Opinion of the European Central Bank of 20 January 2025 on national cybersecurity system (CON/2025/2)
OPINION OF THE EUROPEAN CENTRAL BANK of 20 January 2025 on national cybersecurity system (CON/2025/2) Introduction and legal basis
On 18 November 2024 the European Central Bank (ECB) received a request from the Polish Ministry of Digital Affairs for an opinion on a draft law amending the Law on the national cybersecurity system and certain other laws (hereinafter the ‘draft law’). The ECB’s competence to deliver an opinion is based on Articles 127(4) and 282(5) of the Treaty on the Functioning of the European Union and Article 2(1), third and fifth indents, of Council Decision 98/415/EC , as the draft law relates to Narodowy Bank Polski (NBP) and to payment and settlement systems. In accordance with Article 17.5, first sentence, of the Rules of Procedure of the European Central Bank, the Governing Council has adopted this opinion.
1. Purpose of the draft law
1.1 The draft law amends the Law on the national cybersecurity system currently in force, which implemented Directive (EU) 2016/1148 of the European Parliament and of the Council . The main purpose of the draft law is to improve cybersecurity in Poland by strengthening and enhancing the existing measures and procedures to bolster the security of network and information systems of essential and important entities, as set out in Directive (EU) 2022/2555 of the European Parliament and of the Council , which, inter alia, repealed Directive (EU) 2016/1148. 1.2 More specifically, the draft law significantly expands the scope of the national cybersecurity system by including additional sectors, such as wastewaters, the management of information and communication technology (ICT), space, postal services, and the production and distribution of chemicals and food. It strengthens the roles and responsibilities of national authorities responsible for cybersecurity by granting them expanded supervisory powers. Stricter obligations are imposed
1 Ustawa z dnia z dnia 5 lipca 2018 r. o krajowym systemie cyberbezpieczeństwa (consolidated text: Dz. U. z 2024 r. poz. 1077 i 1222).
2 Council Decision 98/415/EC of 29 June 1998 on the consultation of the European Central Bank by national authorities regarding draft legislative provisions (OJ L 189, 3.7.1998, p. 42).
3 Directive (EU) 2016/1148 of the European Parliament and of the Council of 6 July 2016 concerning measures for a high common level of security of network and information systems across the Union (OJ L 194, 19.7.2016, p. 1).
4 Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 on measures for a high common level of cybersecurity across the Union, amending Regulation (EU) No 910/2014 and Directive (EU) 2018/1972, and repealing Directive (EU) 2016/1148 (NIS 2 Directive) (OJ L 333, 27.12.2022, p. 80). on essential and important entities, which categories, in line with Directive (EU) 2022/2555, replace operators of essential services and providers of digital services. According to the explanatory memorandum accompanying the draft law, the rapidly changing international landscape and the need to provide services to an increasing number of new clients underscore the importance of strengthening cybersecurity measures. This is reflected in the statistics reported by one of the Computer Security Incident Response Teams (CSIRT): over 39 000 cybersecurity incidents were recorded in 2022, and more than 75 000 in 2023. 1.3 The draft law also introduces a National Incident Response Plan to address large-scale cybersecurity 5 6 incidents and crises , and implements the 5G Toolbox to ensure 5G network security and harmonise cybersecurity policies across Member States. 1.4 Subject to certain exceptions, the draft law applies to NBP, which will qualify as an essential entity under the new framework. Provisions concerning the withdrawal of ICT products, services and processes stemming from high-risk suppliers do not apply to NBP. In particular, whilst the Minister for Digital Affairs is empowered to identify high-risk suppliers through formal decisions and to issue security orders specifying actions to mitigate the effects of ongoing critical incidents, these powers are restricted in relation to NBP. Instead, the Minister of Digital Affairs will notify the Governor of NBP about any decisions designating a supplier as high-risk. It is then the Governor’s prerogative to decide whether to withdraw the ICT products, services, or processes identified in the decision . According to the explanatory memorandum accompanying the draft law, these exclusions uphold NBP’s constitutional independence and operational autonomy within the national cybersecurity framework. 1.5 The draft law imposes obligations on essential and important entities to implement appropriate and proportionate technical, operational, and organisational measures to mitigate risks and protect networks and information systems , in line with Directive (EU) 2022/2555. At the same time, it strengthens the supervisory powers of the authorities responsible for cybersecurity, allowing them to ensure compliance through measures such as issuing warnings, appointing monitoring officers, and mandating information system security assessments or cybersecurity audits . The draft law introduces new financial penalties for non-compliance with the obligations imposed by it . In addition, the draft law anticipates that a financial penalty may also be imposed on persons in charge of essential entities for failure to ensure compliance with cybersecurity-related tasks . Supervision over the application of the provisions of the draft law is entrusted to the authorities responsible for
