Mandatory KSeF is now in force for all active VAT taxpayers in Poland, yet many businesses still have not generated their KSeF certificate. This is a mistake that can backfire — without a certificate you cannot issue invoices in offline24 or emergency mode, and from 1 January 2027 certificates will completely replace the current authorisation tokens. Here is what the KSeF certificate is and how to obtain one.

What is a KSeF certificate?

A KSeF certificate is an electronic proof of identity issued free of charge by the KSeF 2.0 system. It works much like a qualified certificate — it contains the data of the individual or entity it was issued for and serves to confirm identity in the system. A certificate is valid for a maximum of 2 years from its creation date (or from a specified start date), after which a new one must be generated.

Two types of certificates

The Ministry of Finance provides two kinds of certificates, generated separately:

  • Authentication certificate (type 1) — used to log in to KSeF in interactive and batch sessions. After login, the system applies the permissions linked to the NIP or PESEL number stored in the certificate.
  • Offline certificate (type 2) — required to mark invoices with the second QR code (labelled "CERTYFIKAT"), which confirms the issuer's identity for invoices issued in special modes: offline24, offline (system unavailability) and emergency mode.

Why does the certificate matter so much?

An invoice issued in offline24 mode must carry two QR codes: the first provides access to the invoice in KSeF, and the second — generated using the certificate — confirms the issuer's identity. Without a certificate, issuing invoices outside the system (for example during a KSeF outage or without internet access) is impossible.

Moreover, from 1 January 2027 authorisation tokens will stop working — certificates will remain the only method of automated authentication (e.g. integrating accounting software with KSeF). Note that tokens and certificates are not equivalent: a token carried permissions within it, while a certificate is purely a means of authentication — permissions must be granted separately.

How to generate a KSeF certificate — step by step

  1. Log in to the KSeF 2.0 Taxpayer Application — as the taxpayer or an authorised person, using a trusted signature (Trusted Profile), a qualified electronic signature or a qualified seal. Applications can also be submitted via the KSeF 2.0 API (for system integrations).
  2. Select the working context — the NIP number of the entity you are acting for.
  3. Go to the certificates module and submit an application — provide the personal or entity data matching the authentication data and choose the certificate type (authentication or offline).
  4. Download the certificate — once the application is processed, the certificate is ready to download, usually within minutes.

Security first

The certificate allows acting in KSeF on behalf of your company, so the private key and password should be treated like online banking credentials — stored separately and never shared. If compromised, a certificate can be revoked and a new one generated.

Do not wait until year end

The KSeF transition period ends on 31 December 2026. It is worth generating both certificates now, testing offline24 mode and reviewing permissions in the system. If you need support implementing KSeF in your business, contact LinTax — we will guide you through the entire process.