Polish Companies Face Major Cybersecurity Changes Under the New KSC Act

LAWPolish Companies Face Major Cybersecurity Changes Under the New KSC Act
- Advertisement -Translation agency in Poland – professional language servicesTranslation agency in Poland – professional language services

Poland’s key and important entities are preparing to meet a broad range of new obligations following the entry into force of the amended National Cybersecurity System Act, known as the KSC Act. They have until 3 April 2027 to implement the required measures, but representatives of Orange Polska warn that reviewing suppliers of services, equipment and technology may require more time.

The telecommunications company is also calling for the introduction of an ISO-style certification system that would help organisations assess their compliance with the new regulations. Orange Polska believes that screening requirements for employees responsible for cybersecurity should also be expanded.

“The National Cybersecurity System Act presents organisations with numerous challenges, particularly operators of critical infrastructure such as Orange Polska,” Sławomir Chmielewski, Security and Compliance Director at Orange Polska, told the Newseria news agency.

“These challenges include demonstrating that the law has been implemented in accordance with the legislator’s requirements, dealing with formal and practical issues such as the scope of screening for candidates who will work with information security management systems, and determining how thoroughly suppliers should be assessed and how quickly this process should be completed.”

According to Chmielewski, the new obligations will require companies to reorganise multiple areas of their operations.

“These are new and highly important requirements. They need to be implemented correctly, but the organisation must also be capable of handling them because the workload is considerable,” he said.

Poland implements the EU’s NIS2 Directive

The amendment to the KSC Act, implementing the European Union’s NIS2 Directive in Poland, entered into force on 3 April 2026. It requires key and important entities to introduce appropriate technical, operational and organisational measures to protect their networks and information systems.

Between 13 April and 6 May 2026, the Minister of Digital Affairs added previously identified operators of essential services, trust service providers, telecommunications companies and public-sector entities to the official register of key and important entities.

Organisations that were not entered in the register automatically can apply for registration independently through the S46 system. The self-registration period runs from 7 May to 3 October 2026.

The new rules cover sectors considered particularly important to the economy and society. These include telecommunications, energy, transport, healthcare, digital infrastructure, financial services, public administration and selected manufacturing and technology activities.

Orange Polska proposes ISO-style certification

Orange Polska argues that the complexity of the KSC Act makes it difficult for organisations to determine whether every requirement has been implemented correctly.

“The Act is a very extensive document covering many different areas. From our perspective, an ISO-style certification system would therefore be a very good idea,” Chmielewski said.

“It would provide important guidance, helping us understand how individual provisions and chapters of the Act should be addressed within a large corporation. A properly verified and audited certificate would also assure our partners and customers that we comply with the law.”

The Ministry of Digital Affairs has prepared a draft list of standards and norms that could support organisations in fulfilling their obligations, particularly those associated with an Information Security Management System.

The list is intended to help entities identify standards covering areas such as system security, risk management, business continuity and supply-chain security. It will, however, be advisory and informational rather than a legally binding source of requirements.

Companies have until April 2027 to implement new measures

Key and important entities that met the statutory criteria when the amendment entered into force have until 3 April 2027 to implement their new obligations.

These include establishing and operating an Information Security Management System, managing cybersecurity incidents, reporting incidents to the relevant Computer Security Incident Response Team and appointing individuals responsible for maintaining contact with other entities within the national cybersecurity system.

Organisations must also begin using the S46 system for statutory communication and incident reporting by the end of the adjustment period.

The implementation process may be especially difficult for companies that have not previously been subject to regulations covering critical infrastructure or essential services.

Supplier verification may require more time

Supply-chain security is expected to be one of the most demanding aspects of compliance.

Organisations must assess the cybersecurity risks associated with the companies from which they purchase equipment, software, technology and individual components of their services. For a large corporation working with numerous domestic and international suppliers, this could involve an extensive review of contracts, procedures and technical safeguards.

“When it comes to supply-chain verification, meaning assessing the companies from which we purchase individual service components or equipment, the adjustment period should be extended by 12 months,” Chmielewski said.

“This would give us a better chance of conducting proper and reliable supplier assessments.”

The proposal would effectively give organisations more time to verify whether suppliers meet the cybersecurity standards required under the amended KSC Act.

Broader screening of cybersecurity employees

Another issue concerns the screening of employees and candidates who will perform cybersecurity-related duties.

Under the new legislation, organisations must verify whether individuals responsible for cybersecurity have been convicted of offences against the protection of information. The entities covered by the Act must complete this process by 3 April 2027.

“An important issue is how we verify employees who will work with the Information Security Management System or handle information security incidents,” Chmielewski said.

“The Act has taken the first step, but in our view the relevant provisions should be formulated more broadly.”

Under the law, cybersecurity duties cannot be performed by people convicted of offences involving the unauthorised disclosure of classified or official information, illegal acquisition of information, destruction of data or disruption of networks and information systems.

Orange Polska believes that the verification process should cover a broader category of offences.

“We believe candidates should also be screened for offences such as terrorism or espionage, because access to sensitive information could create opportunities for this type of activity,” Chmielewski said.

He also argued that organisations should be able to assess potential conflicts of interest and determine whether candidates have links to entities or countries that could create a security risk.

Digital residency could become part of employee screening

Orange Polska is also drawing attention to what it describes as the digital residency of employees.

This refers to the actual country or location from which a person accesses an organisation’s systems and performs their duties, which may be different from the location declared by the employee.

“A candidate may say that they work from a particular country, while in practice digital tools can make it appear that they are working there even though they are physically located elsewhere,” Chmielewski said.

In the company’s view, screening should not be conducted only once during recruitment. It should be repeated periodically, for example every two years, particularly for employees who have access to sensitive systems or handle serious cybersecurity incidents.

According to Chmielewski, similar proposals were discussed during a conference organised by Poland’s Personal Data Protection Office on the implementation of NIS2 and the amended KSC Act.

Other proposals included simplifying cooperation between public authorities and private companies in the reporting and handling of cybersecurity incidents.

“I hope these discussions will result in specific legislative proposals,” the Orange Polska representative said.

First external cybersecurity audits due by April 2028

Key entities that were not previously classified as operators of essential services will have to conduct their first external cybersecurity audit by 3 April 2028.

Subsequent audits will have to be performed at least once every three years. Reports documenting the audits will have to be submitted to the relevant cybersecurity authorities.

From 3 April 2028, the competent authorities will also be able to impose financial penalties for failure to comply with the statutory obligations. In the telecommunications sector, the responsible authority is Poland’s Office of Electronic Communications.

“The level of awareness among companies regarding the obligations introduced by the Act varies significantly,” Chmielewski said.

“It depends largely on whether a company has previously worked with critical infrastructure, whether it is itself a critical infrastructure operator and how mature its cybersecurity systems already are.”

He stressed that even highly experienced organisations will need time to adapt to such extensive legislative changes.

“Regardless of an organisation’s level of awareness or maturity, implementing such a major legal change takes time. Companies for which these requirements are completely new will probably need even more time,” the Orange Polska executive said.

Check out our other content
Related Articles
The Latest Articles