<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>cybersecurity certification - KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</title>
	<atom:link href="https://www.kg-legal.eu/info/tag/cybersecurity-certification/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.kg-legal.eu/info/tag/cybersecurity-certification/</link>
	<description>KIELTYKA GLADKOWSKI LEGAL &#124; CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</description>
	<lastBuildDate>Mon, 07 Sep 2026 20:31:08 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	
	<item>
		<title>The MyDr Data Breach – Lessons for Healthcare Service Providers and e-Health Platforms</title>
		<link>https://www.kg-legal.eu/info/pharmaceutical-healthcare-life-sciences-law/mydr-data-breach-lessons-for-healthcare-providers-kglegal/</link>
					<comments>https://www.kg-legal.eu/info/pharmaceutical-healthcare-life-sciences-law/mydr-data-breach-lessons-for-healthcare-providers-kglegal/#respond</comments>
		
		<dc:creator><![CDATA[jakub]]></dc:creator>
		<pubDate>Mon, 07 Sep 2026 20:30:11 +0000</pubDate>
				<category><![CDATA[PHARMACEUTICAL, HEALTHCARE & LIFE SCIENCES LAW]]></category>
		<category><![CDATA[Act on Patients Rights]]></category>
		<category><![CDATA[AI Act]]></category>
		<category><![CDATA[AI cybersecurity]]></category>
		<category><![CDATA[AI in healthcare]]></category>
		<category><![CDATA[AI-enabled attacks]]></category>
		<category><![CDATA[anomaly detection]]></category>
		<category><![CDATA[anonymisation]]></category>
		<category><![CDATA[anonymization]]></category>
		<category><![CDATA[Artificial intelligence]]></category>
		<category><![CDATA[breach notification]]></category>
		<category><![CDATA[cloud healthcare]]></category>
		<category><![CDATA[controller liability]]></category>
		<category><![CDATA[Cyber Five]]></category>
		<category><![CDATA[cyber insurance]]></category>
		<category><![CDATA[Cyber Resilience]]></category>
		<category><![CDATA[cyber resilience healthcare]]></category>
		<category><![CDATA[cyber risk]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[cybersecurity certification]]></category>
		<category><![CDATA[cybersecurity insurance]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[data breach response]]></category>
		<category><![CDATA[data controller]]></category>
		<category><![CDATA[data minimisation]]></category>
		<category><![CDATA[data minimization]]></category>
		<category><![CDATA[Data Privacy]]></category>
		<category><![CDATA[data processing agreement]]></category>
		<category><![CDATA[data processor]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[data protection impact assessment]]></category>
		<category><![CDATA[deepfake]]></category>
		<category><![CDATA[digital health]]></category>
		<category><![CDATA[digital healthcare]]></category>
		<category><![CDATA[DPA]]></category>
		<category><![CDATA[DPIA]]></category>
		<category><![CDATA[e-health]]></category>
		<category><![CDATA[eHealth platforms]]></category>
		<category><![CDATA[electronic medical records]]></category>
		<category><![CDATA[EMR security]]></category>
		<category><![CDATA[EU AI Act]]></category>
		<category><![CDATA[gdpr]]></category>
		<category><![CDATA[GDPR Article 28]]></category>
		<category><![CDATA[GDPR Article 32]]></category>
		<category><![CDATA[GDPR Article 33]]></category>
		<category><![CDATA[GDPR Article 34]]></category>
		<category><![CDATA[GDPR Article 35]]></category>
		<category><![CDATA[GDPR Article 82]]></category>
		<category><![CDATA[GDPR Compliance]]></category>
		<category><![CDATA[GDPR compliance healthcare]]></category>
		<category><![CDATA[health data]]></category>
		<category><![CDATA[health tech]]></category>
		<category><![CDATA[Healthcare AI]]></category>
		<category><![CDATA[healthcare compliance]]></category>
		<category><![CDATA[healthcare contracts]]></category>
		<category><![CDATA[healthcare cybersecurity]]></category>
		<category><![CDATA[healthcare data breach]]></category>
		<category><![CDATA[healthcare data security]]></category>
		<category><![CDATA[healthcare IT]]></category>
		<category><![CDATA[healthcare providers]]></category>
		<category><![CDATA[healthcare software]]></category>
		<category><![CDATA[healthcare technology]]></category>
		<category><![CDATA[identity verification]]></category>
		<category><![CDATA[Incident Response]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[information security management]]></category>
		<category><![CDATA[ISO 27001]]></category>
		<category><![CDATA[IT supplier contracts]]></category>
		<category><![CDATA[joint and several liability]]></category>
		<category><![CDATA[liability insurance]]></category>
		<category><![CDATA[medical data protection]]></category>
		<category><![CDATA[medical records]]></category>
		<category><![CDATA[medical technology]]></category>
		<category><![CDATA[MedTech]]></category>
		<category><![CDATA[MFA]]></category>
		<category><![CDATA[multi-factor authentication]]></category>
		<category><![CDATA[MyDr data breach]]></category>
		<category><![CDATA[National Cybersecurity System]]></category>
		<category><![CDATA[network segmentation]]></category>
		<category><![CDATA[NIS2]]></category>
		<category><![CDATA[patient data]]></category>
		<category><![CDATA[patient privacy]]></category>
		<category><![CDATA[patients rights]]></category>
		<category><![CDATA[Personal data breach]]></category>
		<category><![CDATA[personal data protection]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[phishing attacks]]></category>
		<category><![CDATA[Poland cybersecurity]]></category>
		<category><![CDATA[Polish GDPR]]></category>
		<category><![CDATA[Polish healthcare law]]></category>
		<category><![CDATA[privacy by design]]></category>
		<category><![CDATA[processor liability]]></category>
		<category><![CDATA[pseudonymisation]]></category>
		<category><![CDATA[pseudonymization]]></category>
		<category><![CDATA[Regulatory Compliance]]></category>
		<category><![CDATA[risk assessment]]></category>
		<category><![CDATA[Risk Management]]></category>
		<category><![CDATA[sensitive personal data]]></category>
		<category><![CDATA[special category data]]></category>
		<category><![CDATA[sub-processors]]></category>
		<category><![CDATA[subprocessor management]]></category>
		<category><![CDATA[supplier risk management]]></category>
		<category><![CDATA[technology contracts]]></category>
		<category><![CDATA[telemedicine]]></category>
		<category><![CDATA[third-party liability]]></category>
		<category><![CDATA[UODO]]></category>
		<category><![CDATA[vendor risk]]></category>
		<category><![CDATA[voice deepfake]]></category>
		<guid isPermaLink="false">https://www.kg-legal.eu/?p=8909</guid>

