Short answer
Apart from the head of the entity, the Polish Act on the National Cybersecurity System (KSC) names only one more role. It is the person entrusted with the head’s duties in the area of cybersecurity. For everyone else the obligation is built differently. The Act sets out neither positions nor frequency, but it does describe a result — staff must be aware of their cybersecurity duties and know the entity’s internal rules (Article 8d(4)). The circle of people to be trained is therefore marked out by involvement in the tasks under Articles 8 and 11 and by access to the information system used to provide the service.
Why the question comes up at all
Two training obligations in the same Act are built in completely different ways. The first has an addressee, a cycle and a proof. The head of an essential or important entity completes training once each calendar year, and participation in it is documented (Article 8e). The second obligation has none of those three elements. Cybersecurity education for the entity’s staff is one of the elements of the information security management system (Article 8(1)(2)(i)), alongside basic cyber hygiene practices (point (j)). Neither a deadline nor a list of positions stands next to them.
The second source of doubt lies in the difference between the directive and the Act. Directive (EU) 2022/2555 imposes a training obligation on the members of management bodies, while towards employees it merely “encourages” entities to offer similar training (Article 20(2)). The Polish legislator went further and wrote staff education into the catalogue of measures an entity has to implement. Anyone who reads the directive alone concludes that training beyond the board is voluntary. That conclusion does not follow from the national Act.
The third reason is organisational. The question about the circle of people usually comes up once training for the head of the entity is already in the calendar. That is when it turns out there is no ready list for the rest of the organisation. The organisational chart will not replace it, because duties under the Act are distributed differently than positions.
What to establish before deciding
Who besides the head of the entity is named in the Act
Article 8e(1) names two roles. They are the head of an essential or important entity and the person entrusted with the head’s duties in the area of cybersecurity. Both are subject to the same annual cycle and the same scope set out in paragraph 2. Both must have documented participation in training.
The second role is often overlooked, because in many organisations it exists in fact rather than formally. Someone runs the subject day to day and prepares materials for the board, but the entrustment has never been recorded. Entrustment requires that person’s consent and does not relieve the head of the entity of responsibility (Article 8c(3)). The practical conclusion is simple. If the entrustment exists, both sides are trained. If it does not, the first thing to settle is whether it should.
A separate article is devoted to the scope of training for these two roles. Here it is enough to note that this is the scope of the head of the entity’s responsibility, not a programme for specialists.
Who performs the tasks under Articles 8 and 11
This is the most useful criterion for selecting groups, because the Act uses it for an entirely different purpose. Before a person is admitted to tasks under Article 8 or Article 11, the organisation must obtain from them a certificate from the National Criminal Register confirming no conviction for offences against the protection of information (Article 8f(1)). Meeting that obligation requires a list of named individuals.
That same list is the natural starting point for a training plan. It covers the people who perform the tasks of the information security management system and those involved in handling and reporting incidents. In a medium-sized organisation this is usually a dozen or so people from several different departments, not a single team.
Two things are worth checking at this point. Whether the list covers the people who actually perform the activities, not only the formal owners of areas. And whether it covers deputies as well, because incident duties run regardless of holidays and staff turnover.
The people designated for contact with the national cybersecurity system
An essential or important entity designates at least two people responsible for maintaining contact with the entities of the national cybersecurity system (Article 9(1)(1)). One person is enough only for micro and small enterprises and for an important entity that is a public entity (Article 9(2) and (3)). Once entered in the register, the entity begins using the ICT system through which it submits its reports (Article 9(1)(4)).
The Act does not provide a separate training obligation for these people. The task itself, however, determines the scope of preparation. It is about operating the reporting system and about the deadlines counted from detection of a significant incident. This is a practical assessment, not the content of a provision. It is an assessment that is easy to defend, though, because a contact person without that knowledge will not perform the task they were designated for.
