New regulations on cybersecurity in Poland. Fines up to EUR 10 million

This move is the result of the implementation of the EU NIS2 directive into Polish law.
Read also: New limits at stations. Fuel will be more expensive during the May weekend
The Ministry of Digitization has made it clear: the burden of proof rests with the entrepreneur. It is up to the management boards and owners of companies to independently determine whether their activities fall within the new, drastically expanded rigors of the Act on the National Cybersecurity System (KSC).
Three-step procedure: how to check your company?
The ministry has published instructions to help entrepreneurs find their way in the new maze of regulations. The self-identification process is divided into three stages.
- Sector analysis: checking whether the company operates in the industries listed in the annexes to the Act. Annex No. 1 defines key entities, and Annex No. 2 – important entities.
- Size verification: determining the company's status (micro, small, medium or large). The exception are telecommunications companies – they are subject to the Act regardless of their size.
- Article analysis 5: this is a decisive clash with the regulations. Article 5 determines whether a company becomes a key or important entity, taking into account not only its size but also its importance for the state.
When do you have to register?
There is little time to act and the schedule is tight. May 6, 2026 the Minister of Digital Affairs ex officio enters public entities, telecoms and digital service providers into the list. May 7, 2026 the web application is launched at sklep-ksc.gov.pl for other companies. October 3, 2026 deadline for self-registration.
Read also: There is a statement regarding Pobierowo
It is worth emphasizing that the process is fully digitized. The application can only be submitted electronically, and each document must be accompanied qualified electronic signature.
Astronomical penalties for ignorance
Ignoring the obligation to register or failing to implement cybersecurity procedures may result in a financial disaster. The sanctions provided for in the amendment are very strict:
- key entities: fines from PLN 20,000 PLN to even 10 million euros,
- important entities: fines from PLN 15,000 PLN to 7 million euros,
- most serious violations: fines to PLN 100 million,
- personal responsibility: the unit manager may face a fine of up to 300%. monthly salary.
“Lack of awareness does not release you from the obligation,” reminds the Ministry of Digitization.
It's not bureaucracy, it's defense
The new regulations are a response to the rapidly growing number of ransomware attacks and sabotage incidents. For regulated companies, this means the need for urgent investments in security systems, employee training and the development of incident response procedures.
Experts advise not to wait until autumn. The self-identification process and preparation of technical documentation take weeks, and from May 7, the registration application will be the only way to avoid being included on the “blacklist” of entities violating the state's digital security.




