DORA for Financial Entities in Poland

Post navigation

Last Updated: 16.06.2026

Digital Operation Resilience Act in Poland Since 2025, financial entities operating in Poland, from banks and payment institutions through investment firms to insurers and crypto-asset service providers, have been subject to a single set of EU rules on digital operational resilience. The DORA Regulation changes how the financial sector manages technology risk, operational risks and its relationships with IT providers, including cloud service providers and other third-party service providers, and since August 2025 the Polish Financial Supervision Authority (KNF) has had the tools to monitor and enforce compliance.

Below we explain what DORA is, exactly who it covers, what obligations it imposes and how supervision works in Poland. For any entity that relies on external IT or cloud providers, now is a good time to check its compliance before the regulator does.


Digital Operational Resilience Act (DORA): Key takeaways

Key information
What is DORA EU Regulation 2022/2554 on the digital operational resilience of the financial sector, directly applicable, with no need to transpose it into national law
Application date Applicable from 17 January 2025 across EU Member States; the Polish implementing act entered into force on 7 August 2025
Scope of application Around 20 categories of financial entities and their critical external ICT service providers
Supervisor in Poland Polish Financial Supervision Authority (KNF)
Five core areas ICT risk management, incident reporting, resilience testing, ICT third-party risk, information sharing on threats
Main compliance risks KNF fines and supervisory measures, reputational risk, challenges to provider contracts
Legal support Recommended for reviewing ICT provider contracts, maintaining the register of information and updating procedures against DORA risk management rules and technical standards

What is DORA and why does digital operational resilience matter?

DORA (the Digital Operational Resilience Act) is Regulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 on digital operational resilience for the financial sector. Its goal is to ensure that financial entities can withstand disruptions and attacks affecting their IT systems, ICT systems and information and communication technology, and still maintain continuity of service.

Before DORA, IT security requirements in finance were scattered across many national acts, financial regulations and supervisory guidelines. DORA brings them together into one consistent set of rules that applies across the entire EU. Digital operational resilience is a broader concept than classic „cybersecurity”. It covers not only protection against attacks (such as ransomware or DDoS), but an organisation’s whole ability to use technology safely, including services from external providers.

As an EU regulation, DORA applies directly and does not need to be rewritten into a Polish statute. The national legislator did, however, have to designate the competent authority and equip it with powers, which we explain below.


Who must comply with DORA in Poland?

DORA covers a very broad catalogue of financial entities, in practice almost the entire regulated market.

It includes, among others:

  • banks (credit institutions),
  • payment institutions and electronic money institutions,
  • investment firms and investment fund management companies,
  • insurance and reinsurance undertakings and insurance intermediaries,
  • crypto-asset service providers (CASPs, under the MiCA Regulation),
  • crowdfunding service providers,
  • credit rating agencies, trade repositories, central counterparties and many others.

Importantly, DORA applies the principle of proportionality. Smaller entities (for example certain small payment institutions) may use a simplified ICT risk management framework. The scale and complexity of the obligations should match the size and risk profile of the organisation.

The principle of proportionality allows smaller entities to adopt simplified ICT risk management frameworks flexibly tailored to their size and lower risk profile. In contrast, large institutions must implement comprehensive frameworks that require rigorous third-party audits and advanced Threat-Led Penetration Testing (TLPT).

A second group covered by DORA is external ICT service providers, including cloud providers. The largest of them, designated as „critical” providers (CTPPs), are subject to direct oversight at EU level, exercised by the European Supervisory Authorities: the European Banking Authority, the European Securities and Markets Authority and the European Insurance and Occupational Pensions Authority.


What obligations does DORA impose?

DORA rests on five pillars. In simple terms:

  1. ICT risk management. The entity must have a coherent framework for managing technology risk: from identifying IT assets, through safeguards, to business continuity and disaster recovery plans. The management body (the board) bears full responsibility for this framework. It cannot be entirely delegated to the IT department or to a provider.
  2. ICT incident reporting. Major incidents must be classified and reported to the supervisor within set deadlines (initial, intermediate and final reports). This calls for procedures and decision-making paths to be prepared in advance. The reporting framework covers ICT-related incidents, and in particular major ICT-related incidents. Financial entities should be able to identify, classify and escalate an ICT-related incident management case quickly, including by assessing the impact on clients, services, data, systems and business continuity.
  3. Digital resilience testing. Regular testing of systems. The largest and most significant entities must additionally carry out advanced penetration testing using the TLPT method (Threat-Led Penetration Testing, tests based on real threat scenarios). This means that digital operational resilience testing and broader operational resilience testing should not be limited to technical vulnerability checks. Proper testing should also verify how the organisation detects, escalates and responds to incidents under various cyber risk scenarios, including realistic cyber risk scenarios involving phishing, ransomware, cloud service failures, data integrity issues or outages affecting critical ICT services.
  4. ICT third-party risk management. This is often the most labour-intensive area. The entity must keep a register of information on all contracts with ICT providers, ensure those contracts contain the provisions required by DORA (including on access, audit and exit from the service) and assess the risk of concentration with a single provider.
  5. Information sharing on threats. DORA encourages entities to share information on cyber threats within trusted communities. Such information sharing arrangements may help financial entities detect emerging threats earlier, compare attack patterns and improve resilience across the market.

