Free online invoicing software
with KSeF support
A KSeF (National e-Invoicing System) certificate is a digital seal: a special file that will be used to authenticate a company in the e-invoicing system from 1 February 2026. Its purpose is to identify the company so that nobody can impersonate it, and to enable invoices to be issued offline. Until the end of 2026, businesses will be able to choose whether to authenticate in KSeF using the tokens used so far or whether they are ready to implement certificates. This article explains what a KSeF certificate is for and how to obtain it.
What is a KSeF certificate?
After 1 February 2026, a KSeF certificate will be one method of authentication in the National e-Invoicing System, alongside tokens, whose fate has nevertheless been decided. It will be required to mark an invoice with a code allowing the issuer's identity to be confirmed when issuing invoices in special modes: offline24, offline (system unavailability), and emergency mode.
Certificates work similarly to a qualified signature or electronic seal: they allow unambiguous verification of who issued an invoice or logged into the system.
The Ministry of Finance has distinguished two basic types of KSeF certificates.
- The first type is used for authentication in KSeF by people working in KSeF systems and accessing it through the National e-Invoicing System.
- The second type is used to issue invoices offline when a connection to the system is impossible because of a lack of internet access or a system outage.
When an invoice needs to be issued offline, regardless of the reason, the certificate will allow it to be marked with a special QR code or a link confirming the issuer's identity.
What is a KSeF certificate used for?
- KSeF certificates will be used for authentication in the system. They will be a key element of Poland's e-invoicing system.
- The certificate system aims to standardise user identification and enable fully automated login without having to use a qualified signature every time.
- A correctly issued certificate will confirm the company's identity and make impersonation more difficult.
- Certificates will allow invoicing even during a KSeF outage or without an internet connection.
- All of this is intended to improve the security, stability and continuity of invoicing.
How can you obtain a KSeF certificate?
KSeF certificates are generated online through the Certificates and Permissions Module (MCU).
- First, the user must log into MCU using a chosen authorisation method: a trusted profile, a qualified certificate with a NIP or PESEL number, or a qualified certificate without these details.
- The user then specifies the taxpayer identifier (NIP, EU VAT number or internal identifier).
- After authentication, the user applies for a certificate using a special form, specifying, among other things:
- the certificate type (signing the issuer verification link or authentication in KSeF),
- its custom name,
- the validity start date (if none is selected, validity will run from the date of issue).
- Once the application is approved, the user will be able to download the certificate. It should be kept in a secure place.
Each time they log into MCU, users can:
- manage system users' permissions,
- apply for certificates,
- download issued certificates.
Accounting that understands your business
Leave your email address and receive guides supporting your business’s growth once a week
Timetable of changes
Changes to authentication in KSeF will not take effect overnight: the whole process will take a year and a half. The following key milestones can be identified:
- From 1 November 2025, businesses and authorised individuals can apply for certificates in the Certificates and Permissions Module (MCU).
- From November 2025 until the end of January 2026, all certificates will be issued exclusively through MCU.
- On 1 February 2026, the new system version, KSeF 2.0, will launch. From that day, logging in using type 1 certificates and issuing offline invoices using type 2 certificates will be possible.
- Throughout 2026, businesses will be able to authenticate using tokens or KSeF certificates, according to their preferences (discussed further later in this article).
- 31 December 2026 is the last day of validity for tokens.
- From 1 January 2027, KSeF certificates will become the only method of authentication in KSeF.
Although KSeF launches on 1 February 2026, the Ministry of Finance has provided earlier access to MCU so businesses can plan how to grant and manage permissions in KSeF 2.0. They can use this time to:
- adapt their procedures and IT systems;
- make sure everything works in compliance with regulations;
- increase security and control over access to data and documents.
Security of KSeF certificates
KSeF certificates contain personal or company data. To prevent unauthorised access by others, make sure that:
- a certificate containing an individual's personal data is used only by that individual;
- certificates assigned to companies (for example, corporate entities) are not linked to specific employees.
Companies should have clear rules for downloading, transferring, using and revoking certificates.
Limits on certificates issued
One method of improving KSeF certificate security during authentication is to limit the number of active and new certificates one user or entity can hold. The number depends on the user's organisational form and is:
- a maximum of two active and two new certificates for an individual with a PESEL identifier,
- up to one hundred active and one hundred new certificates for an individual with a NIP number,
- up to one hundred active and one hundred new certificates for an entity other than an individual,
- a maximum of two active and two new certificates for an entity authenticating with a so-called fingerprint.
The Ministry of Finance has also introduced a limit on certificate issuance requests within a 30-day period. The limits are:
- six for a PESEL identifier,
- three hundred for a NIP identifier,
- six for authentication based on a so-called fingerprint.
Tokens versus KSeF certificates
Companies currently using KSeF can authenticate with tokens: unique access keys assigned to a user. A token contains assigned permissions and has no limited validity period. After 1 January 2026, when KSeF 2.0 is implemented, a KSeF certificate will also perform this role.
Until 1 January 2027, tokens and KSeF certificates will operate in parallel, but after that date tokens will be disabled and certificates will become the only authentication method.
Businesses should use the 12-month transition period to adopt the new KSeF authentication method.
From 1 February 2026, both methods will operate in parallel, enabling businesses to move smoothly to the new solution. The transition period will last until the end of the year, and from 1 January 2027 certificates will become the only applicable method of authentication in KSeF.
If you have questions about KSeF certificates or the operation of the National e-Invoicing System itself, seek support from the experienced accounting firm TaxCoach. We provide effective accounting for sole proprietorships, companies and foundations. Contact our adviser!
Interested in this article? Explore our accounting services and see how we can help:
Summary
FAQ
What if a business does not obtain a KSeF certificate?
Businesses without a certificate will still be able to log into KSeF through the Taxpayer Application using a trusted profile or qualified signature. However, the absence of a certificate will prevent integration of the accounting system with the Ministry of Finance's KSeF platform (through API 2.0) and prevent offline invoicing.
Do KSeF certificates invalidate tokens?
Companies currently using KSeF can authenticate using tokens: unique access keys assigned to a user. Tokens and KSeF certificates will operate in parallel until the end of 2026, but after that date tokens will be disabled and certificates will become the only authentication method.
How can a company obtain a KSeF certificate?
An application for a certificate is submitted through the Certificates and Permissions Module using a qualified electronic signature or qualified electronic seal. For security reasons, the authentication process includes a limit on the number of active and new certificates that one user or entity can hold.
Interested in this article?
Enter your email address and once a week you will receive practical materials and tips to help you grow your business.
Book a free consultation
Grow your business with accounting combined with advisory services:
or