ConfirmedPolandNIS2 (Poland transposition - Ustawa o KSC)

Poland: KSC key/important entities must register within 6 months of the NIS2 amendment

25 days from today

Date note: 6 months from the amended KSC's entry into force on 2026-04-03; this deadline was extended from an originally proposed 3 months during the Sejm's second reading. Entities that qualify later must still register within 6 months of first meeting the criteria - an ongoing rule, not only a one-off deadline for this initial batch.

What changes

Entities newly brought into scope as 'key' or 'important' by Poland's amended Cybersecurity Act (KSC), implementing NIS2, must submit a registration application to the competent authority within 6 months of the Act's entry into force.

Who is affected

Medium and large companies in NIS2 sectors that are or become in scope of the amended KSC, plus smaller entities designated as critical or sole providers of a service.

Sizes: medium, large · Sectors: Energy, Transport / logistics, Finance / insurance, Health, Software / SaaS, Manufacturing, Agriculture / food, Professional services · Applies if: We operate in a critical sector (NIS2); We rely on cloud services

What to do

Determine whether your organisation meets the key/important entity criteria under the amended KSC. If you qualify from the Act's entry into force, submit your registration application by 3 October 2026; if you qualify later, register within 6 months of first meeting the criteria. Begin preparing risk-management measures and incident-reporting workflows in parallel, ahead of the 3 April 2027 implementation deadline.

Penalty

Administrative fines apply under the Act, first enforceable from 3 April 2028 (2 years after entry into force).

Sources

Last verified 8 September 2026. Informational only, not legal advice.

More NIS2 (Poland transposition - Ustawa o KSC) deadlines