Our Expert in Poland
No results available
Regulatory sandbox Poland has become one of the most searched routes to market for FinTech and crypto teams preparing to test regulated products under supervision in 2026. In practice, the primary structured channel for innovators in Poland is the Polish Financial Supervision Authority’s (KNF) Innovation Hub, through which firms can engage with the supervisor, clarify how their product is classified, and prepare for authorisation. Discussion of a fully operational “regulatory sandbox” in Poland should be approached carefully: firms should confirm the exact form of any current supervised‑testing programme directly with the KNF, because arrangements evolve.
This year the pathway carries added weight because the EU Markets in Crypto‑Assets Regulation (MiCA) now shapes how crypto activities must be documented and classified, and because Polish authorities continue to promote innovation‑friendly supervision. This guide sets out the operational playbook, eligibility, documents, timelines, costs, regulator engagement and the transition to a full licence, that founders, product leads, compliance officers and in‑house counsel need before they engage.
The engagement model exists to let firms validate a product against real‑world conditions while the regulator observes and guides. Any supervised testing is not a shortcut around authorisation and it does not exempt participants from core obligations such as anti‑money‑laundering (AML) controls, data protection or consumer safeguards. It is a structured way to generate the evidence a supervisor needs to become comfortable with an innovation before it scales.
In practical terms, engagement typically begins through the KNF’s innovation‑support channels (see the KNF at knf.gov.pl), where firms can raise questions and prepare before any formal authorisation submission. Where a supervised pilot is available, it is generally time‑boxed, conducted with a limited cohort of users, framed around agreed key performance indicators (KPIs), and subject to clear consumer protections. Every stage should be documented so that outcomes can support a subsequent licence application. Confirm the current form and availability of any testing programme directly with the KNF.
Before investing time, run this quick decision checklist:
Eligibility rests on demonstrating that your firm is a properly constituted legal entity, that your product is genuinely innovative and regulated (or borderline‑regulated), and that you can contain and manage the risks of live testing. Applicants are expected to show AML/CTF readiness, a data protection framework compliant with the GDPR, and a credible consumer redress plan. National statutory obligations, including payment services and AML legislation (notably the Polish Act on Payment Services and the Act on Counteracting Money Laundering and Terrorist Financing), remain in force during any pilot and can be reviewed via the Internet System of Legal Acts (ISAP) at isap.sejm.gov.pl.
Products commonly considered for supervised engagement include:
Certain activities are poorly suited to supervised testing because they carry systemic or acute consumer risk. These generally include high‑value deposit‑taking, unqualified investment advice to retail clients, and any model that cannot cap consumer losses. Where an activity depends on a full authorisation that cannot be waived, for example, prudential capital requirements, supervised testing will not substitute for licensing.
The KNF Innovation Hub is an advisory engagement channel; a supervised pilot, where available, is a testing environment. Many firms use the Innovation Hub first to clarify requirements, then progress to a pilot, and finally to a full licence. The comparison table below sets out how the three differ; note that Polish law does not, in general, permit the KNF to waive statutory obligations, so any relief is limited and must be confirmed with the regulator.
| Feature | Supervised Pilot | KNF Innovation Hub | Full Licence |
|---|---|---|---|
| Purpose | Controlled testing under supervision | Advisory engagement and pre‑application support | Full market access under licence |
| Regulatory relief | Limited and subject to statutory constraints | None, guidance only | None; full compliance required |
| Duration | Time‑boxed (months) | Ongoing engagement | Ongoing |
| Typical outcome | Proof‑of‑concept or transition to licence | Clarified requirements | Authorisation to operate |
The process is best treated as a sequence of well‑prepared stages rather than a single filing. Below is a practical, numbered playbook with realistic durations, sample language and the regulator engagement tactics that tend to shorten review. Timelines below are indicative planning estimates, not KNF‑published service standards; confirm current expectations with the KNF.
Assemble your core team, CEO or founder, legal lead, product owner and technical lead, and appoint a single regulatory lead who will own all communication with the supervisor. Complete an internal legal review that maps your product to the relevant Polish and EU rules, identifies which obligations you cannot meet without relief, and drafts the test plan skeleton. This is the stage to define your KPIs and exit conditions. Sample KPI language:
Sample exit condition: “The pilot concludes at 6 months, or earlier if cumulative consumer losses exceed the reserved compensation pool, at which point all balances are refunded and data is handed over per the exit plan.”
