Chors.net
Blog & Insights

Precyzyjna wiedza
o ciemnych systemach.

Ekspercka analiza i studia przypadków dla decydentów. Nawigacja po złożonościach nowoczesnej infrastruktury cyfrowej z niekompromisowymi standardami bezpieczeństwa.

How to report NIS2 in Poland — KSC registry self-registration step by step (deadline 3.10.2026)

How to report NIS2 in Poland — KSC registry self-registration step by step (deadline 3.10.2026)

If your company operates in a sector listed in Annex I or II of the KSC Act and exceeds the size threshold, you must file for entry in the KSC registry by 3 October 2026 at the latest (Article 7c(1)). The procedure runs as online self-registration, opened on 7 May 2026 through a dedicated government portal. First, identify the sector you actually operate in (the criterion is real activity, not the PKD code in the commercial register), confirm the threshold, and choose between “essential entity" and “important entity." After the entry, you must implement operational duties by 3.04.2027 and complete the first cybersecurity audit by 3.04.2028 (Article 16 KSC).

Key facts

  • Statutory deadline: self-registration open from 7 May 2026, window closes 3 October 2026 (Article 7c(1) KSC).
  • Sector identification: the sector list sits in Annexes I (essential entities) and II (important entities) to the KSC Act (Dz.U. 2026 item 20). The criterion is current, real activity — not the PKD code registered years ago.
  • General size threshold: medium-sized enterprise ~50 staff / EUR 10m turnover or balance-sheet total.
  • MSSP threshold (some Annex II sectors): from ~10 staff / EUR 2m — even small companies may be captured.
  • Missing the deadline = breach of a statutory duty; the authority may enter the record ex officio and impose administrative sanctions (Article 73 KSC).

Procedure — self-registration step by step

Step 1: Identify your sector

Open Annexes I and II to the KSC Act (Dz.U. 2026 item 20). Check whether your current activity matches a sector description. If you run several lines of business, you qualify under the sector you actually operate in (manufacturing in Annex I has different consequences than ICT-B2B in Annex II). The PKD in the commercial register is a starting point, not a determination.

Step 2: Check the size threshold

For most entities, the medium-sized enterprise rule applies. For the MSSP sector (e.g. ICT-B2B suppliers in Annex II), the threshold is lower and already captures small enterprises. When in doubt, a law-firm consultation is cheaper than an administrative penalty.

Step 3: Choose your qualification — essential or important

Annex I = essential entity (energy, transport, health, water, digital infrastructure, public administration). Annex II = important entity (everything else). The difference affects the supervisory regime, audit cadence, and the upper ceiling of penalties.

Step 4: File via the self-registration portal

The portal is operated by the Ministry of Digital Affairs (see Infor.pl guidance, 7.05.2026). The form captures: sector, registration data, contact for the person responsible for cybersecurity. The application is signed electronically by an authorised person (KRS/CEIDG).

Step 5: Keep the entry confirmation and prepare for operational duties

After the entry, you have until 3.04.2027 to implement operational duties: an ISMS, security policies, an incident-reporting procedure (24 h / 72 h / 30 days), and staff training. The first cybersecurity audit (Article 16) is due by 3.04.2028.

Decision table — common mistakes in self-registration

MistakeWhy it hurtsWhat to do instead
Postponing the entry “until 2027"After 3.10.2026 the authority may enter the record ex officio and apply Article 73 sanctionsSubmit in the first week the portal is open
Relying only on PKD codesSector is determined by real activity; PKD is often outdated or impreciseCross-check the Annex I/II description against current operations
Missing a group-level qualificationParent and subsidiaries qualify separately; missing one = a gapMap the group structure and qualify each entity separately
Naming an untrained contactAn empty entry means no CSIRT contactName a person trained in incident reporting (24/72/30)
No escalation playbookIncidents leave the company past 24h; the entity breaches its reporting dutyPrepare the escalation playbook before the first incident

Perspective from Marcin Białczyk (CHORS.NET)

I have worked with companies that had full ISMS documentation but never registered in the KSC — because nobody connected the date 3.10.2026 with the operational calendar. In practice the most common cause is “I did not know it applies to us". On the other side there are companies that registered on day one but have no incident-reporting procedure — and that is the second, equally serious problem.

That is why in CHORS.NET we treat this cluster thematically: the registry entry is not the goal, it is the milestone. Real work starts after it — an ISMS proportional to scale, training, tabletop exercises. In our security posture report P1_AUTH_VA + P3_NIS2_READINESS we link statutory requirements to real IT and OT risk, so the client does not build parallel “NIS2 projects" next to normal operations.

The third thing I flag: statutory deadlines are independent of the company budget cycle. If your IT budget lands in December, you still have time for the entry, but not for the 2028 audit — the audit requires earlier implementation. I plan to return to a scenario where a company went into an audit with full documentation but no working incident-reporting process — for now, a contrast, not a case study.

Frequently asked questions

Can I report NIS2 after 3.10.2026?

Formally, you can file after the deadline, but missing the entry in time is a breach of a statutory duty. The authority may enter the record ex officio and impose administrative sanctions under Article 73 KSC. Legal interpretation requires consultation with a law firm.

How do I decide whether I am essential or important?

Essential entities come from Annex I (energy, transport, health, water, digital infrastructure, public administration). Important entities come from Annex II (e.g. manufacturing, ICT-B2B, motor vehicles, food, chemicals). Legal interpretation requires consultation with a law firm.

Does a small ICT supplier for energy companies fall under NIS2?

Yes — ICT-B2B suppliers sit in Annex II, and for MSSPs the threshold is lower (~10 staff / EUR 2m). Legal interpretation requires consultation with a law firm.

Can I file without naming a person responsible for cybersecurity?

No — the form requires a CSIRT contact. An entry without such a contact is rejected or returned for completion.

What changes after the registry entry?

The operational duties clock starts: implementation by 3.04.2027 and the first cybersecurity audit by 3.04.2028 (Article 16 KSC).

Sources

  1. Infor.pl — KSC self-registration instruction (start 7.05.2026)
  2. KSC Act — consolidated text Dz.U. 2026 item 20
  3. CGO Legal — deadlines and filing procedure
  4. LegalGeek — Article 7c self-registration and 6/12/24-month milestones
  5. Ministry of Digital Affairs — KSC system
  6. NASK PIB — KSC
  7. ENISA — essential and important entities in the EU

How CHORS.NET helps

The KSC registry entry is not the goal, it is the milestone — after it comes the implementation of operational duties: ISMS, incident reporting, training, audit.

Scope and limitations

  • We are not a 24/7 SOC and we do not guarantee detection of every incident. Our model is P0_PASSIVE_SNAPSHOT and P1_AUTH_VA — not continuous monitoring with a coverage promise.
  • We do not certify NIS2/KSC compliance and we do not issue standalone legal opinions. The KSC registry entry is an administrative act, and we provide readiness assessment and implementation support.
  • The deadlines and procedures in this article reflect the state as of 9 August 2026 and may require updates after subsequent implementing acts.
  • For qualification and interpretation of KSC provisions, CHORS.NET works with partner law firms.
  • This material is informational and technical; it does not constitute legal advice.

CHORS Cryptogram

Minimalistyczny zapis na miesięczne analizy. Surowe dane, trendy audytowe i analiza zero-day prosto na skrzynkę. Zero marketingowego szumu.

Klucz GPG dostępny na życzenie.