Skip to content
RESEARCH INDEX BREACHROAD / INTELLIGENCE NOTE

S46 now accepts cross-border eID: people without PESEL can handle Polish KSC duties

S46 supports European eID through login.gov.pl. We explain what this means for foreign representatives and how to govern their access.

PUBLIC RESEARCH
AUTHOR
/ CEO of Breachroad · OSCP · PNPT
PUBLISHED
30 September 2026
READING TIME
8 min read
TOPIC
Identity and Access
S46 now accepts cross-border eID: people without PESEL can handle Polish KSC duties

A person without a Polish PESEL number can now sign in to S46 with an electronic identity issued by another European country. Poland’s Ministry of Digital Affairs activated the feature on 2 September for both the KSC Register and S46 Cyber Hub. This is a practical change for Polish companies whose board member, authorised representative or cybersecurity lead is based abroad.

The user goes through login.gov.pl, selects “Use eID”, chooses the country and authenticates with its mechanism. The feature removes an important administrative barrier, but it does not solve access governance automatically. The company still has to decide who may act for it, how to provide cover for that person and how to review permissions.

Countries currently supported

The ministry lists eID methods from Austria, Belgium, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Italy, Latvia, Liechtenstein, Lithuania, Luxembourg, Malta, the Netherlands, Portugal, Romania, Slovakia, Slovenia, Spain and Sweden.

This does not mean that every identity document from those countries will work in any form. Users rely on the national electronic identification method available through the European system. Test it before the deadline rather than discovering a missing activation, code or device requirement on the day a filing is due.

The feature covers two applications. The KSC Register handles records for essential and important entities. S46 Cyber Hub supports statutory processes, including communication and incident reporting. Access to either system should be treated as access to a regulated process, not as an ordinary information account.

An international board still needs a local operating process

A multinational group may manage security centrally, but a Polish entity still needs a process that works locally. If one board member in another country is the only person with access, holidays, a role change, a lost phone or an urgent incident can interrupt the organisation’s response.

The organisation should have a business owner, a named deputy and an operational person able to understand the communications. It also needs to distinguish actions that require legal representation from those that an appointed employee can perform. Technical access alone does not prove authority to make every declaration.

A simple access matrix helps: person, role, application, permitted actions, authority basis, review date and removal procedure. This reduces both continuity gaps and stale access after someone changes role.

Treat the first login as a process test

A useful test goes beyond seeing a welcome screen. Confirm that the identity data is correct, the person can see the correct organisation and functions, the path does not depend on someone else’s private device, and the business can continue when that person is unavailable.

Do not pass authentication codes through chat or create a shared “board” account. Electronic identification is valuable because an action can be attributed to an individual. Shared credentials destroy accountability and create an easier route for fraud.

When a director, representative or security supplier leaves, S46 should appear on the same offboarding list as banking, e-Delivery, accounting systems and domain administration. An offboarding process that ends with the email account leaves important authority channels outside control.

What to do before 3 October

If the organisation must self-register in the KSC Register, its application is due by 3 October 2026. A company relying on cross-border eID should test login now, confirm legal representation, prepare its signature and application data, and name a deputy. An integration error or missing identification method is better investigated before the final evening.

Our guides to MFA deployment and Zero Trust security explain broader account controls. Organisations can connect identity governance with statutory duties through a NIS2 readiness review.

Source facts and Breachroad conclusions

The Ministry of Digital Affairs notice on eID login confirms the launch date, applications covered, login.gov.pl path and supported countries. The KSC implementation timeline confirms the role of S46 and the self-registration deadline.

The access matrix, continuity test, prohibition on shared accounts and inclusion of S46 in offboarding are Breachroad recommendations. A person’s legal authority should be confirmed for the relevant action.

SHARE / COPY