					<description><![CDATA[<p>Publication date: September 07, 2026 What happened On 10 August 2026, MyDr, one of Poland&#8217;s largest providers of electronic medical records software, confirmed that it had been the target of a deliberate criminal attack on its systems. Two days later, the Ministry of Digital Affairs announced that the incident may affect close to 19 million [&#8230;]</p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/pharmaceutical-healthcare-life-sciences-law/mydr-data-breach-lessons-for-healthcare-providers-kglegal/">The MyDr Data Breach – Lessons for Healthcare Service Providers and e-Health Platforms</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-cyan-blue-color">Publication date: September 07, 2026</mark></strong></p>



<h2 class="wp-block-heading"><strong>What happened</strong></h2>



<div class="wp-block-media-text is-stacked-on-mobile" style="grid-template-columns:42% auto"><figure class="wp-block-media-text__media"><video controls src="https://www.kg-legal.eu/wp-content/uploads/2026/09/generated-video-1-1.mp4"></video></figure><div class="wp-block-media-text__content">
<p>On 10 August 2026, MyDr, one of Poland&#8217;s largest providers of electronic medical records software, confirmed that it had been the target of a deliberate criminal attack on its systems. Two days later, the Ministry of Digital Affairs announced that the incident may affect close to 19 million individuals and more than 12,000 healthcare facilities, and that the exfiltrated database exceeds 2 terabytes.</p>
</div></div>



<p>The attackers supplied the security portal Zaufana Trzecia Strona with a data sample suggesting that they hold PESEL numbers (Polish national identification numbers) and at least fragments of prescription information.</p>



<span id="more-8909"></span>



<p>To date, the company has not publicly confirmed the full scope and nature of the compromised data, referring instead to a pending forensic analysis. The investigation is being conducted by the Central Bureau for Combating Cybercrime under the supervision of the Warsaw Regional Prosecutor&#8217;s Office, and the President of the Personal Data Protection Office (UODO) has opened an inspection covering the technical and organisational measures applied and the underlying risk analysis. Since 29 August, the dataset from the incident has been available on the government portal bezpiecznedane.gov.pl, where anyone can check whether their data was affected.</p>



<p>The scale of the incident prompted the Ministry of Digital Affairs to announce, within three weeks, a legislative package branded the &#8220;Cyber Five&#8221;. Its key elements include certification of entities processing medical data within the existing national cybersecurity certification framework; a mandatory risk assessment before processing begins and at least every two years thereafter; new obligations for entities serving more than 100 controllers or processing data of more than 100,000 individuals (including rapid transfer of affected persons&#8217; data to CSIRT NASK and a duty to inform client facilities about the level of their own security); and notifications of medical events via the mObywatel and mojeIKP applications. The amendments are to cover the Act on Patients&#8217; Rights and the legislation governing the National Cybersecurity System.</p>



<h2 class="wp-block-heading"><strong>Why roles in the processing chain decide everything</strong></h2>



<p>From a legal standpoint, the critical point is that, in relation to medical records, MyDr acts as a processor, while each facility – from a large clinic network to a single-doctor practice – remains the controller. The consequences of this structure became fully apparent after the incident:</p>



<ul class="wp-block-list">
<li><strong>The obligation to notify UODO (Article 33 GDPR) and to communicate the breach to patients (Article 34 GDPR)</strong> rests with the controller, i.e. the facility. The processor is merely required to inform the controller &#8220;without undue delay&#8221; (Article 33(2) GDPR). In practice, thousands of healthcare providers had to assess risk and communicate with patients on the basis of fragmentary information from the supplier.</li>



<li><strong>Liability for damages (Article 82 GDPR)</strong> is joint and several: a patient may sue the facility, the supplier, or both. The processor is liable where it has failed to comply with obligations specifically imposed on processors by the GDPR or acted contrary to the controller&#8217;s instructions – but the facility is liable for having entrusted data to an entity that did not provide sufficient guarantees (Article 28(1) GDPR).</li>



<li><strong>Sector-specific requirements under the Act on Patients&#8217; Rights</strong> (Article 24(4)) impose on any entity entrusted with the processing of medical records a duty of confidentiality and data security – this is precisely the provision now slated for extension to include certification and minimum technological standards.</li>
</ul>



<p>Deputy Minister of Digital Affairs Dariusz Standerski stated openly that in this case, liability under the contract remained entirely with the controllers, i.e. small medical practices. This is the most important lesson of the incident: a data processing agreement is not a formality but the document that, on the day of a breach, determines who pays.</p>



