Amendment to the Act on the National Cybersecurity System (UKSC) – published in the Journal of Laws

03. 03. 2026

On 19 February 2026, the President of Poland signed an amendment to the Act on the National Cybersecurity System[1] , thus concluding the legislative process, which had been ongoing for years and involved numerous changes and versions of the draft. At the same time, the President referred the Act to the Constitutional Tribunal for subsequent review.
 
On 2 March 2026, the act amending the existing UKSC was published in the Journal of Laws[2] . Thus, we now know exactly when the deadlines specified therein for organisations to adapt to the new requirements will begin.
 
The long-awaited amendment to the UKSC is one of the most important regulatory changes in recent years in the area of compliance and IT. Its origins lie in the obligation to transpose the EU’s NIS2 Directive[3] into Polish law, which aims to strengthen the cybersecurity of EU Member States.
 
The amendment introduces significant changes in the obligations of entities covered by the regulation and the powers of supervisory authorities, while extending the scope of the UKSC to a much wider range of entities than before.
 

Who is covered by the new regulations?

 
The amendment introduces a division into key entities and important entities, replacing the existing categories of key service operators and digital service providers. Qualification for one of the two categories depends on the sector of activity, the size of the enterprise and its importance for the economy or national security, and will be based on self-identification by the entity concerned. This is one of the fundamental changes compared to the previous model, which involved obtaining the status of a key service operator on the basis of an administrative decision.
 
Among the newcomers to the national cybersecurity system are entities from the following sectors, among others: ICT (information and communication technologies) management, postal services, waste management, and selected entities from the manufacturing and industrial sector (chemicals, food sector, medical devices, computers and electronics). In addition, the circle of entities operating in the sub-sectors of the market covered by the UKSC in its current wording has been expanded. For example, in the energy sector, the new regulations will cover operators of electric vehicle charging infrastructure, and in the digital infrastructure sector – cloud computing providers (who, under the former UKSC, qualified as digital service providers).
 
In practice, this means that, according to estimates, cybersecurity obligations will apply to over 37,500 entities[4] , compared to nearly 400 companies currently classified as operators of essential services.[5]
 

Key changes

 
In addition to expanding the list of entities covered by the Act, the amendment increases digital security obligations, and entities covered by the Act will be required to implement systematic risk management in the area of ICT. More stringent requirements have been introduced, including the implementation of continuity management systems and incident reporting.
 
The authorities responsible for cybersecurity are gaining broader control powers, including the possibility of conducting ad hoc inspections even when it was not possible to notify the inspected entity in advance of the date of the inspection, and the right to access IT systems remotely.
 
The responsibility of management has also been increased, and members of the management board may bear greater personal responsibility for failure to ensure compliance with the regulations.
 
The Act also introduces higher administrative penalties than before. As a rule, the maximum amount of financial penalties increases to EUR 10,000,000 or 2% of the revenue generated by a key entity from its business activities in the financial year preceding the imposition of the penalty, whichever is higher (for important entities, this is EUR 7,000,000 and 1.4%, respectively). We say “as a rule” because if a key or important entity violates the provisions of the Act, causing a direct and serious cyber threat to national defence, state security, public order or human life and health, or a threat of serious property damage or serious disruption to the provision of services, the upper limit of the penalty increases to PLN 100,000,000.
 
The national cybersecurity system will be tightened by the creation of additional sectoral CSIRTs, i.e. Computer Security Incident Response Teams, dedicated to specific sectors of the economy. These will include: CSIRT Cyfra (digital infrastructure sector), CSIRT Infrastruktura (created at the Ministry of Infrastructure – for transport and access to water) Sektor Ochrony Zdrowia (health sector), CSIRT for the energy sector (planned by the Ministry of Climate and Environment).
 

Why is the amendment to the UKSC groundbreaking?

 
The amendment to the UKSC changes the way we think about cybersecurity, which until now has been mainly the domain of IT departments, viewed through the prism of technical infrastructure and its security. From now on, cybersecurity will no longer be treated solely as a technical issue and will become one of the fundamental elements of corporate governance and business strategy.
 
