On July 21, 2026, the Act of May 15, 2026, amending the Penal Code (Journal of Laws of 2026, item 902), entered into force and was published in the Journal of Laws on July 6, 2026. The amendment completes the transposition of Article 7 of Directive 2013/40/EU of the European Parliament and of the Council of August 12, 2013, on attacks against information systems, which—as stated in the bill's explanatory memorandum—the Republic of Poland has not yet fully implemented. Although the editorial change is minimal and amounts to the rephrasing of a single reference, its practical consequences for the entire IT security environment are disproportionately large.

What is the change?

The previous wording of Article 269b § 1 of the Penal Code criminalized the production, acquisition, sale, or making available to other persons devices or computer programs adapted for committing a number of offenses specified in that provision. However, in relation to Chapter XXXIII of the Penal Code, the reference covered only Article 267 § 3 of the Penal Code, i.e., an act consisting in the unlawful installation or use of a listening device, visual device, or other device or software for the purpose of obtaining information to which the perpetrator is not authorized. The amendment replaced this reference with a reference to Article 267 § 1–3 of the Penal Code. Consequently, the scope of criminalization also covered tools adapted for committing the offense of illegal interception of information (Article 267 § 1 of the Penal Code) and unauthorized access to all or part of an IT system (Article 267 § 2 of the Penal Code).

The provision in the wording in force from 21 July 2026 provides that anyone who manufactures, acquires, sells or makes available to other persons devices or computer programs adapted to commit the offense specified in Article 165 § 1 point 4, Article 267 § 1-3, Article 268a § 1 or § 2 in connection with § 1, Article 269 § 1 or 2, Article 269a, Article 270 § 1 or Article 270a § 1, as well as computer passwords, access codes or other data enabling unauthorized access to information stored in an IT system, an IT system or an IT network, shall be subject to the penalty of imprisonment from 3 months to 5 years.

The essence of the problem, therefore, lies not in the tightening of sanctions—those remain unchanged—but in the fact that an entire category of software, which constitutes the basic equipment of every IT security specialist, has now become the subject of enforcement action. Vulnerability scanners, password cracking tools, network traffic sniffers, and operating system distributions that aggregate these tools are, when assessed solely on their functionality, devices and programs designed to gain unauthorized access to an IT system.

Why the Mark of "Adaptation" Is Crucial to Defense Today

The legislator did not introduce into Article 269b § 1 of the Penal Code the element of the purpose for which the perpetrator creates, acquires, sells, or makes available the tool. This omission constitutes a fundamental difference from the structure adopted in Directive 2013/40/EU, which penalises such conduct only when undertaken with the intent to use the tool to commit a crime, and provides for the exclusion of liability for tools created and used for authorized testing or system protection. The entire burden of distinguishing between legal and illegal conduct has thus shifted to the interpretation of the element of "adaptation" and the subjective aspect of the act.

The direction of the defense in cases based on Article 269b § 1 of the Penal Code is therefore determined by three parallel lines of argumentation. The first is based on a pro-EU interpretation: since the national provision transposes a directive, its scope cannot exceed the scope of criminalization provided for in the transposed act, which argues for a narrow interpretation of the "adaptation" element and the exclusion from its scope of dual-purpose tools whose primary purpose is diagnostic, audit, or protective. The second focuses on the subjective aspect – the offense under Article 269b § 1 of the Penal Code is an intentional offense, and therefore the prosecutor is obliged to prove at least the perpetrator's consent to the fact that the tool being acquired or made available is a tool adapted to commit the offense; in the realities of the work of a security auditor, acting on the basis of a contract and written authorization, establishing such intent is a far more difficult task than is usually assumed at the pre-trial stage. The third refers to the substantive content of the offense and to Article 1 § 2 of the Penal Code - an act devoid of social harm to a greater degree than insignificant does not constitute an offence, and a legal penetration test conducted within the limits of the granted authorization does not carry such a charge of illegality.