6 Cybersecurity of 5G networks: EU Toolbox of risk mitigating measures, CG Publication 01/2020. cybersecurity, which are also empowered to impose the abovementioned penalties. For public entities, such as NBP , the competent authority responsible for cybersecurity is the Minister for Digital Affairs . For the banking sector and financial market infrastructures, the competent authority is Komisja Nadzoru Finansowego (KNF, Polish Financial Supervision Authority). 1.6 The draft law establishes additional sectoral cyber security incident response teams (CSIRTs), which are tasked with supporting essential and important entities in responding to cybersecurity incidents, ensuring specialised assistance tailored to the unique needs of each sector. The draft law also strengthens national-level CSIRTs, enhancing their capacity to address a broader range of cybersecurity challenges and support an increasing number of entities. Essential and important entities are required to report incidents through an IT system managed by the Minister for Digital Affairs, directing notifications to the relevant sectoral or national-level CSIRTs . Additionally, CSIRTs are authorised to conduct security assessments of information systems used by entities within the national cybersecurity system. However, security assessments of NBP information systems may only be carried out with NBP’s explicit consent . 1.7 The role of the Government Plenipotentiary for Cybersecurity is also reinforced, granting him/her the authority to issue recommendations aimed at improving the cybersecurity of information systems within the national framework .
2. General observations
2.1 Directive (EU) 2022/2555 is a minimum-harmonisation directive. Article 5 of that Directive provides that it does not preclude Member States from adopting or maintaining provisions ensuring a higher level of cybersecurity, provided that such provisions are consistent with Member States’ obligations laid down in Union law. The draft law goes beyond Directive (EU) 2022/2555, which excludes central banks (along with parliaments and the judiciary) from the definition of a ‘public administration entity’ . This would have the consequence that the Polish component of Eurosystem-owned and operated financial market infrastructures, such as TARGET, would not benefit from the exclusion of central banks from the application of Directive (EU) 2022/2555 . 2.2 The ECB refers to its previous stance taken in the context of national measures implementing Directive (EU) 2016/1148, whereby the ECB supported the aim of Directive (EU) 2016/1148 of ensuring a high common level of network and information security across the Union and of achieving a consistency of approach in this field across business sectors and Member States . The ECB
12 See Appendix 1 of the draft law.
17 See Article 6, point (35), of Directive (EU) 2022/2555.
18 See paragraph 2.1 of Opinion CON/2024/14 and paragraph 2.1 of Opinion CON/2024/24. All ECB opinions are published on EUR-Lex.
19 See paragraph 2.1 of Opinion CON/2014/58 of the European Central Bank of 25 July 2014 on a proposal for a directive of the European Parliament and of the Council concerning measures to ensure a high common level of network and information security across the Union (OJ C 352, 7.10.2014, p. 4), paragraph 2.1 of Opinion CON/2017/10, paragraph 2.2 of Opinion CON/2018/22, paragraph 2.2 of Opinion CON/2018/27 and paragraph 2.2 of Opinion CON/2019/17. strongly supports the objectives of Directive (EU) 2022/2555 to increase the level of cyber resilience across all relevant sectors, reduce inconsistencies across the internal market and improve the level of situational awareness and the collective capability to prepare and respond by ensuring efficient cooperation in the Union . As already noted by the ECB, it is important to ensure that the internal market is a safe place to do business and that all Member States have a certain minimum level of preparedness for cybersecurity incidents . Directive (EU) 2022/2555 produces benefits from synergies and economies of scale. In particular, the dedicated national cyber security authorities have the potential to become repositories of considerable resources and expertise which the European System of Central Banks (ESCB) may draw upon. Concurrently, it should be ensured that the provisions of the national legislation transposing Directive (EU) 2022/2555 are interpreted and applied consistently with the ESCB’s competences and respect the principle of central bank independence enshrined in Article 130 of the Treaty. Indeed, NBP’s independent exercise of its tasks and responsibilities, such as its tasks relating to the smooth operation of payment and settlement systems, should not be affected. Central bank independence does not have the consequence of separating the Union’s central banks entirely from the Union and exempting them from every rule of Union law . This also applies to national legislative measures capable of applying to national central banks (NCBs) in the ESCB. Furthermore, the exercise of the powers of the authorities responsible for cybersecurity, which in the case of NBP, would be the Minister for Digital Affairs, is subject to various specific rules, guarantees and limitations, whilst the purpose for which they may be used is clearly delineated. The ECB welcomes the exclusion of provisions concerning the withdrawal of ICT products, services, and processes in relation to NBP. This exclusion upholds NBP’s operational autonomy within the national cybersecurity framework and reflects the importance of maintaining the specific safeguards applicable to the independence and operational integrity of central banks. The fact that the information system security assessment of NBP can be carried out only after obtaining the consent of NBP also upholds NBP’s independence . In addition, certain provisions of the draft law provide for specifically listed powers of the responsible authority to be exercised with a view to achieving the objectives of the draft law . Therefore, national measures implementing Directive (EU) 2022/2555 that extend to NCBs, such as the draft law, are not per se precluded from applying to NCBs.
