Key entity vs important entity – how KSC distinguishes them
Key entity vs important entity under KSC
Under the Polish National Cybersecurity System (KSC) Act, key entities and important entities are two regulatory categories. The practical difference is chiefly the intensity of supervision and the audit regime: a key entity must undergo an audit at least every three years, while an important entity has no fixed three-year cycle but can be ordered to undergo an audit by the authority. Neither label is a business ranking; both can carry substantial cybersecurity duties.
Legal status checked: 27 July 2026. This is informational material, not legal advice. Formal classification should be confirmed with legal counsel, especially where a company operates in several sectors or is near a company-size definition.
The amendment entered into force on 3 April 2026. Entities meeting the conditions on that date have until 3 October 2026 to enter the KSC Register; the general rule is six months from meeting the conditions. For the initial group, obligations and use of S46 are due by 3 April 2027. A key entity that was not previously an operator of essential services (OUK) must complete its first audit by 3 April 2028; existing OUK operators remain on their three-year audit cycle. Penalties apply from 3 April 2028.
Contents
- Short answer
- How classification works
- Shared and different obligations
- Sector, annexes and company size
- Article 5 exceptions
- Illustrative scenarios
- Audit, manager and dates
- FAQ
Short answer
| Area | Key entity | Important entity |
|---|---|---|
| Typical statutory basis | Annex 1 plus statutory criteria | Annex 2 plus statutory criteria |
| Register entry | Required when conditions are met | Required when conditions are met |
| ISMS, risk and serious incidents | Required | Required |
| Recurring audit | At least once every 3 years | No fixed cycle; authority may order an audit |
| Initial audit for the new group | By 3 Apr 2028 if not previously OUK | Not governed by a fixed audit date |
Both categories need a working information security management system (ISMS), risk management, incident handling, documentation and use of the S46 System after register entry. Read Does your company fall under KSC? for a qualification method and the KSC overview for the wider framework.
How classification works
Classification begins with the activity actually performed, not with a convenient label. The Act uses sectors and services in its annexes together with statutory company-size criteria and exceptions. A company can be treated differently when its principal activity falls under Annex 1 rather than Annex 2, and company size is assessed under the EU enterprise rules rather than by a simple payroll count.
This is why “we have more than 50 employees” is not a sufficient conclusion. The analysis needs the legal entity, services delivered, sector, employment and financial data, the relationships with partner and linked enterprises, and any relevant exception. Document the conclusion and the underlying facts; a short internal memo is more useful than an undocumented assumption.
Shared and different obligations
Key and important entities share many core obligations: entry in the KSC Register, use of S46 as required, an ISMS, risk analysis, asset and service inventory, supply-chain security, serious-incident management and operational evidence. The organisation also needs an accountable security function and documented processes that work in practice, not merely policies stored in a folder.
The key distinction is ongoing audit. A key entity must complete an audit at least every three years. An important entity should still retain evidence and be ready for scrutiny, because the authority can order an audit in the situations set out by law. Outsourcing technical work does not remove the regulated entity’s responsibility for its own system and reporting process.
Sector and size
Annex 1 typically covers sectors of the highest criticality, including areas such as energy, transport, banking, financial-market infrastructure, health, water, digital infrastructure and space. Annex 2 covers a wider set of activities, including certain manufacturing, food, postal and courier services, and research. The exact statutory wording and the entity’s actual service are decisive.
Company size uses the EU concept of an enterprise. It considers employment, turnover and balance-sheet totals and may require data from partner and linked enterprises. A company outside the annexes is not automatically covered because of its employee count; conversely, a smaller local company may not be safely excluded merely because its standalone headcount is low. Where a group prepares consolidated accounts, group information may matter.
Article 5
Article 5 contains statutory exceptions and special cases. They are narrow and fact-specific, so they should not be treated as a generic exemption strategy. If a company believes an exception applies, document the services, sector, customers and scale that support the assessment, then seek legal confirmation where the conclusion has material consequences.
Illustrative scenarios
These examples explain the method; they are not legal classifications. A medium enterprise operating a regional pharmacy network and patient-facing systems may need to assess Annex 1 health activity and the key-entity criteria. A manufacturer of machine components in an Annex 2 activity may be an important entity if the statutory conditions are met. A software company with 120 employees does not become covered merely because of headcount: its actual service, role and applicable sector criteria still need analysis.
Audit and dates
The accountable manager remains responsible even when work is delegated to IT, a SOC or an external provider. The manager’s annual training must be documented, and Article 8f personnel requirements apply subject to statutory exceptions. For an initial qualifying entity, plan the register deadline, S46 implementation, ISMS evidence and—where relevant—the first audit as one coordinated programme rather than separate projects.
FAQ
Can an important entity later become a key entity?
Yes. A change in activity, sector or applicable size conditions may change classification. The general register rule is six months from meeting new conditions.
Does an important entity report serious incidents?
Yes. The serious-incident definition is shared. The reporting rhythm includes a 24-hour early warning, 72-hour notification and a final report generally within one month, subject to statutory exceptions and the status of handling.
Does SIEM establish KSC compliance?
No. SIEM can support monitoring and evidence, but it does not replace risk management, continuity, supplier arrangements, training, procedures or documentation.
DevSentinel supports practical implementation and preparation, but does not guarantee compliance, certification or an authority’s decision.