Abstract gold shield of network nodes over a dark navy background representing Polish financial-sector cybersecurity compliance

DORA Covers PKO BP, Pekao, and mBank — But KNF Still Requires This NIS2 Registration Step Before October 2026

Poland’s amended cybersecurity law, the ustawa o krajowym systemie cyberbezpieczeństwa (KSC), entered into force on 3 April 2026. For most of the 42,000-odd entities it touches, that meant a new set of NIS2-style obligations. For banks, it meant something narrower and more confusing: a statutory carve-out — Article 8i — that hands most of the technical rulebook to DORA, while quietly keeping a handful of KSC obligations in force underneath it. Poland’s largest credit institutions, PKO BP, Bank Pekao, and mBank, sit squarely inside that carve-out. So do smaller payment institutions and e-money firms — except the carve-out’s own wording doesn’t clearly include them. This article maps exactly what Article 8i keeps, what it hands to DORA, and where Poland’s financial supervisor, KNF, still expects a filing. For Poland’s broader NIS2 transposition beyond finance, see our Poland NIS2 guide.

Does NIS2 or DORA Apply to Your Polish Financial Institution?

Start with the entity type, not the sector label. DORA’s Article 2(1) scope list runs from credit institutions (point a) through payment institutions, account information service providers, e-money institutions, and investment firms (points b–e) [1]. If your entity sits in that list, DORA — not the KSC’s technical rulebook — is your primary operational-resilience regime. If it doesn’t (a fintech vendor selling only software, for instance, or a financial entity DORA’s own Article 2(3) excludes, such as certain small occupational pension schemes), the KSC’s full NIS2-style obligations apply directly.

Entity type DORA-covered? Poland KSC treatment
Bank / credit institution (PKO BP, Pekao, mBank, cooperative savings banks) Yes — Art. 2(1)(a) Article 8i carve-out applies — most KSC technical rules replaced by DORA
Payment institution, AISP, e-money institution (KIP/MIP/BUP) Yes — Art. 2(1)(b–d) Ambiguous — not named in the KSC’s banking-sector Annex definition (see below)
Financial market infrastructure (CCPs, clearing houses, trading venues) Yes, separately scoped Article 8i carve-out applies
DORA-excluded financial entity (e.g. small occupational pension scheme) No Full KSC obligations apply directly, as for any other sector

The Lex Specialis Mechanism: NIS2 Article 4 Meets DORA Article 1(2)

NIS2’s Article 4 lets a sector-specific EU law take over from NIS2 where that law imposes cybersecurity measures at least equivalent in effect to Article 21(1)/(2), or gives competent authorities and CSIRTs incident-notification access matching Article 23(1)–(6) [1]. DORA doesn’t leave that to interpretation. Its own Article 1(2) states plainly: financial entities identified as essential or important under national NIS2 transposition rules are to be treated as covered by “a sector-specific Union legal act for the purposes of Article 4” of the NIS2 Directive [2]. That single clause is why every EU country’s NIS2 transposition has had to write a banking carve-out — Poland’s is Article 8i of the amended KSC. For the general EU-level mechanics of this hand-off, see our NIS2 vs DORA comparison and our banking and finance sector guide.

What that carve-out does not do is exempt banks from Poland’s cybersecurity law altogether. It swaps out the technical rulebook — risk-management measures, incident classification, testing — for DORA’s equivalent (Articles 6–14, 24–27), while leaving the KSC’s administrative layer — registration, personnel accountability, basic cyberhygiene — in place [4].

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Article 8i KSC: What Poland’s Banks Keep and What DORA Takes Over

Legal analysis of the enacted Article 8i(1) describes a deliberately partial exemption, not a blanket one [4][7]. For critical and important entities in the banking and financial-market-infrastructure sectors, it removes 13 of the KSC’s 14 Article 8(1)(2) technical sub-points, the Article 10 documentation regime, Articles 11–12 incident classification and reporting, and the Article 15 triennial security audit — all replaced by DORA’s own ICT risk-management articles and its Article 24–27 resilience-testing regime, including threat-led penetration testing (TLPT) [4].

