Let’s talk
Wondering how this plays out in your organisation? Get in touch — I answer personally.
Short answer
The third of October closes the schedule for filing applications, but it does not close the registration obligations. An organisation that has filed its application now has a continuing duty. It has fourteen days to report every change of data and seven days to correct the entry after a request from the authority. An organisation entered ex officio completes its data through an application to amend the entry within six months of the request. An organisation that has not filed despite meeting the criteria is still an essential or important entity. It should file now. Entry in the KSC register after the deadline takes effect on filing, and the alternative is an entry made by the authority.
Why this question arises at all
The Communication of the Minister of Digital Affairs set the window for filing applications from 7 May to 3 October 2026. In many organisations the closing date was read as the end of the matter. The provisions on the register are built differently. The entry is declaratory in nature, so it creates nothing and closes nothing. An entity’s status follows from meeting the criteria in Article 5, and the register is meant to reflect that status on an ongoing basis. Three clocks therefore run after 3 October. A fourteen-day clock runs from a change of data, a seven-day clock from a request issued after verification, and a six-month clock from a request to complete an entry made without an application.
The second source of doubt is the KSC register after the deadline, that is the position of organisations that missed it. A provision on a penalty for failing to file on time exists, so the question arises whether filing after the deadline still makes sense. It does, for several independent reasons set out below.
The scope of data in the application and the rules for signing it are described in When and how to apply for entry in the KSC register?
What has to be established before a decision
The KSC register after the deadline — which of the four situations the organisation is in
The answer to the question in the title depends on what happened before 3 October. Each of the four situations has its own provision and its own clock.
| Situation | What applies after 3 October | Clock | Legal basis |
|---|---|---|---|
| Application filed, entry made | reporting changes of data, correction after a request, starting to use S46 | 14 days from the change; 7 days from the request | Article 7c(3), Article 7k(2), Article 9(1)(4) |
| Entry ex officio without an application | completing the missing data through an application to amend the entry, also for activity not covered by the entry | 6 months from service of the request | Article 7a(2), Article 7b(2) and (4) |
| Criteria met on 3 April 2026, no application | the duty to file continues; the authority may enter the entity itself and request completion | 6 months from notification of the entry by the authority | Article 7c(1), Article 7j, Article 73(1a) |
| Criteria met after 3 April 2026 | the schedule does not apply; the entity has its own deadline | 6 months from the day the criteria were met | Article 7c(1) |
The fourth situation is often confused with the third. An organisation that crossed the size thresholds in mid-2026, or started an activity listed in an annex after the amendment entered into force, was not covered by the schedule. Its deadline runs from the day the criteria were met and may expire long after 3 October.
Situation one — the entry exists, the obligation does not end
An application to amend the entry is filed within fourteen days of the day the data covered by the application changed (Article 7c(3)). That scope covers eighteen items under Article 7(2). Several of them change more often than organisations assume. This concerns contact persons, ranges of IP addresses and domains, and information on a contract with a provider of managed cybersecurity services. A change of the person in a post, a domain migration or a contract with an external SOC starts the fourteen-day period. The application to amend the entry identifies the data being changed and the entity’s number in the register (Article 7c(4)) and requires the same declaration by the head of the entity as the application for entry.
The second clock is started by the authority. The authority competent for cybersecurity may verify whether the data in the register match the facts (Article 7k(1)). If it finds a discrepancy, it requests an amendment of the entry within seven days of service of the request (Article 7k(2)). Seven days is the time in which the data have to be gathered, the application prepared and the signature of the head of the entity or an authorised person obtained. Without a person designated in advance as responsible for the register, and without a power of attorney ready, that deadline is hard to meet.
The third consequence of the entry is the system. After obtaining the entry, the entity starts using the S46 ICT system (Article 9(1)(4)). The Act allows twelve months from meeting the criteria (Article 46(4)), and the ministry’s communication points to 3 April 2027. I recommend not waiting until the end of that period. An account in the system is the channel for reporting significant incidents, and an incident does not wait for the end of a transition period.
Situation two — an ex officio entry is a beginning, not an end
The minister responsible for computerisation enters four groups ex officio (Article 7a(2)). These are telecommunications undertakings, trust service providers, public entities and critical entities. The data come from public registers, from the electronic address database or from supervisory authorities. They cover only eight basic items under Article 7(2) plus the items completed by the minister. The authority does not know the rest.
