Let’s talk
Wondering how this plays out in your organisation? Get in touch — I answer personally.
Short answer
An essential or important entity manages supplier risk within its information security management system (the “management system”). The Polish Act on the National Cybersecurity System (KSC) requires measures ensuring the security and continuity of the supply chain of ICT products, ICT services and ICT processes on which the provision of the service depends (Article 8(1)(2)(e)). The measures are to be proportionate to the estimated risk, and when implementing them the entity takes into account four factors from Article 8(2). Two concern the supplier itself, namely the vulnerabilities related to it and the overall quality of its ICT products, services and processes. The other two are the results of the coordinated security assessment carried out by the EU Cooperation Group and the results of the proceedings on recognition as a high-risk supplier.
The Act does not list the measures towards suppliers. Implementing Regulation (EU) 2024/2690 is binding in this respect on the entities listed in Article 8b(1) and on trust service providers (Article 8b(2) in conjunction with Article 1 of the Regulation). I recommend that other entities treat both the Regulation and the non-binding answers of the Minister of Digital Affairs as a model. Both documents describe a policy with criteria for selecting suppliers, contractual provisions and an up-to-date list of direct suppliers. In practice supply chain security usually starts with a list of ICT suppliers with assigned services and with dividing suppliers into groups. It is worth making the depth of the assessment, the changes to the contract and the review cycle depend on the group. Supply chain security also means a repeatable assessment of suppliers, because risk estimation is to be systematic (Article 8(1)(1)). The result is worth recording, because the competent authority may request evidence of the implementation of the requirements (Article 53(2)(6)).
An entity that met the criteria on 3 April 2026 implements the management system together with the measures towards suppliers by 3 April 2027. Other entities have 12 months for this from meeting the criteria or from being served with the recognition decision. An agreement with a managed security service provider (Article 14) does not relieve the entity of the obligation. The head of the entity is responsible for the entity’s performance of the obligations under Article 8 and Article 14 (Article 8c(1)). Different rules apply to an important entity that is a public entity or one of the higher education and science entities under Article 8(3) with regard to public tasks performed using information systems. The banking and financial market infrastructure sectors apply the DORA provisions to ICT suppliers, but the obligations relating to a high-risk supplier also bind those sectors (Article 8i(1)).
Why this question arises at all
In Article 8(1) and (2) the Act devotes one point of the catalogue of measures (Article 8(1)(2)(e)) and one paragraph (Article 8(2)) to suppliers. Point (e) of Article 8(1)(2) refers to the security and continuity of the supply chain, taking into account the relationships between the direct supplier of hardware or software and the entity. The Act separately regulates the high-risk supplier (Articles 67b to 67f) and the managed security service provider (Article 14). It contains neither model contracts with suppliers nor assessment thresholds.
The Minister of Digital Affairs states expressly that there is no register of secure and verified suppliers of hardware and software for essential and important entities (question 3.22). Entities must themselves manage the risk associated with the supply chain and estimate the risk associated with a given supplier.
The reference point for the level of detail is Commission Implementing Regulation (EU) 2024/2690. Within the system under Article 8(1) it is applied by the entities listed in Article 8b(1), including cloud computing service providers, data centre service providers and managed service providers. Supply chain security is described in point 5 of the Annex to that Regulation. Other entities apply the Commission implementing acts issued for their type (Article 8b(2)). For trust service providers that act is Regulation 2024/2690 itself. Until an act for a given type of entity exists, I recommend treating Regulation 2024/2690 as a model.
What has to be established before a decision
Supply chain security — who is bound and from when
The rule is set by Article 8(1)(2)(e) and Article 8(2), which bind an essential entity and an important entity in the same wording. Three groups in the table have different requirements or an additional source of requirements. High-impact and critical-impact entities from the electricity subsector also apply additional measures (Article 8b(3)).
