Self-registration for KSC/NIS2: Why checking your NACE code and submitting a government form isn't enough

Before listing your company in the KSC Registry, find out what you are actually reporting
NIS2 and the amendment to the Act on the National Cybersecurity System (KSC) are introducing a new reality for thousands of organizations in Poland. For many companies, the first real step will be self-identification, which means answering the question: are we an essential or important entity, and do we need to register in the KSC Registry?
Sound formal? In practice, this is not just a form to fill out. It is a decision that requires a thorough understanding of the business operations, systems, suppliers, operational dependencies, and risks. The Ministry of Digital Affairs indicates that entities operating in the sectors covered by the amendment should independently analyze whether they are subject to the regulations, particularly based on Article 5 and Annexes 1 and 2 to the Act.
And this is precisely where the first pitfalls begin.
Self-registration is not the first step. The first step is thorough self-identification
At first glance, the process seems straightforward:
check the sector,
check the PKD (Polish Classification of Activities) code,
check company size,
analyze Article 5 of the Act,
make the decision: we are subject to it or we are not.
In practice, however, each of these answers may require a deeper analysis.
The Ministry points out that self-identification must take into account the business profile, the appropriate PKD code, and the size of the entity. At the same time, it highlights a very important point: PKD codes are auxiliary, and the actual scope of services provided or tasks performed is what truly matters.
This means that simply checking your entry in the National Court Register (KRS) or Central Registration and Information on Business (CEIDG) may not be enough.
Pitfall No. 1: "We have a manufacturing PKD, so we probably have to comply"
Let’s imagine a company that formally has manufacturing PKD codes registered. At first glance, it looks like a classic manufacturing entity: it operates within a capital group, sells technical components, has a warehouse, provides service and customer support, and uses ERP, WMS, and integration systems.
During a professional "gap analysis" (audit zero), however, it turns out that no physical manufacturing takes place locally in Poland. The company buys components from headquarters abroad, and the Polish entity is only responsible for sales, logistics, warehousing, servicing, and customer support.
Does such a company fall under KSC/NIS2 as a manufacturer? Or is its actual business profile different? Do secondary activities matter? Are the systems supporting warehousing, service, and customer support significant?
This perfectly illustrates why PKD codes alone are not enough. Under NIS2, you need to ask not just "what do we have registered in the registry?" but, above all, "what do we actually do, what systems run it, and who could disrupt our service?"
Pitfall No. 2: "We only trade, so NIS2 doesn't apply to us"
The second example works the other way around.
A company declares that it "only trades" or "only supplies IT solutions." It is not a manufacturer, a hospital, a bank, or a critical infrastructure operator.
In practice, however, they supply and maintain WMS, TMS, MES, ERP systems, or a B2B platform for a major manufacturing, logistics, or transport company. They have access to customer data, maintain operationally critical applications, and are responsible for integrations, updates, or business continuity.
In this scenario, the question is no longer just: "are we directly subject to KSC/NIS2?"
A second question arises: "are we a critical supplier in the supply chain of a client who is subject to the regulation?"
Even if the company is not required to register in the KSC Registry, customers may very quickly begin asking about procedures, security measures, incidents, business continuity, data access, and proof of compliance.
What do you actually need to prepare for self-registration?
If an organization determines after analysis that it meets the criteria in Article 5 of the Act, it should apply for entry into the KSC Registry. According to the S46 System guidelines, the deadline is 6 months from the date of meeting the criteria, and the application must be submitted and signed by the head of the entity or an authorized representative.
This is a critical moment: self-registration is not solely an IT task. The application includes a declaration signed by the head of the entity, made under penalty of perjury.
What about the data for the form? It is often scattered across the entire organization.
Before starting the process, you will need, among other things, the entity's identification details, S46 System account administrator details, an active system account, any potential power of attorney, and the S46 space code positive identity if the entity already has one.
The form itself covers:
basic information,
regulated activity registries,
classification of activities,
address details,
contact persons,
public IP addresses and domains,
representative details,
managed service providers (MSPs),
information on information exchange,
attachments,
legal declarations.
This is data that compliance teams often do not have, IT departments might not view as regulatory, and management boards might not even realize they will need to formally verify.
What might surprise you during self-registration?
First: the system may pre-fill some data based on NIP or REGON numbers, but the Ministry emphasizes that you must double-check its accuracy.
Second: if an application or an entity with the same NIP or REGON already exists in the system, the application status may change to "Awaiting Verification." In this case, you must check whether the entity has already been registered officially (ex officio) or if someone else has applied on its behalf.
Third: if a company conducts several types of activities covered by the Act, it does not submit multiple separate applications. Instead, each type of activity must be declared separately in the "Classification" section of a single application.
Fourth: some entities may be added to the registry automatically (ex officio). The Ministry has indicated that by May 6, 2026, this applies to public entities, telecommunications operators, digital service providers, and entities that previously held the status of operators of essential services.
