NIS2 in Poland: register with the KSC list by 3 October 2026, a checklist

Fryderyk Pryjma·published September 1, 2026·updated September 1, 2026·12 min · 2768 words
[nis2]NIS2KSC ActNCSAKSC register
NIS2 in Poland: register with the KSC list by 3 October 2026, a checklist

Reading time: about 8 minutes

Contents

  1. What exactly closes on 3 October
  2. Self-identification: who decides they are in scope
  3. Who is a key entity, and who is important
  4. Who gets entered ex officio, and who must apply
  5. How the register entry works, step by step
  6. Checklist before 3 October
  7. What happens after registration: the next NIS2 clocks
  8. Where AI deployment fits in
  9. Common mistake: confusing registration with full compliance
  10. FAQ

Answer first

If your company operates in one of the sectors covered by Poland's amended National Cybersecurity System Act and exceeds the size threshold, you have until 3 October 2026 to enter the register of key and important entities. The amendment, which transposes the NIS2 directive, entered into force on 3 April 2026 and runs on a self-identification model: you assess whether the law applies to you and file the application yourself, rather than waiting for a letter from an authority. The entry is made electronically through the "KSC register" application at wykaz-ksc.gov.pl, after logging in via the National Node and having the application signed by the head of the entity. Registration is only the entry point, not the full set of obligations, but it is the first hard deadline and the only one you cannot make up later without exposure.

What exactly closes on 3 October

The amendment to the National Cybersecurity System Act, in Poland shortened to the KSC Act, is the domestic transposition of the NIS2 directive. It entered into force on 3 April 2026, and from that day a six-month window runs for one specific act: entry into the register of key and important entities. The window closes on 3 October 2026.

This is not the deadline for implementing security measures or building an incident procedure. It is the deadline for formally notifying the state that your organisation falls within the scope of the law. Only after the entry do the clocks for the remaining obligations actually start, and those have their own, later dates. Registration is therefore a gate: you pass through it once, on time, and only beyond it does the rest of the schedule open up.

The meaning of this date gets misread in two directions. Some assume that because the full security obligations are a year away, registration can wait too. It cannot, because these are two separate acts with two separate deadlines. Others assume that entering the register requires having a complete information security management system in place on the day of filing. It does not, because the entry is a declaration that you fall within the scope of the law, not a statement of readiness.

Self-identification: who decides they are in scope

The most important mechanism in this law is self-identification. Under the previous regime, the authority designated operators of essential services by administrative decision. Now the burden has shifted to the company: you assess whether you operate in a covered sector and whether you exceed the size threshold, and if so, you enter yourself into the register on time.

This changes the nature of the risk. The absence of a decision from an authority does not mean the law does not apply to you. If you meet the criteria, the obligation exists regardless of whether anyone reminded you of it. The most common trap is not that a company knows about the obligation and ignores it, but that it never ran the analysis at all and assumes cybersecurity is a topic for banks and telecoms. In fact the scope of NIS2 is markedly wider than the previous directive and reaches manufacturing, waste management, food and chemicals, among others.

The analysis comes down to three questions: do I operate in one of the sectors listed in the law, do I exceed the size threshold, and, if so, am I a key or an important entity. Only the answers to those three questions tell you whether and how to register.

Who is a key entity, and who is important

The law splits its addressees into two categories, and the split maps onto how they are supervised. Key entities are, as a rule, large organisations in the sectors of highest criticality, such as energy, transport, banking, financial market infrastructure, healthcare, water and digital infrastructure. They are subject to proactive supervision, meaning the authority can inspect them without waiting for an incident.

Important entities are the remaining covered sectors and smaller organisations. Here supervision is reactive: it steps in when a signal of non-compliance appears. Sectors that most often land in this category include manufacturing, waste management, food and chemical production, and digital services that are not critical infrastructure.

Which category you belong to follows from combining the sector with the size of the company, measured by headcount and by turnover or balance-sheet total. The size criterion generally excludes micro and small firms, although the law provides exceptions where size is irrelevant because the entity's role alone decides. The exact thresholds and the assignment of a sector to a category need to be checked against your own activity, because this is precisely where self-identification goes wrong most easily.

