01 October 2026

[kt_reading_time]

KSC Register Entry by October 3, 2026. Who Does It Apply To and How Should You Prepare?

Łukasz Ratajczyk

CTO

Linkedin

If an organization meets the criteria for an essential or important entity under the KSC Act, it is responsible for determining its status and registering in the KSC Register. For entities that met the statutory criteria on the date the new regulations came into force, the deadline for submitting an application is October 3, 2026.

However, this date is not a one-off “registration window.” As a rule, an application must be submitted within 6 months of the date on which the organization meets the criteria for classification as an essential or important entity. The obligation may therefore arise later, for example after the scale of operations changes or the company starts providing a new type of service.

Registration is completed through the KSC Register, which is part of the S46 System. Submitting the application does not, however, complete the work related to KSC compliance. It is the first formal step, followed by further organizational and operational obligations.

Below, we explain how to make an initial check of whether the obligation may apply to your organization, when self-registration applies, what to prepare before completing the application, and who can sign it.

Does your organization need to register in the KSC Register?

The registration obligation does not begin with a letter from an authority. The organization itself must determine whether it meets the criteria for classification as an essential or important entity.

Three elements of the initial assessment

Start by checking three things:

  • business sector – whether the organization operates in one of the sectors or subsectors listed in Annexes 1 and 2 to the Act,
  • company size – whether it meets the relevant size criteria,
  • specific criteria under Article 5 of the KSC Act – in some cases, status may be based on criteria other than company size alone.

There is no need to repeat the full classification rules here. They are discussed in more detail in our material on who is covered by the new KSC obligations. At this stage, the main point is the outcome of the assessment. If it shows that the organization is subject to the KSC Act, the next step is to determine the correct registration procedure.

Essential or important entity?

You also need to determine whether the organization is an essential or important entity. This affects its later obligations and liability, so it is better not to leave this decision until the form is being completed.

It is a good idea to document the basis for the classification from the start. This makes things easier for compliance, the CISO, and the management board, and later helps the organization move more efficiently to the next obligations under the KSC Act.

Self-registration or registration by the authority – which route applies?

The Act provides for two ways to enter an organization in the KSC Register: self-registration and registration by the authority. Organizations subject to KSC obligations that have not been entered based on data from public registers should submit an application themselves through the S46 System.

ProcedureWhen does it apply?What does the organization do?
Self-registrationWhen the organization meets the criteria for an essential or important entity and has not been registered by the authorityPrepares the required information and submits an application in S46
Registration by the authorityApplies, among others, to certain public entities, telecommunications undertakings, and trust service providersCompletes the required information after receiving notice of registration

Before starting a new application, it is worth checking whether the organization is already listed in the KSC Register. If it has been registered by the authority, another application should not be submitted “just in case.” Instead, the organization should complete the information required after registration.

The consistency of identification data also matters. If the information in the application does not match data already held in the system, for example the NIP or REGON number, the application may be sent for additional verification.

So first determine the organization’s status and check whether an entry already exists. Only then choose the correct route.

Why is October 3, 2026 important?

For organizations that met the criteria for classification as an essential or important entity on April 3, 2026, the deadline for submitting an application for entry in the KSC Register is October 3, 2026.

This does not mean that the obligation disappears after that date. If an organization starts meeting the statutory criteria later, it still has 6 months from the date on which those criteria are met.

From the perspective of the management board and compliance, the question is therefore not only whether the company will meet the October 3 deadline. The main task is to determine exactly when the organization began meeting the required criteria and from which date the six-month period should be counted.

The Act provides for financial penalties for essential and important entities, as well as personal liability for the head of the entity. The general minimum penalties are PLN 20,000 for an essential entity and PLN 15,000 for an important entity. The penalty for the head of the entity may be up to 300% of remuneration in the private sector or 100% in the public sector.

This does not mean, however, that even a short delay automatically results in the minimum penalty being imposed. It is therefore better not to reduce the issue to the message “one day late = PLN 20,000.”

The safest approach is to determine when the obligation arose, document the basis for the classification, and avoid leaving registration until the last possible moment.

our service

The KSC Register entry is just the start. Find your gaps

Entities covered by the KSC Act since 3 April 2026 have until 3 April 2027 to put the required processes, documentation and safeguards in place. During a free 4-hour audit, our engineers assess your IT infrastructure, data protection and incident readiness. You get a report listing the gaps with prioritised recommendations – a starting point for your compliance roadmap.

What should you prepare before starting the application in S46?

A lot of time can be saved before the form is even opened. The application includes not only basic registration details, but also information about the entity’s classification, contact persons, and some infrastructure details.

Before starting self-registration, prepare:

  • organization details – name, NIP, REGON, address, and the relevant sector, subsector, and type of activity,
  • confirmed classification – essential or important entity, together with the basis for that classification,
  • a person responsible for the entire process – someone who will collect information from compliance, IT, and the people authorized to represent the company,
  • contact persons – including those responsible for communication with the relevant CSIRT,
  • an S46 account administrator,
  • representation details – so that before the application is submitted, it is clear who can sign it and whether a power of attorney is required,
  • technical information – including public IP address ranges and internet domains,
  • other information required in the form – for example details concerning a representative, managed service providers, or the exchange of cybersecurity-related information.

It is better not to leave the entire task to one person. Compliance can be responsible for classification and the legal basis, the CISO or IT team for technical and contact information, and the person authorized to represent the organization for signing the application or granting the appropriate authorization.

At the same time, it is a good idea to appoint one process owner. This person should keep track of the deadline, make sure the information is complete, and ensure that data from different departments actually makes it into the form.

Who can sign the application and how should it be submitted?

The application for entry in the KSC Register is submitted and signed by the head of the entity or a person authorized by them. If an attorney-in-fact is acting on behalf of the entity, check in advance whether their authority is recorded in the relevant register or whether a separate power of attorney will be required.

Before submitting the application, go through three steps:

  1. Determine who formally represents the organization. Check the KRS or CEIDG and the organization’s internal representation rules. If the application is to be signed by an authorized person, prepare the appropriate authorization.
  2. Prepare the signing method. The application can be signed, among other methods, using a Trusted Profile or an electronic signature applied through an external application.
  3. Check the information before submission. The head of the entity makes a declaration under penalty of criminal liability for making a false statement, so the final review should not be treated as a routine formality.

Representation issues often surface only at the end, once all the information has already been collected. It is better to deal with them in parallel with preparing the application.

What happens after the application is submitted?

After submitting the application, check its status in S46. The status “Approved” means that the organization has been entered in the KSC Register. “Pending verification” may appear if the system detects a discrepancy in the data, for example concerning the NIP or REGON number.

After registration, you should also make sure that the administrator has access to the additional functions of the S46 Cyber Hub.

This is where the next stage of work begins. Entry in the KSC Register does not mean that the organization has achieved compliance with the Act. The remaining obligations still need to be addressed, responsibilities assigned, incident handling and reporting procedures prepared, and further actions planned.

If you are not sure whether your organization has determined its status correctly or what it should do after registration, the next step is to review the scope of its obligations and prepare a compliance roadmap.

Check your organization’s KSC status and prepare a roadmap for the next obligations with Tenesys.