Three minutes and one question the board cannot answer
The board of a mid-sized energy company in southern Poland — four hundred employees, nine-figure revenues, two dispersed sites, its own data centre — meets on the twelfth of May for its weekly management session. Item six on the agenda: "KSC self-identification". The IT director, introducing it, asks three questions. Are we an essential entity? A derivative one? An important entity? Nobody in the room can settle those questions there and then. After twenty minutes of discussion, the CFO says what everyone is thinking: "Let's check which of our competitors have already registered." They check. Of the ten names they know from the subcontractor market, not one yet appears in the register. The board's decision is pushed back to the end of the month. It will come back before them — under greater pressure — in June, when the minister for digitisation confirms in a single press statement that the supervisory authority is already monitoring the pace of registrations and preparing the first ex officio proceedings against obviously essential entities that have remained silent.
That board is not unusual. Our diagnostic conversations with two dozen companies, eight local government units and four municipal companies in the first fortnight of May 2026 all follow a single pattern. The Act entered into force on 3 April. The self-identification application went live on 7 May. Most boards have only now started treating the subject as urgent. And that is despite the fact that the deadline of 3 October 2026 sounds comfortable, when in reality it means that by the third week of May you should already have your classification settled, your filing channel chosen and a first draft of the information you will enter into the application. Because the application — counter-intuitively — is not a five-click form.
What self-identification changed — this is not just a form
The previous regime under the national cybersecurity system act rested on an administrative decision issued by the competent authority. Under the 2018 Act, you became an operator of essential services once you had been individually designated, following proceedings. The circle of entities in scope was narrow, the list was publicly known, and the obligations — serious though they were — applied to a few hundred entities across the whole of Poland.
The amendment that entered into force on 3 April 2026 — the Polish NIS-2 implementing act (the KSC Act) — turns that order through a hundred and eighty degrees. The NIS-2 Directive, and with it the Polish transposition, has replaced a regime of designation with a regime of self-identification. Every entity operating in one of the eighteen sectors listed in the Act must assess for itself whether it meets the statutory criteria to be treated as an essential entity or an important entity — and, within six months of the Act entering into force, register itself in the register of essential and important entities through the application launched on 7 May 2026. The number of entities in scope rises from a few hundred to tens of thousands — and even that is only an estimate, because it is precisely this six-month self-identification window that is meant to answer the question of how many such entities there really are.
Here lies the first trap, and it is not visible on a reading of the Act. The decision as to whether you are an essential entity, an important entity or neither is your decision. The full legal analysis, the audit trail, the classification documentation, the signature on the justification — all of it sits with you. The competent authority does not designate you in advance; it verifies you after the fact. And if it concludes that an obviously essential entity failed to register in time, the minister for digitisation issues a decision entering it in the register ex officio — with the full package of statutory consequences counted from the moment at which self-identification should have taken place.
Eighteen sectors and the concept of a derivative entity
Annex 1 to the amended KSC Act lists eleven sectors of particular importance (the source of essential entities): energy, transport, banking, financial market infrastructure, healthcare, drinking water, waste water, digital infrastructure, public administration, space, and the management of business-to-business ICT services. Annex 2 adds seven other sectors: postal and courier services; waste management; the manufacture, distribution and transmission of chemical substances; the production and processing of food; manufacturing in sectors of particular risk (computers and electronics, machinery, vehicles, transport equipment, medical devices, pharmaceutical products); digital service providers (online marketplaces, search engines, social networking services); and scientific research. These sectors are the source of important entities.
The first classification trap hides in the word "activity". The Act does not ask what your primary PKD business code is — it asks whether you actually provide a service in a given sector. A pet food producer formally registered under a PKD code corresponding to food processing, but half of whose revenues come from the distribution of chemical products, falls into two sectors at once, with a classification reaching further from each of them. A municipal company that simultaneously supplies drinking water, collects waste water and handles waste management falls into three sectors, each with a different threshold and a different status.
The second trap — and in our experience the hardest — is derivative status. The Act introduces the concept of a derivative essential entity (one providing business-to-business ICT management services to an essential entity from another sector), and also brings in entities treated as essential regardless of size — including providers of public electronic communications networks, entities designated in European Commission implementing acts, qualified trust service providers, top-level domain name registries, DNS service providers and central government public administration. An external company running the SOC for an electricity transmission operator must enter itself in the register, regardless of its own size. What makes it a derivative essential entity is whose systems it supports, not how many employees it has of its own. That sentence is worth pasting into the first three sentences of the note you write for your board.