The five pillars of DORA encompass ICT risk management, structured incident reporting, regular resilience testing, third-party risk monitoring, and strategic threat intelligence sharing. Together, they establish a comprehensive framework designed to ensure the technical security and operational continuity of financial entities.


How is DORA implemented in Polish law?

Although the regulation applies directly, Poland still had to adopt procedural rules. This was done through the Act of 25 June 2025 amending certain acts in connection with ensuring the digital operational resilience of the financial sector and the issuance of European green bonds. The act entered into force on 7 August 2025.

What this means in practice:

  • the competent authority in Poland is the Polish Financial Supervision Authority (KNF);
  • KNF has a clear legal basis to inspect compliance with DORA (on-site and remotely), issue post-inspection recommendations and apply supervisory measures;
  • KNF may impose fines for failing to comply with DORA;
  • in specific cases KNF may order a financial entity to temporarily suspend the use of a given ICT provider’s service or to terminate the contract with that provider.

Under DORA, the Polish FSA (KNF) wields explicit power to conduct inspections, impose financial fines, and enforce strict supervisory measures—up to ordering the immediate suspension or termination of your critical ICT vendor contracts.

For financial entities, the stage of „preparing on paper” is over. What matters now is the actual implementation of procedures and the ability to demonstrate that they work during an inspection.


Main DORA risks for financial institutions

  • Administrative fines imposed by KNF for compliance gaps.
  • Supervisory measures: from post-inspection recommendations to intervention in relationships with providers.
  • Reputational risk: supervisors may publicly announce decisions on penalties imposed.
  • Weak points in ICT provider contracts. Standard agreements (especially cloud contracts) rarely meet DORA requirements on their own.
  • An incomplete register of information on ICT contracts, which is subject to annual submission to the supervisor.

When to consult a lawyer?

Legal support is particularly useful for:

  • reviewing and renegotiating ICT and cloud provider contracts against the clauses required by DORA,
  • assessing whether and to what extent the organisation can rely on the simplified framework (proportionality),
  • preparing or updating ICT policies, incident reporting procedures and business continuity plans,
  • building and verifying the register of information on ICT providers,
  • preparing the organisation for a KNF inspection.

A practical example: DORA compliance for a Fintech

A foreign fintech (a payment institution within a UK-based group) starts operating in Poland and assumes that its group IT security policies and a global cloud provider contract are fully sufficient. In practice, DORA requires the Polish entity to demonstrate compliance on its own: to keep its own register of information on ICT contracts, to secure access and audit rights in the provider contract in line with DORA, and to implement an incident reporting procedure tailored to KNF’s expectations. Relying solely on group documents, without local review, increases the risk that compliance will be challenged during an inspection.


Need support with DORA?

If your institution is preparing for a KNF inspection or wants to verify whether its ICT provider contracts are compliant, our lawyers can help you assess the risks and prepare compliant documentation. We regularly support UK and US clients entering the Polish financial market, including with ICT compliance and supervisory requirements.

Contact us to discuss the scope of DORA obligations applicable to your organisation and plan the next steps in line with its operating model.


FAQ: DORA for financial institutions in Poland

FAQ: DORA for financial institutions in Poland

Does DORA apply to small payment institutions?

As a rule yes, but thanks to the principle of proportionality smaller entities may use a simplified ICT risk management framework. The scope of obligations depends on the entity’s size and risk profile.

Is it enough to apply group security policies?

Not necessarily. The Polish entity must demonstrate compliance with DORA on its own, including keeping its own register of information, properly drafted contracts with ICT providers and local procedures. Group documents are a good starting point, but usually need to be adapted.

Who in the organisation is responsible for DORA compliance?

The management body (the board) bears full responsibility. That responsibility cannot be entirely transferred to the IT department or to an external provider.

What are the 5 Pillars of the Digital Operational Resilience Act?

The 5 pillars of DORA are ICT risk management, ICT incident reporting, digital operational resilience testing, ICT third-party risk management, and information sharing on cyber threats.

Who needs to comply with DORA?

DORA applies to a wide range of financial entities operating in the EU, including many financial institutions active in Poland. This includes banks, payment institutions, e-money institutions, investment firms, insurers, crypto-asset service providers, crowdfunding service providers and other regulated financial entities. Some ICT third-party service providers, especially critical third-party providers, are also covered by DORA oversight rules.

What is the difference between DORA and GDPR?

DORA focuses on digital operational resilience in the financial sector, while GDPR focuses on the protection of personal data. DORA is about keeping financial services running during ICT disruptions, cyber incidents and provider failures. GDPR is about how organisations collect, use, store and protect personal data. In practice, both regulations may apply at the same time, for example when a cyber incident affects personal data and financial operations.

Expert team leader D&P Legal Piotr Putyra
Contact our expert
Write an inquiry: [email protected]
check full info of team member: Piotr Putyra
Expert team leader D&P Legal
Contact our expert
Write an inquiry: [email protected]
check full info of team member: Piotr Putyra