How to check if your company falls under the KSC Act
Your company may fall under Poland’s National Cybersecurity System (KSC) Act when it operates in a sector or service listed in Annex 1 or Annex 2, meets the statutory company-size conditions where they apply, and no Article 5 exception applies. Employee headcount alone does not decide the result.
Legal status checked: 27 July 2026. This article is informational and does not replace legal advice. A borderline classification should be reviewed with counsel who understands the relevant sector.
The amendment has applied since 3 April 2026. For entities that met the criteria on that date, entry in the KSC Register is due by 3 October 2026. In other cases, the general deadline is six months after the criteria are met. S46 self-registration has been available since 7 May 2026, and the initial group has until 3 April 2027 to implement the obligations.
Contents
- Nine assessment steps
- Data checklist
- Annexes and actual activity
- Company size without the “50 employees” myth
- Article 5 exceptions
- What to do after assessment
- FAQ
Nine assessment steps
- Identify the legal entity. Establish whether the potential applicant is a company, branch or public-sector body. In a group, identify the relationships relevant to company-size assessment.
- Map actual activity. PKD codes are a useful starting point but do not decide the issue. Describe services actually delivered, customers and the operational role of each entity.
- Check Annex 1. Compare the activity with the sectors and services used for key-entity assessment.
- Check Annex 2. If Annex 1 does not fit, examine the broader group of activities that can lead to important-entity status.
- Assess enterprise size. Collect employment in FTE, annual turnover and balance-sheet totals for the relevant periods, including partner and linked enterprises where required.
- Analyse Article 5. Record whether a statutory exception or special case is potentially relevant. Do not assume an exception from a marketing description of the service.
- Review dependencies. Map material suppliers, customers and services so that the actual role is understood; a contract title is not a classification.
- Document the result. Write down the input data, annex interpretation, conclusion, unresolved questions and responsible approver.
- Set the action plan. If in scope, plan register entry, the accountable security role, S46 and ISMS implementation. If not in scope, set a trigger for reassessment after growth, acquisition or a service change.
Data checklist
Collect the entity’s registration data, group structure, current service descriptions, customers and sector relevance. Finance and HR should provide FTE, turnover and balance-sheet data for the relevant periods. IT and procurement should identify hosting, cloud, outsourced operations and critical suppliers. Legal and product owners should help assess exceptions and the date on which statutory conditions may have been met. Without this evidence, a conclusion can be impossible to defend later.
Annexes and actual activity
Annex 1 covers high-criticality areas such as energy, transport, banking, financial-market infrastructure, health, water, digital infrastructure and space, according to the statutory definitions. Annex 2 covers a broader group, including specified chemical, food, medical-device, electronic, machinery and vehicle manufacturing, postal and courier services, and research. Check the current Act rather than relying on a simplified sector list.
The relevant question is what the entity truly provides. A PKD entry may be outdated or broad, while the real service can be materially different. Separate entities in one group can have different activities and status even when shared IT services support them all.
Company size
The Act refers to the EU enterprise concept, which combines employee count, turnover and balance-sheet totals. It is therefore inaccurate to treat “50 employees” as an automatic KSC threshold. A company with 200 employees outside the annexes is not covered merely for that reason. Equally, a company with a smaller local payroll can require a wider assessment if it belongs to a group or performs an Annex activity.
Use reliable financial and organisational data, and record the period used. If consolidated reporting or partner-enterprise relationships affect the result, get the relevant figures before deciding that the entity is out of scope.
Article 5 exceptions
Article 5 contains exceptions and special cases. They are not a substitute for classification and should be interpreted against actual facts. If an exception appears relevant, retain the supporting analysis and arrange legal review where needed. A change in service model, customer base or sector can invalidate an earlier conclusion.
Next steps
If the entity is in scope, arrange entry in the register—see KSC register entry and S46—and establish the accountable role, risk assessment, ISMS and serious-incident process. The 24-hour early warning, 72-hour notification and final report generally within one month need a tested operating procedure, not a last-minute form.
If it is not in scope, retain the assessment and decide when to repeat it. Growth, a merger, a new sector service or changed group data are sensible triggers. Compare the categories in key entity vs important entity.
FAQ
Does every company with 50 or more employees fall under KSC?
No. Sector, actual activity, enterprise size under the EU criteria and statutory exceptions all matter.
Who should conduct the assessment?
It normally requires legal, finance, IT or operations and management input. DevSentinel can support the technical work, but it does not replace legal classification or guarantee compliance.
Does outsourced IT remove the obligation?
No. Outsourcing may change the control and supplier-management work, but it does not remove the regulated entity’s responsibilities.