EdLaw nat/pl/ksc/README.md

language: en · source language: pl · status: in-force · last checked: 2026-09-06

Poland — Ustawa o krajowym systemie cyberbezpieczeństwa (KSC)

The Act of 5 July 2018 establishing Poland's national cybersecurity system, comprehensively rewritten by the Act of 23 January 2026 (Dz.U. 2026 poz. 252) transposing NIS2. Curated here is the personal scope after that rewrite: who is a podmiot kluczowy (essential entity) or podmiot ważny (important entity), and the public-sector annex row.

Fact text is Polish (authentic language); this README is curation.

Applicability to EdTech

Contents

Document Covers
ZAKRES-PODMIOTOWY.md KSC art. 5 (podmioty kluczowe i ważne) + załącznik nr 1, sektor "Podmioty publiczne"

Scope note: obligations (risk management, incident reporting, registration), supervision and fines are further chapters of the rewritten act — add them when a Poland deployment question needs that level.

Enforcement

Organy właściwe do spraw cyberbezpieczeństwa (sector ministers) with CSIRT NASK / CSIRT GOV / CSIRT MON at national level.

Sources

Meta

Statute text in ZAKRES-PODMIOTOWY.md is reproduced verbatim in Polish from the Kancelaria Sejmu tekst ujednolicony PDF (ELI text type U for the TJ Dz.U. 2026 poz. 20 — the only machine-readable text that already integrates the 2026 NIS2 rewrite; its header names the integrated positions 20, 252, 815, 1003) by tools/sejm-eli/build_pl_ksc.py. verify fails if the API lists a post-TJ amendment the ujednolicony header does not name, and demands exact canonical equality between the document's statute text and the PDF slice. Page stamps and Kancelaria footnotes are stripped mechanically (footnotes reproduced under Odnośniki). Anchors derive from printed labels ({#a5-1-4} = art. 5 ust. 1 pkt 4). When ISAP publishes a post-NIS2 tekst jednolity, re-run the builder against it.