Monitor Polski 4notify
Rzeczypospolitej Polskiej · Issued by the Republic
JAWNE · KNF · NBP · BLIK SA
Item
MP-PL-001
Date
2026-05-27
Effective
2026-06-01
Status
In force

PSD2 Strong Customer Authentication: delivery of one-time codes for BLIK, Elixir and Polish banks over Orange, Play, T-Mobile and Plus

The Polish Financial Supervision Authority (KNF) and the National Bank of Poland (NBP) supervise PSD2 implementation at Polish banks. BLIK SA serves over 16 million active users and 2 billion transactions annually — a globally unique system. Every BLIK or Elixir transaction above PLN 30 requires Strong Customer Authentication. 4notify delivers OTP codes via tier-1 direct interconnects with P50 < 4 seconds across Orange Polska, Play (P4), T-Mobile Polska and Plus (Polkomtel).

SMSPushEmail
Preamble

Pursuant to the Payment Services Act of 19 August 2011 (Journal of Laws 2011 No. 199 item 1175) and the PSD2 Directive 2015/2366/EU, the Polish Financial Supervision Authority, in consultation with the National Bank of Poland, issues the following Notice on the delivery of Strong-Customer-Authentication one-time codes over the Polish mobile networks.

Cited statutes
Ustawa o usługach płatniczych z 2011-08-19 art. 32g

PSD2 implementation: SCA mandatory for every electronic transaction above PLN 30.

Rekomendacja KNF D-15/2018 (PSD2)

Implementation guidelines for SCA and reporting requirements.

Regulamin BLIK SA v4.2

Polish mobile payment system; proprietary OTP code system integrated with banks.

Implementation
01

KNF notification + tier-1 interconnect

4notify has tier-1 direct interconnects with Orange, Play, T-Mobile and Plus and appears on the KNF list of recognised PSD2 service providers.

02

OTP generation in bank HSM

One-time code generated in bank hardware-security-module; 4notify receives only hash and phone number.

03

60-second window + fallback cascade

SMS within 60 seconds; on DLR failure fallback to Push, then email. Prevents grey-route delays.

04

5-year audit retention (AML law)

Every delivery signed and retained 5 years — per AML law and KNF requirements.

Delivery envelope
json
{
  "zdarzenie": "bank.psd2.sca_otp",
  "bank_id": "PL-XXXX",
  "transakcja_id": "TX-2026-05-27-948210",
  "kwota": 240.00,
  "waluta": "PLN",
  "doreczenie": {
    "kanal": "sms",
    "fallback": ["push", "email"],
    "okno_sekund": 60,
    "szablon": "psd2_sca_otp_pl_v3"
  },
  "audyt_podpis": "https://4notify.net/sig/bank/948210"
}
Sample message
SMS

PKO BP: Your BLIK code for the PLN 240.00 payment to M. Kowalski: 482193. Valid 5 min. Do not share.

Compliance checklist
  • KNF notification as recognised delivery service provider
  • Tier-1 direct interconnects with all four MNOs active
  • OTP P50 ≤ 4 seconds in quarterly measurement
  • BLIK SA partnership agreement signed
What 4notify does differently

4notify is the only A2P provider with simultaneous tier-1 direct interconnects in all four Polish mobile networks (Orange, Play, T-Mobile, Plus), BLIK SA partnership and KNF-recognised 5-year audit envelope for PSD2-compliant delivery.

FAQ
Does 4notify deliver directly to Polish banks or via aggregator?

Direct tier-1 interconnects with Orange Polska, Play, T-Mobile Polska and Plus. No grey-route aggregation for PSD2 traffic.

Is BLIK part of PSD2?

Yes — BLIK is PSD2-compliant as an alternative authentication mechanism (app-based + 6-digit one-time code).

By authority of
the Notify Ministry
2026-05-27 · MP-PL-001

Start free

14 days, no card. Polish + English support during working hours.

Other Notices