{"id":3175,"date":"2026-02-20T22:05:00","date_gmt":"2026-02-20T21:05:00","guid":{"rendered":"https:\/\/www.virtuosoc.com\/the-nis2-directive-in-poland-current-status-deadlines-and-challenges-in-2025\/"},"modified":"2025-01-29T18:22:06","modified_gmt":"2025-01-29T17:22:06","slug":"the-nis2-directive-in-poland-current-status-deadlines-and-challenges-in-2025","status":"publish","type":"post","link":"https:\/\/www.virtuosoc.com\/en\/the-nis2-directive-in-poland-current-status-deadlines-and-challenges-in-2025\/","title":{"rendered":"The NIS2 Directive in Poland: Current Status, Deadlines and Challenges in 2025"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">With the beginning of 2025, the process of implementing the Network and Information Systems Directive 2 (NIS2) in Poland remains one of the most important legislative challenges in the area of cyber security. Although the deadline for bringing national legislation into compliance with the directive expired on October 17, 2024, legislative work is still ongoing, raising questions about future changes, deadlines for implementation and the consequences of delays. In this article, we discuss the current state of the law, the planned compliance deadlines and the challenges facing businesses and public administration.  <\/p>\n\n<p class=\"wp-block-paragraph\"><strong>NIS2 Directive &#8211; Purpose and Significance<\/strong><\/p>\n\n<p class=\"wp-block-paragraph\">The NIS2 Directive is a development of the first NIS Directive, adopted in 2016, aimed at raising the level of cyber security in the European Union. It aims to: <\/p>\n\n<ul class=\"wp-block-list\">\n<li>Introduce uniform standards for cyber security risk management.<\/li>\n\n\n\n<li>Expanding the scope of regulated sectors, such as health, energy, transportation, financial services and the water supply sector.<\/li>\n\n\n\n<li>Introduce greater accountability for company boards to implement cyber security requirements.<\/li>\n<\/ul>\n\n<p class=\"wp-block-paragraph\">The adaptation of Polish law to the requirements of NIS2 is being implemented through an amendment to the Law on the National Cyber Security System (KSC).<\/p>\n\n<p class=\"wp-block-paragraph\"><strong>The Current State of Legislation in Poland<\/strong><\/p>\n\n<p class=\"wp-block-paragraph\">The first draft of the amendment to the KSC Law was published in April 2024 and subjected to extensive public consultation. As a result of numerous comments, the Ministry of Digitization prepared another version of the draft, published on October 7, 2024. The second draft took into account about 70% of the comments made, with the aim of improving the clarity of the law and improving oversight of its implementation.  <\/p>\n\n<p class=\"wp-block-paragraph\">Despite intensive legislative work, the amendment to the law was not passed before the end of 2024. The authorities have announced that the law may reach the Parliament in the first quarter of 2025. The legislation is scheduled to finally come into force in the second half of the year, but the lack of specific dates is causing uncertainty among entrepreneurs.  <\/p>\n\n<p class=\"wp-block-paragraph\"><strong>Planned Timing and Anticipation<\/strong><\/p>\n\n<p class=\"wp-block-paragraph\">Although the amendment to the KSC Law has not yet been enacted, it is clear from the drafts so far that the expected compliance dates for regulated entities will be as follows:<\/p>\n\n<ol class=\"wp-block-list\">\n<li><strong>Registration of key and important entities<\/strong>:\n<ul class=\"wp-block-list\">\n<li>3 months from the date of entry into force of the law or from the moment the criteria for recognition as such are met.<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>Implementation of an information security management system<\/strong>:\n<ul class=\"wp-block-list\">\n<li>6 months from the entry into force of the law or meeting the criteria.<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>Conducting the first audit<\/strong>:\n<ul class=\"wp-block-list\">\n<li>24 months from the effective date of the legislation, with an audit validity period of 3 years.<\/li>\n<\/ul>\n<\/li>\n<\/ol>\n\n<p class=\"wp-block-paragraph\">However, these periods are subject to change depending on the final version of the law.<\/p>\n\n<p class=\"wp-block-paragraph\"><strong>Challenges with Delayed Implementation<\/strong><\/p>\n\n<p class=\"wp-block-paragraph\">Delays in the implementation of the NIS2 directive in Poland are causing a number of problems and challenges:<\/p>\n\n<ol class=\"wp-block-list\">\n<li><strong>Risk of sanctions from the EU<\/strong>:\n<ul class=\"wp-block-list\">\n<li>Failure to comply with EU requirements could result in financial penalties for Poland.<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>Increased risk of cyber attacks<\/strong>:\n<ul class=\"wp-block-list\">\n<li>The lack of up-to-date regulations undermines the country&#8217;s level of cyber security, putting key sectors of the economy at risk.