The third trap is the public administration sector. Under the Act and the NIS-2 Directive, central government administration is covered as a matter of course, regardless of thresholds. For local government — communes, counties and regions — the question was the subject of long debate during the legislative process. In the end, the amended KSC Act covers local government units, their organisational units and municipal companies, with obligations differentiated according to size and the nature of the services provided. In practice this means that a small commune does not escape the obligation; a communal social welfare centre, a library or a school will — depending on how it is constituted — either inherit the status of its parent authority or register itself as an important entity.
Size thresholds — where micro ends and important begins
For the private sector, the Act applies the EU thresholds corresponding to the SME definition. An essential entity is, as a rule, an undertaking in an Annex 1 sector that employs at least 250 people, or has an annual turnover above EUR 50 million and a balance sheet total above EUR 43 million. An important entity is an undertaking that employs between 50 and 249 people, or has a turnover above EUR 10 million and a balance sheet total above EUR 10 million. Below those thresholds you are, in principle, out of scope — but with significant exceptions: entities designated by the Act as essential regardless of size (telecommunications operators, trust service providers, DNS providers and so on) and derivative entities.
In practice those three sentences conceal three surprises worth preparing for. The first: headcount is calculated on a consolidated basis for the capital group, where the relationships between companies meet the conditions of Commission Recommendation 2003/361/EC. A small subsidiary of a holding company with three hundred employees in the parent may be an essential entity even though it employs twenty people itself. The second: full-time equivalents and temporary workers are counted, with trainees excluded; outsourcing production services does not remove the obligation to count the people actually employed on the supplier's side. The third: in sectors where the Act designates essential status regardless of thresholds, check your category against the statutory list first, and only then against the arithmetic of the thresholds.
For local government, the financial thresholds do not apply. What decides is the nature of the activity and — in the case of subordinate units — membership of the administrative structure.
The wykaz-ksc.gov.pl application — what to write in field two
The self-identification application, operated by the minister responsible for digitisation, went into production on 7 May 2026. Access is via the trusted profile (profil zaufany) or e-ID of a person authorised to represent the entity as recorded in the National Court Register (KRS) or another relevant register. The first application for entry in the register is submitted by a person representing the entity in accordance with the representation rules recorded in the KRS — this is not a form the IT director can complete from their own account. It is a declaration of will by a body of a legal person. In companies with joint representation, this means at least two board members must be involved — which has considerable implications for the management timetable.
The data the application requires falls into four blocks. The first — identification of the entity: name, tax number (NIP), statistical number (REGON), KRS number, address and contact details of the registered office and places of business, and details of the persons representing the entity. The second — sector classification: identification of the sector and sub-sector from the statutory annex, a description of the service provided, and the justification of the classification as an essential or important entity; where the entity is active in several sectors, a separate classification for each. The third — size data: headcount, annual turnover, balance sheet total, status within a capital group. The fourth — operational data: a list of the services provided in the sector, the Member States in which the entity operates, contact details for the person responsible for cybersecurity (the cybersecurity officer or equivalent), and incident reporting channels.
The second block — sector classification — is simultaneously the easiest and the hardest. The easiest, because formally you make your selection from a ready-made list. The hardest, because for every classification the application demands a justification — a free-text field in which you file, under your own signature, a document that every inspector will come back to in a year, in two years or in five. This is where legal analysis begins. This is where your line of defence in any future dispute is settled. And this, in our experience, is where most entities improvise — which can prove expensive.
What not to write in the "justification of classification" field
Over the first two weeks of the application's operation, in conversations with clients who consulted us on the wording of their justifications, we have assembled a catalogue of the most frequently recurring errors. The first — a three-sentence justification along the lines of "the company provides services in sector X, we exceed the thresholds". That is not a justification; it is a one-sentence conclusion. A justification contains: a description of the activity carried on; identification of the specific point of the statutory annex; an explanation of why that point covers your activity (quoting the statutory definition and mapping it onto reality); the threshold calculation with the sources of the data identified (financial statements, periodic social insurance filings, statistical office data); and finally an indication of whether there are grounds on which you should be treated as essential despite not exceeding the thresholds — or, conversely, why you are not essential even though you would formally fit the sector.