| Entity | What it applies to suppliers | Exceptions and limitations | Deadline |
|---|---|---|---|
| Essential or important entity | Article 8(1)(2)(e) and Article 8(2) | former operators of essential services apply a system compliant with the previous Article 8 until the new system is implemented (Article 33(6) of the amending act); telecommunications undertakings that performed the obligations under Division VIIa of the Telecommunications Law perform them on the existing terms until they begin performing the obligations under Chapter 3 (Article 33(5) of the amending act) | by 3 April 2027 where the criteria were met on 3 April 2026 (Article 33(1) of the amending act and question 3.1); in other cases 12 months from meeting the criteria (Article 16(1)) or from being served with the recognition decision (Article 7l(7) and Article 7m(6)) |
| Provider of services under Article 8b(1) (e.g. cloud or managed services) or trust service provider | the same plus points 5 and 6.1 of the Annex to Regulation 2024/2690 | the Regulation applies within the system under Article 8(1) | the same deadline |
| Important entity that is a public entity and higher education and science entities under Article 8(3) | Annex 4 instead of Article 8(1). Relevant to suppliers are the inventory of ICT products, services and processes used to process information (Part I point 1) and documenting the protection of information when using cloud computing or data centre services (point 3(c)). Added to this is monitoring the frequency of releases of new versions of ICT products and their distribution sources and life cycle (point 15) | security provisions in service contracts are in Part II, which the system “may additionally cover” (point 7); a public entity performs the obligations under Article 8 if it uses an information system to perform a public task (Article 16d) | the same deadline |
| Banking and financial market infrastructure sectors | the DORA Regulation, including the principles for managing ICT third-party risk (Articles 28 to 30) | of the provisions on the management system Article 8i(1) leaves Article 8(1)(1) and (2)(j) in place; the obligations relating to a high-risk supplier apply (Articles 67c and 67d under Article 8i(1)) and Articles 8c to 8f apply accordingly (Article 8i(2)) | DORA applies from 17 January 2025 (Article 64) |
With regard to public tasks performed using information systems an important entity that is a public entity and higher education and science entities under Article 8(3) do not apply Article 8(1). They are therefore also not bound by Article 8(2), which refers to the measures under point (e). Annex 4 does not list the four factors from Article 8(2). These entities nevertheless perform the obligations under Article 67c(1) after a decision recognising a supplier as a high-risk supplier, because they are important entities (Article 67b(1)(1)). A public entity also includes in its management system an information system provided by another public entity (Article 8(4)). It does so to the extent corresponding to the scope of competences of that entity. That scope follows from the security policy of that system or from the provisions on its operation.
Which suppliers fall within the scope
The scope is set by two elements of point (e). The first is the subject of the supply, namely ICT products, ICT services and ICT processes. The second is dependency, because point (e) concerns supplies on which the provision of the service depends. A list of all contractors is therefore not needed. In my assessment dependency nevertheless covers not only the availability of the service but also the integrity and confidentiality of the information system used to provide it. This is supported by the fact that the management system is also to ensure the confidentiality and integrity of data (Article 8(1)(5)(a)). A narrower reading is supported by the fact that point (e) links dependency with the provision of the service and not with the system. On my reading the list also includes a supplier with remote access to systems, even if a failure on its side would not stop the entity’s service. It is different for the relevant entities applying Regulation 2024/2690, which maintain a registry of their direct suppliers and service providers without a dependency criterion (point 5.2 of the Annex).
Under the Act a supplier of hardware or software is a manufacturer, authorised representative, importer or distributor within the meaning of Regulation (EC) No 765/2008 (Article 2(4c)). The definition covers an ICT product, service and process. The Minister expects an up-to-date list of direct suppliers with contact details and an indication of which ICT products, services and processes they supply (question 3.3).
I recommend assigning to each supplier straight away the service and the system that depend on it. Next it is worth dividing suppliers into critical, significant and other suppliers. It is worth classifying as critical the suppliers without which the service stops and those that have privileged access to systems or store data covered by the service. Suppliers whose failure can be worked around with substitute measures or those with limited access to systems can be classified as significant. Suppliers without access to systems whose product or service is easy to replace can be classified as other suppliers. I recommend a full assessment and a full contract review for critical suppliers, a shortened assessment for significant ones and for the others a check at purchase and at contract renewal. For hardware and software purchased through an integrator it is worth also recording the manufacturer and the end of the support period in the list. This is because vulnerability notices are issued by the manufacturer and not by the integrator.
