Skip to content
TrustList
News

Poland: key and important entities must self-register in the national cybersecurity list by 3 October

Editorial

By TrustList Editorial

Under Poland’s amended National Cybersecurity System Act, its NIS2 law in force since 3 April 2026, key and important entities must apply for entry in the KSC list by 3 October 2026 and meet the other duties by 3 April 2027.

About Poland: key and important entities must self-register in the national cybersecurity list by 3 October

Poland: key and important entities must self-register in the national cybersecurity list by 3 October

28 September 2026 — Poland's Ministry of Digital Affairs reminded organisations on 28 September 2026 that the deadline to self-register in the list of the National Cybersecurity System (wykaz KSC) is Saturday 3 October 2026. The amended Act on the National Cybersecurity System, which brings the EU's NIS2 directive into Polish law, took effect on 3 April 2026 and gave organisations six months to identify themselves.

Who must register

Organisations that already met the criteria for a key entity or an important entity under the amended act on 3 April 2026 must apply for entry in the list by 3 October. Classification depends on the sector the organisation works in and its size, as the act sets out; the obligation falls on the organisation itself, so it has to work out whether it is covered.

Some are entered automatically, ex officio: public entities, telecommunications businesses, trust service providers and existing operators of essential services. They do not file an application, but must complete their details when asked.

How

Applications are made through the KSC list application in the government system S46. Foreign organisations can sign in with an eID.

What comes next

Registration is the first step. By 3 April 2027 registered entities must meet the act's other duties, including risk management, the security of their information systems and incident reporting.

Who is affected

Medium and large organisations in the sectors NIS2 covers operating in Poland, including many digital-service and ICT providers: cloud and data-centre operators, managed-service and managed-security providers, and online marketplaces. International groups with a Polish subsidiary need to check the subsidiary separately.

What to do

  • If you have not yet decided whether your Polish entity is key or important, do it now against the act's criteria, and file in S46 before 3 October.
  • Keep a record of the assessment if you conclude you are not covered.
  • Plan the controls for April 2027 — risk management, security measures and incident reporting — and ask your managed-service and cloud providers how they will support them.
  • If you buy IT or security services in Poland, ask your suppliers whether they are themselves registered entities.

Not yet independently verified. This rests on the Ministry of Digital Affairs’ own announcement; no independent report was sought, and penalties for missing the date were not stated on the page read. We will update this when it can be confirmed, and remove this note.

Sources

Categories & features