NIS2 in Poland — the KSC amendment in force, a 3 October registration deadline, and three CSIRTs.
Poland's transposition cleared its parliament in a single early-2026 sequence: the Sejm on 23 January, the Senate on 28 January, presidential signature on 19 February, publication in the Dziennik Ustaw on 2 March 2026 — in force from 3 April 2026. The amendment rebuilds the national cybersecurity system (KSC) around NIS2 categories and keeps the country's distinctive three-CSIRT structure: NASK for the private sector, GOV for public administration, MON for defence, with sectoral CSIRTs alongside.
The nearest clock is close: registration and self-identification are due by 3 October 2026 — weeks away, not months. Security measures follow by 3 April 2027, and the first audit of essential entities runs to 3 April 2028. The amendment also brings high-risk-vendor decision powers into the KSC framework — the mechanism that can reshuffle a supply chain overnight.
Who it applies to
Essential and important entities across the NIS2 sectors, with sector determining CSIRT routing — NASK for private-sector entities, GOV for public administration, MON for defence and security, sectoral CSIRTs alongside. Registration is due by 3 October 2026; security measures by 3 April 2027; the first audit of essential entities by 3 April 2028. Entities crossing thresholds later register without delay.
The clock
Competent authority: CSIRT NASK, CSIRT GOV and CSIRT MON + sectoral CSIRTs under the KSC. Transposition: KSC Act amendment (Dz.U. 2026).
| When | What happens |
|---|---|
| 23 Jan – 2 Mar 2026 | Sejm, Senate, presidential signature, Dziennik Ustaw · amendment enacted |
| 3 Apr 2026 | Amendment enters into force · KSC rebuilt around NIS2 |
| 3 Oct 2026 | Registration / self-identification deadline |
| 3 Apr 2027 | Security-measures implementation due |
| 3 Apr 2028 | First audit of essential entities — window closes |
Three-CSIRT structure, sector-based routing
Poland's three-CSIRT structure is genuinely distinctive among member states. CSIRT NASK handles the private sector, CSIRT GOV handles public administration, CSIRT MON covers defence and security, and the 2026 amendment adds sectoral CSIRTs on top. Most countries operate a single national CSIRT; Poland operates several, and the routing question is not obvious from the directive text. For organizations subject to NIS2 in Poland, incident reporting depends on sector and entity classification, not just on whether thresholds are met. TruSecure's incident workflow routes to the correct CSIRT from the entity's facts, and the 2026 amendment's high-risk-vendor powers are one more reason the supplier register is a live record rather than a spreadsheet.
What it asks, in operating terms
Read as an operating requirement rather than a legal text, the Poland transposition reduces to a handful of standing asks — each answerable with evidence on demand, not reconstructed when the authority asks for it.
| What the law asks | Where it is answered |
|---|---|
| Register by 3 October 2026 | Entity profile · classification and registration facts held as records, deadline live |
| Determine your CSIRT routing | Applicability engine · sector and entity class route NASK, GOV or MON |
| Implement security measures by 3 April 2027 | Control library · continuously evidenced, gap list dated |
| Report incidents to the correct CSIRT | Incident workflow · clocked, routed by sector |
| Prepare for the first audit by 3 April 2028 | Audit trail · evidence assembled continuously, sealed exports |
What you'd actually look at
In the dashboard, every figure opens on click to the control, the evidence and the person behind it. This excerpt is what a readiness file is made of:
- CSIRT routing
- CSIRT NASK · private-sector entity confirmed
- Registration
- due 3 Oct 2026 · prepared, facts complete
- Measures deadline
- 3 Apr 2027 · 82/99 evidenced, 17 open with owners
- High-risk vendors
- 28 suppliers screened · none designated to date
- Export
- sealed · sha256:8c4e...5b2f
Where teams usually start
With a demo walked through by TruSecure — your CSIRT routing identified, the controls you already operate mapped against the April 2027 measures deadline, and the 3 October registration facts prepared. A Resilience Sprint produces the first baseline; the subscription keeps it current. Packaging is scoped in the conversation, not a price list.
TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.
The short answer
NIS2 (Directive (EU) 2022/2555) is enforced in Poland by CSIRT NASK, CSIRT GOV and CSIRT MON + sectoral CSIRTs under the KSC. TruSecure determines applicability against Poland's national transposition specifically, rather than the EU baseline alone, and maps its requirements to a single control model shared across every framework it supports. TruSecure is operated by European entities — TRUSECURE S.R.L. in Romania and Trusecure Ltd in the United Kingdom — and stores all Customer Content with a single EU sub-processor in French and German datacentres. No Customer Content is transferred to the United States or to Asia, so the EU–US Data Privacy Framework is not a dependency.