Poland makes token authentication permanent in KSeF 2.0
Poland's Ministry of Finance removed the end date for token authentication in KSeF 2.0. Tokens stay as a permanent method. Integrations for businesses with Polish VAT liability or a Polish establishment can now plan for a lasting setup.
Poland’s Ministry of Finance published updated KSeF 2.0 manuals on 6 August 2026. It removed the earlier end date of 31 December 2026 for token authentication. Tokens now remain a permanent authentication method. The KSeF mandate covers any organisation with Polish VAT liability or a fixed establishment in Poland, wherever it is incorporated.
Poland’s Ministry of Finance removed the end date for token authentication in KSeF 2.0 on 6 August 2026. Tokens are now a permanent authentication method, not a temporary one. The ministry published four updated manuals. They cover starting to use KSeF, issuing and receiving invoices, additional functionality, and permission models for VAT groups and local government units.
Token authentication was originally planned to end on 31 December 2026. Many integrations had treated it as short-lived and planned to migrate away from it. With the deadline gone, organisations can settle on a lasting token-based setup instead of a temporary one.
Who must comply and when
The mandate is phased by turnover threshold:
- 1 February 2026: Taxable persons with more than PLN 200 million (roughly €46 million) in annual turnover
- 1 April 2026: All other taxable persons
- 1 January 2027: The smallest taxable persons
The mandatory format is FA(3), a structured XML schema.
Scope is determined by Polish VAT liability and fixed establishment in Poland, not by where a company is incorporated. A foreign company with no Polish VAT registration or establishment is not in scope for the B2B mandate, even if it supplies Polish customers. A company that holds Polish VAT liability or operates a fixed establishment in Poland is in scope, regardless of where its head office sits.
How KSeF differs from Peppol
KSeF operates as a clearance model. Invoices pass through a central government platform and are registered there before they become legally valid. Peppol uses a four-corner model. Two Access Points exchange documents between sender and receiver without government involvement.
Because of this difference, Peppol cannot be used for mandatory B2B submission to KSeF. For B2G invoicing, organisations may choose from 1 February 2026 between PEF and KSeF. PEF is the Polish platform that runs on Peppol. An organisation that supplies both Polish public bodies and Polish companies therefore needs to manage two separate routes.
What to do now
Steps for businesses with Polish VAT liability or a fixed establishment:
- Establish scope by testing against Polish VAT liability and fixed establishment, not incorporation location
- Determine the phase: 1 February 2026, 1 April 2026, or 1 January 2027
- Arrange authentication and record who holds which permission
- Set up offline mode with an offline certificate as a fallback
- Assign ownership of the correction process, which follows its own procedure in Poland
- Separate the B2G flow from the B2B flow and choose between PEF and KSeF for public sector invoices
For integrators and Peppol service providers:
- Build the
FA(3)mapping from the existing EN 16931 model - Handle certificate and token authentication side by side, with an explicit choice per customer and environment
- Build offline mode, including later submission and QR codes on offline invoices
- Test delegation of permissions and self-billing separately
- Document for customers that Polish B2B traffic does not run over Peppol
The mandate does not apply directly to businesses trading with Poland without Polish VAT liability or establishment. A Polish supplier in scope must still register the invoice in KSeF. The foreign buyer then receives it outside KSeF. This is typically a visualisation with a QR code and the KSeF identification number. Suppliers to Polish customers should check whether the customer is in scope and agree on a delivery method. Accounting and procurement systems should be able to process and archive a QR code and a KSeF identification number.
The broader European picture
Poland is not an outlier. The Netherlands is building its B2B mandate on Peppol towards 2030. Belgium, France and other member states have each chosen their own route. ViDA makes structured e-invoicing mandatory for cross-border EU transactions from 1 July 2030. A business active in several EU countries must support a different system, format and deadline in each one.