3. Impact of the draft law on TARGET and on payment systems overseen by the ECB, NBP and the ESCB
3.1 In accordance with Article 127(2), fourth indent, of the Treaty, promotion of the smooth operation of payment systems is one of the core tasks of the ESCB. Article 139(2), point (c), of the Treaty stipulates, inter alia, that the basic tasks of the ESCB as listed in Article 127(2) of the Treaty, including
20 See Opinion CON/2022/14 of the European Central Bank of 11 April 2022 on the Proposal for a Directive of the European Parliament and of the Council on measures for a high common level of cybersecurity across the Union, repealing Directive (EU) 2016/1148 (OJ C 233, 16.6.2022, p. 22), General observations.
21 See paragraph 2.2 of Opinion CON/2019/17.
22 See judgment of the Court of Justice of 10 July 2003, Commission v ECB, C-11/00, EU:C:2003:395, paragraphs 134 to 136. promoting the smooth operation of payment systems, shall not apply to Member States with a derogation, such as Poland. However, the ability of an NCB of a Member State with a derogation, including NBP, to independently achieve its primary objective of maintaining price stability, as required under Articles 127 and 130 of the Treaty, would be jeopardised if that NCB’s basic payment system tasks are not subject to central bank independence requirements . Thus, the ESCB as a whole has a particular interest in an enhanced level of network information security in respect of payment systems, as it fosters confidence and the smooth functioning of the economy . 3.2 Systemically important payment systems (SIPS) such as, for example, TARGET, are identified pursuant to ECB decisions and are thus overseen by the ECB. Among SIPS, TARGET plays a distinct role, as it is the large value payment system for the euro, which is owned and operated by the Eurosystem and which serves as the channel for the implementation of the euro area’s monetary policy. TARGET is subject to harmonised legal conditions defined in Guideline (EU) 2022/912 of the European Central Bank (ECB/2022/8) . NBP, acting as a connected NCB, facilitates Polish participation in TARGET . The Polish component of TARGET, TARGET-NBP, for which NBP acts as the operator, would appear to fall within the scope of the draft law, as the draft law applies to NBP and, except for the provisions concerning the withdrawal of ICT products, services, and processes which do not apply to NBP, no exemption with regard to infrastructures or payment systems operated by NBP is provided. 3.3 Further, in addition, to its role as a connected NCB facilitating Poland’s participation in TARGET, NBP exercises oversight competences in respect of the payment systems’ infrastructures under Polish law. The main objectives of this oversight are to ensure the smooth and safe functioning of the payment system and verify compliance with legal provisions governing the operation of supervised systems, schemes, and services. These objectives are integral to fulfilling NBP's statutory tasks, such as organising monetary settlements and contributing to the stability of the national financial system . Specifically, NBP is responsible for monitoring the safety and operational reliability of key payment systems, such as SORBNET2 and TARGET-NBP, as well as several retail payment systems, payment schemes and clearing and settlement systems. The Governor of NBP exercises
25 See paragraph 2.8 of Opinion CON/2020/13.
26 See paragraph 3.1 of Opinion CON/2024/14 and paragraph 3.1 of Opinion CON/2024/24.
27 Regulation of the European Central Bank (EU) No 795/2014 of 3 July 2014 on oversight requirements for systemically important payment systems (ECB/2014/28) (OJ L 217, 23.7.2014, p. 16).
