All postsJournal · post 04 / 04
No jargon

Short answer: The amendment to the Polish National Cybersecurity System Act (KSC), which transposes the NIS 2 directive, has applied since 3 April 2026. Under it, a district office (starostwo) is a key entity, as is a municipal office employing at least 50 people, while smaller offices and local-government organisational units are generally important entities. Responsibility for carrying out the obligations rests with the head of the entity, even where these have been delegated to someone else. There are 12 months to implement the requirements, i.e. until 3 April 2027, and penalties may be imposed for the first time after two years from the Act's entry into force. The first step is not technical: it is a structured inventory of systems, owners, contracts and risks.

This post is for district heads (starostowie), heads of municipalities (wójtowie), mayors (burmistrzowie), secretaries and treasurers (skarbnicy). It does not describe how to secure systems, as that is a task for IT staff and security specialists. It sets out what the Act means for those who sign off decisions and the budget.

What has changed, and from when

The Act of 23 January 2026 amending the Polish National Cybersecurity System Act (Journal of Laws of 2026, item 252) entered into force on 3 April 2026. It introduced a distinction between key entities and important entities, and local-government offices are named explicitly within it, in the "public entities" sector.

Transitional deadlines that leadership should be aware of:

  • 12 months to fulfil the obligations set out in Chapter 3 of the Act, counted from its entry into force. For offices covered by the Act from the outset, this means 3 April 2027.
  • 24 months for the first audit of the information system's security. This applies to key entities; the audit is subsequently repeated at least once every 3 years.
  • Financial penalties may be imposed for the first time after 2 years from the Act's entry into force, i.e. after 3 April 2028.

The register of key and important entities has been operating since 13 April 2026. The minister responsible for digitalisation enters public entities into it ex officio, and subsequently calls on them to supply any missing data. There are 6 months from service of the request to complete this, on pain of a penalty. It is worth checking whether such a request has already reached the office, and who is dealing with it.

Self-registration and public offices. The deadline for self-registration in the register passed on 3 October 2026, but according to a Ministry of Digital Affairs announcement, this applied to organisations that register themselves, such as companies. Public entities are entered ex officio and do not submit an application for entry. Their task begins once they receive a request: they then need to complete the data in the register. An office that has not yet received such a request is therefore not late with self-registration, but it is worth establishing who in the office receives such correspondence, and whether organisational units and municipal companies (spółki komunalne) have checked their status separately. The announcement does not describe the consequences of missing the 3 October deadline, so I am not drawing any conclusions about penalties from it.

Does the Act apply to our office

Annex 1 to the Act, in the "public entities" sector, lists, among others:

  • district offices (starostwo powiatowe), regardless of size;
  • municipal offices (urząd gminy), if on 1 January of a given year they employ at least 50 people under employment contracts, calculated as full-time equivalents.

These units are key entities. An important entity, in turn, is a public entity that is not a key entity but is a local-government budgetary unit, a local-government budgetary establishment, a local-government cultural institution, or a company performing tasks of a public-utility nature, provided it carries out a public task using information systems. Smaller municipal offices and local-government organisational units therefore also have obligations, albeit a narrower set. It is worth confirming each unit's status with the office's legal counsel.

A key entity implements the full information security management system described in Article 8 of the Act and undergoes an audit. An important entity that is a public entity applies instead the shorter list of requirements set out in Annex 4. The Act also allows local-government units to organise joint handling of these obligations, or to delegate them by agreement to one of the units.

What the Act requires of the head of the entity

These provisions cannot be delegated to the IT department. Under Article 8c, the head of the entity is responsible for carrying out cybersecurity obligations, even where some or all of them have been delegated to another person. In a public-finance-sector unit, the "head" is the head of the unit within the meaning of the Public Finance Act.

Article 8d lists what the head of the entity must do personally:

  1. take decisions on the preparation, implementation, application, review and oversight of the information security management system;
  2. plan adequate financial resources for these obligations;
  3. assign tasks and supervise their performance;
  4. ensure that employees are aware of their duties and internal regulations;
  5. ensure that the entity's operations comply with the law.

On top of this comes training: the head of the entity and any person to whom obligations have been delegated must undertake it once per calendar year, and attendance must be documented (Article 8e).

For financial oversight

Point two is a task for now. The draft 2027 budget is drawn up in autumn, and the 3 April 2027 deadline falls within that budget year. A "cybersecurity" budget line cannot be costed reliably without knowing how many systems the office has, who maintains them, and which contracts will need to change. The treasurer (skarbnik) is entitled to ask for that groundwork.

What are the sanctions

A financial penalty can be imposed on the entity and separately on its head.

For a key entity, the penalty ranges from PLN 20,000 to EUR 10 million, or 2% of business revenue; for an important entity, from PLN 15,000 to EUR 7 million, or 1.4%. The authority takes into account the public entity's financial capacity when setting the amount.

The head of a public entity may be fined up to 100% of their remuneration (Article 73a). Grounds for this may include, among others, failure to perform the obligations under Articles 8 and 8d, or failure to complete training.

Why the first step is an inventory

Annex 4, the list of requirements for an important entity that is a public entity, opens with the following item: an inventory of the ICT products, services and processes used to process information. A key entity, in turn, must systematically assess risk, manage assets and ensure the security of its supply chain. None of these obligations can be fulfilled if the office does not know what it has.

Analogy for the board

An insurer cannot price a policy on a building that nobody can describe: how many storeys it has, who holds the keys, when the installations were last inspected. Security specialists likewise need, first of all, a list of what they are meant to protect.

The office's own team can prepare the inventory. It should cover four things:

  • Systems. Every system and service used by the office and its units, including those purchased by departments outside the IT division.
  • Owners. Who in the department is responsible for the system, and who decides on access to it.
  • Contracts. The supplier, term, scope of service, security provisions, and what happens once the contract ends.
  • Risks. What happens if the system stops working, and how long the office can operate without it.

What to ask IT staff and security specialists

The head of the entity does not need to assess technical solutions. They should obtain clear answers to a few questions:

  1. Are we a key entity or an important entity? What is the position for our organisational units and companies?
  2. Has a request to complete data in the register arrived, and who is responsible for the deadline?
  3. Do we have an up-to-date inventory of systems, services and contracts? When was it last checked?
  4. Who carries out the risk assessment, and where is it documented?
  5. To whom, and by what procedure, do we report a serious incident? The Act requires notification without delay, no later than 72 hours after detection.
  6. Which tasks will we carry out ourselves, which jointly with other units, and which will we outsource?
  7. How much will this cost in 2027, and which parts are mandatory versus discretionary?

Without an answer to the third question, the rest will be guesswork.

Sources

Legal status as at 4 October 2026. This post does not constitute legal advice or security advice.

Does a small municipal office also fall under the Act?
An office employing fewer than 50 people is not a key entity, but as a local-government budgetary unit carrying out public tasks using information systems, it is generally an important entity. In that case, it applies the shorter list of requirements in Annex 4.
Can the head of the entity delegate responsibility to an IT officer?
They can delegate obligations to another person with that person's consent, but under Article 8c they remain responsible. This is why they need documentation showing what they decided and on what basis.
Is an inventory of systems alone enough to comply with the Act?
No. The inventory is a starting point, not the fulfilment of the obligations. Without it, however, it is impossible to assess risk reliably, plan the budget, or show the grounds on which leadership made its decisions.
If the office does not have an up-to-date inventory of systems, owners, contracts and risks, I can help prepare one within 2–6 weeks. See what the inventory covers →

Let’s talk about your situation — specifically, not in general terms.