It is worth emphasizing that mere possession of a tool is not included among the executive actions. The verbs include production, acquisition, sale, and making available, meaning that the subject of evidence must be the specific causative action, not the state of affairs revealed during the search. This distinction is often blurred in practice, and its consistent emphasis has significant procedural significance, especially when the software was installed on a storage device before the amendment entered into force.

An entity providing offensive security testing services currently operates in conditions where the only real safeguard against the charges under Article 269b § 1 of the Penal Code and Article 267 § 2 of the Penal Code remains precise order documentation. The system administrator's consent excludes unlawful conduct only within the limits of its granting, and these limits are determined by the content of the document, not the intentions of the parties. In practice, this means that the scope of the test must be clearly defined by specifying the addresses, domains, and systems covered by the authorization, specifying the timeframe, clearly enumerating permissible techniques, and—sometimes overlooked—confirming that the person granting the authorization is authorized to use the given resource. Particular risks arise in cloud environments and when using third-party infrastructure, where the client often has no authority to provide effective consent regarding the layer on which the test is actually conducted.

A separate issue is the situation of a researcher acting without prior authorization who discloses a vulnerability and reports it to the system administrator. Reporting after the fact does not invalidate prior access, and the good intentions of the reporter do not constitute a stand-alone basis for excluding criminal liability. However, publishing the code verifying the vulnerability—even after the agreed-upon embargo period and even for purely educational purposes—may be classified as providing others with access to a program adapted for committing a crime. In our opinion, such an assessment is controversial and open to effective debate, but the very fact that it is legally possible today should encourage caution in formulating vulnerability disclosure policies.

IT departments and managed service providers

The amendment also impacts entities that do not conduct offensive activities. An administrator maintaining a repository of diagnostic tools, a security department collecting malware samples for analysis, or an incident response team using password recovery tools fall under the verb "acquires" and "makes available." This risk can largely be mitigated through organizational measures: by implementing an internal policy defining a catalog of permitted tools along with a justification for their use; by maintaining a register of individuals authorized to use them; by restricting access to separate and segregated environments; and by including provisions in employment contracts and service agreements that clearly define the permitted scope of use of such software. This documentation serves a dual purpose: it organizes internal processes and, if proceedings are initiated, constitutes evidence against attribution of intent.

It is worth noting that these obligations coincide with those arising from the amended Act on the National Cybersecurity System, implementing the NIS2 directive. Key and important entities currently preparing information security management system documentation can and should also include rules for using testing tools.

Side effects of conviction

A conviction for an offense under Article 269b § 1 of the Penal Code carries consequences beyond the penalty. This provision provides for the forfeiture of items used by the perpetrator, which in professional settings means the loss of equipment that constitutes a basic work tool. A final conviction for an information protection offense may also result in the loss of the ability to perform certain functions in entities subject to the National Cybersecurity System Act, which requires verification of the criminal record of individuals working in the cybersecurity field. For industry professionals, this poses a real risk of professional exclusion.

For acts committed before 21 July 2026, the rule set forth in Article 4 § 1 of the Penal Code applies, according to which the new law applies unless the previous law is more lenient to the perpetrator. Therefore, expanding the scope of criminalization cannot cover conduct committed before that date, and attempts to base a charge on the new wording of the provision in relation to earlier enforcement actions should be met with a firm response from the defense. This issue takes on particular significance in the case of acts that extend over time and when constructing a continuous act.

Summary

The amendment of May 15, 2026, does not create a new type of prohibited act, but rather shifts the threshold of criminalization to the stage preceding any attack—the moment a tool is acquired. For entities operating in the IT security industry, this means that the legality of their activities increasingly depends not on what they actually do, but on how they document it. Streamlining agreements, authorizations, and internal tool policies is currently the most cost-effective form of criminal risk management available.

This article is for informational purposes only and does not constitute legal advice

Legal status as of July 29, 2026.

Author:

Series editor:

    Have any questions? Contact us – we'll respond as quickly as possible.