28 Decision ECB/2014/35 of the European Central Bank of 13 August 2014 on the identification of TARGET2 as a systemically important payment system pursuant to Regulation (EU) No 795/2014 on oversight requirements for systemically important payment systems (OJ L 245, 20.8.2014, p. 5); Decision ECB/2014/36 of the European Central Bank of 13 August 2014 on the identification of EURO1 AND STEP2-T as systemically important payment systems pursuant to Regulation (EU) No 795/2014 on oversight requirements for systemically important payment systems, available on EUR-Lex.
29 Guideline (EU) 2022/912 of the European Central Bank of 24 February 2022 on a new-generation Trans-European Automated Real-time Gross Settlement Express Transfer system (TARGET) and repealing Guideline ECB/2012/27(ECB/2022/8) (OJ L 163, 17.6.2022, p. 84); see also paragraph 3.5 of Opinion CON/2024/14 and paragraph 3.5 of Opinion CON/2024/24.
30 See Article 4 of Guideline (EU) 2022/912 (ECB/2022/8). oversight through mechanisms such as granting authorisations for the operation and modification of payment systems and schemes, issuing binding recommendations, and conducting assessments to monitor compliance and operational risks. Specific activities include collecting and analysing data, investigating incidents, and collaborating with entities managing payment systems and schemes. In performing its oversight duties, NBP also assesses payment systems for compliance with cybersecurity standards, aiming to enhance their resilience and operational security. This includes evaluating large-value payment systems for their compliance with the Cyber resilience oversight expectations (CROE) of December 2018 issued by the Eurosystem oversight function . In addition, the Governor of NBP may issue decisions to address deficiencies, such as suspending or revoking authorisations if necessary. Furthermore, NBP cooperates with other supervisory authorities, including KNF, to ensure coordinated oversight. While its primary focus is on safeguarding payment system operations within Poland, NBP also plays a pivotal role in aligning its oversight practices with ESCB standards . The draft law should aim to respect NBP’s oversight competences over the payment systems infrastructure as established under Polish law. Against this background, the ECB would welcome the establishment under the draft law of additional cooperation arrangements between the cybersecurity implementing bodies and NBP. The ECB suggests that, in the context of such cooperation, effective information-sharing and consultation mechanisms are put in place in order to prevent situations which could undermine NBP’s ability to perform its ESCB tasks independently or to preserve the confidentiality of ESCB information. In particular, NBP would need to be informed about actual and potential cyber incidents, as well as planned or adopted measures which may affect the TARGET-NBP component in a timely and efficient manner in order to enable NBP to fulfil its obligations under the Treaty and the Statute of the ESCB. Such arrangements would also ensure that the cybersecurity implementing bodies and NBP exchange information and consult on actual and potential cyber incidents or threats in the financial sector’s systems, and in particular infrastructures operated by the Eurosystem, and on planned and adopted measures, in an effective and timely manner without the need to resort to the unilateral enforcement measures envisaged under the draft law. 3.4 In addition, the ECB stands ready to cooperate with cybersecurity implementing bodies, in particular the Polish Minister for Digital Affairs, with a view to ensuring that best practices with regard to Directive (EU) 2022/2555 are established and followed . The ECB also suggests that the respective cooperation and information-sharing arrangements are established between the Minister for Digital
32 See ‘Cyber resilience oversight expectations for financial market infrastructures’ (December 2018), approved by the ECB’s Governing Council, available on the ECB’s website at www.ecb.europa.eu.
33 See the Polish Payment System Oversight Report for 2022, which references the applicable national legal framework: Act of 24 August 2001 on Settlement Finality in Payment and Securities Settlement Systems and the Rules of Oversight of these Systems; Act of 29 July 2005 on Trading in Financial Instruments; Act of 19 August 2011 on Payment Services. Available on NBP’s website at www.nbp.pl.
34 See paragraph 6.3 of Opinion CON/2018/22 and paragraph 2.4 of Opinion CON/2019/17. Affairs and the ECB, through NBP, to ensure that the overall functioning of TARGET is not undermined. This opinion will be published on EUR-Lex. Done at Frankfurt am Main, 20 January 2025. [signed] The President of the ECB Christine LAGARDE