Top
Top

NIS2 Implementation in the EU

Poland

(Europe) Firm Wardynski & Partners

Contributors Jakub Barański

Updated 06 Feb 2025
Status

Ongoing

Status of the NIS2 Implementation Act

A draft legal act has been prepared by the relevant Ministry for Digital Affairs and published on 23 April 2024.

Public consultations of the initial draft bill have been held for a one-month period and formally concluded on 24 May 2024. The initial draft implementing act has been subject to significant criticism, particularly the extent to which it proposes solutions going beyond the minimum requirements set by the NIS2 Directive.
In response to this criticism, the Ministry for Digital Affairs published a revised version of the draft act on 7 October 2024. According to the Ministry for Digital Affairs, the revised draft will be shortly submitted for deliberation by the Polish Parliament, formally beginning the actual legislative process.

If available, foreseeable significant deviations of the National Implementation Act from the NIS2 Directive
  • The draft act, including the revised version, is generally considered more rigorous and wider in scope than the directive. In particular, it includes a wider list of sectors considered essential, e.g. wastewater supply, managed IT and cybersec services, as well as manufacturing of medical devices.
  • The draft act goes somewhat beyond the directive with respect to the personal responsibility of management. It specifies, for example, that in the case of multi-member management, if a single member has not been appointed as responsible for cybersec, all members will bear joint and several responsibilities.
  • The draft act also foresees an additional type of fine in case a regulated entity causes a direct and serious cybersecurity threat to Polish defense, state security, public safety and order, human life and health. In such cases, the maximum threshold for the fine is higher, i.e., up to PLN 100.000.000 (approx. EUR 23.000.000).
  • The draft act will also transpose the EU Commission’s Toolbox for 5G Security to Polish law.
Expected date of entry into force of the Implementation Act

Q1-Q2/2025.

NIS2 Implementation in the EU

Poland

(Europe) Firm Wardynski & Partners

Contributors Jakub Barański

Updated 06 Feb 2025