The second — omitting corporate relationships. A company operating within a capital group but justifying its classification as though it were independent has a serious problem in the event of an inspection: the competent authority has access to the KRS and to the provider's management documentation, and will add up the group thresholds itself. The third — describing the service in marketing language. "The company is a leader in digital transformation" is wrong even as an opening line; a justification uses the concepts of the Act, not the concepts of a website. The fourth — failing to identify the EU Member States in which the entity operates. For entities providing cross-border services, the competent authority may be the authority of another country, and in some cases registration in more than one Member State is required. The fifth, and most serious — registering as an important entity when you are in fact essential. This error is highly visible in the application's data, because the authority can easily compare your declaration with publicly known revenues. The consequence is often an ex officio decision correcting the entry and — in unfavourable circumstances — an administrative fine for failing to implement essential-entity obligations within the deadline applicable to essential entities, even if for several weeks you lived in the belief that you were merely important.
What happens after registration — the calendar of the first few days
Entry in the register does not end the process; it starts it. Day three after entry activates the obligation to formally appoint a person responsible for cybersecurity (the cybersecurity officer) and to report their contact details to the relevant CSIRT — sectoral or national, depending on your classification. Day fourteen closes the window for the first internal communication measures: informing senior management of the new status, establishing an internal reporting procedure, and putting cybersecurity on the agenda of the next meeting of the management body.
From there, two clocks start running, both of which we discussed in our article on the amendment of the KSC Act. The first — 3 April 2027 — is the deadline for implementing cybersecurity risk management measures (risk analysis, security policy, incident handling, business continuity, supply chain, security in development and maintenance, assessment of the effectiveness of measures, cyber hygiene and training, cryptography, access control and assets, multi-factor authentication). The second — 3 April 2028 — is the point at which administrative penalties apply in full. In practice this means that after entry in the register you have a little under eleven months to build the system — and at best nineteen months of calm before your first real exposure to an administrative fine. "Calm" in inverted commas: the competent authority may carry out inspection activities from the date of entry in the register, and any shortcomings identified may well become the starting point for proceedings that end in decisions issued after April 2028.
The third and less obvious obligation is reporting significant incidents. This one does not wait until April 2027. It runs from the date of entry in the register, as a consequence of the classification you have adopted. The three-stage scheme — an early warning within 24 hours, a full notification within 72 hours and a final report within 30 days — requires an operational readiness that most mid-sized companies do not have. Without so much as a declared CSIRT address and a short email note setting out the three-stage procedure next to the CEO's phone, your first real incident will end with the 24-hour window breached, and with it exposure to a standalone sanction, independent of whether the rest of your ISMS has been built.
What happens if you ignore self-identification
In the short term, nothing. Judging by the ministerial practice we observed during the registration of operators of essential services between 2018 and 2023, the administration acts patiently but consistently. Over the first twelve months of the amendment being in force, the minister will above all be verifying the completeness of the register, drawing on data from the KRS, the statistical office, sectoral regulators (URE, UKE, UTK, UODO) and the opinions of industry bodies. Lists of entities that obviously fall within the Act but have not registered in time are — and will continue to be — compared against the list of entries.
Once the six-month window has closed, the minister for digitisation acquires an express statutory power to issue an administrative decision entering an entity in the register ex officio. The consequences of such a decision are far-reaching. First, the statutory deadlines run as if the entry had been made on time, and what bites hardest here is 3 April 2027, because you are then left not with eleven months to implement the requirements in full, but with however long separates the date of the decision from April 2027 — in extreme cases a matter of weeks. Second, the case file records a failure to comply with the self-identification obligation, which is an aggravating circumstance in setting any administrative fine. Third, information about failing to register on time is available to every inspection and every due diligence auditor; in public tenders, in financing and in negotiations with cyber-risk insurers, it becomes a liability.
The administrative fine for failing to register in the register on time is an autonomous basis for a sanction — it does not require any failure in security measures to be demonstrated. The Act allows the authority to impose an administrative fine of up to EUR 10 million or 2% of annual turnover for an essential entity, and EUR 7 million or 1.4% of turnover for an important entity. Yes: for the absence of a register entry alone.
