Reading time: about 8 minutes

If you are an essential or important entity under the amended National Cybersecurity System Act (KSC), you have until 3 October 2026 to enter the KSC register. No one will send you a letter: the system runs on self-identification, meaning you have to work out whether the rules apply to you and file the application yourself. The amendment implementing the NIS2 directive took effect on 3 April 2026, and registration is the first of several staggered deadlines. Below we pull together in one place who is covered, the full timeline to 2028, how much the fines are, and how to prepare your plant step by step. This is not legal advice, just a practical way to organize the topic from a manufacturer's point of view.

What exactly you have to do by 3 October

The core of this deadline is simple: essential and important entities must file an application to be entered in the KSC register, kept by the minister responsible for digital affairs. The entry is not paperwork for the office, it is the moment a company formally joins the system and the clock on its further obligations starts to run. Some entities, for example existing operators of essential services, are entered by the minister automatically. Everyone else who meets the criteria has to come forward on their own, and the cut-off date is 3 October 2026. That deadline is being flagged widely right now, because it reaches a far wider group of companies than the previous law, including many manufacturers that had nothing to do with the KSC before.

The application is filed electronically and has to be signed. It is not a one-off tick: after registration a company has to designate a contact person, connect to the S46 system used to report incidents, and implement the security measures set out in the act. Registration is a gate, not a finish line.

Who NIS2 covers: essential or important entity

Whether a company is in scope is decided by two things at once: the sector it operates in and its size. The act lists sectors in its annexes, splitting them into high-criticality sectors (energy, transport, banking, digital infrastructure, healthcare, water, and similar) and other critical sectors, which include manufacturing, for example of medical devices, electronics, machinery and vehicles.

On top of that sits a size threshold based on the EU definition. In short: an essential entity is a large enterprise (from 250 employees, or turnover above 50 million euro) operating in a high-criticality sector. An important entity is a medium enterprise (from 50 to 249 employees, or turnover between 10 and 50 million euro), plus large firms in the second-annex sectors such as manufacturing. Micro and small firms, below 50 people and below 10 million euro turnover, are generally left outside the system, though there are exceptions. In practice most mid-sized and large manufacturers land in the important category, and some, those also active in a high-criticality sector, in the essential one. The risk-management security obligations are the same for both categories; the difference is mainly the intensity of supervision and the fact that the first mandatory audit applies to essential entities.

Decision table: are you covered and what follows

The simplest way to settle your situation is to line up your sector and size against the category and action that follow from them.

Company situation Category What to do
Large firm in a high-criticality sector (e.g. energy, digital infrastructure) Essential entity Register by 3 Oct 2026, prepare for audit by 3 Apr 2028
Manufacturer (machinery, electronics, medical devices, automotive), medium or large Important entity Register by 3 Oct 2026, implement obligations by 3 Apr 2027
Micro or small firm (under 50 people and under 10 million euro turnover) Usually out of scope Check exceptions (e.g. sole-supplier status) and document the finding
ICT or digital-service supplier to a covered entity Depends on profile, often important Verify status, since scope can arrive through the supply chain
Unsure about sector or size threshold To be determined Run a self-identification and keep the record of the decision

The pattern is clear: the word "manufacturing" alone does not settle the category, the combination of an annex sector and a size threshold does. If you recognise your company above the threshold in any row, registration applies to you.

The full timeline to 2028

Registration is the first threshold, not the only one. To avoid treating 3 October as the end of the topic, it helps to see the whole timeline, which the Ministry of Digital Affairs sets out.

Date What happens
3 April 2026 The KSC amendment implementing NIS2 enters into force
3 October 2026 Deadline to enter the KSC register for essential and important entities
3 April 2027 Connection to the S46 system and implementation of the security obligations
3 April 2028 First mandatory cybersecurity audit (essential entities)

The calendar says one thing: registration is close, and the real work starts right after it. Implementing the obligations by April 2027 sounds like a distant horizon until you count how long it takes to inventory systems, sort out suppliers and choose tools you cannot swap overnight.

Timeline of NIS2 implementation in Poland across four consecutive deadlines from 2026 to 2028 NIS2 implementation runs in sequence: registration in 2026, obligations in 2027, the first audit in 2028.

