work of the parliamentary committee to answer MPs’ questions and convince those hesitant to support the bill.
Why does Prime Minister Donald Tusk consider cyber-security to be an absolute state priority, and how important is it to Poland’s national security?
Prime Minister Donald Tusk, during the public part of the cabinet meeting, left no doubt about the importance the current cabinet places on the issue of cyber security. He stated bluntly that “today cyber security is crucial from the perspective of internal and external security.” The prime minister also emphasized the geopolitical dimension of this struggle, saying: “Whoever loses the confrontation in cyberspace loses on all other fields. This is where the fate of war is decided.”
Prime Minister Tusk’s words are part of a broader geopolitical context in which cyberspace has become a key field of competition between states. Contemporary conflicts, as the example of the war in Ukraine shows, have a significant cyber dimension. Attacks on critical infrastructure, disinformation campaigns on social media, sabotage of communications and management systems - all of these are an integral part of modern warfare and hybrid warfare.
Prime Minister Tusk is well aware of the threats facing Poland. As Ukraine’s neighbor and a NATO member located on the Alliance’s eastern flank, Poland is a natural target for cyberattacks from hostile states. Polish government institutions, energy companies, critical infrastructure operators and the financial sector regularly record unauthorized access attempts, DDoS attacks or phishing campaigns targeting employees.
According to the Prime Minister, strong cyber resilience is not just a matter of protecting data or information systems, but a fundamental element of state sovereignty. In the digital age, a state that cannot effectively protect its cyberspace loses control over key aspects of government, economy and society. That is why Donald Tusk’s government is treating the implementation of the NIS2 directive as a strategic priority that cannot be further postponed.
The prime minister also stressed the economic dimension of cyber security. Polish companies, especially those involved in exports and working with foreign partners, are increasingly faced with the requirement to have cyber security certificates and standards. Thus, the lack of appropriate regulations and verification mechanisms can be a barrier to accessing international markets and cooperating with foreign counterparties.
What specific requirements for the control of IT equipment and the replacement of devices in state institutions will the new KSC Law introduce?
Donald Tusk paid special attention to the issue of equipment on which state institutions work. He noted that there must be full control over this equipment. He also stressed the need for systematic replacement of equipment in those places where there is an increased risk. He cited the country of origin of the equipment and the lack of adequate technical support from the manufacturer as reasons for this risk, among others.
The issue of control over IT equipment in state institutions is one of the most controversial, yet most important, elements of the new law. Provisions on so-called high-risk suppliers are aimed at limiting the possibility of using in Poland’s critical infrastructure hardware and software from manufacturers that may be influenced by hostile states or secret services.
In practice, this means that state institutions and entities deemed crucial to the functioning of the state will have to undergo detailed verification of their technological park. Network equipment, telecommunications systems, servers and cloud solutions will be subject to special scrutiny. If equipment or software from high-risk vendors is identified, these entities will be required to develop a plan to replace such equipment within a specified timeframe.
Prime Minister Tusk made it clear that this is not about arbitrary decisions or discrimination against specific manufacturers, but about rational risk management based on the analyses of secret services and cyber security experts. The country of origin of equipment is an important risk factor, especially when we are talking about countries that pursue aggressive policies in cyberspace or are involved in conflicts with NATO countries.
The second key aspect raised by the prime minister is the issue of technical support. IT equipment requires regular security updates, patches to fix identified vulnerabilities, and support from the manufacturer in case of incidents. The lack of such support - whether due to the end of a product’s life cycle or for political reasons - makes the equipment in question particularly vulnerable to attacks. The new law is intended to put in place mechanisms to monitor the status of technical support for critical systems and force their replacement before they become a security threat.
Implementing these requirements will entail significant costs, especially for large state institutions that have spent years building their IT infrastructure. However, the government has announced a financial support program to help public entities cover the costs of replacing high-risk equipment. Details of this program are expected to be unveiled in the coming weeks.
When will the bill on the KSC go to the Diet and the Senate, and what is the timetable for the amendment to be processed in parliament?
Once the draft has been approved by the Council of Ministers, the next step is to send it to parliamentary work. The amendment will now be handled by the Sejm and then the Senate. Deputy Prime Minister Krzysztof Gawkowski expressed hope that both chambers of parliament will carry out the legislative process smoothly, so that the law will be passed later this year.
The timetable for parliamentary work is currently being intensively agreed between the government and the Sejm leadership. In the coming days, the draft will go to the Speaker of the Sejm, who will refer it for the first reading. According to the procedure, the first reading can be held at the plenary session of the Sejm or immediately in a committee - the decision on this is up to the Speaker after consultation with the Convention of Seniors.
Given the urgent nature of the project and the missed deadline for the implementation of the NIS2 Directive, it is highly likely that the law will be placed under the urgent procedure. This would mean a shortening of some procedural deadlines and the possibility of faster proceedings. However, the decision on the urgent procedure requires the consent of a majority of MPs, which in turn depends on the commitment of the ruling coalition and possible support from the opposition.