Request an introductory contact through the KNF Innovation Hub before you submit anything formal. A short, precise opening message tends to secure a meeting faster. Sample email:
Subject: Pre‑engagement enquiry, [Company] FinTech project (payments / crypto)
Dear KNF Innovation Hub team, [Company] is a Polish‑registered [entity type] developing [one‑line product description]. We are preparing for supervised engagement and would value a 30‑minute pre‑application call to confirm scope, applicable obligations and expected evidence. We can share a two‑page summary in advance. Kind regards, [Name, Regulatory Lead].
Bring a three‑point agenda to the meeting: (1) confirm product classification and applicable law; (2) agree the pilot’s scope, cohort size and duration; (3) clarify the evidence and documentation the regulator expects. Take detailed minutes, the points agreed here shape a smoother formal review.
Submit the application form, cover letter and full attachment set. In your cover letter, emphasise:
Where crypto‑assets are involved, include an explicit MiCA classification analysis so the reviewer can see how each token is categorised and which obligations attach.
Expect written queries. Common regulator questions concern the depth of AML transaction monitoring, the realism of KPIs, the size and vulnerability profile of the test cohort, and the completeness of the exit plan. Respond quickly and completely: acknowledge each query within a day or two, provide a consolidated response with clearly labelled attachments, and avoid piecemeal replies. Prompt, well‑organised answers are the single biggest lever on review speed.
Once accepted, agree the start date and reporting cadence with the supervisor. During the pilot, maintain a live KPI dashboard, submit periodic reports (commonly monthly), and log every incident with its remediation. Keep consumer safeguards active throughout: informed consent, a working complaints channel, and the ability for participants to withdraw and be refunded. Treat the monitoring phase as the evidence‑generation engine for your future licence file.
Every pilot ends. Execute your exit plan: notify consumers, settle balances, hand over or securely delete data as agreed, and produce a closing report against your KPIs. If the pilot succeeded, this closing evidence feeds directly into a full authorisation application. If it did not, document the lessons and wind down cleanly.
Begin licensing conversations with the regulator early, ideally during Step 2, so the evidence you gather in the pilot maps to what a full payment institution or crypto‑asset service provider (CASP) authorisation under MiCA will require. Align your KPI reporting to licence criteria from the outset to avoid re‑gathering evidence later.
| Step | Who (owner) | Indicative duration |
|---|---|---|
| 1, Internal readiness & legal review | Applicant (CEO, Legal, Tech lead) | 2–4 weeks |
| 2, Pre‑meeting with KNF Innovation Hub | Applicant + KNF Innovation Hub contact | 1–3 weeks to schedule |
| 3, Formal submission | Applicant (Regulatory lead) | Day 0 (submission) |
| 4, KNF assessment & Q&A | KNF review team (+ external experts) | 4–12 weeks (indicative) |
| 5, Acceptance & test start | KNF + Applicant | 1–4 weeks from acceptance |
| 6, Live testing & reporting | Applicant (operations) + KNF monitoring | 1–12 months |
| 7, Exit / transition to licence or closure | Applicant + KNF | 2–8 weeks |
Submissions are assessed by the KNF’s relevant department, supported where relevant by technical input. Your internal review board should mirror the regulator’s concerns, AML, consumer protection, technical resilience, so that your submission anticipates their questions.
The table below maps each commonly expected document to its purpose and the person who typically signs it. Submit documents as signed PDFs; any document not originally in Polish should be accompanied by a Polish translation, and a Polish one‑page summary checklist should accompany the pack. Confirm the exact current requirements against KNF guidance at knf.gov.pl before filing.
| Document | Purpose / minimum content | Who signs / notes |
|---|---|---|
| Cover letter & executive summary | Project overview, pilot objectives, target users, expected benefits and risks, requested relief | CEO or Regulatory Lead |
| Business plan & legal status | Company registration, statutes, ownership, corporate governance | Company secretary / legal |
| Detailed test plan | Scope, timeline, KPIs, sample transactions, cohort size, geographic limits | Product owner & CTO |
| Consumer protection plan | Notices, consent forms, complaints handling, redress routes | Compliance officer |
| AML / KYC controls description | Customer due diligence, transaction monitoring, sanctions screening | AML officer |
| Risk assessment & mitigation | Threat model, incident response, data protection measures | CTO & DPO |
| Technical architecture & security tests | System diagrams, penetration test reports, encryption methods | CTO / security lead |
| Financial projections & capacity | Capital adequacy to run the pilot, refund reserves if applicable | CFO |
| KPI dashboard template | Metrics definitions, reporting cadence | Product / Analytics |
| Exit plan & transition to licence | Success criteria, governance for post‑pilot operations | Regulatory lead |
To accelerate preparation, have a native Polish‑speaking regulatory lawyer review the Polish‑language summary before submission, and confirm the current document set with the KNF.