That is why a request to complete the missing data follows the notification of the entry. The request states the legal basis of the entry, the entity’s number in the register, the data already entered together with their source, and the data to be completed (Article 7b(3)). The deadline is six months from service and is backed by a penalty (Article 7b(2)). Completion is made through an application to amend the entry, not through an application for entry. An application for entry by an entity already entered will not be processed (Article 7d(3)(2)).
Two things in this situation tend to be overlooked. First, the entity completes the data also for activity that was not covered by the ex officio entry (Article 7b(4), second sentence). A public entity that carries on, alongside its public tasks, an activity listed in Annex 1 cannot stop at an entry covering only the former. Second, the notification and the request are served under the provisions of the Code of Administrative Procedure on service (Article 7b(5)). A letter sent to an address for electronic service may be deemed served even if nobody in the organisation has opened the mailbox. The six months run from the day of service, not from the day of reading.
An entity entered ex officio does not have to wait for the request. It may file an application to amend the entry on its own initiative and complete the data earlier. I recommend this option, because it moves control over the deadline from the authority to the organisation.
Situation three — the KSC register after the deadline
An organisation that met the criteria on 3 April 2026 and did not file is still an essential or important entity after 3 October. It did not stop being one because the deadline passed. All obligations under Chapter 3 run against it exactly as against entities that are entered, including the 3 April 2027 deadline. What the lack of an entry takes away is access to the S46 system, and with it the channel for a significant incident report.
Entry in the KSC register after the deadline still follows from an application. The entry is made when the application is filed in the system (Article 7d(1)), and the Act does not make that effect conditional on meeting the deadline. The four grounds for refusing an entry under Article 7d(3) concern defects in the application, not its lateness. An application filed late therefore remains an effective way of putting the situation in order.
The alternative is an entry made by the authority. The authority competent for cybersecurity may enter in the register an entity that meets the criteria and has not filed an application on time (Article 7j(1)). It draws on public registers, on data available to it under separate provisions and on information obtained from the entity itself. The basis for the latter is a request for information enabling a preliminary assessment of status (Article 43(1)). The reply to such a request may become the basis for the entry (Article 43(6)). After the entry the authority notifies the entity and requests completion of the data within six months under threat of a penalty (Article 7j(3)). The entry requires reasons and may be challenged before an administrative court (Article 7j(5)).
The difference between an entity’s own application and an entry by the authority does not lie in the outcome, because in both cases the organisation ends up in the register. It lies in who establishes the data and in what procedure. With its own application the organisation describes its own types of activity and declares its size. With an entry by the authority the data come from outside, and the organisation enters a request procedure with a deadline and a sanction.
That leaves the penalty for failing to file on time. The provision is discretionary. The authority may impose a penalty if the gravity and significance of the provisions infringed justify it (Article 73(1a)(1)). Separately, the Act provides for the liability of the head of the entity for failing to perform the duty under Article 7c(1) (Article 73a(1)(1)). The transitional provisions of the amendment defer the first imposition of penalties under Article 73(1)–(4) and Article 73a until two years after the Act entered into force (Article 35). Whether the deferral also covers paragraph 1a does not follow directly from the wording and has not yet been settled. In a risk assessment it is worth taking the cautious view, but the penalty is not the argument for filing. The argument is that without an entry the organisation remains subject to the Act with no reporting channel and with its data established by the authority instead of by itself.
Situation four — an own deadline, not the schedule
An entity that met the criteria after 3 April 2026 files its application within six months of the day they were met (Article 7c(1)). Where status depends on the size of the entity, the criteria are assessed as at the day the financial statements were drawn up (Article 5(5)). For many organisations the day the criteria were met will therefore be the day the statements for 2025 or for 2026 were drawn up. The deadline has to be counted from that day, not from 3 October.
A separate procedure applies to entities recognised by a decision of the authority as essential or important despite not meeting the size criteria (Article 7l). Such an entity does not file an application for entry, because the authority enters it itself without delay (Article 7l(6)). In the decision the authority requests completion of the data within six months of service, and the decision is immediately enforceable.
When the status has ceased — removal does not happen by itself
The reverse situation also calls for action. An organisation that has stopped meeting the criteria files an application for removal from the register with reasons (Article 7f(3)). The application may cover the whole entry or only one sector or type of activity. Typical reasons are a drop in headcount below the threshold or the disposal of part of the business. The authority has one month to examine it. A refusal requires reasons and may be challenged before an administrative court, and the absence of a refusal within the deadline results in removal. Until removal the organisation remains in the register with the full set of obligations.
