SaaS provider
Qualification of the activities of a SaaS provider under the provisions of the Act on the National Cyber Security System and the Cyber Resilience Act
We advised service providers on the website and in the mobile app in:
Qualification of the activities of a SaaS provider under the provisions of the Act on the National Cyber Security System (UKSC) and the Cyber Resilience Act (CRA)
An increasing number of EU regulations are establishing a legal framework in the area of cybersecurity. Examples include, among others:
- Directive (EU) 2022/2555 of the European Parliament and of the Council of December 14, 2022, on measures to ensure a high common level of cybersecurity within the Union (NIS2 Directive), which was transposed into Polish law through an amendment to the Act on the National Cybersecurity System (UKSC), and
- Regulation (EU) 2024/2847 of the European Parliament and of the Council (EU) 2024/2847 of October 23, 2024, on horizontal cybersecurity requirements for products with digital components (the Cyber Resilience Act).
The UKSC and the CRA impose numerous new obligations on entities within their scope of application in the broadly defined area of cybersecurity and digital resilience. At the same time, from a legislative standpoint, both the UKSC (following the NIS2 Directive) and the CRA leave much to be desired. These regulations use numerous general, broad, and vague terms and definitions, and determining their meaning often requires referring to definitions contained in other legal acts. As a result, one of the fundamental practical challenges is determining whether—and, if so, to what extent—a given entity or its operations are subject to the UKSC or CRA. Determining that the UKSC or CRA applies (or will apply) to a given entity’s activities, in turn, necessitates identifying the relevant regulatory obligations and bringing the entity’s operations into compliance with the requirements set forth in those statutes.
CRA:
The concept of a product with digital elements—which refers to computer software or computer hardware and related remote data processing solutions, including software or hardware components that are marketed separately.
The CRA imposes obligations primarily on manufacturers of products with digital elements. They are required to ensure that the product is designed, developed, and manufactured in accordance with the essential cybersecurity requirements set forth in the CRA.
CRA:
- As a general rule, it applies to products with digital components placed on the market on or after December 11, 2027, and
- applies to products with digital components placed on the market before December 11, 2027, only if significant modifications to those products occur after that date.
By way of derogation, the obligations set forth in Article 14 of the CRA (reporting actively exploited vulnerabilities and serious incidents) apply to all products with digital components falling within the scope of the CRA that were placed on the market before December 11, 2027 (Article 69(3) of the CRA).
Commission Implementing Regulation (EU) 2025/2392 of November 28, 2025, was also adopted pursuant to the CRA on the technical description of categories of essential and critical products with digital components in accordance with Regulation (EU) 2024/2847 of the European Parliament and of the Council, which contains detailed technical descriptions for selected product categories (e.g., standalone and embedded browsers, password managers, software that detects, removes, or quarantines malware, and physical and virtual network interfaces). It provides interpretive guidance on which services and products are subject to the CRA.
UKSC:
As a general rule, the UKSC covers key entities and important entities, i.e., entities that provide a specific range of services and meet the criteria regarding company size.
For example:
- A key entity would include, among others:
- a managed services provider or cloud computing provider that exceeds the requirements for a medium-sized enterprise set forth in Article 2(1) of Annex I to Commission Regulation (EU) No. 651/2014 (i.e., one that employs at least 250 employees or whose annual turnover exceeds EUR 50 million and whose annual balance sheet total exceeds EUR 43 million),
- a provider of managed cybersecurity services that at least meets the requirements for a small or medium-sized enterprise set forth in Article 2(1) of Annex I to Regulation 651/2014/EU or exceeds them (i.e., in the case of a small enterprise: employs at least 10 to 49 employees and has an annual turnover or annual balance sheet total not exceeding 10 million EUR, whereas, in the case of a medium-sized enterprise: it employs between 50 and 249 employees and has an annual turnover not exceeding EUR 50 million or an annual balance sheet total not exceeding EUR 43 million; or exceeds these requirements),
- regardless of the entity’s size:
- a qualified trust service provider within the meaning of Article 3(20) of Regulation (EU) No. 910/2014,
- a critical entity as defined in Article 2(1) of Directive (EU) 2022/2557 of the European Parliament and of the Council of December 14, 2022, on the resilience of critical entities,
- An eligible entity will include, among others:
- a managed services provider or cloud computing provider that meets the requirements for a medium-sized enterprise as defined in Article 2(1) of Annex I to Regulation (EU) No. 651/2014 (i.e., employs between 50 and 249 employees and has an annual turnover or annual balance sheet total exceeding 10 million EUR, but not exceeding 50 million EUR, or an annual balance sheet total not exceeding 43 million EUR) and which is not a key entity,
- a postal operator as referred to in Article 3(12) of the Act of November 23, 2012—Postal Law, a digital service provider (i.e., a provider of an online trading platform, a search engine provider, or a social networking platform provider), which meets the requirements for a medium-sized enterprise set forth in Article 2(1) of Annex I to Regulation (EU) No. 651/2014 or exceeds those requirements (i.e., employs between 50 and 249 employees and has an annual turnover not exceeding EUR 50 million or an annual balance sheet total not exceeding EUR 43 million; or exceeds these requirements) and which is not a key entity;
Cloud Computing Provider
Pursuant to Article 2(4e) of the UKSC, a cloud computing provider is defined as: an entity providing a service that enables access to a scalable and flexible set of computing resources for shared use by multiple users.
