← All insights

Compliance & Integrity August 11, 2026 · E-KMC.EU P.S.A.

Poland’s NIS2 Law: Get on the KSC Register by 3 October

Poland has implemented NIS2 through the amended National Cybersecurity System Act (the KSC Act), and the first hard deadline is close: essential and important entities must be entered in the KSC List (Wykaz) by 3 October 2026. The first test is self-identification. Many companies covered by the Act, including Polish subsidiaries of foreign groups, do not yet know that they qualify as an “important entity”.

“Are we even an important entity?”

Tuesday, 9:10. The CFO of a Polish subsidiary opens an email from the group compliance lead in Munich: “Please confirm by Friday whether the Polish entity falls under the local NIS2 law and whether it has been registered.” The answer “we assume it does not apply” will not survive, because the group reports the status of every subsidiary.

The Act works through self-identification: the entity itself determines that it is covered and applies for entry in the List. Scope follows the NIS2 annex sectors. Alongside energy, transport and health, they include ICT service management, postal and courier services, waste management, chemicals, food and the manufacturing of electronics, machinery and vehicles, among others. The entry threshold is, as a rule, at least a medium-sized enterprise under EU law, meaning 50 or more staff or annual turnover above EUR 10 million, and some entities are covered regardless of size. A mid-sized IT provider, a logistics company or a manufacturing plant that has never dealt with a cybersecurity regulator is often in scope and unaware of it.

Three dates for the board calendar

The timeline published on gov.pl is short:

  • 3 October 2026: entry in the KSC List.
  • 3 April 2027: obligations in place, including an information security management system (ISMS), incident reporting and designated responsible persons, plus connection to the S46 system.
  • 3 April 2028: first mandatory cybersecurity audit, then at least every three years.

The entry itself needs identification data, sector assignment and contact details. The harder part is the scoping decision behind it, and that analysis belongs in August and September, with a margin for borderline cases.

The “we will make it in March” trap

The tempting plan looks like this: register in October, rest over the winter, then push the documentation through in the first quarter of 2027. That plan fails in 2028. The auditor will ask about a year of the system in operation: risk analyses performed, incidents handled and reported, reviews held, decisions taken by the responsible persons. An ISMS implemented at the last minute formally meets the 3 April 2027 deadline and still produces no track record to show a year later.

What we recommend now

For the next two weeks:

  • Map the company’s activities against the NIS2 annex sectors and the size thresholds; record the conclusion in writing: in scope, out of scope, or borderline and referred for legal analysis.
  • If you are in scope, appoint an owner, collect the registration data and plan the filing for September, leaving room for questions and corrections.
  • Put the three dates in the board calendar and table them at the next meeting together with a 2027 ISMS budget estimate.
  • Plan backwards from the audit: decide what must operate from April 2027 so that the 2028 audit finds a year of evidence.
  • In a group, prepare one consolidated answer for headquarters with the status of every Polish entity.

Sources: gov.pl: amended KSC Act (obligations of essential and important entities)

This material is provided for general information and does not constitute legal, investment, tax, audit or other regulated professional advice. Its application depends on the facts, jurisdiction and current law. Verify the current status of the cited sources and obtain appropriate advice before acting.