Register your business in Poland’s Wykaz KSC by 3 October 2026 if it falls under NIS2 - an essential or important entity in a sector listed in UKSC Annex I or II that also meets the size threshold. Self-registration has been open since 7 May 2026 at wykaz-ksc.gov.pl. Missing the deadline carries administrative fines of up to EUR 10 million.
The deadline and who must file
The registration deadline is 3 October 2026. Poland’s amended National Cybersecurity System Act (UKSC), which transposes the EU NIS2 Directive, took force on 3 April 2026 and gave in-scope entities six months to register. The Ministry of Digital Affairs opened self-registration on 7 May 2026, so the window is already live.
You only need to file if your business is actually in scope - and that is a narrower group than most owners assume. NIS2 applies when two conditions hold at once: your business operates in a sector listed in UKSC Annex I or II, and it employs at least 50 people or turns over at least EUR 10 million. If you are not sure which side of that line you fall on, work through does NIS2 apply to my business before you touch the register - this post assumes you have already concluded that you must file.
Two ways you end up in the register
The register is called the Wykaz KSC, part of the national S46 system, and there are two distinct routes into it. Most coverage mentions only the first.
| Self-registration | Ex officio (by the Minister) | |
|---|---|---|
| Who | You qualify and have not been entered by the Minister | The Minister of Digital Affairs enters you directly |
| What you do | File the entry application yourself | Wait for a notification, summons, and access code, then complete your data |
| Deadline | 3 October 2026 | 6 months from receiving the summons |
| Where | wykaz-ksc.gov.pl | The same register, using the access code you were sent |
Self-registration is the path for most private businesses that clear the two-condition test. You file the entry yourself, before the deadline. The ex officio route applies when the Minister has already identified your entity and enters it directly - you then receive a summons with an access code and complete the missing data within six months. The same six-month clock applies if your business grows into scope after 3 October 2026: you register within six months of meeting the criteria, not on some fixed annual date.
What you need before you file
Filing goes faster if you gather four things first. The entry in the Wykaz KSC asks for:
- Entity identifiers - your KRS or REGON number and NIP.
- Your sector - the Annex I or II category your activity falls under, which also fixes whether you are an essential or an important entity.
- Size data - the employee count or turnover figure that puts you over the threshold.
- A cybersecurity contact person - a named individual the CSIRT and supervisory bodies can reach. This is a real appointment, not a formality; the register exists partly to enable immediate contact during an incident.
Once you file, your entity receives formal status - essential or important - and the Chapter 3 obligations under UKSC start to apply. The full obligation set and the 10 Article 21 measures are laid out in the NIS2 and UKSC compliance guide; many of them overlap with GDPR Article 32, which we map in the data security and compliance guide.
What happens if you miss it
Failing to register when the obligation applied is sanctionable - administrative fines reach up to EUR 10 million or 2% of global annual turnover for essential entities, and EUR 7 million or 1.4% for important ones. The duty to identify yourself sits with your business, not with a regulator who will remind you; there is no grace for “we did not realise we qualified.” If your sector or size is genuinely ambiguous, get a determination from Polish counsel before 3 October rather than after.
Registration is only the first deadline. Full compliance with the 10 Article 21 measures follows on 3 April 2027, and the first mandatory audit for essential entities on 3 April 2028. What the 2026 amendment changed across all of these is summarised in NIS2 in Poland: what changed in 2026.
FAQ
When is the NIS2 registration deadline in Poland?
The deadline is 3 October 2026. In-scope entities had six months from the amended UKSC taking force on 3 April 2026. Self-registration opened on 7 May 2026. Businesses that grow into scope later must register within six months of meeting the criteria.
Where do I register for NIS2 in Poland?
You register in the Wykaz KSC, the national register of essential and important entities maintained by the Ministry of Digital Affairs, at wykaz-ksc.gov.pl. It is part of the S46 system. You file the entry yourself unless the Minister has already entered your entity ex officio.
What if the Minister registered my entity ex officio?
You do not file a fresh application. You receive a notification, a summons, and an access code, then complete the missing data in the register within six months of receiving the summons. Check that the details entered for you are accurate.
What if my business qualifies after 3 October 2026?
You register within six months of meeting the criteria, not on the general deadline. The 3 October 2026 date applies to entities that were already in scope when the amended act took force; the six-month rule covers everyone who crosses the threshold afterwards.
What is the penalty for not registering?
Failure to register when required carries administrative fines up to EUR 10 million or 2% of global annual turnover for essential entities, and EUR 7 million or 1.4% for important entities. Management board members can also be held personally liable for cyber risk management failures.
Not sure whether the systems you would list in the register actually hold up from the outside? Book a free PreScan - a passive external check of your company’s attack surface, with results in 24 hours and no obligation. It is the technical evidence layer that Article 21 and an external vulnerability assessment build on.
Informational material, not legal advice. Legal position as of August 2026. Whether your business must register depends on an individual assessment of sector and size - consult Polish counsel or a Data Protection Officer before the 3 October 2026 deadline.