In turn, pursuant to Article 6(30) of NIS2: “cloud service” means a digital service that enables the on-demand management of a scalable and flexible set of computing resources for shared use and broad remote access to that set, including when such resources are distributed across multiple locations.”
The fundamental problem with the definition contained in the UKSC is that it does not fully correspond to the definition of cloud services set forth in NIS2. Specifically, the UKSC definition does not include the element (condition) of “on-demand management.”
Similarly, Recital 33 of NIS2 states that: “Cloud services should include digital services that enable the on-demand administration of a scalable and flexible set of distributed computing resources for shared use, as well as broad remote access to that set, including when such resources are deployed across multiple locations. Computing resources include resources such as networks, servers, or other infrastructure, operating systems, software, storage, applications, and services. Cloud service models include, among others, Infrastructure as a Service (IaaS), Platform as a Service (PaaS), Software as a Service (SaaS), and Network as a Service (NaaS). Cloud service deployment models should include private, community, public, and hybrid clouds. Cloud service models and deployment models have the same meaning as the services and their implementation models defined in ISO/IEC 17788:2014. The ability of cloud service users to unilaterally provision computing resources, such as server time or network storage, without any human interaction on the part of the cloud service provider can be defined as “on-demand management.”
Managed Services Provider
Pursuant to Article 2(4)(i) of the UKSC, a managed services provider is defined as: a natural person, a legal entity, or an organizational unit without legal personality that provides services related to the installation, operation, or maintenance of ICT products, ICT services, ICT processes, or information systems through support or active administration carried out at the service recipient’s premises or remotely.
Managed Cybersecurity Services Provider
Pursuant to Article 2(4j) of the UKSC, a managed cybersecurity services provider is defined as a natural person, a legal entity, or an organizational unit without legal personality that provides services consisting of the implementation of or support for activities related to cybersecurity risk management, including incident response, security testing, information system audits, and consulting.
Obligations under the UKSC
Meeting the criteria for classification as a key entity or an important entity requires compliance with UKSC requirements (in particular: inclusion in the register of key and important entities, implementation of cybersecurity obligations, connection to the ICT system (S46); for critical entities, additionally: information system security audits).
Financial Entities
Separately, the UKSC also imposes certain obligations on financial entities as defined by DORA (Regulation (EU) (EU) 2022/2554 of December 14, 2022, on the operational digital resilience of the financial sector). As a general rule, the UKSC imposes specific obligations on financial entities, with the proviso, however, that certain provisions (e.g., Article 67k(2) of the UKSC) provide for situations in which these obligations do not apply to entities that, while having the status of a financial entity within the meaning of the UKSC, are subject to Article 16(1) of DORA. This provision refers, among others, to payment institutions exempted under PSD2.
DLK’s advisory included:
- an analysis of the entity’s operations and services provided (website, mobile app) to determine whether the entity should be classified as a key or significant entity under the UKSC, or whether the entity is subject to the UKSC in another capacity
- an analysis of the entity’s operations and services provided to determine whether they qualify as products with digital elements within the meaning of the CRA and to determine whether the entity is subject to the obligations set forth in the CRA
- practical recommendations
Lawyers involved in the project:
Bartosz Wyżykowski
attorney-at-law, partner Bartosz Wyżykowski
IT & Outsourcing
TelecommunicationsOnline & eCommerce
Online & eCommerceAlso check
#Banking & Fintech #DLK Legal #Online & eCommerce
Polish commercial bank
Bank’s obligations under Polish gambling legislation
Bank’s obligations under Polish gambling legislation#Banking & Fintech #IT & Outsourcing
inFakt & Unicredit / Vodeno
Integration of inFakt accounting with UniCredit accounts (embedded banking)
Integration of inFakt accounting with UniCredit accounts (embedded banking)#Banking & Fintech #Online & eCommerce #Retail
Reservise sp. z o.o.
Entry in the register of issuers of so-called “Limited Network” instruments
Entry in the register of issuers of so-called “Limited Network” instruments
