Prawo Nowych Technologii

no. 3/2024

Amendment of the National Cybersecurity System Act in light of the DORA regulation and the NIS2 Directive

DOI: 10.32027/PNT.24.3.6
Joanna Wziątek-Ładosz
Autorka jest niezależnym ekspertem ds. cyberbezpieczeństwa, autorką podcastu pt.: „Cyberbezpieczni” Polskiego Radia, www.purecybersec.pl
Abstract

The article presents an analysis of key regulatory changes regarding network and information systems security arising from implementation of the NIS2 Directive, the DORA regulation, and other legal acts such as the National Cybersecurity System Act. It discusses the most important regulatory changes, including technical, operational, and organizational requirements that the affected entities must meet. The article outlines the obligations of these entities, the penalties for non-compliance, and the supervisory authorities’ powers as regards monitoring and enforcing the rules. Special has been given to DORA requirements for financial market entities and their impact on ICT risk management. The author also reviews the steps organizations should take to comply with the new requirements.

Keywords
NIS2, DORA, amendment of the National Cybersecurity System Act, cybersecurity, cyber resilience, cyber risk management