26 February 2026
Share Print

NIS2 Directive finally implemented in Poland: What businesses need to know

To The Point
(5 min read)

Poland completed the implementation of the EU Network and Information Security Directive (Directive (EU) 2022/2555 – NIS2) through amendments to the National Cybersecurity System Act (UKSC). Following a one month vacatio legis, the new regime is expected to apply from late March 2026. Businesses operating in Poland should now move from legislative monitoring to implementation, starting with a self assessment to determine whether they qualify as essential or important entities and preparing to meet new cybersecurity, governance and reporting obligations.

On 19 February 2026, the President of Poland signed the amendment to the National Cybersecurity System Act (“UKSC”), implementing Directive (EU) 2022/2555 (“NIS2 Directive”) in Poland. Presidential signature marks the final legislative step before the new regime enters into force.

The law will enter into force following a one-month vacatio legis from its publication in the official journal of laws, which is still to come (so the law will likely become applicable in late March 2026).

For businesses operating in Poland, this signals a shift from legislative monitoring to active implementation and the need to effectively start a regulatory compliance journey.

Key regulatory changes compared to the NIS1 regime
Likely implementation timeline
First step – self assessment
Compliance steps
Sanctions and enforcement exposure
Management board liability
How can we help?

To the Point 


Subscribe to receive legal insights and industry updates directly into your inbox

Sign up now