Which roles follow from the catalogue of measures itself
The Act lists the elements of the information security management system in Article 8(1)(2). Each of them has an owner in the organisation, and a substantial part of them sits outside the IT department. The table below assigns the elements to roles and indicates what the preparation of those people covers. It is a practical assessment based on the typical structure of a medium-sized and large organisation, not a catalogue that follows from the provision.
| Element of the system (Article 8(1)(2)) | Who usually decides | What the preparation covers |
|---|---|---|
| Human resources security (point (d)) | HR department and line managers | Hiring, change of role and departure of an employee; the criminal record check before admission to tasks under Article 8f |
| Security and continuity of the ICT supply chain (point (e)) | Procurement and contract owners | Supplier assessment criteria under Article 8(2) and security clauses in contracts |
| Security in the acquisition, development and maintenance of the system (point (b)) | Development and maintenance teams, project leads | Security requirements in the project and testing of the system before go-live |
| Asset management and access control policies (points (m) and (n)) | Access administrators, managers approving requests | Least privilege, access reviews, revoking rights after a change of role |
| Business continuity and recovery plans (point (f)) | Process owners | The role of the process in providing the service, the conditions for invoking the plan, taking part in tests |
| Staff education and cyber hygiene (points (i) and (j)) | All staff who use the system | Recognising events, the internal reporting path, the rules in force |
The table shows why a list of groups built from the organisational chart is usually incomplete. The first three rows concern departments that are not the first to come up in a conversation about cybersecurity, yet they are responsible for decisions that are hard to reverse after the fact.
Where the boundary of “all staff” runs
The information security management system is implemented in the information system used in processes that affect the provision of the service (Article 8(1)). That narrows the minimum scope. The obligation covers the people who use that system, not automatically every person employed in the organisation.
The narrowing works only where the organisation can point to the boundary of the system. Where support processes use the same infrastructure and the same accounts, that boundary effectively does not exist. Covering all staff is then a simpler solution than proving who falls outside the system.
It is worth noting separately that the Act speaks of the entity’s “staff”, not of employees. People working on a basis other than an employment contract use the same systems and make the same mistakes. The dividing criterion is the scope of tasks and access, not the type of contract.
An important entity that is a public entity has a different point of reference
An important entity that is a public entity does not apply Article 8(1); it applies the requirements of Annex 4 to the Act (Article 8(3)). The same provision covers some universities to the extent that they carry out public tasks. On the subject that interests us here, the annex is more specific than the general provisions.
Part I of the annex lists training for people involved in the processing of information as a measure that minimises the occurrence of incidents (point 17). It also sets out the subject scope. These are the types of cyber threats, basic cyber hygiene practices, responding to an incident, and awareness of the consequences of breaching information security rules. A separate point requires cyber hygiene practices to be applied by employees who use information systems, including by the head of the entity (point 14). The whole system is reviewed at least once a year (Part III of the annex).
For this group of entities the answer to the question in the title is therefore closest to being ready-made. The circle is marked out by involvement in the processing of information, and the subject scope is written out in the annex.
What to do about the provider’s staff
An entity performs its tasks through its own structures responsible for cybersecurity or under a contract with a managed cybersecurity services provider (Article 14). The choice of model does not change the addressee of the obligations towards its own staff. The entity is responsible for the awareness of its own people.
What remains to be settled is the interface between the two sides. Someone on the entity’s side receives information from the provider, assesses it and triggers the decision to report. That person needs preparation regardless of the provider’s competence, because the addressee of the reporting obligation remains the essential or important entity.
When the list has to be ready
Entities that met the qualification criteria on 3 April 2026 have twelve months to meet the obligations set out in the chapter on essential and important entities, that is until 3 April 2027 (Article 33(1) of the amending act of 23 January 2026). An entity that meets the criteria later has twelve months from that moment (Article 16 of the KSC Act). Staff education belongs to the same chapter as the other elements of the system.
The list of groups, however, comes into being earlier and almost as a by-product. It is the by-product of two other pieces of work. The first is establishing the scope of the information security management system, the second is identifying the people who perform the tasks under Articles 8 and 11. An organisation that is still establishing the scope of its obligations and its state of readiness will not build a credible list of groups before that is settled.