Self-identification: no letter is coming

This is the most misread part of the new system. Under the old model a company waited for the authority to designate it an operator of an essential service and issue a decision. Now it is the other way round: the burden of establishing status sits with the business. As an analysis by prawo.pl stresses, every company using digital solutions has to examine for itself whether it meets the criteria of an essential or important entity, and the application is filed under penalty of liability for a false statement.

The practical takeaway is that the absence of a letter from the office does not mean the absence of an obligation. A company that assumes "no one contacted us, so this does not apply" may wake up past the deadline, formally in default. That is why self-identification is worth running as a deliberate, documented process: establish the sector, count the size threshold, record the result and the reasoning. That documentation pays off twice, because it is also the first thing an auditor will ask for.

Fines, or why this is not optional

The scale of the penalties explains why registration is not worth putting off. For an essential entity an administrative fine can reach 10 million euro or 2% of annual turnover, whichever is higher. For an important entity the ceiling is 7 million euro or 1.4% of turnover. On top of that comes personal liability: the act provides for a fine of up to 300% of annual salary against the head of the entity for gross negligence. That moves the topic out of the IT department and up to the board, because the risk stops being abstract.

It is worth remembering the fine is a ceiling, not an automatic outcome. The supervisory authority weighs the severity of the breach and whether the company acted in good faith. Documented preparation, even if imperfect, works in your favour. That is one more reason to treat self-identification and registration as a trail on paper, not a verbal decision no one remembers six months later.

How to prepare your plant step by step

Registration is one point on a longer path. Here is a practical order of steps that lets you meet the deadline without a scramble.

  1. Establish your status. Check the sector in the annexes and count the size threshold. Record the result together with the reasoning, that is your self-identification.
  2. File the application by 3 October 2026. Designate a contact person and prepare an electronic signature, because without it the application cannot be filed effectively.
  3. Inventory data and systems. Where your sensitive documents go, including AI tools used informally by teams. Without that map you cannot assess the risk.
  4. Review the supply chain. Suppliers, including AI and cloud vendors, become part of your risk surface. You must be able to say where and how they process your data.
  5. Plan implementation by 3 April 2027. Connecting to S46, incident-reporting procedures and technical measures are a matter of months, not the week before the deadline.

The good news is that most of these steps are housekeeping, not a rebuild of the company. The worst case is leaving the technology choice, especially AI tools working on sensitive data, to the last quarter before an audit. If you want to check your readiness with no strings attached, our readiness mini-audit takes 10 minutes and leaves no data behind. The wider picture of what NIS2 means for an AI deployment is in our guide NIS2 and AI: what applies and how to prepare.

Where AI fits into all this

For a manufacturer, NIS2 registration and an AI deployment are not two separate topics, they are the same landscape. The security obligations require you to know where your data is and who can reach it, and more and more document work is moving into AI tools. If such a tool ships drawings and documentation to a public cloud with no control over where they end up, it becomes a problem at audit, not a help. We set this out in our pieces on why public-cloud AI won't pass your audit and when private AI beats public. Registration is a good moment to join these two threads rather than run them separately.

Frequently asked questions

By when do you have to register under NIS2?

Essential and important entities have until 3 October 2026 to enter the KSC register. Some entities are entered by the minister automatically, but the rest that meet the criteria must file the application themselves.

How do I know whether my company is subject to NIS2?

The system runs on self-identification. You have to check whether you operate in one of the sectors listed in the act and whether you cross the size threshold: a medium enterprise is usually an important entity, a large firm in a high-criticality sector is an essential entity.

What is the difference between an essential and an important entity?

The risk-management security obligations are the same for both. The difference lies in the intensity of supervision, the level of maximum fines, and the fact that the first mandatory audit applies to essential entities.

What fines apply for failing to register or for negligence?

For an essential entity up to 10 million euro or 2% of annual turnover, for an important entity up to 7 million euro or 1.4% of turnover. Against the head of the entity the act additionally provides for a personal fine of up to 300% of annual salary.

What if we miss the 3 October deadline?

The duty to register does not disappear after the deadline, and the company is formally in default, which raises the risk of sanctions. It is better to file late and document the steps taken than to do nothing. If in doubt, consult a lawyer or a compliance advisor.

This is not legal advice. The scope of obligations depends on your organization's profile; if in doubt, consult a lawyer or compliance advisor.