It remains open whether the assessment covers further links in the chain. A broader reading is supported by the fact that the subject of the obligation is the supply chain and not only the relationship with the direct supplier. A narrower reading is supported by the wording of the Act, by Article 21(3) of the NIS2 Directive in the part on vulnerabilities and by point 5.1.1 of the Annex to Regulation 2024/2690, which refer to direct suppliers. Recital 85 of the Directive adds that entities could consider risks stemming from other levels of suppliers and service providers. In my assessment the entity takes into account the risk of further links through the direct supplier, for example in requirements for subcontractors, and does not have to assess each of them on its own.
How to assess a supplier under Article 8(2)
The four factors indicate what the assessment is to concern, and its depth follows from the estimated risk. According to the Minister the purchaser should assess the acquired ICT solutions each time in the light of the reliability of the supplier and the security of the hardware, software and services offered as well as the potential risks associated with the supply chain (question 3.22).
Vulnerabilities related to the supplier (point 1). The NIS2 Directive refers to the vulnerabilities specific to each direct supplier and service provider (Article 21(3)). What counts is therefore how the supplier handles vulnerabilities in its products. It is also worth assessing the supplier’s own security when it has access to the entity’s systems.
Overall quality of ICT products, services and processes (point 2). The Directive frames this factor more broadly and refers to the overall quality of products and cybersecurity practices of suppliers and service providers, including their secure development procedures (Article 21(3)). The relevant entities applying Regulation 2024/2690 lay down criteria to select and contract suppliers and service providers, and those criteria include four elements (point 5.1.2 of the Annex). They cover the cybersecurity practices of the supplier and its ability to meet cybersecurity specifications set by the entity. Added to these are the overall quality and resilience of ICT products and ICT services and the cybersecurity risk-management measures embedded in them. The fourth element is, where applicable, the ability of the entity to diversify sources of supply and limit vendor lock-in.
According to the Minister entities concluding contracts of adhesion with global suppliers should choose those that have cybersecurity certification of their own products and services (question 3.9).
Remember
A certificate is worth reading together with the scope of certification, because it may not cover the service provided to the entity.
Results of the coordinated security assessment (point 3). The Cooperation Group may carry out coordinated security risk assessments of specific critical ICT services, ICT systems or ICT products supply chains in cooperation with the European Commission and ENISA (Article 22(1) of the Directive). When implementing measures towards suppliers the entity takes into account the results of such an assessment (Article 8(2)(3)). It is worth recording in the risk assessment whether such an assessment concerns the products or services of its suppliers and with what result.
Results of the proceedings under Article 67b (point 4). Once the Minister issues a decision recognising a supplier as a high-risk supplier, the entity does not put into use the ICT products, services and processes covered by it. Under Article 67c(1)(2) it withdraws those it already has, as a rule no later than 7 years after the decision is announced in Monitor Polski (the Official Gazette). The shorter 4-year deadline for the critical functions listed in Annex 3 concerns the telecommunications undertakings under Article 67b(1)(2) (Article 67c(2)). The same deadline applies to products for critical functions acquired in a public procurement procedure before the decision was announced (Article 67c(5)). The President has applied to the Constitutional Tribunal for a review of the conformity with the Constitution of some of the provisions on the high-risk supplier, including Article 67b(1) and Article 67c(1) (case K 19/26). According to the Tribunal’s website as at 4 October 2026 the case is pending, with no hearing and no ruling.
The recommendations of the Government Plenipotentiary for Cybersecurity on the use of ICT products or ICT services published in the Public Information Bulletin are a separate source of information on ICT products and services (Article 33(4) and (4c)). Failure to take them into account is a ground for the Plenipotentiary to refer the matter to the supervisory authority (Article 33(8)).
In practice a full assessment of a critical supplier draws on several sources. The first is a questionnaire on safeguards and vulnerability handling, and the second is a certificate or an audit report. Added to these are the history of incidents and vulnerabilities in the supplier’s products, the scope of its access to systems and the possibility of replacing it with another supplier. A shortened assessment may be limited to a certificate with its scope, a review of access and a check of the key contract clauses. For suppliers in the other group a check against the criteria in the policy and an entry in the list may suffice. In every group the assessment takes into account the four factors from Article 8(2). It is worth keeping the assessment record in a fixed layout that shows the supplier with its dependent services and group, the sources of information and the risks identified, and the decision with the date of the next review. The decision may be acceptance, acceptance with conditions or discontinuing the supplier.