Most common mistakes
- One course for everyone treated as the whole obligation. A module on passwords and phishing covers cyber hygiene, not the tasks of the people who perform Articles 8 and 11.
- A list of groups built from the organisational chart. The starting point is the scope of the system and the division of tasks, not the structure of departments.
- Leaving out the person entrusted with the head’s duties. The Act names them alongside the head of the entity in Article 8e(1).
- Excluding procurement and HR because “they are not technical roles”. Supplier assessment and admitting a person to tasks are activities set out in the Act.
- Assuming that a contract with a provider removes the obligation towards your own staff. What changes is the model for performing the tasks, not the addressee of the obligations.
- Training the people under Articles 8 and 11 without a list of names first. The same list is needed for the criminal record check, so it comes into being in the organisation either way.
- Repeating the content of the head’s training in training for staff. The scope under Article 8e(2) concerns responsibility for meeting obligations, not an employee’s day-to-day activities.
Conclusions and next steps
The Act answers the question in the title indirectly, and that is exactly why the answer is often missed. It names one role beyond the head of the entity. The circle of the remaining people is something the organisation derives itself — from the scope of its own system, from the division of tasks and from involvement in handling incidents. The result of that work is both a training plan and evidence that the result required by Article 8d(4) has been planned deliberately.
The order below puts that exercise in place.
- Check whether anyone has been entrusted with the head’s duties in the area of cybersecurity and whether there is a record of it. That person is subject to the training obligation together with the head of the entity.
- List by name the people who perform the tasks under Articles 8 and 11, together with their deputies. The list is needed for the criminal record check anyway.
- Add the people designated for contact with the entities of the national cybersecurity system.
- Go through the catalogue of measures in Article 8(1)(2) and assign to each element the role that actually decides about it.
- Settle the boundary of “all staff” by access to the information system, not by the type of contract.
- In an important entity that is a public entity, set the result against points 14 and 17 of Annex 4.
- Write down how you will know that the result under Article 8d(4) has been achieved — otherwise a year later all that will be left is an attendance list.
Related materials
- What should NIS2 training for the board cover? — the scope of the mandatory training for the head of the entity and for the person entrusted with their duties.
- How do you know that training produced a real effect? — how to check the result required by Article 8d(4).
- What to do after detecting an incident? — the sequence of the first day, that is the material for the groups named in points two and three.
Sources
- Act of 5 July 2018 on the National Cybersecurity System, Article 8, Articles 8c–8f, Article 9, Article 14, Article 16 and Annex 4, consolidated text — Chancellery of the Sejm, ISAP: isap.sejm.gov.pl (in Polish; accessed 19 August 2026)
- Act of 23 January 2026 amending the Act on the National Cybersecurity System and certain other acts (Journal of Laws 2026, item 252), Article 33 — Journal of Laws: dziennikustaw.gov.pl (in Polish; accessed 19 August 2026)
- Directive (EU) 2022/2555 of the European Parliament and of the Council (NIS 2), Article 20(2) and Article 21(2)(g) — EUR-Lex: eur-lex.europa.eu (accessed 19 August 2026)
- Amendment of the KSC Act — questions and answers, question 3.8 on training for staff — Ministry of Digital Affairs: gov.pl (in Polish; accessed 19 August 2026)
- Amendment of the KSC Act — obligations of essential and important entities — Ministry of Digital Affairs: gov.pl (in Polish; accessed 19 August 2026)
Let us match the training to the roles in your organisation
If the list of groups does not exist yet, it is worth starting by setting the tasks under Articles 8 and 11 against the people who actually perform them. That comparison defines the programme for each group separately. Training and workshops are built on it.
This material is general and educational. It is not individual legal advice or a recommendation for any specific organisation. The scope of obligations should be assessed in the light of that organisation’s circumstances.
Legal status: August 2026.