KSC register entry and S46 system – step by step
KSC register entry and S46 — step by step
Entry in the KSC Register is the formal step for an entity that has confirmed it is covered by the Polish National Cybersecurity System Act. It opens access to the S46 System (Cyber Hub) and connects the entity to incident-reporting and communication duties. Do not treat registration as proof that the wider implementation is complete: the ISMS, risk, supplier and incident obligations still need to operate.
Legal status checked: 27 July 2026. This is informational material, not legal advice. The system operator can update form and technical requirements, so verify current instructions on the official pages before submitting.
Key dates are: amendment in force 3 April 2026; entry by 3 October 2026 for entities meeting conditions on that date; otherwise six months after qualifying; S46 self-registration available from 7 May 2026; and implementation of obligations and S46 use by 3 April 2027 for the initial group.
Contents
- Who applies and when
- Data and documents
- S46 self-registration
- Application workflow
- Authority and roles
- After entry
- Common errors
- FAQ
Who applies and when
The qualifying legal entity applies as a key or important entity. The person who submits must have authority to act for the entity, whether as a board member, authorised employee or valid attorney. Establish classification before opening the application: see Does your company fall under KSC?. An inaccurate category or an unsupported assumption about scope creates avoidable administrative risk.
For the initial group, the register deadline is 3 October 2026. The general rule is six months from meeting the qualifying conditions. Keep the analysis that establishes the date, especially where a new service, acquisition or group change is relevant.
Data and documents
Prepare entity registration details, legal form and address; a concise description of the activity and applicable sector; the provisional category and internal justification; contact details for the accountable information-security function and the incident-response route; and, where required, a power of attorney. Also prepare an initial map of systems and services that will feed the risk assessment and ISMS work.
The accountable security manager role needs careful preparation. The Act includes personnel requirements under Article 8f, subject to statutory exceptions, and requires documented annual training. Do not list a nominal contact who cannot take part in escalations or obtain operational information.
Self-registration and application workflow
Self-registration in S46 has been available since 7 May 2026. Follow the official S46 register-entry guidance for current technical steps. A practical sequence is:
- Access S46 with the appropriate entity-administrator authority.
- Complete the entity profile and verify registration data.
- Record the sector, category and service scope using the evidence from the classification.
- Identify the accountable security function and incident contacts.
- Attach authority documents or other items requested by the system.
- Submit the application for entry and retain its reference and submitted data.
- Monitor the status and respond to requests for clarification within the stated time.
- After entry, confirm that authorised people can access the required S46 functions.
Use identifiable individual accounts rather than a shared login. This supports accountability and makes it possible to trace who submitted or amended information.
Authority and roles
If an IT employee or external adviser submits, the power of attorney or authorisation should explicitly cover submission, representation in S46 and receipt of correspondence where appropriate. Internally, separate the responsibilities for formal representation, security management, 24/7 incident escalation, technical investigation, legal review and executive decisions. Delegating a task does not move the regulated entity’s accountability away from its manager.
After entry
Entry is the beginning of the operational programme. For the initial group, implement the obligations by 3 April 2027: ISMS, risk management, asset and service inventory, supplier security, continuity and incident procedures. Build the serious-incident path around an early warning within 24 hours, notification within 72 hours and a final report generally within one month. See serious incident reporting for the operating sequence.
A key entity also plans its recurring audit; a new key entity that was not previously OUK has its first audit due by 3 April 2028. An important entity does not have the same fixed audit cycle, but should maintain evidence because the authority may order an audit.
Common errors
Common failures include waiting to register until the entire ISMS is complete, assuming entry equals compliance, recording the wrong category, leaving no workable 24-hour contact, using a vague authorisation, and failing to keep S46 information aligned with real roles. Test contacts and escalation before an incident. A tabletop exercise cannot replace the statutory process, but it can show whether the organisation could submit a timely, accurate report.
FAQ
Can an external provider submit for us?
It can support the process with valid authority, but the entity remains responsible and an authorised representative should retain control of the submission.
Does one application cover a group?
Each qualifying legal entity normally needs its own assessment and entry unless the Act provides otherwise for a specific form. Group data can still matter when assessing size.
Does DevSentinel submit the application?
DevSentinel can help prepare technical materials, processes and ISMS work. The application is submitted by the entity’s authorised representative. DevSentinel does not guarantee compliance.