<h2 class="wp-block-heading has-luminous-vivid-amber-background-color has-background"><strong>How a healthcare service provider can protect itself</strong></h2>



<p><strong>1. The data processing agreement and the main contract as risk-allocation tools.</strong> Standard DPA templates offered by software vendors focus on satisfying the minimum requirements of Article 28(3) GDPR. A healthcare provider should negotiate further: a precise deadline and format for incident notification (e.g. 24 hours, with a defined scope of information enabling a risk assessment); audit and penetration-testing rights; an obligation to maintain specified certifications (ISO 27001 and, in future, certification under the National Cybersecurity System Act); a duty to cooperate in communications with patients and the supervisory authority; liability and recourse clauses not capped at the annual fee; and a requirement that the vendor hold cyber insurance with a defined sum insured, with the facility named as a co-insured or beneficiary.</p>



<p><strong>2. Cyber and liability insurance.</strong> Standard professional liability policies for healthcare providers typically do not cover the cost of notifying patients, crisis management, administrative fines or claims arising from data breaches. A dedicated cyber policy covers these elements, but its exclusions must be read carefully: insurers increasingly condition cover on the implementation of MFA, system patching and backups, and an incident at an external supplier (a so-called <em>third-party breach</em>) is often covered only under an express extension. It is also worth verifying whether the software vendor&#8217;s own policy actually exists and what its limit is – given the number of facilities relying on a single system, such amounts may prove illusory.</p>



<p><strong>3. A map of relationships between entities.</strong> In a real-world e-health ecosystem, patient data flows between the facility, the EMR vendor, the hosting or cloud provider, the e-prescription and e-referral operator, laboratories, IT subcontractors and billing companies. Each link is a distinct legal relationship: processing on behalf of the controller, sub-processing (Article 28(2) and (4) GDPR) or joint controllership (Article 26 GDPR). A facility should maintain an up-to-date register of these entities, know where the data is physically located and control the chain of sub-processors – a &#8220;general&#8221; consent to sub-processors without a list and without a right to object is, in practice, an abdication of control.</p>



<p><strong>4. Anonymisation, pseudonymisation and data minimisation.</strong> Data that is not in the system cannot leak. Healthcare providers and vendors should separate identifiers (PESEL numbers, contact details) from clinical data, apply pseudonymisation (Article 4(5) and Article 32(1)(a) GDPR) in test, analytical and research environments, and store statistical data exclusively in anonymised form. It should be remembered that anonymisation is an irreversible process and only such a process removes data from the scope of the GDPR; pseudonymisation remains processing of personal data, but it significantly limits the consequences of a breach and is a valuable argument both in proceedings before UODO and in litigation over damages.</p>



<p><strong>5. Internal obligations and incident readiness.</strong> A breach response procedure should be tested, not merely written down: who decides on notifying UODO within 72 hours, who communicates with patients, who with the media, who secures the evidence. Regular risk analysis and a data protection impact assessment (DPIA) for EMR systems – which, given their scale and the categories of data involved, almost always meet the criteria of Article 35 GDPR – is an obligation already today, and once the &#8220;Cyber Five&#8221; enters into force it will additionally become a sector-specific requirement with a prescribed frequency.</p>



<h2 class="wp-block-heading has-luminous-vivid-amber-background-color has-background"><strong>AI-enabled attacks</strong></h2>



<p>The healthcare sector is particularly exposed to a new generation of AI-supported attacks. Large language models enable the mass generation of credible phishing messages in flawless Polish, personalised on the basis of data from previous breaches – a PESEL number, a surname and information about a prescription are enough to construct a convincing message &#8220;from your clinic&#8221; or &#8220;from the National Health Fund&#8221;. AI tools also automate the discovery of vulnerabilities in systems and the generation of malicious code, shortening the window between disclosure of a vulnerability and its exploitation. There is a growing number of cases involving voice deepfakes used to impersonate medical staff or IT administrators in order to obtain access credentials.</p>



<p>For vendors and facilities, this means that traditional &#8220;don&#8217;t click suspicious links&#8221; training is no longer sufficient. Technical mechanisms are required (phishing-resistant MFA, network segmentation, AI-assisted anomaly monitoring on the defensive side), together with identity verification procedures for every request for data access or a change of permissions. Regulatory risk should also be kept in mind: AI systems deployed in healthcare facilities – including tools supporting diagnostics or triage – fall under the AI Act, and their integration with EMR systems constitutes yet another link in the processing chain that must be reflected in contracts and in the risk analysis.</p>



<h2 class="wp-block-heading has-luminous-vivid-amber-background-color has-background"><strong>How we support institutional clients</strong></h2>



<p>KG Legal advises healthcare providers, medical networks, telemedicine platform and e-health software vendors, and investors in this sector on managing liability for data. Our support includes auditing existing data processing agreements and IT supplier contracts for risk allocation; negotiating liability, recourse and insurance clauses; mapping the chain of processors and vetting subcontractors; preparing and testing breach response procedures; handling notifications to UODO and communications with patients; and representation in inspection proceedings and in damages litigation. For medical technology vendors, we prepare documentation and contract templates meeting the requirements of the GDPR, the Act on Patients&#8217; Rights, NIS2 and – once enacted – the &#8220;Cyber Five&#8221; provisions, and we assess the compliance of AI-based solutions with the AI Act and the MDR. Our aim is that, on the day an incident occurs, the client knows exactly who is responsible for what and has evidence of having exercised due diligence.</p>



