New Draft Amendment to the Cybersecurity Act – Commentary by Aleksandra Kubiś

10. 06. 2025

Last Friday (6 June), the sixth version of the draft amendment to the Act on the National Cybersecurity System (dated 16 April 2025) was published. This marks another stage in aligning Polish law with the NIS2 Directive. Compared to the version dated 7 February, the new draft does not introduce any groundbreaking changes, but it does contain several important adjustments and clarifications that may have a tangible impact on both public and private sector entities.
 

    • In the area of identification and personal data, the draft introduces the possibility of using European electronic identifiers instead of the PESEL number for the purposes of the register of essential and important entities. Additionally, access to certain data in the ICT system has been restricted to the minister competent for digital affairs and designated entities.
    • The new provisions expand the cooperation of CSIRTs with the National Bank of Poland and the Minister of Foreign Affairs. They also introduce a clean criminal record requirement for individuals performing tasks within CSIRT GOV, CSIRT NASK, and CSIRT MON.
    • Certain aspects of administrative procedure have been further clarified. The new draft requires a mandatory justification when refusing to remove an essential or important entity from the register—where the competent authority finds that the entity still meets the criteria for inclusion despite its request for removal. The rules for submitting applications for entry, amendment, or removal from the register have also been described in more detail.
    • A notable novelty is the introduction of a financial support scheme. The minister competent for digital affairs is to be responsible for co-financing activities that promote the development of cybersecurity—particularly in areas such as education, certification, and the promotion of best practices. This is a significant innovation, and the new provisions (Articles 45a–45c) provide a legal basis for practical support of cybersecurity transformation—applicable to both public and private entities. This is a development worth monitoring closely.
    • This time, there are no systemic changes in the area of sanctions and liability. However, the rules for determining financial penalties in cases of corporate transformations have been clarified. The maximum penalty limits remain unchanged.

 
The draft will now be reviewed by the Standing Committee of the Council of Ministers.
 
Although the deadline for implementing the NIS2 Directive expired in October 2024, delays and the lack of a final version of the Act may mean that the amended Cybersecurity Act will not enter into force until the second half of 2025.
 
The legislative process is progressing slowly but steadily. This is a good time to examine cybersecurity requirements from a practical standpoint and begin preparations—before the changes become binding. If you would like to discuss the impact of NIS2/KSC on your organisation, we invite you to get in touch.
 
Author: Aleksandra Kubiś – attorney-at-law at SKP Ślusarek Kubiak Pieczyk.

Contact

Warsaw

Ks. Skorupki Street 5
00-546 Warsaw

Sopot

Armii Krajowej Street 116/17
81-824 Sopot
+48 22 230 2655biuro@skplaw.pl
More
Copyright 2022 Privacy Policy Terms and conditions