Compliance dates · 3 October 2026 · EU (Poland)
Applications for the Polish register of key and important entities close on 3 October 2026
3 October 2026 is the deadline to apply for entry in the register of key and important entities under the amended National Cybersecurity System Act. That Act is Poland's transposition of NIS2.
Registration is the entry point rather than the whole duty. A business that meets the sector and size criteria and is not entered ex officio has to put itself on the register by the date. Entry can also happen ex officio, so the first question is whether the state has already listed the entity without being asked.
Polish businesses across the 18 listed sectors
Around 42,000 Polish businesses across 18 sectors that meet the sector and size criteria and are not entered ex officio. Sector plus size is the test, so a small firm in a listed sector can be caught while a larger one outside it is not.
Working out whether to apply
- Check your Polish entity against the 18 sectors named in the Act.
- Apply the size criteria to that entity, not to the group.
- Find out whether you have already been entered ex officio.
- If you are not entered, file the application for entry before 3 October 2026.
- Keep the confirmation of entry with your cybersecurity records.
The NIS2 system
The Polish Act transposes NIS2, and the NIS2 system covers the Directive the Act carries into Polish law.
NIS2 Directive £3,000
Cybersecurity risk management and incident reporting for essential and important entities.
Directive (EU) 2022/2555 · European Union
Verified 19 August 2026.