After the first reading, the draft will go to a parliamentary committee - most likely the Committee on Digitization, Innovation and Emerging Technologies, possibly as the lead committee in cooperation with other industry committees. It is at the committee stage that MPs will have the opportunity to study the draft in detail, question experts and submit amendments. The Ministry of Digitization said it would fully involve its representatives in the committee’s work in order to be able to respond to parliamentarians’ questions and concerns on an ongoing basis.
The second reading of the draft at the Sejm plenary session will provide an opportunity for political debate and voting on any amendments tabled in committee. If the process goes smoothly, the second and third readings could even take place within a single session of the Sejm, although a scenario in which several days or weeks pass between these stages is more likely.
After adoption by the Sejm, the bill will go to the Senate, which will have 30 days to consider it (or 14 days in the case of the urgent procedure). The Senate can adopt the bill without amendments, introduce amendments, or reject it in its entirety. In the case of amendments, the law returns to the Sejm, which must respond to them. Only after this process is completed is the law forwarded to the President for signature.
Deputy Prime Minister Gawkowski hopes to complete the entire parliamentary process before the end of the year. This is an ambitious but realistic timetable, provided there are no serious political disputes or extensive amendments requiring lengthy negotiations. Agreement between the government coalition and at least some of the opposition will be key, to ensure that the bill gains the broadest possible political support.
Will the president sign the amendment to the KSC law, and what steps will Minister Gawkowski take to secure the support of the head of state?
After the bill is passed by both houses of parliament, the final legislative stage is the president’s signature. Krzysztof Gawkowski said he will actively seek the support of the head of state for the new legislation. The Deputy Prime Minister stressed that the signing of this law is important from the perspective of the state and strengthening Poland’s cyber resilience.
The president’s role in the legislative process is crucial - he can sign a law, veto it or refer it to the Constitutional Court for preventive control of constitutionality. A presidential veto can then be passed by the Sejm with a 3/5 majority, but such a scenario always leads to further delays and political tensions.
Minister Gawkowski realizes that securing the President’s support for the KSC law is crucial for its swift entry into force. Therefore, he announces active efforts to build consensus with the President’s Office already at the stage of parliamentary work. Working meetings are planned with the President’s advisors and representatives of the National Security Office, during which the government will present the rationale for the new legislation and respond to any concerns.
The Deputy Prime Minister stresses that the KSC law should not be subject to political disputes or party games. This is legislation that addresses fundamental issues of state security and protection of national interests. In this regard, the minister hopes that the president, regardless of possible political differences with the government, will appreciate the importance of the bill and the need for its prompt implementation.
In his public statements, Gawkowski has repeatedly pointed to the international context of NIS2 implementation. Poland is already late with implementation, which exposes the country to proceedings by the European Commission. Each further month of delay increases the risk of financial penalties and diminishes Poland’s image as a responsible member of the European Union. The minister hopes that these arguments will be convincing to the President’s Office.
It is also worth noting that the president has 21 days to decide whether to sign the law. In the case of a law of key importance to state security, one can expect the head of state to use this time to carefully analyze the legislation and consult with experts. Minister Gawkowski announced that the Ministry of Digitization is ready to fully cooperate with the President’s Office at this stage to dispel any doubts and ensure that the law is signed without unnecessary delays.
An optimistic scenario assumes that if the parliament passes the bill in December, the president could still sign it before the end of the year or in the first days of January 2026. This would give Poland a chance to begin actual implementation of the NIS2 directive as early as the first quarter of next year, although it will take many more months to make up for the months-long delay and fully comply with EU requirements.
Related Terms
Learn key terms related to this article in our cybersecurity glossary:
- Security Operations Center (SOC) — Security Operations Center (SOC) is a central location where a team of security…
- SOC as a Service — SOC as a Service (Security Operations Center as a Service), also known as…
- Network Security — Network security is a set of practices, technologies, and strategies aimed at…
- Cybersecurity — Cybersecurity is a collection of techniques, processes, and practices used to…
- Cybersecurity Incident Management — Cybersecurity incident management is the process of identifying, analyzing,…
Learn More
Explore related articles in our knowledge base:
- Amendment to the NSC Act (NIS2): What new obligations await Polish companies and how to prepare for them?
- How to Wisely Choose a Partner for the Cybersecure Local Government Program?
- DORA: one year of application - how the regulation changed the financial sector
- GDPR: eight years of application - how data protection has evolved in Europe
- How CD PROJEKT RED Prepared Work Environment for Developers and Artists
Explore Our Services
Need cybersecurity support? Check out:
- NIS2 Compliance - NIS2 directive compliance
- NIS2 Readiness Check - NIS2 readiness assessment
- Security Audits - comprehensive security assessment
Related topics
See also:
