1. Treat 2026 as an authentication architecture change
KSeF system tokens and certificates can both be used from 1 February 2026, but only certificates remain from 1 January 2027. This is not a conversion exercise, and there is no official post-deadline grace period. A system token contains the permissions declared when generated. A certificate proves identity; it carries neither company context nor KSeF permissions. The login identifies the context, and KSeF checks active permissions there. Use four phases: discover token use and baseline permissions; prepare enrollment, XAdES support and protected key storage; validate both paths in non-production and canary selected production traffic; then switch remaining integrations and remove token secrets after proven stability. Assign an integration owner, KSeF permissions administrator, security owner, operations owner and finance process owner. This makes the authentication change an owned business cutover rather than a credential swap.