<p><em>Facts as at 2 September 2026, based on statements by MyDr, the Ministry of Digital Affairs and UODO, and press reports. This article is for information purposes only and does not constitute legal advice.</em></p>
<p>#MyDr #DataBreach #HealthcareCybersecurity #HealthcareData #DataProtection #GDPR #Cybersecurity #HealthTech #eHealth #DigitalHealth #MedicalRecords #EMR #PatientData #PatientPrivacy #UODO #Poland #CyberRisk #CyberInsurance #IncidentResponse #DataPrivacy #NIS2 #CyberFive #ISO27001 #AIAct #AIinHealthcare #AICybersecurity #MedTech #Telemedicine #CyberResilience #DataSecurity</p>
<p> </p>
<p> </p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/pharmaceutical-healthcare-life-sciences-law/mydr-data-breach-lessons-for-healthcare-providers-kglegal/">The MyDr Data Breach – Lessons for Healthcare Service Providers and e-Health Platforms</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.kg-legal.eu/info/pharmaceutical-healthcare-life-sciences-law/mydr-data-breach-lessons-for-healthcare-providers-kglegal/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		<enclosure url="https://www.kg-legal.eu/wp-content/uploads/2026/09/generated-video-1-1.mp4" length="492961" type="video/mp4" />

			</item>
		<item>
		<title>Act on the national cybersecurity certification system – for whom cybersecurity certificates will be needed.</title>
		<link>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/act-on-the-national-cybersecurity-certification-system-for-whom-cybersecurity-certificates-will-be-needed/</link>
					<comments>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/act-on-the-national-cybersecurity-certification-system-for-whom-cybersecurity-certificates-will-be-needed/#respond</comments>
		
		<dc:creator><![CDATA[jakub]]></dc:creator>
		<pubDate>Tue, 16 Sep 2025 13:05:49 +0000</pubDate>
				<category><![CDATA[IT, NEW TECHNOLOGIES, MEDIA AND COMMUNICATION TECHNOLOGY LAW]]></category>
		<category><![CDATA[cybersecurity certificates]]></category>
		<category><![CDATA[cybersecurity certification]]></category>
		<guid isPermaLink="false">https://www.kg-legal.eu/?p=8328</guid>

					<description><![CDATA[<p>Publication date: September 16, 2025 Cybersecurity certifications are designed for IT professionals, including system and network administrators, security specialists, engineers, and those aspiring to these roles, to validate their knowledge and practical skills in protecting against digital threats. The certification also covers ICT products, services, and processes, and aims to inform consumers about the level [&#8230;]</p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/act-on-the-national-cybersecurity-certification-system-for-whom-cybersecurity-certificates-will-be-needed/">Act on the national cybersecurity certification system – for whom cybersecurity certificates will be needed.</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-cyan-blue-color">Publication date: September 16, 2025</mark></strong></p>



<p class="has-luminous-vivid-amber-background-color has-background">Cybersecurity certifications are designed for IT professionals, including system and network administrators, security specialists, engineers, and those aspiring to these roles, to validate their knowledge and practical skills in protecting against digital threats. The certification also covers ICT products, services, and processes, and aims to inform consumers about the level of digital security and support Polish companies in European markets.</p>



<span id="more-8328"></span>



<p>On August 28, 2025, the Act of June 25, 2025, on the national cybersecurity certification scheme entered into force, implementing Regulation (EU) 2019/881 of the European Parliament and of the Council of April 17, 2019, on ENISA (the European Union Agency for Cybersecurity) and cybersecurity certification in information and communication technologies, and repealing Regulation (EU) No 526/2013 ( Cybersecurity Act ) (OJ L 151, 7.06.2019, p. 15 and OJ L 2025/37, 15.01.2025).</p>



<p>The Act defines the organization of the national cybersecurity certification scheme and the tasks and responsibilities of the entities participating in it. The new regulations allow for the issuance of European and national security certificates for products, services, systems, and processes related to information and communication technologies (ICT). This will confirm that a given product, service, or process meets specific data protection and cyberattack resistance standards.</p>



<p>Regulation 2019/881 aims to harmonize the issuance of cybersecurity certificates by introducing the possibility of creating European certification programs and common procedures for obtaining a certificate. This will allow <strong>cybersecurity certificates to be automatically recognized throughout the European Union</strong>. This is stipulated in Article 2, point 9 of Regulation 2019/881.</p>



<p>The European certification system is complemented by so-called national cybersecurity certification schemes in areas not covered by European cybersecurity certification programs. Regulation 2019/881 requires all European Union Member States to establish a national cybersecurity certification authority to oversee the market and monitor the correctness of certification activities. It is worth noting that the entire certification system will continue to be based on market mechanisms, meaning that private entities will be able to issue certificates under a national cybersecurity certification scheme. The Polish Council of Ministers&#8217; justification for the adopted law states that the solutions based on market opening were adopted, and no single national conformity assessment body was designated to issue certificates with a &#8216;high&#8217; assurance level. Adopting an alternative solution could constitute a barrier to the development of private conformity assessment bodies.</p>



<p>The change therefore involves placing the certificate issuing process under an umbrella and creating mechanisms for its oversight. More information about the European and national cybersecurity certification system, the relationship between European and national certificates, the framework of the national cybersecurity certification system, accreditation, conformity assessment, and the role of the minister as the national cybersecurity certification authority can be found here: <a href="https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/new-provisions-on-cybersecurity-certification-in-poland/">https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/new-provisions-on-cybersecurity-certification-in-poland/</a></p>