<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>Legal uncertainty for entrepreneurs<\/strong>:\n<ul class=\"wp-block-list\">\n<li>Companies do not know the exact requirements, making it difficult to plan and adjust operations.<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>Lack of time to implement changes<\/strong>:\n<ul class=\"wp-block-list\">\n<li>Any further delay in legislation reduces the time available for companies to adjust their procedures.<\/li>\n<\/ul>\n<\/li>\n<\/ol>\n\n<p class=\"wp-block-paragraph\"><strong>Recommendations for Entrepreneurs<\/strong><\/p>\n\n<p class=\"wp-block-paragraph\">Faced with delays in the legislative process, businesses should take preemptive action. Here are key steps to take now: <\/p>\n\n<ol class=\"wp-block-list\">\n<li><strong>Monitoring the legislative process<\/strong>:\n<ul class=\"wp-block-list\">\n<li>Regularly follow developments in the work on amending the KSC Law and respond to new information.<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>Compliance Assessment<\/strong>:\n<ul class=\"wp-block-list\">\n<li>Analyze the requirements of the NIS2 directive and compare them with current procedures in the organization.<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>Investment in cyber security<\/strong>:\n<ul class=\"wp-block-list\">\n<li>Implementing information security management standards and systems even before the regulations go into effect will better prepare you for the new requirements.<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>Employee training<\/strong>:\n<ul class=\"wp-block-list\">\n<li>Raise awareness of cyber threats and implement incident response procedures.<\/li>\n<\/ul>\n<\/li>\n<\/ol>\n\n<p class=\"wp-block-paragraph\">The implementation of the NIS2 Directive in Poland is an inevitable step to strengthen the country&#8217;s cyber security system. The year 2025 will be crucial for enacting amendments to the NSC Act and implementing the new regulations. Although delays in the legislative process create uncertainty, businesses should proactively prepare for the changes by investing in cyber security and adapting their procedures to the anticipated requirements. Proactive measures will avoid risks and ensure compliance with future standards.   <\/p>\n","protected":false},"excerpt":{"rendered":"<p>With the beginning of 2025, the process of implementing the Network and Information Systems Directive 2 (NIS2) in Poland remains one of the most important legislative challenges in the area of cyber security. Although the deadline for bringing national legislation into compliance with the directive expired on October 17, 2024, legislative work is still ongoing,&#8230;<\/p>\n","protected":false},"author":78325372,"featured_media":2296,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_kad_blocks_custom_css":"","_kad_blocks_head_custom_js":"","_kad_blocks_body_custom_js":"","_kad_blocks_footer_custom_js":"","_kad_post_transparent":"","_kad_post_title":"","_kad_post_layout":"","_kad_post_sidebar_id":"","_kad_post_content_style":"","_kad_post_vertical_padding":"","_kad_post_feature":"","_kad_post_feature_position":"","_kad_post_header":false,"_kad_post_footer":false,"_kad_post_classname":"","footnotes":""},"categories":[30],"tags":[],"class_list":["post-3175","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity"],"taxonomy_info":{"category":[{"value":30,"label":"Cybersecurity"}]},"featured_image_src_large":["https:\/\/www.virtuosoc.com\/wp-content\/uploads\/2024\/12\/82727-1024x512.webp",1024,512,true],"author_info":{"display_name":"27web","author_link":"https:\/\/www.virtuosoc.com\/en\/author\/n3a66mi8n-27web\/"},"comment_info":0,"category_info":[{"term_id":30,"name":"Cybersecurity","slug":"cybersecurity","term_group":0,"term_taxonomy_id":30,"taxonomy":"category","description":"","parent":0,"count":2,"filter":"raw","cat_ID":30,"category_count":2,"category_description":"","cat_name":"Cybersecurity","category_nicename":"cybersecurity","category_parent":0}],"tag_info":false,"_links":{"self":[{"href":"https:\/\/www.virtuosoc.com\/en\/wp-json\/wp\/v2\/posts\/3175","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.virtuosoc.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.virtuosoc.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.virtuosoc.com\/en\/wp-json\/wp\/v2\/users\/78325372"}],"replies":[{"embeddable":true,"href":"https:\/\/www.virtuosoc.com\/en\/wp-json\/wp\/v2\/comments?post=3175"}],"version-history":[{"count":1,"href":"https:\/\/www.virtuosoc.com\/en\/wp-json\/wp\/v2\/posts\/3175\/revisions"}],"predecessor-version":[{"id":3176,"href":"https:\/\/www.virtuosoc.com\/en\/wp-json\/wp\/v2\/posts\/3175\/revisions\/3176"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.virtuosoc.com\/en\/wp-json\/wp\/v2\/media\/2296"}],"wp:attachment":[{"href":"https:\/\/www.virtuosoc.com\/en\/wp-json\/wp\/v2\/media?parent=3175"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.virtuosoc.com\/en\/wp-json\/wp\/v2\/categories?post=3175"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.virtuosoc.com\/en\/wp-json\/wp\/v2\/tags?post=3175"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}