The Register of Essential and Important Entities (“Wykaz KSC”) is an electronic register maintained as part of Poland’s government System S46, where organizations covered by the amended National Cybersecurity System Act (KSC) must register. Self-registration has been available since 7 May 2026 at wykaz-ksc.gov.pl, and the deadline to submit an application for organizations that already met the criteria when the act took effect (3 April 2026) is 3 October 2026.
This is the third article in our KSC/NIS2 series – if you’re looking for information on who is covered by the act and what obligations it imposes (including vendor risk management), see our previous KSC/NIS2 article.
In this article we explain who is required to register, how the registration process works step by step, and what happens to an organization after registration.
What Is the KSC Register?
The KSC Register is an electronic register of essential and important entities, maintained by the minister responsible for digital affairs as part of System S46. It replaces the previous register of essential service operators and serves as the central source of information about entities covered by the regulation.
The register lets CSIRT teams and the competent cybersecurity authorities know who to contact in the event of an incident, and registration opens access to S46 Cyber Hub – the operational platform through which further statutory obligations are carried out, most importantly incident reporting.
Who Must Register in the KSC Register?
The registration path depends on whether the organization was already known to the supervisory authorities:
The application is submitted by the head of the entity or a person authorized by them.
What Is the Deadline to Register?
The statutory deadline for submitting a registration application is 6 months from meeting the criteria for essential or important entity status. For organizations that already met these criteria on the date the amendment took effect (3 April 2026), the deadline is 3 October 2026.
For entities registered ex officio that received a notice to complete their data, the deadline is 6 months from the date the notice was delivered.
How to Check If Your Organization Must Register
Before starting registration, make sure your organization actually meets the act’s criteria – sector of activity and company size. You can use the free NIS2/KSC self-assessment tool, and the full classification process (essential entity vs important entity) is covered in our previous KSC/NIS2 article.
What Information Should You Prepare?
The application form at wykaz-ksc.gov.pl consists of several sections, each saved separately. According to the official System S46 instructions, it’s worth preparing in advance:
- Basic information – entity name, tax ID (NIP), business registry number (REGON),
- Regulated activity registries – if the organization carries out regulated activity,
- Classification – sector, subsector and type of activity in line with the annexes to the KSC act,
- Address details – registered office address, correspondence address, and contact details (email, phone, website, electronic delivery address),
- Contact persons – details of the person or persons responsible for liaising with KSC authorities, including the System S46 account administrator.
BCMLogic expert commentary: it’s worth gathering this data before you start filling out the form, not while you’re in the middle of it – especially the sector classification and S46 account administrator details, since these determine how quickly the organization gets access to S46 Cyber Hub after registration.
How Does the Registration Process Work?
According to the official Ministry of Digital Affairs instructions, self-registration proceeds as follows:
- Login – through the National Node (login.gov.pl), using Trusted Profile, the mObywatel app, e-ID, electronic banking, or a qualified electronic signature.
- Start the form – on the wykaz-ksc.gov.pl welcome page, select “Register a new entity.”
- Fill in the form sections – each section (basic information, classification, address details, contact persons, etc.) is saved separately; fields marked as required must be completed before saving that section.
- Submit the application – once all sections are completed, the application is sent to the competent authority for review.
What Happens After Registration?
Once the application is approved, its status changes to “Approved” – the entity appears on the register’s list, and the organization receives email confirmation.
The S46 account administrator, designated in the form as a contact person, receives access to S46 Cyber Hub – the operational platform used for ongoing communication with CSIRT teams and supervisory authorities, including incident reporting.
It’s worth noting that registration in the KSC Register is declaratory in nature – meaning the obligations arising from the act apply to the organization from the date it met the statutory criteria, not from the date of formal registration. Registration itself therefore doesn’t equal full compliance with the act’s requirements.
What Further Obligations Follow Registration?
Registration opens the door to further obligations the organization must fulfill in the following months:
- Starting to use System S46 – within 12 months of meeting the criteria for essential or important entity status,
- Implementing an information security management system (ISMS), including systematic risk assessment,
- Preparing incident reporting and handling procedures in line with statutory deadlines – closely tied in practice to crisis management and business continuity,
- Designating and training the persons responsible for liaising with KSC authorities,
- Preparing for the first mandatory security audit – for essential entities that were not previously essential service operators.
Registering on time doesn’t therefore automatically mean full compliance with the act – it’s only the first, formal step in a considerably broader implementation process.
Common Mistakes When Registering in the KSC Register
- Delaying classification – starting to fill out the form without a prior, documented analysis of status (essential / important / not covered).
- Not having S46 administrator details ready – this delays access to S46 Cyber Hub once registration is approved.
- Treating registration as the end of the process – when it’s actually just the beginning of ISMS, incident reporting and audit obligations.
- Overlooking corporate group structure – subsidiaries of essential service operators may also be subject to the registration requirement.
FAQ
What’s the difference between the KSC Register and System S46?
The KSC Register is the register of essential and important entities – part of the broader System S46. Once registered, an organization gains access to S46 Cyber Hub, the operational platform of System S46 used, among other things, for incident reporting.
Who can submit the KSC Register application?
The application is submitted by the head of the entity or a person authorized by them.
Does every entity have to register itself?
No. Four groups of entities – telecommunications operators registered with the President of UKE, qualified trust service providers, designated public entities, and previous essential service operators and CER-critical entities – are registered ex officio and only need to complete their data after receiving a notice.
What happens if an organization no longer meets the act’s criteria?
The organization should apply to be removed from the KSC Register.
Does registration in the KSC Register mean full compliance with the act?
No. Registration is declaratory and opens access to further obligations (System S46, ISMS, incident reporting, audit), but doesn’t replace fulfilling them.
Summary
Registering in the KSC Register is the first formal step for every organization covered by the amended KSC act – without it, an organization can’t gain access to System S46 or formally operate within the new cybersecurity framework. The key is planning ahead: an early, documented status classification, preparing the data needed for the form, and designating an S46 administrator – rather than leaving it until the final week before the deadline.
See What This Could Look Like for Your Organization
If your organization is preparing to register in the KSC Register and to implement the act’s broader requirements, it’s worth seeing what managing risk, documentation and regulatory compliance looks like on a single GRC platform. BCMLogic Solutions helps financial and technology companies manage operational risk, business continuity and regulatory compliance – in line with ISO 22301, ISO 27001 and requirements such as DORA and NIS2/KSC.