<p><strong>Are cybersecurity certificates mandatory and for whom?</strong></p>



<p>Regulation 2019/881 stipulates that cybersecurity certification is voluntary, unless EU or Member State law provides otherwise (Article 56, paragraph 2). By adopting the Act on the National Cybersecurity Certification System, the <strong>Polish legislator decided to maintain the voluntary nature of certification</strong>. The Council of Ministers&#8217; justification for the adopted Act includes the information that cybersecurity certification will be a complete voluntary process and will be conducted on market principles, and customers will be able to freely choose among entities operating on the market. The Act creates a framework for certification without imposing any obligations on market entities. Anyone interested will therefore be able to both start a business in this field and obtain certification of their ICT product, ICT service, ICT process, or managed security service, without being obligated to do so.</p>



<p>The same justification repeatedly mentions the voluntary nature of certification, which is crucial for two categories of entities: It should be emphasized that private entities will not be forced to join this system in any way. The obligations arising therefrom will therefore apply only to those who voluntarily submit to it. This applies to both conformity assessment bodies and entities undergoing the certification process.</p>



<p>At the EU level, there is currently no regulation introducing a direct certification obligation, although in reality, it is somewhat more complicated. Article 21 of Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 (NIS2 Directive) introduces numerous requirements for cybersecurity risk management measures, which Member States must impose on so-called key and important entities. Paragraph 5 of this article refers to Commission implementing acts specifying technical requirements for, among others, DNS service providers, TLD name registries, cloud service providers, and other entities included therein. Pursuant to Article 24 of NIS2, Member States may require essential and important entities to use specific ICT products, processes, and services certified in accordance with European cybersecurity certification schemes adopted pursuant to Article 49 of Regulation 2019/881.</p>



<p>The Act of 5 July 2018 on the National Cybersecurity System is responsible for implementing the provisions of the NIS1 and NIS2 Directives. Chapter 3 of the Act is devoted to the obligations of essential service operators, which include, among others, the obligation to implement security measures, report incidents, and conduct system security audits. Digital service providers must fulfill similar obligations, as regulated in Chapter 4 of the Act. These obligations do not include the requirement to hold a European cybersecurity certificate, although such a requirement could theoretically exist under the NIS2 regulations. At the same time, obtaining an appropriate cybersecurity certificate by essential service operators in particular, but also by digital service providers, may prove necessary or at least useful. The numerous and costly requirements placed on operators of essential services could be reduced by obtaining a cybersecurity certificate, for example by shortening the mandatory audit period.</p>



<p>The only currently adopted European cybersecurity certification program is based on the Common Criteria (ISO/IEC 15408). The requirements imposed by European and Polish legislation on essential service operators are largely based on widely used standards such as the aforementioned ISO/IEC 15408, ISO/EIC 27001, and ISO/IEC 27002. This means that developing a sufficiently secure infrastructure in accordance with the requirements of the most commonly used standards requires very similar, or even identical, measures to obtain a European cybersecurity certificate. Obtaining such a certificate, in turn, may entail benefits in the form of shortened procedures, such as security audits. The situation is similar with the previously mentioned requirements under the NIS2 Directive, such as DNS<a href="#_ftn1" id="_ftnref1">[1]</a>, which are largely based on the commonly used ISO/EIC standards.</p>



<p>Other EU legal acts also impose or enable the imposition of further cybersecurity requirements on various economic sectors. Such regulations include Regulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 on the digital operational resilience of the financial sector and amending Regulations (EC) No 1060/2009, (EU) No 648/2012, (EU) No 600/2014, (EU) No 909/2014 and (EU) 2016/1011 (DORA Regulation), which aims to increase the digital operational resilience of financial entities and regulate the provision of ICT services in the financial market. As a result of the noticeable trend of introducing further reporting requirements, resilience testing, risk management, etc., European cybersecurity certificates may prove to be a very useful way to meet all these requirements significantly more easily, although it is worth noting that there is no mechanism for automatic compliance upon obtaining a certificate.</p>



<p>It is worth emphasizing that obtaining cybersecurity certificates is not currently mandatory, but may prove necessary in the future in public procurement. The contracting authority has the right to specify a requirement for a specific certificate in the tender specifications (Terms of Reference). While theoretically, the requirements should be proportionate, based on non-discrimination and equal treatment, this means that an equivalent method of demonstrating compliance should be sufficient in most cases. Obtaining a certificate can therefore be useful when participating in tenders, both when the tender specifications specify a specific cybersecurity certificate or when only standards such as ISO/EIC are referenced. As mentioned earlier, cybersecurity certificates are largely based on these standards, allowing for an equivalent method of demonstrating compliance with the requirements.</p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<p><a href="#_ftnref1" id="_ftn1">[1]</a>Detailed requirements in this respect result, among others, from Commission Implementing Regulation (EU) 2024/2690 of 17 October 2024 laying down rules for the application of Directive (EU) 2022/2555 with regard to technical and methodological requirements for cybersecurity risk management measures and specifying the cases in which an incident is considered serious in relation to DNS service providers, TLD name registries, cloud service providers, data center service providers, content delivery network providers, managed service providers, managed security service providers, providers of online marketplaces, online search engines and social networking platforms, and trust service providers.</p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/act-on-the-national-cybersecurity-certification-system-for-whom-cybersecurity-certificates-will-be-needed/">Act on the national cybersecurity certification system – for whom cybersecurity certificates will be needed.</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/act-on-the-national-cybersecurity-certification-system-for-whom-cybersecurity-certificates-will-be-needed/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>New provisions on cybersecurity certification in Poland</title>
		<link>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/new-provisions-on-cybersecurity-certification-in-poland/</link>
					<comments>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/new-provisions-on-cybersecurity-certification-in-poland/#respond</comments>
		
