Technology, Media and Telecommunications (TMT)

High‑Risk Providers (HRP) in the Polish National Cybersecurity System Act

Published on 28th July 2026

The concept of a high‑risk provider (HRP) is one of the crucial and most debated mechanisms introduced by the amendment to the Polish National Cybersecurity System Act (NCS Act). The new legal and procedural requirements have become an immediate operational challenge for entities subject to the NCS Act, requiring appropriate measures to be taken within their internal provider risk assessment processes.

Circuitboard swathed in blue light

The concept of a high‑risk provider (HRP) is one of the crucial and most debated mechanisms introduced by the amendment to the Polish National Cybersecurity System Act (NCS Act). This mechanism is intended to strengthen the resilience of the state, as well as of essential entities and important entities, against hybrid threats and cyber‑attacks, with a particular focus on supply chain security. The new legal and procedural requirements have become an immediate operational challenge for entities subject to the NCS Act, requiring appropriate measures to be taken within their internal provider risk assessment processes.

How does the mechanism for designating an entity as an HRP work?

The designation of an entity as a high‑risk provider does not take place automatically on the basis of formal criteria. It is an individual decision‑making process:

  1. administrative decision – the designation of an entity as an HRP takes place by way of an administrative decision issued by the Minister for Digital Affairs, following an opinion of the Cybersecurity Council;
  2. risk assessment – the assessment covers not only the technical layer (e.g. vulnerabilities in hardware or software), but also non‑technical factors, such as the level of dependence of the provider on third countries outside the EU/NATO and the potential impact on national security;
  3. consequences for entities under the NCS framework – once a decision is issued designating a given entity as an HRP, essential entities and important entities become subject to a prohibition on procuring specified ICT products, services or processes from that provider, to the extent indicated in the decision;
  4. obligation to withdraw equipment and software – ICT equipment and software originating from an HRP will have to be withdrawn from the infrastructure – as a rule, within 7 years from the date of publication of the decision, and in relation to functions critical for security – within 4 years.

Sector‑specific challenges: energy and OT infrastructure

The impact of the HRP mechanism on individual business sectors will vary. The energy sector is particularly sensitive, forming the backbone of national critical infrastructure. It is characterised by a high level of technological complexity and a distributed architecture of operational technologies (OT).

In the case of the energy sector, any decision to effectively exclude a provider does not relate solely to IT software. Supply chain verification requirements may potentially directly affect specialised industrial automation components and end devices, including in particular:

  1. inverters and photovoltaic converters and controllers installed in energy storage facilities,
  2. components of intelligent networks (Smart Grid/AMI), including communication modules used in electricity meters,
  3. PLC controllers and SCADA supervisory systems responsible for the continuity of electricity transmission and distribution,
  4. substation automation and control systems in generation facilities (e.g. wind, photovoltaic and gas power plants).

It should be emphasised that, as of today, no decision designating an entity as a high-risk provider, including in the area of technology providers for the energy sector, has yet been issued in Poland.

What does this mean for organisations?

Entities falling within the scope of the NCS framework (with a particular emphasis on the energy and industrial sectors) should take actions such as:

  1. inventory of ICT/OT assets – a detailed review of existing hardware and software from the perspective of the origin of components and the identification of providers supplying key elements of infrastructure;
  2. review of contracts and procurement processes – implementing appropriate contractual clauses, e.g. regarding liability for a change in the provider's status, technical support, and the right to terminate the contract without negative financial consequences;
  3. supply chain risk management – incorporating HRP‑related criteria and technological security requirements into provider due diligence procedures.

In practice, this means the need to combine legal, procurement, cybersecurity and OT infrastructure maintenance competences, so that regulatory decisions concerning HRPs do not catch organisations off guard and do not result in uncontrolled downtime or increased operating costs.
 

* This article is current as of the date of its publication and does not necessarily reflect the present state of the law or relevant regulation.

Interested in hearing more from Osborne Clarke?