A realistic timeline runs from an initial two to four weeks of internal preparation, through a pre‑meeting scheduled within one to three weeks, to a formal review of roughly four to twelve weeks depending on complexity and the quality of your submission. These are planning estimates rather than statutory service standards. Crypto pilots that require MiCA classification analysis, and cross‑border models, sit at the longer end of that range. After acceptance, expect one to four weeks before live testing begins, and a pilot period of one to twelve months.
The most common causes of delay are incomplete AML documentation, vague KPIs, over‑broad consumer scope and slow responses to regulator queries. You can accelerate the process by holding a productive pre‑meeting, submitting a complete and internally consistent pack, and defining crisp, measurable KPIs. Build in a buffer for the regulator’s internal review cycles and for public holidays, both of which can push decision dates.
Budget conservatively. Fee positions change and depend on the specific authorisation sought, so confirm current fees directly with the KNF and the Ministry of Finance (gov.pl/web/finance) before you rely on any figure. Statutory administrative or supervisory fees may apply at the authorisation stage. The material costs for most firms are internal resource time, external advisory support, technical build and security testing, and a contingency reserve for consumer remediation. The ranges below are illustrative planning estimates only and will vary substantially by scope, provider and firm.
| Cost item | Illustrative range (EUR) | Notes |
|---|---|---|
| External legal & regulatory advisory | 5,000 – 30,000 | Varies by scope and firm |
| Technical setup / test environment | 10,000 – 100,000 | Depends on scale and security testing |
| AML/KYC provider / onboarding integration | 2,000 – 25,000 | One‑off integration plus per‑customer costs |
| Penetration testing & security audit | 3,000 – 20,000 | Expected by many supervisors |
| Operational staff & monitoring | 5,000 – 50,000 (monthly) | Depends on pilot size |
| Contingency / refund reserve | 5,000 – 50,000 | For consumer compensation or remediation |
The defining shift for crypto firms in 2026 is the full application of MiCA, which now governs crypto‑asset issuance and services across the EU, including in Poland. Crypto‑asset projects must present a clear classification of each token (for example, asset‑referenced tokens, e‑money tokens, or other crypto‑assets) and map the corresponding obligations, drawing on the EU framework published via EUR‑Lex and the European Commission’s crypto‑assets policy pages at finance. ec. europa. eu. Poland has adopted national implementing legislation to designate the KNF as the competent authority and to provide for transitional arrangements; firms should confirm the current status of Polish implementing rules and any transitional windows directly with the KNF, as these details continue to develop.
The practical effect is that crypto applicants who build MiCA‑ready documentation from the start will generally move through review more efficiently than those retrofitting it later. Cross‑border and payment‑service applicants should also track guidance from the European Banking Authority (eba. europa. eu) and the European Securities and Markets Authority.
Most avoidable failures cluster in a handful of areas:
Subject: Response to KNF queries, [Company] submission [ref]
Dear [Reviewer], please find our consolidated responses to your queries of [date], with attachments labelled A–[X]. We are available for a call this week should any point need clarification. Kind regards, [Regulatory Lead].
Acknowledge within one working day, answer every question in one consolidated document, cross‑reference each attachment clearly, and flag proactively any point where you propose to strengthen a control. This disciplined approach signals a mature applicant and shortens the path to acceptance.
The KNF engagement pathway offers FinTech and crypto teams a disciplined, evidence‑led route from concept to authorisation, but only for applicants who prepare thoroughly, define measurable KPIs, document their AML and consumer safeguards, and engage the regulator early and precisely. In 2026, MiCA‑ready documentation and a credible exit plan are the difference between a fast acceptance and a stalled review. This guide is general information, not legal advice; requirements evolve, so confirm the current position, including the exact form of any supervised‑testing programme and applicable fees, with the KNF before you file. To prepare with confidence, request a readiness review from a Global Law Experts FinTech specialist.
This article was produced by Global Law Experts. For specialist advice on this topic, contact Aaron Glauberman at LegalBison, a member of the Global Law Experts network.
posted 8 minutes ago
posted 31 minutes ago
posted 40 minutes ago
posted 40 minutes ago
posted 45 minutes ago
posted 56 minutes ago
posted 1 hour ago
posted 1 hour ago
posted 1 hour ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
No results available
Find the right Legal Expert for your business
Send welcome message