January 17, 2025 was the application date for the Digital Operational Resilience Act (DORA). Many financial entities operating in Poland assumed the regulation applied only to large banks. That assumption is wrong – and the consequences of non-compliance are irreversible once a supervisory inspection begins.

DORA (Regulation EU 2022/2554) applies directly in all EU member states, including Poland, without requiring national implementing legislation. The regulation covers a broad range of financial entities – from credit institutions and investment firms to crypto-asset service providers and insurance undertakings. Entities that fail to meet ICT risk management, incident reporting, and third-party oversight requirements face supervisory sanctions and, in some cases, personal liability of management board members.

This alert explains which entities must comply, what the key obligations are, and what immediate steps your organisation should take. The Polish Financial Supervision Authority (Komisja Nadzoru Finansowego, KNF) has already signalled that DORA compliance will be a supervisory priority throughout 2025 and 2026.

Which entities does DORA cover in Poland?

DORA applies to a wide range of financial sector participants. The regulation identifies over 20 categories of obligated entities. In the Polish market, the most affected groups include credit institutions supervised by the National Bank of Poland (Narodowy Bank Polski, NBP), investment firms registered with the National Court Register (Krajowy Rejestr Sądowy, KRS), payment institutions, electronic money institutions, and insurance undertakings. Crypto-asset service providers authorised under MiCA are also in scope from day one.

A proportionality principle applies – but it does not exempt smaller entities. Microenterprises (fewer than 10 employees, annual turnover below EUR 2 million) benefit from simplified requirements under certain provisions. However, they remain subject to core ICT risk management obligations. Assuming your firm is "too small to matter" is precisely the reasoning that forfeits the opportunity to build a compliant framework before supervisory scrutiny arrives.

Third-party ICT providers serving financial entities are also directly affected. Critical ICT third-party providers (CTPPs) designated by the European Supervisory Authorities face direct oversight, including mandatory audits and information requests. If your firm provides cloud services, data analytics, or software to regulated financial entities, DORA's reach extends to your contracts and operational practices.

  • Credit institutions and investment firms
  • Payment and electronic money institutions
  • Insurance and reinsurance undertakings
  • Crypto-asset service providers (MiCA-authorised)
  • ICT third-party providers designated as critical

What are the core DORA obligations and deadlines?

DORA structures its requirements across five pillars. Each pillar carries specific documentation, testing, and reporting obligations. The application date of January 17, 2025 means all obligations were enforceable from that date – there is no transitional grace period for entities already in scope. Delay precludes the ability to demonstrate a compliant track record, which supervisors will examine retroactively.

The ICT risk management framework is the foundation. Entities must maintain a documented framework covering identification, protection, detection, response, and recovery. The framework must be reviewed at least once a year. For entities subject to the simplified regime, a lighter version applies – but written documentation is still mandatory. We assisted a fintech client in Mazowieckie (spring 2025) in building its ICT risk register from scratch within six weeks, avoiding a KNF inquiry that was already scheduled.

Major ICT-related incident reporting is time-critical. Initial notifications to the KNF must be submitted within 4 hours of classifying an incident as major. An intermediate report follows within 72 hours. A final report is due within one month. Missing these windows triggers automatic non-compliance findings. Entities should map these timelines to their internal escalation procedures now – not after an incident occurs.

Digital operational resilience testing is required for all in-scope entities. Basic testing (vulnerability assessments, network security tests) applies broadly. Threat-led penetration testing (TLPT) is mandatory for significant entities, with a minimum cycle of once every 3 years. Firms that have not yet conducted a baseline assessment are already behind schedule. For cross-border technology structures, the IP and technology practice covering US-Poland structures addresses how DORA intersects with contractual frameworks governed by non-EU law.

Third-party risk management requires written contracts with all ICT providers. Contracts must include specific clauses covering audit rights, data location, business continuity, and exit strategies. Existing contracts must be reviewed and, where necessary, renegotiated. This is not optional – supervisors will request contract inventories during inspections.

What should your organisation do immediately?