What to put in the contract with a supplier
The Minister indicates that contracts with suppliers should include provisions on cybersecurity (question 3.3). As examples the Minister gives the confidentiality of information and the reporting of incidents to the entity. The Minister also lists informing about vulnerabilities and requirements concerning personnel.
According to recital 85 of the Directive entities should be encouraged to incorporate cybersecurity risk-management measures into contractual arrangements with their direct suppliers and service providers. A fuller list of provisions is contained in Regulation 2024/2690. Based on the supply chain security policy and the results of the risk assessment the relevant entities applying that Regulation ensure that their contracts with suppliers and service providers specify eight elements where appropriate (point 5.1.4 of the Annex). For other entities these elements may serve as a checklist in negotiations.
| Provision (point 5.1.4 of the Annex to Regulation 2024/2690) | What it relates to in the KSC Act | What to watch out for |
|---|---|---|
| cybersecurity requirements for the supplier, including requirements as regards the security in acquisition of ICT products and ICT services (point (a)) | security in the process of acquiring the system (Article 8(1)(2)(b)) | the requirements follow from the risk assessment of the given supplier |
| requirements regarding awareness, skills and training and where appropriate certifications of the supplier’s employees (point (b)) | human resources security (Article 8(1)(2)(d)) | the Minister points to the personnel of an external supplier (question 3.3) |
| requirements regarding the verification of the background of the supplier’s employees (point (c)) | information from the National Criminal Register for persons performing tasks under Article 8 or 11 (Article 8f) | Article 8f covers only offences against the protection of information; broader criminal record checks require a provision meeting the conditions of Article 10 GDPR; it is worth consulting the data protection officer on the scope of other verification (e.g. references) |
| notification without undue delay of incidents that present a risk to the entity’s systems (point (d)) | the moment of detection of an incident and the reporting deadlines (Article 11) | it is worth setting a notification deadline and a channel also used for notifying personal data breaches |
| the right to audit or right to receive audit reports (point (e)) | assessment of the effectiveness of measures (Article 8(1)(2)(h)) | with large suppliers a report rather than an on-site audit usually comes into play |
| handling vulnerabilities that present a risk to the entity’s systems (point (f)) | information on vulnerabilities and updates (Article 8(1)(3) and (5)(b)) | it is worth agreeing who deploys patches and within what time |
| requirements regarding subcontracting and, where the entity allows subcontracting, cybersecurity requirements for subcontractors (point (g)) | the supply chain (Article 8(1)(2)(e)) | the route to further links in the chain |
| obligations on the supplier at the termination of the contract, such as retrieval and disposal of the information obtained in the exercise of its tasks (point (h)) | business continuity (Article 8(1)(2)(f)) | it is worth adding an exit plan, namely the return of data, its deletion by the supplier and assistance with the transition to a new supplier |
Where the contract cannot be negotiated, it is worth comparing the supplier’s standard terms and the audit reports it makes available to customers against this list. Gaps can be closed with measures on the entity’s side, for example a copy of the data outside the supplier’s service. It is worth presenting the residual risk to the head of the entity, because the head takes decisions on the management system (Article 8d(1)). In the public cloud the environment configuration, accounts and permissions usually remain on the customer’s side, so the contract will not resolve them.
Nor will the contract replace control of the supplier’s access to systems. Regulation 2024/2690 requires the relevant entities to apply controls for remote access by service providers and to allow connections of service providers only after an authorisation request and for a set time period (points 6.7.2(d) and (h) of the Annex). Access rights are to appropriately address supplier access, in particular by limiting access rights in scope and in duration (point 11.2.2(d)). For other entities these requirements may serve as a model for implementing the access control policy (Article 8(1)(2)(n)). Good practice includes named supplier accounts with multi-factor authentication, session logging and revoking access once the work is finished.
Some of these provisions overlap with the data processing agreement, which obliges the processor to take all measures required pursuant to Article 32 GDPR (Article 28(3)(c) GDPR). It is worth conducting a single assessment of the supplier with a part on personal data.
