KS-CYBER_

Insights / Compliance

Is security awareness training mandatory? What Poland's NIS2 act says

Updated: August 2026 · about 6 min read

Yes — and since 3 April 2026 it is no longer a matter of interpreting a directive. The Polish act names staff education explicitly in its list of mandatory measures, obliges management to complete annual training, and provides for a fine imposed personally on the people running the entity — alongside the fine on the company itself.

Which act exactly

This is the Act of 23 January 2026 amending the Act on the National Cybersecurity System and certain other acts, published on 2 March 2026 (Journal of Laws 2026, item 252). Under Article 49 it entered into force one month after publication, that is on 3 April 2026. This is the act that transposes the NIS2 directive into Polish law.

The whole Act on the National Cybersecurity System in one document is available as a consolidated text (Journal of Laws 2026, item 20) — but note that the announcement dates from 29 December 2025, so it predates the amendment discussed here. The training provisions are in item 252.

Provision one: education for personnel is a mandatory measure

Article 8(1) requires an essential or important entity to implement an information security management system. Point 2 lists the technical and organisational measures such a system must cover, and among them:

(i) „cybersecurity education for the entity's personnel"
(j) „basic cyber hygiene practices"

This matters, because the list is not a set of suggestions — it enumerates what the security management system must contain. The measures are to be „appropriate and proportionate to the assessed risk", which lets you scale the training to the size of the organisation, but does not let you leave it out altogether.

Provision two: the head of the entity answers for staff awareness

Article 8d lists the duties of the head of an essential or important entity. Point 4 reads:

The head of the entity „ensures that the entity's personnel are aware of their cybersecurity obligations and know the entity's internal rules in that area".

Note the wording: not „makes materials available", but „ensures that personnel are aware". That is an obligation of result, not of best effort — emailing a slide deck does not discharge it, because it proves nothing about anyone having read or understood it.

Provision three: annual, documented management training

Article 8e is the most concrete of the three:

(1) „The head of an essential entity or an important entity, and the person entrusted with the head's cybersecurity duties, shall complete training once every calendar year."

(3)Participation in the training shall be documented."

Paragraph 2 defines the scope of that training — it covers performing the duties under Art. 7b(4), Art. 7c, Art. 7f(3), Art. 8, Art. 8d, Art. 8f(1) and (2), Art. 9–12b, Art. 14 and Art. 15. In other words: the head of the entity is expected to understand the entity's full set of obligations, not merely to „know about cybersecurity" in general.

Who exactly is the „head of the entity"

This question decides how many people actually have to be trained — and it is where the mistake is usually made. Article 2(8a) of the Polish NIS2 act does not define the term on its own; it refers to Article 3(1)(6) of the Accounting Act, which says that the head of an entity is „a member of the management board or another governing body, and where the body is multi-member — the members of that body, excluding proxies".

In a limited liability company with a three-person management board, the duty under Art. 8e therefore covers three people, not one — and on top of that comes the person entrusted with the head's cybersecurity duties. In a general or civil partnership the head of the entity means the partners conducting its affairs; in a limited partnership, the general partners; for a sole trader, the entrepreneur. For public finance sector units, the act points to the head of the unit within the meaning of Article 53(1) of the Public Finance Act.

Delegating gets nobody off the hook: Article 8c(3) provides that the head of the entity remains liable even where the duties were entrusted to another person with their consent, and Article 8c(2) provides that in a multi-member body with no designated responsible person, all its members bear the responsibility.

A second detail that is easy to miss: the act counts this duty in calendar years, not anniversaries. Training completed in December 2026 does not cover 2027, even if only weeks have passed.

Who answers when the board has several members

Article 8c(2) settles this unambiguously: where the head of the entity is a multi-member body and no responsible person has been designated, all members of that body bear the responsibility. Paragraph 3 adds that entrusting the duties to another person with their consent does not release the head of the entity from liability. Delegating the task is possible; delegating the liability is not.

The fine is personal and calculated from remuneration

Article 73a(1) lists the situations in which the head of the entity personally may be fined. Point 3 concerns failure to perform the duties under Art. 8d; point 4, failure to perform the duty under Art. 8e.

EntityMaximum fine for the head of the entityBasis
Commercial300% of remunerationArt. 73a(4)
Public100% of remunerationArt. 73a(5)

The amount is calculated under the rules applicable to the cash equivalent for annual leave. Importantly, Article 73a(3) makes clear that the fine on the head of the entity is independent of the fine imposed on the entity — both can be applied at once.

How much time there really is — transitional provisions

The act itself has been in force since 3 April 2026, but Article 33(1) gives entities that already met the criteria on the day it entered into force 12 months to perform the duties in Chapter 3 — which is where Articles 8, 8d and 8e sit. The practical deadline for that group is therefore 3 April 2027. Entities that become essential or important later count their deadlines from the day they meet the criteria.

That is not a year of doing nothing, though. Article 8e(1) requires management training once every calendar year, and paragraph 3 requires participation to be documented. Evidence for 2026 cannot be produced in 2027. The first audit of an essential entity has its own, longer deadline — 24 months (Art. 33(2)).

Beware the „3 October 2026" myth

Industry material circulates that date as „the NIS2 implementation deadline". It does not appear in the act. For entities that met the criteria on 3 April 2026, the deadline for applying for entry in the register is set by a schedule announced by the minister responsible for computerisation (Art. 33(3) in conjunction with Art. 34(3)(1)), with separate dates for different categories of entity — and that schedule may be amended (Art. 34(5)). The six-month deadline in Article 7c(1), by contrast, runs from the day the criteria are met, so it applies to entities that acquire that status after the act entered into force.

What evidence discharges the duty

The act requires documentation explicitly only for management training (Art. 8e(3)), but in practice a supervisory authority will ask for evidence of the whole picture. A set that holds up:

EvidenceWhich duty it covers
A named completion register with datesArt. 8(1)(2)(i)
Results of an exam verifying knowledgeArt. 8d(4) — „are aware"
A management certificate from that calendar yearArt. 8e(1) and (3)
The subject scope of the management trainingArt. 8e(2)
Confirmation of familiarity with internal rulesArt. 8d(4) — „know the internal rules"
Periodic refreshers and training for new joinersArt. 8(1)(2)(j)
Disclaimer. This text is an informational summary based on Journal of Laws 2026, item 252, and is not legal advice. Classifying a specific entity as essential or important requires analysis of the annexes to the act and of the organisation's actual circumstances.

Collect the evidence automatically

Not sure whether the act applies to your company at all, or what scope of training it demands? Tell us what you do and how many people you employ — we will send back the scope of the duties and a quote. The platform delivers the training, verifies knowledge with an exam and generates named, dated certificates, separately for staff and for management.

I'd rather look around first

Prefer to talk now: +48 535 740 973 · kontakt@ks-cyber.pl