Who gets entered ex officio, and who must apply

Not every entity has to file an application. Some organisations are entered into the register ex officio, on the basis of data the state already holds. This typically covers public entities, telecommunications undertakings, trust service providers and former operators of essential services from the previous regime. If you are in this group, your role narrows to checking and completing the entry, not creating it from scratch.

The rest, in practice most private companies in covered sectors, must apply on their own. They are the main addressee of the 3 October deadline, and they most often do not know it applies to them. If you are unsure which group you fall into, assume you must act yourself, and verify whether an ex officio entry already exists rather than assuming someone did it for you.

How the register entry works, step by step

Registration is fully electronic. It runs through the "KSC register" application available at wykaz-ksc.gov.pl. Login goes through the National Node, the same identity mechanism that handles the trusted profile, the mObywatel app, the e-ID, electronic banking and a qualified certificate.

The application is signed by the head of the entity, meaning the managing person or body, or a person they authorise. This is not a meaningless formality: the amendment strongly emphasises management accountability for cybersecurity, so the signature under the entry is part of a broader construction in which the management board is personally responsible for meeting the obligations. We cover this in a separate note on management liability after the NCSA amendment.

In practice this means that before the click itself you need three things ready: a settled self-identification, the entity data needed for the application, and a person with signing authority and a working means of authentication in the National Node. What eats the most time is not the application itself, but establishing who is to sign it and whether that person has anything to log in with.

Checklist before 3 October

A sensible order of action looks like this.

First, determine your activity profile and check whether any of your activities falls within the sectors covered by the law. One company can run several activities, and a single qualifying one is enough.

Second, check the size threshold by counting headcount and turnover or balance-sheet total, and remember the rules on aggregating data from linked entities, because they can push a seemingly small company over the line.

Third, assign yourself to a category, key or important, because it determines the scope of later obligations and the mode of supervision.

Fourth, check whether you have already been entered ex officio before you file an application from scratch.

Fifth, identify the head of the entity or an authorised person to sign the application, and make sure they have a working means of authentication in the National Node, for example a trusted profile or a qualified certificate.

Sixth, gather the entity data needed for the entry and designate a cybersecurity contact person, since that is the natural point of contact with the authority after registration.

Seventh, file the application through wykaz-ksc.gov.pl before 3 October, not in the last week, because a login or signature problem on the deadline day can no longer be fixed.

Eighth, save the confirmation of entry and put the next NIS2 dates in the calendar, so that registration does not remain the only thing you did.

What happens after registration: the next NIS2 clocks

Entering the register opens the schedule rather than closing it. Two further hard deadlines follow. The full security obligations, meaning implementation of a risk management system and the technical and organisational measures under the law, apply from 3 April 2027. The first mandatory audit and the real possibility of penalties fall on 3 April 2028, after a two-year transition period.

A separate obligation, which starts working as soon as you are an entity within the system, is incident reporting. NIS2 bases it on a multi-stage model with an early warning counted in hours and a fuller notification in the following days, directed to the competent CSIRT. It is the same pattern of clocks we described for vulnerability reporting under the CRA, with the difference that NIS2 looks at an incident in your services, not at a vulnerability in a product you place on the market. How these regimes overlap and where they operate separately is laid out in the cross-mapping of NIS2, the AI Act, the GDPR and ISO 27001.

Where AI deployment fits in

For a company deploying AI, registration in the KSC list has two effects. The first is direct: if you are subject to NIS2 yourself, your AI system is part of the infrastructure the law requires you to secure and monitor, and an incident in that system may be a reportable incident. The second is indirect but often more important: NIS2 extends obligations across the supply chain, so your AI vendor becomes part of your risk analysis, regardless of whether that vendor is itself a key entity. We map this onto concrete requirements in the note on NIS2 and the AI vendor in the supply chain.

From this angle, how you run the model stops being purely an engineering decision. A model deployed locally, with control over data flow and the ability to log what happens in the system, is easier to audit and to slot into NIS2 obligations than a dependency on a service whose internals you cannot see. This is not an argument that the cloud rules out compliance, only that compliance then demands work on the visibility of dependencies, which on-prem keeps closer to hand. We develop this thread in the piece on minimum NIS2 requirements for network isolation of on-prem AI.