When information about an incident or vulnerability comes from a supplier
The deadlines for reporting a significant incident run from its detection, and the early warning must be submitted without delay and at the latest within 24 hours (Article 11(1)(4) and (4a)). According to the Minister the moment of detection is the moment at which the entity obtained information about an event qualifying as an incident, including from the service provider (question 6.5). In practice a message from a supplier sent on a Saturday to a general mailbox may therefore start the deadline running. The Minister indicates that contracts with suppliers should include an obligation to inform the entity without delay about an incident related to the supplier’s service (question 6.5). It is worth giving suppliers a channel staffed around the clock and a notification deadline shorter than 24 hours, and entering the channel in the incident handling procedure.
From 11 September 2026 a manufacturer of a product with digital elements notifies actively exploited vulnerabilities to the CSIRT designated as coordinator and to ENISA (Article 14(1) and Article 71(2) of Regulation (EU) 2024/2847, the Cyber Resilience Act). It also informs users of such a vulnerability or of a severe incident having an impact on the security of the product (Article 14(8)). The information goes to the impacted users and where appropriate to all users. For the manufacturer’s information to reach the right person, it is worth keeping two-way contact details in the list of suppliers.
Managed security service provider
The entity performs the tasks under Article 8 and Articles 9 to 13 through internal structures responsible for cybersecurity or through an agreement with a managed security service provider (Article 14).
The agreement does not transfer the obligation. The addressee of Article 8 remains the entity, and the head of the entity is responsible for the entity’s performance of the obligations under Article 8 and Article 14 (Article 8c(1)). The head remains responsible also where some or all of the obligations have been entrusted to another person with that person’s consent (Article 8c(3)). According to recital 86 of the Directive managed security service providers pose a particular risk, so entities should exercise increased diligence in selecting them.
A clean criminal record is a separate matter. A person who is to perform tasks under Article 8 or Article 11 presents to the entity information from the National Criminal Register on the absence of convictions for offences against the protection of information (Article 8f(1)). The head of the entity allows that person to perform those tasks after receiving that information. The requirement is deemed met where the person holds a valid security clearance granting access to information classified as “confidential” or higher (Article 8f(3)).
In my assessment the provision also covers the supplier’s employees performing those tasks for the entity. This is because it refers to the person who is to perform them and does not limit that person to the entity’s personnel. Moreover, the Act provides for an agreement with a managed security service provider precisely for performing the tasks under Article 8 and Article 11 (Article 7(2)(16)). A narrower reading is supported by the fact that the Minister describes this obligation using the example of employment and other forms of engagement, such as a contract of mandate (question 3.10). Information on the absence of criminal convictions is also data covered by Article 10 GDPR. Besides a basis under Article 6(1), its processing requires the control of official authority or a provision of law authorising it and providing for appropriate safeguards. It is therefore worth consulting the data protection officer on the choice of reading and recording that choice in the agreement with the supplier.
How to demonstrate supply chain security
The supply chain security policy adopted as a topic-specific policy (Article 8(1)(2)(a)) belongs to the documentation of the information security management system. That documentation in turn is part of the normative documentation (Article 10(3)(1)). The list of suppliers, the assessments and the review records become operational documentation when they attest to the performance of activities required by the normative documentation (Article 10(4)). The competent authority may request evidence of the implementation of the requirements of Article 8(1) (Article 53(2)(6)). This also applies to an important entity, although supervision over it is ex post (Article 53(3)(2) and (17)). The Minister stresses that what is required is proof of applying the provisions and not the presentation of formally correct documents (question 11.6). Application can also be shown by annexes to contracts, decisions of the head of the entity on residual risk and records of granting access to suppliers.
Regulation 2024/2690 requires the relevant entities to review the supply chain security policy and to monitor and evaluate changes in the cybersecurity practices of suppliers at planned intervals. A review also takes place after significant changes to operations or risks and after significant incidents related to the ICT services or ICT products of suppliers (point 5.1.6 of the Annex). I recommend a similar cycle to other entities. It is worth reviewing the policy and critical suppliers at least once a year. Significant suppliers are worth reviewing at contract renewal, and for open-ended contracts together with the policy review. For suppliers in the other group a check at contract renewal is enough. Irrespective of the group, a review is worth carrying out after a significant incident at the supplier or a significant change to its service.
Common mistakes
- A list of all contractors without assigned services and systems. A long list does not show where the risk lies.