What the board should know
After 3 October the register stops being a project with an end date and becomes a process with an owner. The head of the entity is personally answerable for the duties under Article 7b(4) and Article 7c(1) and (3), that is for completing an ex officio entry, for the application for entry and for reporting changes (Article 8c(1) in conjunction with Article 73a(1)(1)). Every application contains the head’s declaration made under criminal liability. If the organisation has not filed, entry in the KSC register after the deadline on its own initiative lets it establish the data itself before the authority does. The board should therefore know who in the organisation tracks changes in the eighteen data items, who holds the power of attorney to sign, and how quickly the organisation can file an application to amend the entry. If the answer to the third question exceeds seven days, the process needs to change.
Common mistakes
- Assuming that after 3 October an application no longer makes sense. The entry takes effect on filing regardless of the deadline, and the obligations run anyway.
- No process for the fourteen-day deadline for changes of data. A change of contact person, domain or security service provider starts a deadline that nobody is watching.
- Filing an application for entry by an entity already entered ex officio. The correct route is an application to amend the entry. An application for entry will not be processed.
- Completing an ex officio entry only to the extent indicated in the request. The Act requires completion also for activity not covered by the ex officio entry.
- Counting the six months from reading the request rather than from service. Service takes place under the Code of Administrative Procedure, including service to an address for electronic service.
- Counting the deadline from 3 October where the criteria were met later. The deadline runs from the day the criteria were met.
- Postponing the start of S46 use until 3 April 2027. An account in the system is the channel for reporting incidents now.
Conclusions and next steps
Remember
After 3 October the question “have we filed the application” gives way to the question “who maintains the entry”.
The order of actions depends on the situation in the table, but several steps are common, and for an organisation without an entry the first of them is entry in the KSC register after the deadline.
- Check the state of the organisation’s entry in the system. Establish whether it exists, on what basis, which types of activity it covers and which data items are empty.
- If there is no entry and the criteria are met, file an application for entry now, with the qualification for each type of activity settled in writing.
- If the entry was made ex officio, file an application to amend it without waiting for a request, covering also activity not included in the entry.
- Designate a person responsible for the register and assign them sources of information on changes in the eighteen data items in HR, IT and procurement.
- Prepare an electronic power of attorney for the person filing applications to amend the entry, so that the seven-day and fourteen-day deadlines do not depend on the availability of the head of the entity.
- Activate the S46 account and designate an account administrator and at least two contact persons.
- Add the registration duties to the annual review of the information security management system as a standing item.
Related materials
- When and how to apply for entry in the KSC register? — deadlines, scope of data and signing the application for entry
- Does every organization fall under NIS2? — the qualification on which each of the four situations depends
- Where should the board begin preparing for NIS2? — Chapter 3 obligations that run regardless of the entry
- What to do after detecting an incident? — why an S46 account is needed before the first event
Sources
- Act of July 5, 2018 on the National Cybersecurity System, consolidated text (as at July 7, 2026), Articles 5, 7–7m, 8c, 9, 43, 46, 73 and 73a — ISAP, Chancellery of the Sejm: isap.sejm.gov.pl (in Polish; accessed September 6, 2026)
- Act of January 23, 2026 amending the Act on the National Cybersecurity System and certain other acts (Journal of Laws 2026, item 252), Articles 33–35 — Journal of Laws: dziennikustaw.gov.pl (in Polish; accessed September 6, 2026)
- Communication of the Minister of Digital Affairs of April 8, 2026 on the schedule for filing applications for entry in the register of essential and important entities (Official Journal of the Minister of Digital Affairs, item 7) — Ministry of Digital Affairs: gov.pl (in Polish; accessed September 6, 2026)
- S46 system, “Self-registration (entry in the KSC register)” — NASK, Ministry of Digital Affairs: gov.pl (in Polish; accessed September 6, 2026)
Put the entry in order before the authority does
If an organisation does not know which of the four situations it is in, it is worth establishing that before the first request arrives. The same goes for organisations with nobody responsible for maintaining the entry. NIS2 and KSC readiness support covers checking the state of the entry, preparing an application for entry or for amendment, and setting up the process for reporting changes.
This material is general and educational in nature. It is not an individual legal opinion or a recommendation for any specific organisation. The scope of the obligations should be assessed against the situation of the organisation concerned.
Legal status: September 2026.