18.08.2026

CyberSec Update #33: Identifying a HRV | KWKR

A High-Risk Vendor You Must Identify Yourself

The UKSC introduces a procedure for declaring an entity a High-Risk Vendor (HRV). The process is conducted through administrative proceedings involving, among others, the minister responsible for digital affairs. Its purpose is to limit the use of hardware or software that may pose a threat to national security, public security, or public order.

Administrative Proceedings Are Not the Whole Story

The possibility of initiating proceedings under the UKSC does not relieve essential and important entities of their obligations related to proper supply chain risk management. In this context, assessing the risks associated with ICT solution providers becomes particularly important.

A properly implemented information security management system, as one of the required technical and organizational measures, should address the security and continuity of the supply chain for ICT products, ICT services, and ICT processes on which service delivery depends.

In practice, this means assessing the risks associated with the potential withdrawal of hardware or software from the IT systems of an essential or important entity if the supplier assessment no longer supports continued cooperation with that vendor.

Do Not Look for Trusted Suppliers in a Registry

As stated by the Ministry of Digital Affairs in its FAQ on the National Cybersecurity System available on cyber.gov.pl, there is no official registry of trusted and verified hardware or software suppliers for essential and important entities.

At the same time, no proceedings have yet been initiated to classify any ICT solutions provider as a High-Risk Vendor.

Where Should Trust in a Supplier Come From?

Every essential and important entity should continuously verify whether its ICT solutions originate from trusted suppliers and meet relevant security requirements.

This raises an important question: what criteria should organizations use when selecting a supplier if no administrative decision has been issued against that vendor?

Stay Up to Date with Official Recommendations

One option is to monitor recommendations issued by the Government Plenipotentiary for Cybersecurity under Articles 33 and 67a of the UKSC. These recommendations may identify vulnerabilities and technological solutions whose use could negatively affect the security level of ICT solutions.

For organizations, such recommendations may serve as an indication that a particular supplier does not meet the required security standards.

Audit Your Suppliers

Another important step is conducting your own audits of suppliers. If current contracts do not provide such rights, they should be established through broader information security and cybersecurity documentation, such as amendments, agreements, or framework contracts.

A properly conducted supplier self-assessment can provide an initial indication of the level of cybersecurity awareness and maturity demonstrated by a business partner.

1 2 3 63

Newsletter

Want to stay up to date?
Subscribe to our newsletter.

By entering your e-mail address above and clicking ‘Subscribe!’ you declare that you have read and accept the Terms of Service and subscribe to the newsletter, i.e. information on legal topics, including information on important legal events, legislative changes and the Law Firm's activities, services and products, via e-mail communication.

The controller of your personal data is KWKR Konieczny Wierzbicki i Partnerzy S.K.A. with its registered office in Kraków, Kącik 4 Street, 30-549 Kraków. Your data will be processed in order to provide the newsletter service and thus send commercial and marketing information to the e-mail address provided, in accordance with the Privacy Policy and the Terms of Service. For more information on the principles of personal data processing, including your rights, please see the Privacy Policy.

Please wait...

Thank you for sign up!