- A one-off security questionnaire. Without a review on a fixed cycle and after a significant incident or a significant change to the service the assessment becomes outdated.
- Clauses only in new contracts. Critical suppliers usually have contracts from before the amendment, and the Minister lists the review of contracts with existing suppliers among the implementation actions (question 3.2). It is worth using the next renewal to change the clauses. Where it falls after the deadline for implementing the management system, it is worth considering an annex. Until the change is made it is worth documenting the gap and the measures on the entity’s side.
- Supplier service accounts without an owner and an end date. Permanent access by a supplier through a generic account shortens the path from an incident at the supplier to an incident at the entity.
Conclusions and next steps
Supply chain security requires the cooperation of several departments. The list and the contracts are usually kept by procurement together with the legal department, while IT assigns dependencies and access.
- Identify the services covered by the Act and the systems that support them.
- Draw up a list of direct ICT suppliers and divide them into critical, significant and other suppliers.
- Adopt a supply chain security policy with selection and assessment criteria.
- Assess suppliers against the four factors from Article 8(2) with a depth that depends on the group, and record the result.
- Compare the contracts with critical suppliers against the eight elements from Regulation 2024/2690 and plan changes, and present gaps with no prospect of change to the head of the entity for a decision.
- Limit supplier access to named accounts and to the duration of the work, log their sessions and revoke access once the work is finished.
- Establish who on the suppliers’ side performs tasks under Article 8 or 11, and decide on criminal record checks after consulting the data protection officer.
- Set a supplier review cycle that depends on the group and record its results.
Related materials
- What risk management measures must an essential entity implement? — the system within which supplier risk management operates.
- What NIS2 documentation must an essential or important entity keep? — the place of the supply chain policy and assessment records in the documentation.
- What should a NIS2 gap analysis contain? — comparing the current state with the requirements of the Act.
- What does a significant incident report to a CSIRT contain? — the full sequence of reports after the early warning.
- Where should the board begin preparing for NIS2? — the order of the board’s decisions.
Sources
- Act of 5 July 2018 on the National Cybersecurity System, consolidated text as at 18 August 2026 — Article 2(4c), Article 7(2)(16), Article 7l(7), Article 7m(6), Article 8, Articles 8b to 8f, Article 8i, Article 10(3) and (4), Article 11(1), Article 14, Article 16(1), Article 16d, Article 33, Article 53, Articles 67b to 67f and Annex 4 (in Polish) — isap.sejm.gov.pl.
- Act of 23 January 2026 amending the Act on the National Cybersecurity System and certain other acts (Journal of Laws 2026, item 252) — Article 33(1), (5) and (6) (in Polish) — isap.sejm.gov.pl.
- Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 (NIS2) — Article 21(3), Article 22(1) and recitals 85 and 86 — eur-lex.europa.eu.
- Commission Implementing Regulation (EU) 2024/2690 of 17 October 2024 — Article 1 and points 5, 6.1, 6.7.2 and 11.2.2 of the Annex — eur-lex.europa.eu.
- Minister of Digital Affairs, National cybersecurity system — questions and answers on the amendment of the KSC Act, update of June 2026 — questions 3.1 to 3.3, 3.9, 3.10, 3.22, 6.5 and 11.6 (in Polish) — gov.pl.
- Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024 (Cyber Resilience Act) — Article 14 and Article 71(2) — eur-lex.europa.eu.
- Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR) — Article 6(1), Article 10, Article 28(3) and Article 32 — eur-lex.europa.eu.
- Regulation (EU) 2022/2554 of the European Parliament and of the Council (DORA) — Articles 28 to 30 and Article 64 — eur-lex.europa.eu.
- Constitutional Tribunal, case K 19/26, case record in the judgments portal, as at 4 October 2026 (in Polish) — ipo.trybunal.gov.pl.
Check which suppliers your service depends on
Work on suppliers is best started from a list of dependencies and not from a questionnaire. NIS2 and KSC readiness support covers the list of suppliers and the assessment of their risk, a review of contracts with critical suppliers and a supply chain security policy.
This material is general and educational in nature. It is not an individual legal opinion or a recommendation for any specific organisation. The scope of the obligations should be assessed against the situation of the organisation concerned.
Legal status: October 2026.