What to do in the remaining days of May
We set out the sequence of steps we recommend to boards starting work today in six stages, achievable within a three-week horizon that ends around mid-June, leaving a buffer at both ends before 3 October.
Step one — sector classification. A one-page document answering three questions: in which sector (from Annexes 1 and 2) do we operate; do we meet the EU SME thresholds (with group consolidation); and are there grounds on which we are essential regardless of the thresholds. Achievable in three days with a lawyer and the CFO.
Step two — service inventory. A list of all the services you provide within the sector — the input data for block four of the application. For most entities this is two to four hours of work by the operational team.
Step three — the justification. A formal document of five to seven pages, signed by a board member, containing the sector classification, the threshold calculation and the analysis of group relationships. This is the document that will come back in every audit for the next five years. It takes seven to ten working days to write, ideally with the involvement of an external information security officer or a legal adviser experienced in the KSC field.
Step four — appointing the person responsible for cybersecurity. A function that can be performed internally (most often by the information security officer, sometimes the CISO, in smaller entities the data protection officer) or contracted out. For most mid-sized companies and local authorities we recommend a hybrid model — we wrote about this in our article on outsourcing the information security officer role.
Step five — the complete data set for the application. KRS extracts, financial statements, a list of related entities, address and contact details, and trusted profiles for the representing persons. An administrative step, but skipping it can delay your filing by a week.
Step six — filing the application. We recommend signing the application in the first half of September 2026, leaving a three-week buffer before the deadline. Applications filed in the last week of September will pile up, and the application — like every newly launched public service — may slow down.
Meeting this timetable gives you the comfort of reaching April 2027 (full implementation of risk management measures) with your ISMS documentation in order, a cybersecurity officer in post, a completed risk analysis and a trained board. Disregarding it reduces you — at best — to "let's finish this in October" mode, and to exposure to an ex officio entry.
Why Fib.Code for self-identification
NIS-2 self-identification sounds like an administrative formality; in practice it is a strategic board decision whose financial, reputational and operational consequences reach three years ahead. Getting the classification wrong — in either direction — costs you either an unnecessarily built ISMS if you overshoot, or unimplemented obligations and an open road to a fine if you undershoot. The decision has to be legally sound, financially sensible and operationally deliverable — and defended by a justification the competent authority will return to more than once.
The Fib.Code team handles self-identification and entry in the cybersecurity register for entities in the three groups we work with most often: local government (communes, counties, regions and their subordinate units), municipal companies (water and sewerage, district heating, waste management, public transport) and mid-sized businesses in the sectors covered by the annexes to the Act. Our approach follows three principles. First, classification before application. The full expert analysis, closed out in a classification document, is produced before anyone touches a free-text field in the ministerial application. Second, the justification as a defence document. We write every justification so that, in the event of an inspection, the competent authority has nothing to take hold of; every figure is documented and every fragment of a statutory definition is quoted in full. Third, entry is the beginning, not the end. Alongside the application we deliver an implementation timetable running to April 2027 — with a list of tasks, roles and deadlines in which self-identification is the first item, not the only one.
We work in a model in which we can take on the full burden of self-identification, or in a support model in which your teams do the operational work and we provide quality control and the classification document. In both variants the outcome is a complete set of documentation that will stand up to inspection, and a clear allocation of responsibility within the organisation.
What to do this week, before you file
One email. From the board, to the CFO, the legal director and the information security officer (if one has been appointed), with four questions. First: in which sectors from Annexes 1 and 2 do we operate? Second: what are our size figures, on a consolidated capital group basis? Third: are there grounds on which we are essential regardless of the thresholds (for example derivative status, or a sector treated as essential irrespective of size)? Fourth: who in our organisation is doing the self-identification work between now and the end of August?
If the answer to any of those four questions is "I don't know" or "we don't have that", you have just under four months left — and the holiday season starts in the third week of August. It is time to begin.
Get in touch: l.grabowski@fibcode.com | fibcode.com/en/contact. We have written on directly related themes in The 2026 KSC amendment — what you need to know after 3 April, The Cyber Resilience Act — your buggy device will soon disappear from the EU market and Water utilities and NIS-2 — what is specific about the water and sewerage sector — self-identification is the first link in the implementation chain, and all three come back to it.


