Short answer
The deadline depends on the day the organization met the conditions for being treated as an essential or an important entity. Entities that met them on 3 April 2026 file the application under the schedule set by the Minister of Digital Affairs, that is by 3 October 2026. Everyone else has six months from the day the conditions were met. The application is filed by the head of the entity, or by a person they authorise, electronically and through the ICT system that maintains the register.
Why this question comes up at all
Entry in the register is often read as the moment an organization “enters” the scope of the Act on the National Cybersecurity System. That reading is the reverse of the legal position. The act applies once the conditions in Article 5 are met, and entry in the register is an administrative-technical act that is declaratory in nature (Article 7d(5)). The register discloses a status it does not itself create.
The practical consequence is uncomfortable. An organization that has not filed the application is not outside the act because of it — every deadline for implementing its obligations is already running. The reverse holds too: an entry does not establish that the classification was made correctly, because the data comes from the entity itself.
The second source of doubt is the pair of parallel deadline regimes. The act sets a standing rule of six months from the day the conditions are met (Article 7c(1)). Alongside it runs a transitional rule for entities that existed and met the conditions on the day the amendment entered into force. The second rule is not written into the KSC act itself, but into the amending act and a ministerial communication. Reading the consolidated text alone, it is easy to miss.
The third source is organisational. The application looks like a registration formality that can be handed to an administrative team. In reality it contains a declaration of the size of the entity, a sectoral classification and technical data. None of these can be completed without first determining what the organization is for the purposes of the act.
What has to be established before the decision
Which deadline binds the organization
The starting point is the date the conditions were met, not the date the obligation was discovered. Which side of 3 April 2026 that date falls on determines the whole schedule that follows.
| Situation of the entity | Deadline for filing the application | Legal basis |
|---|---|---|
| Met the conditions on 3 April 2026 | by 3 October 2026 | Article 33(3) of the amending act and the communication of the Minister of Digital Affairs |
| Met the conditions after 3 April 2026 | 6 months from the day the conditions were met | Article 7c(1) of the KSC act |
| Entered ex officio | no application for entry is filed, the data is completed within 6 months of service of the request | Article 7b(2) and (4) |
| Designated by a decision of the authority | the data is completed within 6 months of service of the decision | Article 7l(3)(2) |
The ministry’s schedule opened filing on 7 May 2026 and closes it on 3 October 2026. The same deadline applies to essential entities and to important entities — the ministry did not split them into separate stages. The communication may be changed, but only for technical or organisational reasons on the side of the system (Article 34(5) of the amending act). As at 19 August 2026 no change had been recorded.
The deadlines for implementing the substantive obligations run independently of the registration deadline. Entities that met the conditions on 3 April 2026 implement the obligations of Chapter 3 by 3 April 2027, and essential entities carry out their first audit by 3 April 2028. For entities that met the conditions later, the same periods are 12 and 24 months from the day the conditions were met (Article 16).
Whether the entity has already been entered ex officio
This check comes first, because it settles which document the organization should be looking for at all. The minister responsible for computerisation enters four groups of entities ex officio: telecommunications undertakings, trust service providers, public entities and critical entities (Article 7a(2)). Former operators of essential services were placed in the register ex officio as a separate group.
An entry made ex officio covers only the data available in public registers. The authority does not know the rest, so it issues a request to supplement it, and the addressee has six months from service. The gap is filled by an application to change the entry, not by an application for entry (Article 7b(4)). The distinction matters in practice, because an application for entry concerning an entity that is already registered will not be processed (Article 7d(3)(2)).
A separate situation arises where an entity carries on several types of activity. An entry made ex officio may cover one of them and omit the others. The act then requires the register to be supplemented with the activity not covered by that entry.
What data has to be gathered before the form is opened
The scope of the application is set by Article 7(2)(1)–(18). The register is maintained in the KSC ICT system, and the self-registration form is available at wykaz-ksc.gov.pl. Some items are registry data the organization has to hand. The rest calls for work across several teams at once, and it is that part which decides how long preparation takes.
Six groups of data have to be gathered before filling in begins.
- the sectoral classification, meaning the sector, subsector and type of activity under Annex 1 or 2, separately for each type of activity carried on;
- the declaration of the size of the entity against the micro, small and medium-sized enterprise criteria, and for a healthcare provider that is not an entrepreneur and for a municipal office — the number of persons employed as at the date the financial statements were drawn up;
- the ranges of public IP addresses and the domains used on a continuous basis;
- the details of at least two contact persons, and for the person acting as administrator of the account in the system additionally their PESEL number;
- information on the member states in which the entity carries on activity, together with the type of that activity;
- information on any contract with a managed cybersecurity services provider, where one has been concluded, together with that provider’s details.
Two items on this list cause the most trouble. The ranges of IP addresses and domains have to be agreed between the network team and the owners of the services, and in organizations with distributed infrastructure nobody maintains such a list on a current basis. The PESEL number of the account administrator is in turn often read as excessive, although it follows directly from the provision and serves to authenticate that person in the system.
It is worth knowing that data held in the register is not subject to the act on access to public information or to the provisions on the re-use of public sector information (Article 7(3)). What is publicly available is only the number of entities broken down by sector, updated at least once a quarter.
Who signs the application and what they are answerable for
The application is signed by the head of the entity or by a person they authorise. A qualified electronic signature, a trusted signature and a personal signature are all admissible, as is a qualified electronic seal identifying the person (Article 7c(6)). Where an attorney acts, a power of attorney in electronic form is attached. No power of attorney is attached by a commercial proxy disclosed in the National Court Register or by an attorney disclosed in CEIDG.