The window for proactive compliance is narrowing. KNF has publicly committed to DORA-focused supervisory reviews. Entities that cannot demonstrate a functioning ICT risk management framework risk sanctions including fines and – for management board members – personal liability for organisational failures. The irreversible consequence is a formal supervisory finding that becomes part of your regulatory record.

Start with a gap analysis. Map your current ICT governance against DORA's five pillars. Identify missing documentation, untested processes, and contracts lacking mandatory clauses. This analysis should take no more than four weeks for a mid-sized entity. Our team obtained a clean supervisory outcome for a payment institution client in Lower Silesia (autumn 2024) by completing a structured gap analysis and remediation plan before the KNF review commenced.

The AI Act's risk classification framework intersects with DORA where AI systems are embedded in ICT infrastructure. Entities deploying AI in trading, credit scoring, or fraud detection should review both regimes simultaneously. The AI Act high-risk classification analysis provides a starting framework for that assessment. For entities with complex corporate structures, the corporate and M&A practice page outlines how group-level DORA obligations interact with Polish corporate governance requirements.

Immediate action checklist:

  • Confirm whether your entity falls within DORA's scope (including simplified regime eligibility)
  • Conduct an ICT risk management gap analysis within 4 weeks
  • Review all ICT third-party contracts for mandatory DORA clauses
  • Establish a major incident classification and reporting procedure (4-hour initial notification)
  • Schedule baseline resilience testing if not yet completed

Compliance with DORA, GDPR Poland obligations, and the AI Act Poland framework increasingly overlap. Firms that treat these as separate workstreams waste resources and create gaps. A unified compliance review – covering IP lawyer Warsaw-level contractual protections, trademark registrations for digital assets, and ICT governance – is more efficient and more defensible before supervisors.

Your specific situation requires a tailored assessment. Waiting for a supervisory inquiry to arrive forfeits the ability to demonstrate proactive compliance – a factor that directly affects the severity of any sanctions imposed.

If your entity is in scope under DORA and has not yet completed a gap analysis, contact info@kordeckipartners.com. We will review your ICT governance framework, identify contractual gaps, and prepare a remediation roadmap within agreed timelines.

Frequently asked questions

Q: Does DORA apply to Polish fintech startups that are not yet supervised by the KNF?

A: DORA applies to entities that fall within its defined categories, regardless of size or supervisory status at the time of application. If your startup holds a payment institution licence, an electronic money institution authorisation, or a MiCA crypto-asset service provider registration, it is in scope. The simplified regime reduces the burden for microenterprises, but does not eliminate it. Entities awaiting authorisation should build DORA compliance into their licence application documentation from the outset.

Q: How long does a DORA gap analysis typically take, and what does it cost?

A: For a mid-sized financial entity with 50 to 200 employees, a structured gap analysis covering all five DORA pillars typically takes three to six weeks. Cost depends on the complexity of the ICT environment and the number of third-party providers involved. Entities with a single core banking system and fewer than ten ICT providers can expect a more streamlined process. The cost of remediation after a supervisory finding is invariably higher than the cost of proactive analysis.

Q: Is it a misconception that DORA only applies to banks?

A: Yes – this is the most common misunderstanding we encounter. DORA covers investment firms, insurance undertakings, payment institutions, crypto-asset service providers, crowdfunding platforms, and data reporting service providers, among others. The regulation also reaches ICT third-party providers that are designated as critical by the European Supervisory Authorities. Any entity operating in the financial sector should verify its status rather than assume it falls outside the regulation's scope.

KORDECKI & Partners is a law firm based in Warsaw and Krakow, advising business clients across 30 jurisdictions. Our team combines expertise in Polish and international law with a practical approach to technology regulation, DORA compliance, and digital operational resilience. We work with Polish entrepreneurs, foreign investors, and in-house legal teams. To discuss your situation, contact info@kordeckipartners.com.

Disclaimer: This publication is provided for informational purposes only and does not constitute legal advice. The information herein should not be relied upon as a substitute for professional legal counsel tailored to your specific circumstances. KORDECKI & Partners assumes no liability for actions taken or not taken based on the contents of this material. For advice regarding your particular situation, please contact info@kordeckipartners.com.