This is most clearly reflected in the change in the very definition of cybersecurity, which under the previous regulations was defined as “the resilience of information systems to actions that violate the confidentiality, integrity, availability and authenticity of the data processed or related services offered by these systems”. This definition focused on the security of IT systems and had its origins in a technological approach centred on protecting IT infrastructure as such. The new concept of cybersecurity, on the other hand, refers to the definition contained in the Cybersecurity Act[6] , according to which cybersecurity is “the measures necessary to protect networks and information systems, users of such systems and other persons against cyber threats.” This modification has far-reaching practical consequences – we protect not only systems, but above all people, and cybersecurity itself changes from “resilience” (a state, a feature of systems) to “action” (i.e. a continuous process), reflecting the requirement for a proactive approach to the digital resilience of an organisation.
 

What entrepreneurs should do now – key dates

 
The Act enters into force one month after its publication.
 
On the date of entry into force of the Act, i.e. 3 April 2026, operators of key services will become key entities.
 
Entities that, as of 3 April 2026 meet the criteria for being considered a key or important entity have 12 months to fulfil the obligations specified in the Act, including, among others, adapting their information security management systems and documentation, implementing the full range of technical and organisational measures provided for in the amendment, and appointing and training personnel responsible for cybersecurity.
 
Entities that meet the criteria for being considered a key entity as of 3 April 2026 shall conduct the first security audit of the information system used in the service provision process within 24 months.
 
By 3 May 2026, the Minister of Digital Affairs is required to create a list of key entities and important entities.
 
Considering the start of the deadlines for implementing solutions compliant with the new regulations and the broad and systemic nature of the new solutions, it is recommended to start working on introducing the new UKSC into the organisation as soon as possible. However, there is no need to panic – the vast majority of financial penalties will only be imposed after two years from the date of entry into force of the Act.
 
In accordance with the transitional provisions, the existing provisions shall apply to inspections and administrative proceedings concerning the imposition of financial penalties initiated and not completed before the date of entry into force of the Act.
 

Recommendations for obligated entities – where to start?

 
First and foremost, companies should analyse whether they are subject to the new regulations. If the result of such verification is positive, we recommend first assessing the compliance of currently implemented solutions with the new requirements, particularly in the area of ICT (gap analysis). As part of adapting the organisation to the requirements of the amended UKSC, it is necessary to develop an implementation schedule from an organisational perspective, in which we will plan adaptation measures taking into account statutory deadlines and secure an appropriate budget after estimating the costs of necessary investments in infrastructure and processes. We also recommend reviewing contracts with IT service providers to ensure that they include the new compliance requirements, and, depending on the needs, preparing or updating internal procedures, including incident reporting procedures, and training management staff.
 
The amendment to the UKSC is not only a regulatory obligation, but also an element of building organisational resilience, and cybersecurity is moving from the technical domain to become a strategic element of organisational management. It is worth taking advantage of the implementation of the new regulations to make a real change in the approach to cybersecurity, significantly increasing resilience to cyber threats and gaining a competitive advantage in the process.
 
If you have any questions about the amendment and its impact on your organisation, please contact our team specialising in new technology and cybersecurity law.
 
Author: Aleksandra Kubiś – attorney-at-law at SKP Ślusarek Kubiak Pieczyk
 
[1] Act of 23 January 2026 amending the Act on the National Cybersecurity System and certain other acts https://www.senat.gov.pl/download/gfx/senat/pl/senatdruki/14231/druk/609.pdf

[2] https://www.dziennikustaw.gov.pl/D2026000025201.pdf

[3] Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 on measures for a high common level of cybersecurity across the Union, amending Regulation (EU) No 910/2014 and Directive (EU) 2018/1972 and repealing Directive (EU) 2016/1148 (NIS2 Directive) https://eur-lex.europa.eu/legal-content/PL/TXT/PDF/?uri=CELEX:32022L2555

[4] https://orka.sejm.gov.pl/Druki10ka.nsf/0/EAE89BDA7AEC8DECC1258D450063FA62/%24File/1955.pdf, p. 1629 et seq.

[5] https://dane.gov.pl/p/dataset/3409/resource/1061314/table?page=1&per_page=20&q=&sort=

[6] Article 2(1) of Regulation (EU) 2019/881 of the European Parliament and of the Council (EU) 2019/881 of 17 April 2019 on ENISA (European Union Agency for Cybersecurity) and cybersecurity certification for information and communications technology and repealing Regulation (EU) No 526/2013 (Cybersecurity Act) (OJ EU L 151 of 07.06.2019, p. 15, as amended)

Contact

Warsaw

Ks. Skorupki Street 5
00-546 Warsaw

Sopot

Armii Krajowej Street 116/17
81-824 Sopot
+48 22 230 2655biuro@skplaw.pl
More
Copyright 2022 Privacy Policy Terms and conditions