Poland — Ustawa o krajowym systemie cyberbezpieczeństwa (KSC)
The Act of 5 July 2018 establishing Poland's national cybersecurity system, comprehensively rewritten by the Act of 23 January 2026 (Dz.U. 2026 poz. 252) transposing NIS2. Curated here is the personal scope after that rewrite: who is a podmiot kluczowy (essential entity) or podmiot ważny (important entity), and the public-sector annex row.
Fact text is Polish (authentic language); this README is curation.
Applicability to EdTech
- Schools are expressly out of scope: in the "Podmioty publiczne" sector of załącznik nr 1, local-government coverage excludes "jednostek organizacyjnych, o których mowa w art. 2 ustawy — Prawo oświatowe, oraz ich zespołów" (schools and their complexes); at powiat level only the starostwo is covered, and at gmina level only the urząd gminy with ≥50 FTE (Załącznik nr 1 — Podmioty publiczne). A Polish school is therefore not a KSC-regulated entity.
- The vendor side is where KSC bites: cloud-computing providers, data-centre services, CDNs and trust services sit in załącznik nr 1 (digital infrastructure) — an entity above the medium-enterprise thresholds of Regulation 651/2014 is a podmiot kluczowy (art. 5 ust. 1 pkt 1); at medium size it is a podmiot ważny (art. 5 ust. 2 pkt 1); DNS providers, TLD registries and domain registrars are covered regardless of size (art. 5 ust. 1 pkt 4).
- Extraterritorial reach: entities without an EU establishment offering services in Poland fall under the Polish authority once they designate a representative (art. 5 ust. 9); public entities are covered wherever seated (ust. 10).
- The EU-level substance is in NIS2 — the KSC supplies Poland's entity classification, supervision and CSIRT structure.
Contents
| Document | Covers |
|---|---|
| ZAKRES-PODMIOTOWY.md | KSC art. 5 (podmioty kluczowe i ważne) + załącznik nr 1, sektor "Podmioty publiczne" |
Scope note: obligations (risk management, incident reporting, registration), supervision and fines are further chapters of the rewritten act — add them when a Poland deployment question needs that level.
Enforcement
Organy właściwe do spraw cyberbezpieczeństwa (sector ministers) with CSIRT NASK / CSIRT GOV / CSIRT MON at national level.
Related
- EU NIS2 — the transposed directive
- UODO — the 2026 KSC amendment also redirected 50% of certain GDPR fines to the Cybersecurity Fund (UODO art. 104, not extracted)
Sources
- ISAP — KSC, najnowszy tekst jednolity Dz.U. 2026 poz. 20
- ISAP — nowelizacja NIS2, Dz.U. 2026 poz. 252
Meta
Statute text in ZAKRES-PODMIOTOWY.md is reproduced verbatim in Polish from the Kancelaria Sejmu tekst ujednolicony PDF (ELI text type U for the TJ Dz.U. 2026 poz. 20 — the only machine-readable text that already integrates the 2026 NIS2 rewrite; its header names the integrated positions 20, 252, 815, 1003) by tools/sejm-eli/build_pl_ksc.py. verify fails if the API lists a post-TJ amendment the ujednolicony header does not name, and demands exact canonical equality between the document's statute text and the PDF slice. Page stamps and Kancelaria footnotes are stripped mechanically (footnotes reproduced under Odnośniki). Anchors derive from printed labels ({#a5-1-4} = art. 5 ust. 1 pkt 4). When ISAP publishes a post-NIS2 tekst jednolity, re-run the builder against it.