Poland's NIS2 cybersecurity registry takes no paper filings: registration only goes through with a qualified e-signature
The Story
or Trusted Profile, and the window closes 3 October 2026.
Why It Matters
Before a company can even open the registration form at wykaz-ksc.gov.pl, it needs three things most 30 to 150 person firms have never assembled: a documented decision naming who is accountable for cybersecurity, a working contact list for incident reporting, and a full inventory of the company's public IP ranges and domains. None of that exists by default, and gathering it typically takes longer than the filing itself.
What To Do About It
If your business might fall under NIS2 (energy, transport, healthcare, digital infrastructure, and more), do not wait for the October deadline to discover nobody holds e-signature access. Confirm this week who holds a qualified e-signature or Trusted Profile for the company, and get the cybersecurity-accountable-officer decision written down.
Sources
Related Signals
Poland cut mandatory tax-scheme reporting (MDR) down to cross-border arrangements only from 1 October 2026, dropping domestic schemes, MDR-2 forms, and the internal-procedure requirement.
6 Aug 2026A hacked vendor account let attackers into Żabka's internal systems for days before anyone noticed; the retailer confirmed the breach on 4 August after the data went up for sale.
5 Aug 2026KSeF carries no administrative penalties until 1 January 2027, but the tax code's separate criminal-fiscal liability for false or missing invoices already applies in full.
5 Aug 2026