		<dc:creator><![CDATA[jakub]]></dc:creator>
		<pubDate>Sun, 31 Aug 2025 18:37:41 +0000</pubDate>
				<category><![CDATA[IT, NEW TECHNOLOGIES, MEDIA AND COMMUNICATION TECHNOLOGY LAW]]></category>
		<category><![CDATA[cross border cases]]></category>
		<category><![CDATA[cybersecurity certification]]></category>
		<category><![CDATA[cybersecurity certification system]]></category>
		<category><![CDATA[ENISA]]></category>
		<category><![CDATA[Poland]]></category>
		<category><![CDATA[Regulation 2019/881]]></category>
		<guid isPermaLink="false">https://www.kg-legal.eu/?p=8222</guid>

					<description><![CDATA[<p>Polish Act on the national cybersecurity certification system Publication date: August 31, 2025 On August 28, 2025, the Polish Act of June 25, 2025, on the national cybersecurity certification scheme, entered into force, implementing Regulation (EU) 2019/881 of the European Parliament and of the Council of April 17, 2019, on ENISA (the European Union Agency [&#8230;]</p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/new-provisions-on-cybersecurity-certification-in-poland/">New provisions on cybersecurity certification in Poland</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<h3 class="wp-block-heading"><strong>Polish Act on the national cybersecurity certification system</strong></h3>



<p><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-cyan-blue-color"><strong>Publication date: August 31, 2025</strong></mark><a href="https://www.kg-legal.eu/wp-admin/edit.php?post_type=post"></a></p>



<p>On August 28, 2025, the Polish Act of June 25, 2025, on the national cybersecurity certification scheme, entered into force, implementing Regulation (EU) 2019/881 of the European Parliament and of the Council of April 17, 2019, on ENISA (the European Union Agency for Cybersecurity) and cybersecurity certification in information and communication technologies and repealing Regulation (EU) No 526/2013 ( Cybersecurity Act ) (OJ L 151, 7.06.2019, p. 15 and OJ L 2025/37, 15.01.2025).</p>



<span id="more-8222"></span>



<p>Regulation 2019/881 established a European cybersecurity certification framework, introducing the possibility of creating European certification schemes and common rules for obtaining certificates. Recital 69 of the aforementioned Regulation states: &#8220;It is therefore necessary to adopt a common approach and establish a European cybersecurity certification framework, specifying the main horizontal requirements for the European cybersecurity certification schemes to be developed and enabling the recognition and use in all Member States of European cybersecurity certificates and EU statements of conformity for ICT products, ICT services or ICT processes. [&#8230;] This European cybersecurity certification framework should have a two-fold objective. Firstly, it should help to increase trust in ICT products, services and processes certified under European cybersecurity certification schemes. Secondly, it should help to avoid the proliferation of conflicting or overlapping national cybersecurity schemes, thereby reducing costs for undertakings operating in the digital single market.&#8221; Recital 70 further states: &#8220;The European cybersecurity certification framework should be established in a harmonised manner across Member States in order to prevent certification shopping practices due to differences in the levels of requirements in different Member States.&#8221;</p>



<h2 class="wp-block-heading"><strong>Unification of certificates in the European Union?</strong></h2>



<p>Each certificate issued under a specific European cybersecurity program, as referred to in Article 2, point 9 of Regulation 2019/881, <strong><u>will be automatically recognized</u></strong> throughout the European Union. As indicated in the Council of Ministers&#8217; justification for the adoption of the Act, Regulation 2019/881 requires all EU Member States to establish a national cybersecurity certification authority, which will oversee the market and monitor the correctness of certification activities. To implement the Regulation&#8217;s provisions, it was also necessary to introduce a procedure for the accreditation of entities authorized to issue certificates into the Polish legal system. The Act also provides for the introduction of a national cybersecurity certification scheme in areas not covered by European cybersecurity certification programs.</p>



<p>Pursuant to Article 1 of the Act on the National Cybersecurity Certification System, the Act specifies the organisation of the national cybersecurity certification system and the tasks and responsibilities of the entities comprising this system, including the method of supervising the activities of the entities comprising this system, controlling the activities of these entities and coordinating their activities.</p>



<h2 class="wp-block-heading"><strong>The complex relationship between European and national certificates</strong></h2>



<p>The relationship between these models (the European and Polish certification systems), or between the Act on the National Cybersecurity Certification System and Regulation 2019/881, appears in some respects rather complicated, incomprehensible, or even chaotic. The problem with this provision appears to lie in the parallel operation of the national and European systems.</p>



<p>Under the Regulation, Poland will issue a European cybersecurity certificate as defined in Article 2, point 11 of Regulation 2019/881, a definition to which the Act on the National Cybersecurity Certification System refers. In addition to the European cybersecurity certification scheme (Article 2, point 9) and the related European cybersecurity certificate (Article 2, point 11), Regulation 2019/881 provides for a national cybersecurity certification scheme (Article 2, point 10).</p>



<p>The Act on the national cybersecurity certification system, specifically in Article 2, point 12, additionally mentions a national certificate defined as:</p>



<p>&nbsp;a document confirming that a given ICT product, a given ICT service, a given ICT process, a given managed security service, a given cybersecurity management system or a given natural person has been assessed for compliance with the detailed requirements specified in <strong>the national</strong> <strong>diagram</strong> <strong>cybersecurity certification.</strong></p>



<p>The concept of a national cybersecurity certification scheme is interesting because it is a way to expand the national cybersecurity certification program defined in Regulation 2019/881. A national cybersecurity certification program can only apply to ICT products, services, and processes, as well as managed security services. However, this definition leaves Member States without the basis to issue certificates covering individuals (e.g., cybersecurity experts) or security management systems under national certification programs.</p>