Stays under KSC (Article 8i retains it) Moves to DORA (Article 8i removes it)
Registration and classification (Art. 7-7m, Art. 5(1-3)) Technical risk-management measures (Art. 8(1)(2), most sub-points)
Manager duties: 5 tasks, annual training, criminal-record checks (Art. 8c-8f) Security-documentation regime (Art. 10)
Basic cyberhygiene only — the sole technical area kept (Art. 8(1)(2)(j)) Incident classification and reporting (Art. 11-12, 12a-12b)
Cyberthreat information-sharing, contact persons, S46 use (Art. 8h, Art. 9) Triennial security audits, replaced by DORA’s Art. 24-27 testing, incl. TLPT (Art. 15)
Vulnerability disclosure, S46 supervisory reporting, security orders (Art. 26a, 37, 46(1), 67g-67i) Cybersecurity structures, per DORA Art. 6(4) (Art. 14)

In practice, a Polish bank’s compliance team ends up running two parallel programmes rather than one: a DORA-driven ICT risk and resilience-testing programme, and a slimmer KSC administrative track covering registration, board sign-off, staff vetting, and basic hygiene controls.

PKO BP, Pekao, and mBank: Why Poland’s Largest Banks Sit Under DORA, Not Full KSC

PKO BP, Bank Pekao, and mBank are licensed credit institutions — the exact entity type Article 2(1)(a) of DORA names first [3]. That places their ICT risk management, incident reporting, and resilience testing squarely under DORA’s five pillars, supervised by KNF as Poland’s designated DORA competent authority since the regulation became applicable on 17 January 2025 [6][7]. What it does not do is release them from the KSC entirely. Under Article 8i, each still owes the National Cybersecurity System a completed registry filing, documented management-body training and background checks for the people running its cybersecurity function, and evidence of basic cyberhygiene controls — MFA, patch management, access controls, backup testing, and staff awareness — sitting alongside its DORA programme, not replacing it [4].

The Payment Institution Gap: KIP, MIP, BUP, and E-Money Institutions

Here is where Poland’s implementation gets genuinely unresolved. Article 8i(1)’s carve-out applies to entities the KSC’s Annex defines as the “banking and financial market infrastructure” sector — credit institutions, domestic banks, branches of foreign banks, and cooperative savings and credit unions (SKOK) [4]. Payment institutions (krajowe instytucje płatnicze — KIP), small payment-service providers (MIP), payment-services bureaus (BUP), account information service providers, and e-money institutions are DORA-regulated financial entities under Article 2(1)(b)-(d) [3] — but they are not named in that same KSC banking-sector definition. Legal commentators on the enacted text flag this as an unresolved gap: without further regulatory clarification, a Polish payment institution could face DORA’s full regime and the KSC’s full NIS2-style technical rulebook simultaneously, rather than the narrower administrative-only track banks get [4]. If your entity is a payment or e-money institution rather than a licensed bank, don’t assume Article 8i’s narrower carve-out applies to you by default — verify your classification with KNF before scoping your compliance programme.

KNF’s Double Hat: One Regulator, Two Enforcement Tracks

KNF supervises Polish financial entities under both regimes at once — as the KSC’s sectoral cybersecurity authority for finance, and as DORA’s designated competent authority [6][7]. For a DORA-covered bank, that means the same regulator can act on two separate legal bases for related conduct: KSC administrative sanctions for a missed registration or an undocumented board sign-off, and DORA’s own supervisory powers — which, per professional-services analysis of the implementing framework, include a requirement to notify KNF around 14 days before concluding ICT third-party arrangements covering critical or important functions — for an ICT risk-management failure [7]. Nothing in the sourced analysis of Article 8i describes an explicit anti-double-jeopardy clause comparable to how NIS2 coordinates with GDPR supervisory authorities elsewhere in the Directive; treat the two tracks as genuinely parallel rather than assuming one automatically absorbs the other; a compliance programme should keep evidence for each obligation separately, not just for whichever regime feels more relevant that quarter. For how KNF fits alongside Poland’s other sector regulators and the 3-CSIRT reporting structure, see our Poland competent authority guide.

Narodowy Bank Polski: The Exception Inside the Exception

NIS2 generally lets member states leave central banks out of scope entirely. Poland didn’t take that option for its own central bank’s infrastructure: reporting on the enacted KSC 2026 Act confirms Narodowy Bank Polski is explicitly named, alongside energy, transport, and digital-infrastructure entities, in the Act’s annexes as a particularly sensitive entity [8]. NBP is not a DORA entity itself — DORA governs commercial financial entities, not central banks — so it sits inside the KSC’s own framework rather than under the Article 8i carve-out built for banks.