However, registration ex officio does not mean the issue is "settled." This data still needs to be completed, maintained, and verified for accuracy.
Why the Ministry's website is not enough
The materials provided by the Ministry are an excellent starting point. They outline the general path, deadlines, basic criteria, and the logic behind entering the KSC Registry.
But the Ministry's website cannot answer the most challenging, organization-specific questions:
does our actual business operations really fit within the sectors listed in the annexes?
do secondary activities also carry weight?
is our information system dependent on headquarters or affiliates?
are our vendors critical to business continuity?
who holds the data on public IP addresses and domains?
who is formally responsible for KSC contacts?
what evidence of compliance will we present during an audit?
are we operationally ready, or only compliant on paper?
This is why simply reading the guidelines and filling out the form may fall short. First, you need to understand the reality of your own organization.
Audit Zero: the safest first step before registration
A "gap analysis" (audit zero) is not just a report to be archived. It is a practical roadmap of your organization’s current state.
A well-executed audit zero helps answer key questions:
are we subject to KSC/NIS2?
as an essential or important entity, a supply chain partner—or not at all?
which services and processes rely on our information systems?
which IT, OT, ERP, MES, WMS, TMS, or SCADA systems support our operations?
which ICT providers, B2B partners, sole proprietors, or subcontractors are critical to security?
what data must we collect before registration?
what documents, procedures, and evidence do we already have, and what is missing?
are we fully prepared for an audit or official inspection?
Only with this roadmap can you confidently make decisions about registration and prepare your organization for ongoing obligations.
After the audit: why Excel quickly falls short
In many companies, the initial response is to build an Excel spreadsheet: list the systems, list the vendors, list the risks, list the documents, list the actions.
Initially, this works. For a brief moment.
The challenges start when:
data is scattered across several departments,
no one knows who is responsible for updating it,
there is no version history or change tracking,
there is no established workflow,
there are no designated risk owners,
there is no evidence showing when actions were completed,
the number of suppliers continues to grow,
you need to prepare for an imminent audit,
an incident occurs,
the board asks: "are we actually ready?".
NIS2 is not a one-off compliance exercise. It demands a sustained process, clear accountability, auditable evidence, and up-to-date data.
And that is precisely why, during our webinar, we will show you how to transition from an audit zero and scattered files to a systematic compliance management approach.
Webinar: a practical walkthrough
Join us on June 17 at 11:00 AM for our webinar:
NIS2: Are you ready for registration? Suppliers, risks, and the data you need right now—get it sorted before the summer break
During the session, we will show you:
how to approach self-identification step by step,
why PKD codes are simply not enough,
the most common mistakes organizations make,
what an audit zero looks like prior to registration,
what data you must gather for the KSC Registry,
the "surprises" that can arise during self-registration,
why relying on Excel is a bottleneck,
how to organize suppliers, risks, documentation, incidents, and proof of compliance in a single, system-wide workspace.
In the self-identification segment, we will also share a practical tool that supports the initial assessment of your organization's status. We will then walk through real-world scenarios: a company with a manufacturing PKD that has no local production, and a "trading" firm that turns out to be a key systems supplier to a customer in a regulated sector.
In the second half, Red Into Green will demonstrate how to transition from Excel to structured compliance management: managing risks, suppliers, documentation, incidents, corrective actions, and audit-ready evidence.
Who will lead the session?
This webinar is co-hosted by Spiree and Red Into Green.
Our co-speaker is Arkadiusz Reiter—Strategic Governance & Risk Advisor at DAPR and an expert in information security, cybersecurity, personal data protection, risk analysis, and compliance with over 20 years of experience.
Arkadiusz specializes in security and compliance audits, risk analysis, IT vendor and service assessments, business continuity, and implementing frameworks under GDPR, NIS2, DORA, ISO 27001, ISO 27701, and ISO 22301. He is a Lead Auditor for ISO 27001 and ISO 22301, holds a CIPP/E certification, and serves as a Board Member of SABI. At DAPR, he supports organizations in translating complex regulatory demands into practical governance, control, and risk management mechanisms.
Who is this webinar for?
This session is tailored for companies that:
are unsure if they fall under KSC/NIS2,
have manufacturing, technical, logistical, or operational activities,
rely on ERP, MES, WMS, TMS, SCADA, OT systems, or complex IT infrastructure,
act as suppliers to larger organizations or regulated sectors,
need to organize their suppliers, systems, risks, and documentation,
want to prepare for self-registration proactively, avoiding last-minute scrambles.
Key takeaway
It’s not just about getting listed in the KSC Registry.
It’s about understanding whether you truly need to do so, what exactly you are reporting, the data validating it, and whether you can prove compliance down the road.
That’s why taking a step back before registering is invaluable: analyze your true operations, systems, suppliers, and risks.
And then—instead of leaving it all in Excel—build a process that remains sustainable long after the holidays are over.
Register for the webinar and get NIS2 checked off your to-do list before summer.