<p>For this reason, the Polish legislator created the concept of a national cybersecurity certification scheme in Article 2, point 13, which reads as follows: &#8220;national cybersecurity certification scheme &#8211; a national cybersecurity certification program referred to in Article 2, point 10 of Regulation 2019/881 and a comprehensive set of regulations adopted by a national cybersecurity certification authority, applicable to the certification of cybersecurity management systems or natural persons in the field of cybersecurity.&#8221;</p>



<h2 class="wp-block-heading"><strong>What is the national cybersecurity certification system?</strong></h2>



<p>As indicated in Art. 3, paragraph 1: &#8220;The national cybersecurity certification scheme is a set of entities referred to in paragraph 2 and procedures related to certification […] under European cybersecurity certification schemes or national cybersecurity certification schemes and procedures for the certification of cybersecurity certification schemes or natural persons under national cybersecurity certification schemes […]&#8221;, and also in paragraph 2: &#8220;The national cybersecurity certification scheme includes: 1) the minister responsible for digitalization; 2) the Polish Centre for Accreditation; 3) conformity assessment bodies; 4) suppliers who subject their products, services, ICT processes or managed security services to a conformity assessment under a given European cybersecurity certification scheme or a given national cybersecurity certification scheme; 5) natural persons who subject their knowledge and practical skills to a conformity assessment under a given national cybersecurity certification scheme; 6) entities that subject the cybersecurity management systems they use to a conformity assessment under a given national cybersecurity certification scheme.&#8221;</p>



<p>The relationship between national cybersecurity certification schemes and European cybersecurity certification schemes is also governed by Article 57(1) of Regulation 2019/881. It states that: &#8220;national cybersecurity certification schemes and related procedures for ICT products, ICT services, ICT processes and managed security services that are covered by a European cybersecurity certification scheme shall cease to have effect on the date specified in the implementing act adopted pursuant to Article 49(7). National cybersecurity certification schemes and related procedures for ICT products, ICT services, ICT processes and managed security services that are not covered by a European cybersecurity certification scheme shall continue to exist.&#8221;</p>



<p>The distinction between <strong><u>a national certificate</u></strong> and <strong><u>a national cybersecurity certificate</u></strong> was outlined in the Council of Ministers&#8217; justification for the act as follows: a national certificate will be issued for a product, service, ICT process, or managed security service, a security management system that ensures the availability, authenticity, integrity, or confidentiality of stored, transmitted, or processed data, or provided functions or services, at a level appropriate to potential cyberthreats, and minimizes known risks related to cyberthreats.</p>



<p>Therefore, possession of such a certificate will guarantee an adequate level of protection. In turn, a national cybersecurity certificate may be issued to an individual who possesses the knowledge and practical skills necessary to effectively perform cybersecurity tasks. Its holders will be able to stand out in the job market, and potential employers, including public institutions, will have proof of their competence.</p>



<h2 class="wp-block-heading"><strong>Framework for the national cybersecurity certification system</strong></h2>



<p>Article 6 of the Act on the National Cybersecurity Certification System specifies that a product, service, ICT process, managed security service, cybersecurity management system, or an individual&#8217;s cybersecurity knowledge and practical skills may be subject to a compliance assessment in accordance with a given national cybersecurity certification scheme. Article 7 of the Act on the National Cybersecurity System specifies the requirements for issuing a national certificate.</p>



<p>These requirements include ensuring the availability, authenticity, integrity, or confidentiality of processed data or provided functions or services at a level appropriate to potential cyberthreats, and minimizing known risks related to cyberthreats. In the case of individuals, a national certificate may be issued to an individual who possesses the knowledge and practical skills necessary to perform cybersecurity tasks.</p>



<p>Methods for verifying whether the requirements are aligned with the appropriate cybersecurity certification scheme include: examination of technical documentation, audits, testing of specific properties, or performance analyses. In the case of individuals, competence will be verified through a knowledge and practical skills test (Article 8 of the Act on the National Cybersecurity Certification System). A national certificate may be issued <strong>for a period of no less than two years and no longer than five years</strong>. According to the justification for the act, this is due to the fact that cybersecurity is a rapidly evolving field, meaning that a certificate issued in the past may not necessarily correspond to the level of competence currently required. However, its validity must be sufficiently long to ensure the certificate continues to function and remains relevant in the market. The certificate&#8217;s validity can be extended (Article 10 of the Act on the National Cybersecurity System).</p>



<p>Obtaining a national certificate also entails certain obligations on the part of its holder, including reporting obligations to the conformity assessment body, as further specified in Article 12 of the Act on the National Cybersecurity Certification System. The act stipulates that technical documentation regarding the subject of certification must be retained for a period of 10 years following the certificate&#8217;s expiry. This is necessary for monitoring and, if necessary, auditing the proper functioning of conformity assessment bodies (Article 14 of the Act on the National Cybersecurity Certification System).</p>



<h4 class="wp-block-heading"><strong>Creating national cybersecurity certification schemes</strong></h4>



<p>Pursuant to Art. 15 of the Act on the national cybersecurity certification system: The minister responsible for digitalization may specify, by regulation, a national cybersecurity certification scheme for selected ICT products, ICT services, ICT processes, managed security services, cybersecurity management systems or individuals, containing:</p>



<p>1) detailed requirements for ICT products, ICT services, ICT processes, managed security services, cybersecurity management systems subject to conformity assessment or individuals whose knowledge and practical skills in the field of cybersecurity are subject to conformity assessment;</p>



<p>2) detailed methods used to demonstrate that an ICT product, ICT service, ICT process, managed security service, cybersecurity management system or individual meets the requirements referred to in point 1;</p>



