Integrated national reporting framework: Cyber.gov.pl, CERT Polska and S46 Cyber Hub: Poland operates an integrated national reporting structure combining a public routing gateway, a general system for incident submission and a protected connection for regulated entities. Cyber.gov.pl asks whether the reporter is a citizen, business or KSC entity (namely, the Act on the National Cybersecurity System) and directs the report to the appropriate system. CERT Polska operates the CSIRT NASK online form, which distinguishes natural persons or other entities from key and important entities. Email submission is also available. For entities in the National Cybersecurity System, S46 Cyber Hub supports cybersecurity communication and incident reporting. Under the amended KSC framework, qualifying entities must enter the KSC register, connect to S46 and implement incident-management and CSIRT-reporting obligations.
Sources: https://www.gov.pl/web/baza-wiedzy/zglaszanie-incydentow
https://cyber.gov.pl/zg%C5%82o%C5%9B-incydent
https://pa.s46.gov.pl/
https://www.gov.pl/web/system-s46/logowanie
https://incydent.cert.pl/#!/lang=en
Simplified public reporting of suspicious SMS, email and websites: CERT Polska provides simplified public-facing channels for reporting suspected phishing, fraudulent communications and potentially harmful websites. Suspicious SMS messages can be forwarded in their original form to the short number 8080, including messages with or without hyperlinks. The official guidance asks users not to remove the link or other content. Suspicious email messages and websites can instead be reported through the CERT Polska form or by email. These channels contribute to CERT Polska’s detection and analysis of cyber threats and offer citizens an accessible alternative to regulated-entity reporting infrastructure. The 8080 service is a specialised public reporting mechanism and does not replace mandatory incident notification by key, important or otherwise regulated entities under KSC, DORA or sector-specific requirements.
Sources: https://www.gov.pl/web/baza-wiedzy/dostales-niepokojacy-sms-albo-email-zglos-go-do-cert-polska-csirt-nask
National governmental and defence reporting: CSIRT GOV and CSIRT MON: Poland’s national-level CSIRT structure includes dedicated teams for incidents falling within the governmental and national-defence spheres. Cyber.gov.pl publishes direct telephone, email, website and postal contact details for CSIRT GOV and CSIRT MON alongside those of CSIRT NASK. Where a reporter already knows the competent team, these contacts provide a direct route; otherwise, the Cyber.gov.pl gateway can be used to navigate to the appropriate system. CSIRT GOV is the national level CSIRT for the government sphere, while CSIRT MON is the dedicated for the national-defence sphere; precise statutory allocation should be checked against the reporter’s legal status and the current KSC Act.
Sources: https://csirt.gov.pl/
https://csirt-mon.wp.mil.pl/en/contact-2019-08-23-c/
Sector-specific reporting mechanisms: CSIRT KNF and CSIRT Cyfra: Poland supplements its national CSIRTs with sectoral teams that receive notifications and support incident handling within defined industries. CSIRT KNF serves the financial market, accepts major-incident reports, supports covered entities, analyses incidents and coordinates with the national CSIRTs. Its also addresses reporting by financial entities classified as key or important and ICT reporting under DORA. CSIRT Cyfra was established in 2026 for key and important entities in digital infrastructure, including data centres, DNS services, domain registries, internet exchange points and content delivery networks. Its stated functions include receiving early warnings, incident notifications, intermediate and final reports, and potential-event notifications.
Sources: https://www.knf.gov.pl/en/MARKET/CSIRT_KNF
https://www.gov.pl/web/cyfryzacja/csirt-cyfra--nowy-zespol-cyberbezpieczenstwa-w-ministerstwie-cyfryzacji