NIS2 · uKSC 2026 · KSC Register deadline 3 October

Does your company fall under uKSC? Check before 3 October 2026

If you are not sure whether the organisation is an essential or important entity, start with an applicability assessment. We establish the sector, size criteria, Article 5 conditions and the correct KSC Register route before you invest in documentation and implementation.

Before 3 October

First establish whether the registration obligation applies to your organisation

Not every company operating in a “digital” sector automatically falls under uKSC, and not every entity covered by the Act registers itself. The first step should therefore be an applicability assessment, not a generic documentation package.

1. Applicability

Review actual activities, sector, company size, partner and linked enterprises, and the special conditions in Article 5.

2. Registration route

Determine whether the organisation submits a self-registration application or belongs to a category entered in the KSC Register ex officio.

3. KSC Register

If self-registration applies, prepare the required data and organise submission before 3 October 2026.

4. What next

Only after scope is confirmed: gap analysis, priorities and a plan for the obligations due by 3 April 2027.

Scope

What NIS2 / uKSC preparation can include

Scope and applicability

Confirm whether the organisation is essential, important or outside scope and which services are covered.

Gap analysis

Compare current policies, processes, controls and evidence against uKSC and NIS2 requirements.

Roadmap and ISMS

Priorities, risks, roles, procedures and documentation implemented in an order driven by risk and deadlines.

Operational readiness

Incidents, suppliers, continuity, management training, communications and evidence that controls work.

Obligations

Core areas that need to work in practice

uKSC requires essential and important entities to implement appropriate and proportionate cybersecurity risk-management measures. In practice this means connecting governance, processes, technology and evidence.

  • risk management and security policies,
  • security in acquisition, development, maintenance and operation of systems,
  • human resources security and access control,
  • business continuity, backups and recovery,
  • ICT supply-chain security,
  • incident management and reporting to the relevant CSIRT,
  • document control and regular review.
Important: policies alone are not enough. Audit and supervision focus on whether controls actually work and whether there is evidence of operation.
Deadlines

uKSC 2026–2028: dates not to miss

KSC Register

For entities subject to self-registration that met the criteria when the amendment entered into force.

Obligations and ISMS

12-month transitional period for implementing the relevant obligations.

S46

The Ministry also points to connection to the S46 system within the implementation timetable.

First audit

For essential entities meeting the criteria at entry into force — 24-month transitional deadline.

FAQ

NIS2 Poland / uKSC — short answers

Has NIS2 been implemented into Polish law?

Yes. The amendment to the Act on the National Cybersecurity System dated 23 January 2026 entered into force on 3 April 2026 and implements NIS2.

Does every organisation covered by uKSC submit its own registration application?

No. The Act provides for self-registration and ex officio entry. Self-registration mainly concerns private entities meeting the statutory criteria that are not in categories entered ex officio.

What does ISMS / SZBI mean under uKSC?

It is the information security management system covering risk, policies, system security, business continuity, suppliers, incidents and document governance.

Does management have obligations under NIS2 / uKSC?

The amended uKSC strengthens management responsibility for cybersecurity tasks and includes an appropriate training requirement for the head of the entity.

Is ISO 27001 enough for uKSC compliance?

ISO 27001 is a strong foundation, but certification does not replace analysis of statutory requirements, sector-specific obligations and reporting duties.

Not sure whether you have to register by 3 October?

Send your industry, company size and a short description of your activities. First we determine whether uKSC applies and which registration route is relevant; only then, if needed, we move to gap analysis and implementation.

Ask about uKSC applicability →