The NIS2 Registration Deadline Is October 3, 2026. Here Is What You Must Do Before Then
Poland’s amended National Cybersecurity System Act (the KSC Act), which implements the EU’s NIS2 directive, has been in force since April 3, 2026. The first hard deadline it sets is closer than most companies realize: by October 3, 2026, covered entities must self-identify and register with the authorities.
Note the phrasing. Nobody sends you a letter telling you that you are covered. The obligation to figure that out is yours, and so is the liability if you get it wrong.
Who is covered
The KSC Act reaches roughly 42,000 companies across 18 sectors, split into two tiers:
- Essential entities: energy, transport, banking and financial market infrastructure, healthcare, drinking water, wastewater, digital infrastructure, ICT service management, public administration, and space. Generally large entities in these sectors (250+ employees or over €50M turnover), though some, like qualified trust service providers and DNS operators, are covered regardless of size.
- Important entities: postal and courier services, waste management, chemicals, food production and distribution, manufacturing (including medical devices, electronics, machinery, and vehicles), digital providers, and research. Generally medium entities (50+ employees or over €10M turnover) in these sectors.
Two traps catch companies here:
- Size is calculated at group level in some cases. A 40-person Polish subsidiary of a large international group may still qualify.
- Sector definitions are broader than they look. “Manufacturing” alone covers a large share of Poland’s industrial base. If you make medical devices, electronics, automotive components, or machinery, read the annexes before assuming you are out.
What registration actually requires
Registration is not a compliance audit. It is a declaration: you identify your organization, its sector, its classification (essential or important), and contact points for the authorities. That is the easy part.
The hard part is what registration triggers. Once registered, you are on the regulator’s map, and the next deadlines apply to you directly:
- April 2027: risk-management measures, security controls, and incident-reporting processes must be fully implemented.
- April 2028: first mandatory security audits.
This is why the smart move is to treat registration and gap assessment as one exercise, not two. Registering in October 2026 and starting your compliance work in 2027 leaves you attempting in twelve months what most organizations need eighteen to do properly.
The penalties are not theoretical
Fines reach €10 million or 2% of global turnover for essential entities. More pointedly for anyone reading this in a leadership role: the KSC Act allows management to be held personally liable for compliance failures. This is not a fine your company absorbs while you move on. It follows the people who signed off on doing nothing.
The three-step check to run this month
If you have not yet confirmed your status, this is a half-day exercise:
- Map your activities against the sector annexes. Not your primary PKD code, but your actual activities. Companies frequently qualify through a secondary line of business.
- Check your size thresholds, including group structure. Headcount and turnover, calculated the way the act calculates them, not the way your org chart suggests.
- Document the conclusion either way. If you determine you are not covered, write down the reasoning and the data behind it. If the regulator later disagrees, a documented good-faith analysis is a very different conversation than a shrug.
If step 1 or 2 comes back positive or ambiguous, the next move is a gap assessment against the act’s risk-management measures, because your real deadline is not October 2026, it is April 2027, and the typical engagement runs four to six weeks before remediation even starts.
Not sure? That is a free conversation
I audit organizations against NIS2 requirements, and the classification question is one I answer without charge: email me your organization’s size, sector, and main services, and I will tell you whether the act covers you, by what date, and what your first step should be. See the FAQ for how engagements work, or grab the compliance checklist if you want to run the first pass yourself.
October 3 is a date with your company’s name on it, whether you have read the act or not. Better to know now.










