There are two days left until the deadline to submit an application for inclusion in the list of key and important entities (KSC List). This obligation applies to entities that met the criteria for recognition as a key or important entity on April 3, 2026, the date the amendment to the Act on the National Cybersecurity System entered into force. The deadline expires on Saturday, October 3, 2026.

Who does the obligation apply to?

An application for entry must be submitted by each key or important entity within six months of meeting the criteria (Article 7c, Section 1 of the Act). The starting point is self-identification. The organization itself assesses whether it operates in the sector specified in Annex 1 or 2 to the Act and whether it meets the size criteria. The Act provides for two paths:

  • Self-registration: Applies to most businesses. Applications can be submitted from May 7, 2026, and the deadline is October 3, 2026. Subsidiaries of existing essential service providers can also submit their own applications if they meet the requirements.
  • Ex officio entry: The Minister of Digital Affairs has entered telecommunications companies, trust service providers, public entities, critical entities, and existing essential service providers, among others, into the register based on public registers. These entities do not submit an application for entry. However, they must provide the missing data within six months of receiving the request, under penalty of a fine. The amendment is made through an application to amend the entry, which should also cover the entity's activities not included in the ex officio entry.

Entities that meet the conditions later, e.g. as a result of an increase in employment or expansion of business, have 6 months from that date to submit an application.

What is an entry in the list?

The entry is declaratory in nature. It does not create the status of a key or important entity, but rather confirms it. Therefore, the obligations arising from the Act arise upon fulfillment of the conditions, regardless of whether the entity has submitted an application. The entry is made upon submission of the application in the IT system. The authority does not issue a decision on the matter, and the entity does not have to wait for its review.

How to submit an application?

The application is submitted exclusively electronically via the KSC List application (wykaz-ksc.gov.pl), which is part of the S46 system. In practice, you must:

  • Prepare data: The application must contain the data listed in Article 7, paragraph 2, points 1–18 of the Act, in particular:
  • name of the entity;
  • sector, subsector and type of activity;
  • registered office and correspondence addresses;
  • NIP and REGON numbers;
  • the range of public IP addresses and Internet domains used continuously;
  • declaration of enterprise size;
  • information about the EU countries in which the entity operates;
  • information about the contract with the provider of managed cybersecurity services, if concluded.

An entity conducting several types of activities shall indicate them separately in the application.

  • Designate contact persons: The application includes contact details for entities within the national cybersecurity system. As a rule, an entity designates at least two such persons, and micro- and small-sized enterprises at least one. For the person who will act as the administrator of the entity's account in the S46 system, the PESEL number or electronic identification device identifier must also be provided.
  • Submit a declaration from the manager: The application includes a declaration from the entity's manager, made under penalty of perjury (Article 233 § 6 of the Penal Code), that the data is true. This liability does not extend to IP address ranges and domain names.
  • Sign the application: The application must be signed with a qualified electronic signature, a trusted signature, or the personal signature of the entity's manager or an authorized person. A qualified electronic seal may also be used, identifying the person using it.
  • Attach a power of attorney (if applicable): When acting through a proxy, attach an electronic power of attorney. This is not required for a proxy listed in the National Court Register or a proxy listed in the Central Registration and Information on Business.

Please ensure your application is complete. Entry will not be made if the application lacks the required data, a manager's declaration, or a signature. Failure to do so may result in missing the deadline.

What happens after I register?

This entry initiates the next stage of compliance with the Act. Once completed:

  • Certificate: Upon request, the Minister of Digital Affairs issues an electronic certificate of registration. This can be useful, for example, in relations with contractors.
  • Data update: Any change to the data covered by the entry must be reported within 14 days.
  • Using the S46 System: Once registered, the entity begins using the S46 system, which is used for incident reporting and communication with CSIRTs, among other things. Entities meeting the requirements from April 3, 2026, should do so no later than April 3, 2027.
  • Implementation of substantive obligations: By 3 April 2027, entities must implement an information security management system (ISMS) and other obligations under Chapter 3 of the Act.

What are the consequences of not registering?

If an entity fails to submit an application by the deadline, the authority responsible for cybersecurity may add it to the register ex officio (Article 7j). It then requests the entity to complete the data within six months. Failure to complete the data despite the request constitutes a separate basis for imposing a penalty. Failure to submit an application by the deadline is also a separate basis for imposing a penalty (Article 73, paragraph 1a, point 1). The amount of the penalty is:

  • for a key entity: up to EUR 10 million or 2% of revenues from business activities achieved in the previous financial year (whichever is higher), but not less than PLN 20,000;
  • for a major entity: up to EUR 7 million or 1.4% of the revenues from business activities achieved in the previous financial year (whichever is higher), but not less than PLN 15,000.

Regardless of the penalty imposed on the entity, a separate penalty may be imposed personally on the entity's manager (Article 73a). It amounts to up to 300% of remuneration, calculated according to the rules applicable to determining holiday pay, and in the case of a manager of a public entity, generally up to 100%. Pursuant to the transitional provision of the amending act, these penalties may be imposed for the first time only two years after its entry into force, i.e., from April 3, 2028. According to the announcement by the Ministry of Digital Affairs, the decision on the penalty will be preceded by a warning.

Organizations that miss the October 3 deadline should submit their application immediately after that date. Late registration is much better than no registration at all.

In summary, the next few days are the final opportunity to confirm your organization's status and submit an application for entry into the KSC Register. The procedure is fully electronic, but requires the collection of complete data, including technical data, and the signature of the entity's manager or authorized person.

This article is for informational purposes only and does not constitute legal advice.
The law is current as of October 1, 2026.

author: series editor:

    Have any questions? Contact us – we'll respond as quickly as possible.