More important than the signing technique is the content of the declaration. The application contains a declaration by the head of the entity that the data is true, made under pain of criminal liability under Article 233(6) of the Criminal Code. The legislator excluded from that liability the reporting of IP address ranges and domain names. Those are precisely the data whose complete currency cannot be guaranteed in a large organization.
A sequencing recommendation follows. The sectoral classification and the declaration of the size of the entity should be settled and documented before the head of the entity is asked to sign. Signing the application is the last step of the classification process, not its beginning.
What happens after the application is filed
The entry is made at the moment the application is filed in the system (Article 7d(1)). There is no proceeding, no decision and no waiting for the matter to be examined. The act does, however, list four situations in which no entry is made (Article 7d(3)).
- the application does not contain the data subject to entry;
- the application concerns an entity already in the register;
- the application does not contain the declaration of the head of the entity;
- the application has not been signed.
An application left without an entry on any of these grounds does not stop the deadline from running.
The entry opens access to the ICT system. The act frames this as an obligation, because the entity begins using the system once it has obtained its entry in the register (Article 9(1)(4)). This is the practical reason not to leave registration until last — the same channel is later used to report significant incidents. An organization without an account in the system has nothing to report through at the moment the reporting obligation arises.
The obligation does not end with the entry. A change in the data covered by the application is reported within 14 days of the day it occurs (Article 7c(3)). This applies equally to a change of contact persons and to changes in IP address ranges and domains. If the organization ceases to meet the conditions, it files an application for removal together with a statement of reasons, and the authority has one month to examine it (Article 7f(3) and (4)).
Finally, the question that comes up most often in board meetings. Failure to file the application on time is a ground for a discretionary financial penalty — the authority may impose one where the gravity and significance of the provisions infringed justify it (Article 73(1a)(1)). Financial penalties under Article 73(1)–(4) may in any event be imposed for the first time only two years after the amendment entered into force (Article 35 of the amending act). The real consequence of delay this year is therefore not a penalty. It is an entry made by the authority ex officio, on the basis of data the organization did not prepare itself (Article 7j).
Most common mistakes
- Counting the deadline from the day the obligation was learned about. The deadline runs from the day the conditions were met, or follows from the transitional schedule. The date on which the organization found out about the matter has no legal significance.
- Treating the entry as the moment the obligations arise. The entry is declaratory. The periods for implementing an information security management system and for the first audit run regardless of whether the application has been filed.
- Assuming an entry made ex officio closes the matter. Such an entry covers data from public registers. The remaining items are supplied by the entity itself on request, within six months. Failure to supply them carries a penalty.
- Reporting one type of activity instead of all of them. An entity carrying on several types of activity reports them separately. Omitting one means an incomplete entry. Supervision then covers a narrower scope than it should.
- Leaving the entry without updates. The 14-day deadline for reporting a change of data applies at all times. A change of contact person or a rebuild of network addressing are registration events, even though nobody calls them that.
Conclusions and next steps
The application for entry is a technical act. What precedes it is not technical, namely establishing whether and in what character the organization falls under the act. The register reflects that decision, it does not take it. The quality of the entry therefore depends on the quality of the earlier classification, not on how smoothly the form is handled.
The following sequence works in organizations with a complex structure.
- Establish whether the entity has been entered ex officio and whether a request to supplement the data is pending.
- Settle the classification for each type of activity separately and record the reasoning.
- Gather the technical and contact data, starting with the IP address ranges and domains.
- Put the complete set before the head of the entity together with the wording of the declaration they are to sign.
- After the entry, activate the account in the ICT system and appoint the person responsible for reporting changes.
The fifth point tends to be skipped, and it is the one that decides whether the register stays consistent with the facts. The authority may carry out verification activities and call for a correction within seven days (Article 7k). The deadline is short, because the data in the register is meant to be current at all times.
Related materials
- Does every organization fall under NIS2? — the classification of the entity as the step that has to precede the application for entry.
- Where should the board begin preparing for NIS2? — the order of board decisions once the status has been established.
- What should a NIS2 gap analysis contain? — assessing readiness for the obligations of Chapter 3.
Sources
- Act of 5 July 2018 on the National Cybersecurity System, consolidated text (as at 7 July 2026), Articles 5, 7–7m, 9, 16 and 46 — ISAP, Chancellery of the Sejm: isap.sejm.gov.pl (in Polish; accessed 19 August 2026)
- Act of 23 January 2026 amending the Act on the National Cybersecurity System and certain other acts (Journal of Laws 2026, item 252), Articles 33–35 — Journal of Laws: dziennikustaw.gov.pl (in Polish; accessed 19 August 2026)
- Communication of the Minister of Digital Affairs of 8 April 2026 on the schedule for filing applications for entry in the register of essential and important entities (Official Journal of the Minister of Digital Affairs, item 7) — Ministry of Digital Affairs: gov.pl (in Polish; accessed 19 August 2026)
- Ministry of Digital Affairs, “Amendment of the Act on the National Cybersecurity System (KSC) — self-registration in the register of essential and important entities” — gov.pl (in Polish; accessed 19 August 2026)
- S46 System, “Self-registration (entry in the KSC Register)” — NASK, Ministry of Digital Affairs: gov.pl (in Polish; accessed 19 August 2026)
Establish the status before you fill in the application
If the classification of the organization has still not been settled in writing, the application for entry will reflect uncertainty rather than a decision. NIS2 and KSC readiness support covers establishing the status for each type of activity and preparing the data required in the application.
This material is general and educational. It is not individual legal advice or a recommendation for any specific organisation. The scope of obligations should be assessed in the light of that organisation’s circumstances.
Legal status: August 2026.