Failure to comply with the self-assessment obligation is not the only issue that must raise our vigilance. Another issue is late or incorrect registration of an organization in the KSC register. By October 3, 2026, all key and important entities must formally notify the competent authority and submit an application for entry in the electronic register.
Where and how to submit your application? Step-by-step procedure
Registration for the list of key and important entities takes place exclusively in electronic form via a dedicated IT system (KSC Information System / gov.pl portal).
- Representation: The application must be signed with a qualified electronic signature or a trusted signature by persons authorized to represent the entity (in accordance with the National Court Register or CEIDG) or a duly appointed proxy.
- Completing the form: Complete all required sections regarding your business profile and cybersecurity system connectivity.
- Verification and dispatch: Sending the notification to the competent authority supervising the given sector.
- Receiving the UPO: Downloading the Official Receipt Certificate, which is proof that the application has been submitted within the statutory deadline.
Required data in the application form
The application form requires not only the basic company registration data, but also detailed operational and technical information:
- Identification data: Full name, NIP, REGON, KRS number and registered office address.
- Legal classification: Clear definition of status (key or important entity) with an indication of the specific sector, sub-sector and type of service provided.
- Contact points (24/7): Contact details of persons or organizational units designated to maintain constant communication with the relevant CSIRT team (NASK, GOV or DEF) and the supervisory authority.
- Infrastructure and Services: Information about IP addresses, domain names, and underlying infrastructure used to provide critical or important services.
What to watch out for when registering?
Formal errors may prolong the entire process or lead to the application being left unprocessed:
- Incorrect representation and missing powers of attorney: In the case of joint representation, the application must be signed by all required individuals. If the application is submitted by a representative (e.g., a legal counsel), the power of attorney document must be attached electronically with the correct signature and proof of payment of the stamp duty.
- General email inboxes instead of dedicated ones: Entering email addresses like biuro@ or kontakt@ as the contact point for cybersecurity matters is a mistake. The law requires providing addresses and phone numbers that guarantee immediate receipt of incident notifications on a continuous basis.
- Incorrect subsector classification: Registering a company in the wrong sector results in the application being forwarded to the incorrect supervisory authority, which necessitates rectification of the entry.
Consequences of missing the October 3, 2026 deadline.
Failure to submit an application within six months of the Act's entry into force (i.e., April 3, 2026) constitutes a direct violation of the provisions of the KSC. Consequences include:
- Ex officio entry: The supervisory authority, after determining that a given company meets the criteria for a key or important entity, will make an ex officio entry into the lists by way of an administrative decision.
- Financial sanctions: Initiation of proceedings to impose an administrative fine for evading the registration obligation.
Registration on the KSC list is the first formal test of an organization's readiness for new cybersecurity requirements. To avoid formalities and time pressures just before the deadline of October 3, 2026, it's worth verifying the credentials of your representatives, preparing technical data, and designating responsible contact points now.
This article is for informational purposes only and does not constitute legal advice.
The law is current as of August 20, 2026.
