Skip to content
RESEARCH INDEX BREACHROAD / INTELLIGENCE NOTE

Poland's KSC self-registration deadline is 3 October: a final checklist for organisations

Essential and important entities have until 3 October to apply for Poland's KSC register. Here is what to verify and what comes next.

PUBLIC RESEARCH
AUTHOR
/ CEO of Breachroad · OSCP · PNPT
PUBLISHED
30 September 2026
READING TIME
9 min read
TOPIC
Governance and Compliance
Poland's KSC self-registration deadline is 3 October: a final checklist for organisations

Essential and important entities that were not entered automatically in Poland’s KSC register have until 3 October 2026 to apply. This is not a non-binding expression of interest. Registration is the first formal milestone under the amended National Cybersecurity System Act, Poland’s implementation of the NIS2 Directive.

With three days remaining, organisations need to separate two questions. First, does the company meet the statutory criteria for an essential or important entity? Second, does the responsible person have the information, authority and electronic signature required to submit the application? Security-policy work does not replace registration, and registration does not replace the safeguards that must follow.

Who needs to assess its status

The amended Act covers organisations in the sectors listed in its Annexes 1 and 2 when the relevant conditions apply. The service provided, entity size and exceptions for certain categories all matter. A company should not end its analysis by saying that it does not operate critical infrastructure. The KSC scope is broader.

Poland’s Ministry of Digital Affairs says that existing operators of essential services, trust-service providers, telecommunications undertakings and public entities were registered automatically between 13 April and 6 May. Other organisations meeting the criteria use the self-registration route that runs from 7 May to 3 October.

Where the conclusion is not obvious, management should document the data, criteria and legal sources used. Uncertainty should trigger a rapid assessment rather than inaction. The review needs people who understand the group’s structure, operational services, employee count and financial data, together with legal counsel familiar with the Act.

The final pre-submission check

The KSC register operates as a separate S46 web application at wykaz-ksc.gov.pl. Applications for entry, amendment and removal are submitted electronically and signed electronically. Before starting, verify five elements:

  1. the entity’s correct identifying information and current representation rules;
  2. the sector, service and basis for treating the organisation as essential or important;
  3. the authorised representative and access to the correct identity and signature method;
  4. contact details that will actually be monitored after registration;
  5. a retained copy, submission confirmation and an owner for subsequent correspondence.

Do not use a random board member’s address merely because it is available. S46 also supports communications connected with security duties. The mailbox needs an owner, a deputy and an escalation route for holidays and incidents.

3 October is the beginning, not the end

The next major deadline is 3 April 2027. By then, entities that already met the criteria when the amended Act entered into force must begin using S46 and implement their duties. Essential entities that were not previously operators of essential services have until 3 April 2028 for their first information-system security audit. The penalty provisions also begin to apply on that date.

Those later dates do not create a year in which nothing needs to happen. An organisation needs a programme owner, an inventory of services and assets, risk assessment, incident-handling arrangements, supply-chain controls and a measurable implementation plan. Because management carries responsibility, a status report saying only that “IT is handling it” is not adequate oversight.

What to do now if the organisation is late

Appoint a decision-maker and a small working group: the business, legal counsel, finance or HR for size data, and security. Confirm status and registration route, prepare representation data, test login and signing, and leave time for technical failure. The process should not depend on one device, one person or an email sent on the final evening.

After submission, preserve the evidence and create a register of further deadlines. Management should receive a short briefing explaining why the entity is in scope, what was filed, what remains incomplete and who owns the programme through April 2027.

Our guide to NIS2 implementation in Poland explains the wider duties. Organisations can structure the programme through a NIS2 and DORA readiness review and test crisis responsibilities in an incident-response tabletop exercise.

Source facts and Breachroad conclusions

The Ministry of Digital Affairs timeline confirms the self-registration period, electronic application process, role of S46 and the 3 April 2027 and 3 April 2028 milestones. The notice on the amended Act entering into force confirms the 3 October deadline and management responsibility.

The submission checklist, ownership model and escalation approach are Breachroad conclusions. This article is not legal advice; an organisation’s status must be assessed against the Act and its actual activities.

SHARE / COPY