Common mistake: confusing registration with full compliance

It is worth separating two things, because mixing them ends either in lateness or in needless haste. Registration by 3 October 2026 is a declaration that you are within the scope of the law. Compliance, meaning the actual implementation of security measures, is a separate process with a deadline of 3 April 2027 and enforcement from 3 April 2028.

Lateness looks like this: a company delays registration because "we have time until 2027 to implement anyway". It confuses the entry deadline with the compliance deadline and misses the first one. Needless haste looks the opposite way: a company puts off registration because it wants "everything ready" first, and treats the entry as a reward for a finished implementation. The entry is not a reward, only an entry into the system that must be made on time, with the rest built from inside it. For 3 October you need a settled self-identification and a filed application, not a complete information security management system.

FAQ

By when do I have to register in the KSC list? By 3 October 2026. This is the deadline for entry into the register of key and important entities, counted from the amended KSC Act entering into force on 3 April 2026.

Will I get a letter from an authority telling me to register? As a rule, no. The law runs on self-identification: you assess whether you are in scope and file the application yourself. Some entities, such as public bodies, telecoms and trust service providers, are entered ex officio, but most private companies must apply on their own.

How do I know whether I am a key or an important entity? From the combination of your sector and the size of the company, measured by headcount and by turnover or balance-sheet total. Key entities are usually large organisations in the most critical sectors under proactive supervision, important entities are the remaining sectors and smaller organisations under reactive supervision. The thresholds and the sector assignment need to be checked against your own activity.

How do I file the application technically? Electronically, through the "KSC register" application at wykaz-ksc.gov.pl. Login via the National Node, meaning the trusted profile, the mObywatel app, the e-ID, electronic banking or a qualified certificate. The application is signed by the head of the entity or a person they authorise.

What if I miss the deadline? Registration is a statutory obligation, and its breach falls within the supervision and sanctions provided by the law. The real possibility of penalties starts after the transition period, but a late registration remains a breach, not a discretionary matter. Rather than counting on the deadline moving, it is safer to file before 3 October.

Does registration mean I must already have all safeguards implemented? No. The entry is a declaration that you fall within the scope of the law. The full security obligations have a deadline of 3 April 2027, and the first audit and enforcement 3 April 2028.

What I do not cover here

I do not discuss the full catalogue of risk management measures from Article 21 of the directive, nor the detailed content of the security obligations that apply from 3 April 2027, since that is material for separate pieces. I do not give exact headcount and turnover thresholds or the full list of sectors from the annexes, because those must be read directly from the law for your own activity. I do not go into the level of penalties or the supervisory procedure. I leave aside sector-specific regimes with their own obligations, such as DORA for the financial chain or the CRA for manufacturers of products with digital elements, which we cover separately.

// disclosure & biasesDisclosure and biases

I write from the perspective of someone working on AI deployments run outside the public cloud, so I naturally emphasise control over data flow, logging and the auditability of dependencies. I have tried to separate the content of the law from that architectural preference and not to suggest that one deployment path automatically settles NIS2 compliance. This text is not legal advice. The qualification of an entity, the size thresholds and the sector assignment depend on the specifics of a given organisation, and the practice of applying the amended KSC Act is still taking shape. Before compliance decisions, consult a lawyer specialising in cybersecurity.

Next step

If you are subject to NIS2, registration is only the entry point, and the real work starts with risk analysis and the supply chain. See how to map NIS2 obligations onto an AI vendor in the note NIS2 and the AI vendor in the supply chain: mapping Article 21.

Sources

Fryderyk Pryjma. Works on on-prem AI deployments for European manufacturing and writes at the intersection of architecture, compliance and regulation.

FP
// author
Fryderyk Pryjma

Building CortexMine, an on-prem AI platform for European manufacturers under NIS2. Where this bias could affect conclusions, it is flagged inline.

Want to apply this to your case: architecture, compliance, and cost?

→ Book 30 min
// related notes