The deadline for submitting an application for inclusion in the list of key and important entities (KSC List) expired on Saturday, October 3, 2026. This deadline applied to entities that met the criteria for recognition as a key or important entity on the date the amendment to the Act on the National Cybersecurity System entered into force, April 3, 2026. However, missing the deadline does not prevent entry, and sensible corrective actions can significantly reduce the risk associated with delays.
Status verification
Before an organization considers it has missed a deadline, it should confirm that it actually met the deadline. In practice, it's worth verifying three things:
- The Act determines the sector and type of actual business activity, as indicated in Annexes 1 and 2 to the Act, and, as a rule, also the size of the enterprise. It is the actual activity that counts, not the PKD code itself. When determining the size, data from partner and affiliated enterprises are generally taken into account. However, the Act provides an exception for entities independent of them in terms of information systems. According to the Ministry of Digital Affairs, data from such enterprises are not included when the provision of services by the entity does not require their activity or when they do not provide the same service covered by the Act. Companies within capital groups should analyze this issue particularly carefully.
- The Minister of Digital Affairs has officially entered, among others, public entities, telecommunications companies, trust service providers, and existing operators of essential services. These entities did not submit an application for entry. However, they are required to complete their data within six months of receiving the request and must also report any activities not covered by the official entry.
- The October 3rd deadline only applied to entities that met the criteria on April 3rd, 2026. If an organization later became a key or important entity, for example, as a result of an increase in employment, an acquisition, or the commencement of a new business, it has six months from that later date. In such a case, the deadline may not have yet expired.
Submit your application immediately
If the analysis confirms that the organization should have submitted the application by October 3rd, it should do so as soon as possible. The application is submitted electronically via the KSC Register application (wykaz-ksc.gov.pl), which is part of the S46 system. The procedure is the same as before the deadline. Registration takes place upon submission of a complete and properly signed application, and the authority does not issue a decision on the matter.
Documenting the situation
Imposing a penalty for failure to submit an application on time is optional. The authority may impose one if the gravity and significance of the violated provisions warrant it. The NIS2 Directive (Article 34, paragraph 2) also states that the decision on the penalty takes into account, among other things, the duration of the violation, the measures taken by the entity, and the degree of its cooperation with the authority. Therefore, it is worth preparing documentation that will allow for future proof of the organization's diligent approach. This documentation should include:
- A description of when and how the organization determined its status, together with the justification for the classification adopted.
- A factual explanation of the circumstances, e.g. interpretation doubts as to whether a specific activity is covered by the Act.
- Date of submission of the application and adjustment steps taken.
The Act does not impose an obligation to independently inform the authority about the reasons for the delay. However, documentation prepared in advance will be valuable material if the authority becomes interested in the matter.
Further action
Submitting an application after the deadline corrects only one deficiency. The entry is declaratory in nature, and the obligations arising from the Act apply to the entity from the date the conditions are met, regardless of registration. Organizations that are late in registering have less time for subsequent steps. By April 3, 2027, they must begin using the S46 system and implement an information security management system (ISMS), along with the remaining obligations under Chapter 3 of the Act. We discussed the roadmap for ISMS implementation in a previous article in this series.
What are the consequences of not registering?
If the entity still fails to submit the application, the cybersecurity authority may add it to the register ex officio (Article 7j of the Act). It then requests the entity to provide additional information within six months. Failure to respond to the request constitutes a separate basis for imposing a penalty. Simply failing to submit the application by the deadline is punishable by a fine (Article 73, paragraph 1a, point 1) in the amount of:
- for a key entity: up to EUR 10 million or 2% of revenues from business activities achieved in the previous financial year (whichever is higher), but not less than PLN 20,000;
- for a major entity: up to EUR 7 million or 1.4% of revenues (whichever is higher), not less than PLN 15,000.
According to the transitional provisions of the amending act, these penalties can only be imposed for the first time from April 3, 2028. However, the transitional period only postpones the imposition of penalties. It does not exempt from obligations or mean that delays will be insignificant. Registering on your own initiative, even with a delay, puts an organization in a much better position than waiting for official registration.
In summary, the October 3rd deadline doesn't mean the organization's situation is sealed. The most important thing now is to act quickly and systematically: confirm the status, promptly submit a reliable application, document the circumstances of the delay, and engage the management board. In parallel, the organization should continue preparations for ISMS implementation, as April 2027 is just over six months away.
This article is for informational purposes only and does not constitute legal advice.
The law is current as of October 8, 2026.