<p>3) detailed conditions for issuing, maintaining and extending the validity of national certificates;</p>



<p>4) detailed method of monitoring the compliance of ICT products, ICT services, ICT processes, managed security services, cybersecurity management systems or individuals with the requirements referred to in point 1, including mechanisms for demonstrating compliance with these requirements;</p>



<p>5) the detailed scope of technical documentation relating to certification and the method of storing and destroying this documentation;</p>



<p>6) the period of storing technical documentation relating to certification;</p>



<p>7) the period for which the national certificate is issued; 8) the template of the national certificate.</p>



<p><strong>Accreditation and conformity assessment</strong></p>



<p>Conformity assessment is performed by a conformity assessment body accredited to a given European cybersecurity certification program or national cybersecurity certification scheme. To assess the conformity of products, services, processes, managed services related to the security of cybersecurity management systems, and individuals, interested entities will need to obtain accreditation from the Polish Centre for Accreditation (PCA). The Polish Centre for Accreditation will inform the minister responsible for digitalization, no later than 14 days from the date of accreditation, of the granting of accreditation to a given European cybersecurity certification program or national cybersecurity certification scheme, as well as of any refusal, suspension, or limitation of the scope of accreditation to a conformity assessment body no later than 14 days from the date of the relevant decision. <strong>The Polish Centre for Accreditation</strong> supervises, within the scope of accreditation granted, conformity assessment bodies in the area covered by a given European cybersecurity certification scheme or a given national cybersecurity certification scheme, taking into account the requirements referred to in Art. 22 sec. 4 of the Act of 13 April 2016 on conformity assessment and market surveillance systems and the requirements specified in: 1) the annex to Regulation 2019/881, 2) European cybersecurity certification schemes, 3) national cybersecurity certification schemes (Art. 16 and 17 of the Act on the national cybersecurity certification scheme).</p>



<p><strong>Assessment of compliance with the requirements of the European cybersecurity certification program</strong></p>



<p>An ICT product, service, process, or managed security service (which therefore has a narrower scope) <strong>may be subject to a conformity assessment in accordance with a given European cybersecurity certification scheme</strong> based on an agreement between the provider and the conformity assessment body. The conformity assessment in question refers to one of the assurance levels specified in Article 52 of Regulation 2019/881. This agreement specifies, in particular, the ICT product, ICT service, ICT process, or managed security service to be subject to a conformity assessment, the scope of certification, the European cybersecurity certification scheme under which the European certificate is to be issued, the assurance level to which the certificate is to refer, the obligations of the parties related to certification, and the obligations related to the protection of information provided to the conformity assessment body, in particular the method of protecting trade secrets and other confidential information, including trade secrets, as well as the protection of intellectual property rights (Article 5 of the Act on the National Cybersecurity Certification System).</p>



<p>Article 49(7) of Regulation 2019/881 states that the Commission, on the basis of a scheme proposal prepared by ENISA, may adopt implementing acts establishing a European cybersecurity certification scheme for ICT products, ICT services, ICT processes and managed security services that meets the relevant requirements set out in Articles 51, 51a, 52 and 54. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 66(1) and in paragraph 8 that &#8220;ENISA shall evaluate each adopted European cybersecurity certification scheme at least every 5 years, taking into account feedback received from stakeholders. Where necessary, the Commission or the ECCG may request ENISA to initiate the process of developing a revised scheme proposal in accordance with Article 48 and this Article.</p>



<p><strong>Currently, one European cybersecurity certification scheme has been adopted</strong>, i.e. the <strong>European Cybersecurity Certification &#8211; the Scheme on Common Criteria (EUCC)</strong>, effective from February 2025, <strong>applies to ICT products (hardware, software, components) and is based on the Common Criteria standard (ISO/IEC 15408)</strong>. Such a certificate issued in Poland will be recognized throughout the EU. Other programs are in the preparation phase, including the European Cybersecurity program. Certification Scheme for Cloud Services (EUCS) for cloud services.</p>



<p><strong>The role of the minister</strong></p>



<p>The national cybersecurity certification authority, referred to in Article 58 of Regulation 2019/881, is the Minister responsible for computerization (Article 4 of the Act on the National Cybersecurity System). As part of the responsibilities imposed on the national government administration authority responsible for cybersecurity, the minister will conduct a number of administrative proceedings, including: granting consent to the issuance of European certificates referring to the “high” level; issuing authorizations to conduct conformity assessments where the certification program specifies specific requirements for assessment bodies; 3) withdrawing and limiting authorizations to conduct conformity assessments where the certification program specifies specific requirements for conformity assessment bodies; withdrawing a certificate referring to the “high” assurance level issued in contravention of the provisions of Regulation 2019/88 or the Act or in contravention of the provisions of the certification program; and imposing fines.</p>



<p>As part of the certification programs being developed by the European Cybersecurity Agency (ENISA), a procedure for introducing changes to the assessment methodology used by a conformity assessment body has emerged. Such an exception to the standard certification procedure requires the consent of the competent authority for cybersecurity. Therefore, it was necessary to establish an appropriate procedure in national legislation. Article 21, Section 1 of the Act on the National Cybersecurity Certification Scheme states: &#8220;If a given European cybersecurity certification program provides for the possibility of introducing changes to the assessment methodology to be used by a conformity assessment body, that body may submit a request to the minister responsible for digitalization to introduce changes to that methodology. The request shall include proposed changes to the assessment methodology to be used by the conformity assessment body, along with a justification.&#8221;</p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/new-provisions-on-cybersecurity-certification-in-poland/">New provisions on cybersecurity certification in Poland</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/new-provisions-on-cybersecurity-certification-in-poland/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