This isn’t a new tension. In a 2020 legislative opinion on an earlier draft of the cybersecurity law, NBP itself objected to proposed powers for the Government Plenipotentiary for Cybersecurity — warnings and protective orders — that could have reached IT systems inside NBP’s own payment infrastructure, specifically SORBNET2 and TARGET2-NBP, arguing this risked the central bank’s constitutional independence [9]. That objection predates the 2026 Act by several legislative cycles and doesn’t necessarily describe the final Article 8i text, but it’s a useful signal: Poland’s cybersecurity framework treats the payment-system operator differently from the banks that use those payment systems, and the boundary between “NBP’s own infrastructure” and “KNF-supervised commercial banking” is worth knowing if your institution connects to NBP-operated systems.

Compliance Checklist: Deadlines for Poland’s DORA-Covered Entities

Four dates matter for a DORA-covered financial entity working through its residual KSC obligations.

Date What happens
3 April 2026 KSC amendment in force. Registration duty, security orders, and the national-security “super-fine” tier become live.
~3 October 2026 Registry filing deadline via the S46 system for entities meeting classification criteria at entry into force.
3 April 2027 Full KSC security-management-system and documentation obligations apply to non-carved-out entities.
3 April 2028 Standard fine moratorium expires; mandatory initial audit deadline for critical entities.

For a DORA-covered bank, most of the 2027/2028 milestones don’t apply — Article 8i already routes that work to DORA’s own Article 24-27 testing calendar. The registration deadline and the board-documentation duty do apply, regardless of DORA status. Poland’s separate penalty structure — including the standard €10M/2%-turnover ceiling and the personal management-liability provision — is covered in full in our Poland NIS2 penalties guide; the KSC’s administrative sanctions (not DORA’s) are what apply to a missed registration or training gap under Article 8i.

Frequently Asked Questions

Does DORA fully exempt Polish banks from NIS2 and the KSC?

No. Article 8i replaces the KSC’s technical security-management and incident-reporting rules with DORA’s equivalents for banks and financial-market-infrastructure entities, but registration, manager accountability, basic cyberhygiene, and KNF’s supervisory powers under the KSC remain in force [4].

Do payment institutions need to register under the KSC even though DORA covers them?

Likely yes, and possibly under the full KSC regime rather than the narrower bank carve-out — Article 8i’s banking-sector definition doesn’t clearly list payment institutions, AISPs, or e-money institutions. Confirm your entity’s classification directly with KNF rather than assuming bank-level treatment applies [4].

Can KNF fine the same institution under both the KSC and DORA for one incident?

The sourced legal analysis of Article 8i doesn’t describe a coordination mechanism preventing that outcome for related conduct across the two regimes, since KNF holds separate enforcement powers under each [4][7]. Treat KSC and DORA compliance evidence as two distinct files, not one.

Is Narodowy Bank Polski itself subject to NIS2 or DORA?

NBP is named in the KSC 2026 Act’s annexes as a particularly sensitive entity, which is a broader step than the EU-wide NIS2 baseline (which lets member states exclude central banks). It is not a DORA entity — DORA covers commercial financial entities, not central banks [8].

Sources

  • Article 4, NIS2 Directive (EU) 2022/2555 — nis-2-directive.com
  • Article 1(2), DORA Regulation (EU) 2022/2554 — digital-operational-resilience-act.com
  • Article 2, DORA Regulation (EU) 2022/2554 — digital-operational-resilience-act.com
  • “Art. 8i KSC — lex specialis DORA dla sektora bankowości i infrastruktury rynku finansowego” — LegalGeek
  • “Ustawa KSC 2026 — co zmienia nowelizacja NIS2” — LegalGeek
  • KNF official DORA page — knf.gov.pl
  • “Ustawa wdrażająca DORA do prawa polskiego” — Deloitte Polska
  • “Ustawa KSC 2026: obowiązki i weryfikacja firm w systemie” — prawo.pl
  • “NBP: projekt ustawy o cyberbezpieczeństwie narusza niezależność banku centralnego” — Bankier.pl (2020)

This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Don't miss: