Your sales team is about to close the biggest deal in the company’s history. The enterprise client is ready to sign the agreement. But the procurement department sends over a 40-page security questionnaire and a list of required industry standards. The CTO looks at it and says: “We don’t have half of this." The deal is frozen for 3 months – or lost.
This is not a theoretical scenario. It regularly happens to companies that grow faster than their compliance with industry guidelines. In 2024, 74% of Polish companies experienced a cyberattack, while regulators imposed record penalties – in 2025, UOKiK alone issued decisions totaling PLN 1.15 billion. At the same time, four major EU regulations entered into force or became applicable: DORA, NIS2, the AI Act, and updated GDPR requirements.
For CEOs, COOs, and founders of technology companies, this means one thing: industry guidelines are no longer “soft law". They have become a prerequisite for selling to major clients, achieving a successful due diligence outcome, and securing funding.
In this article, I will show you how to map the requirements that apply to your company, how to distinguish obligations from recommendations, and how to build a compliance model in 4 steps that will not hold your business back.
Key concepts before we move on
Before we explore the subject in depth, it is worth explaining a few terms that will appear later in the article.
| Term | What it means for your company |
|---|---|
| Industry guidelines | Regulatory recommendations, technical norms, market standards, and counterparties’ expectations – they do not always have the force of law, but they affect whether you can sell, attract an investor, or pass an audit |
| Compliance | Ensuring that the company operates in accordance with applicable laws, standards, and guidelines – including its documents, processes, and the team’s actual conduct |
| Due diligence | A legal and financial review of a company – conducted by an investor, buyer, or partner before a transaction. It reveals gaps between stated and actual compliance |
| Vendor risk management | The process through which a major client assesses the risks of working with your company – including security questionnaires, certification requirements, and procedure reviews |
| ISO 27001 | An international information security management standard – the de facto market standard for B2B contracts, particularly with entities subject to DORA and NIS2 |
| SOC 2 | A standard for reporting on security controls – required mainly by US clients and international corporations |
Why industry guidelines can now genuinely block your business
The 2024-2025 regulatory wave – four regulations at once
Polish technology companies have found themselves under the combined pressure of several major regulations that entered into force or became applicable over the same period. Here is an overview:
| Regulation | Status | Application date | Who it applies to |
|---|---|---|---|
| DORA (EU Regulation 2022/2554) | In force | From 17 January 2025 | Banks, payment institutions, investment firms, and ICT service providers to the financial sector |
| NIS2 (EU Directive 2022/2555) | Applicable from 18 October 2024; Poland: transposition in progress | Amendment to the National Cybersecurity System Act expected to enter into force by the end of 2025 | ~30,000 companies in Poland – energy, transport, healthcare, digital infrastructure, food, waste, and digital services |
| AI Act (EU Regulation 2024/1689) | In force | Prohibitions from 2 February 2025; high-risk systems from 2 August 2026 | Companies using AI in recruitment, performance assessment, and task allocation |
| GDPR (EU Regulation 2016/679) | In force since 2018 | Ongoing application | Every controller and processor of personal data |
Each of these regulations creates separate obligations: ICT risk management, incident reporting, AI literacy training, and data protection impact assessments. For a company employing 50-200 people without a dedicated compliance department, this means dozens of new requirements spread across IT, HR, operations, and management.
Penalties already imposed – specific amounts
Supervisory authorities in Poland do not stop at warnings. Here are documented penalties from recent years:
| Entity | Authority | Penalty amount | Reason |
|---|---|---|---|
| Poczta Polska S.A. | UODO | PLN 27,000,000 | Unlawful processing of data relating to 30 million citizens from the PESEL database |
| ING Bank Śląski S.A. | UODO | PLN 18,400,000 | Routine scanning of identity cards – violation of the data minimization principle |
| McDonald’s Polska | UODO | PLN 16,932,657 | Failure to conduct a risk analysis when outsourcing data processing, and failure to supervise the processor |
| DPD Polska | UODO | PLN 11,460,000 | No data processing agreements with carriers and no organizational measures |
| Glovo (Restaurant Partner Polska) | UODO | PLN 5,898,064 | Unlawful collection of identity document scans from ~3.4 million users |
| ING Bank Śląski S.A. | GIIF | PLN 21,659,000 | Breach of AML obligations – the highest penalty in history |
Source: UODO – decisions of the President of UODO, Ministry of Finance – AML penalties.
By mid-2025, a total of 216 penalty decisions had been issued under the AML Act, totaling nearly PLN 48 million. The AI Act provides for penalties of up to EUR 35 million or 7% of global annual turnover for using prohibited AI practices – including emotion recognition in the workplace, which has been prohibited since 2 February 2025.
What do these cases have in common? Supervisory authorities explicitly refer to guidelines, recommendations, and industry standards as the standard of due care when determining penalties. Intent is not a prerequisite for liability. What matters are the objective facts: whether procedures existed, whether they were followed, and whether they reflected the actual circumstances.
“Soft" guidelines – hard consequences
The line between statutory obligations, regulatory recommendations, and market standards is becoming increasingly blurred. Here is what this looks like in different sectors:
- KNF and the financial sector. KNF recommendations (e.g. Recommendation Z on internal governance) are not formally binding law. However, under the BION system (Supervisory Review and Evaluation), non-compliance with recommendations is classified as an element of legal and organizational risk. Consequences include administrative penalties, restrictions on business activity, demands to replace members of governing bodies, and additional capital requirements.
- ISO 27001 as a contractual requirement. ISO 27001 is not a legal obligation. However, entities subject to DORA and NIS2 require it from their ICT providers. If your company supplies software to a bank or insurer, a lack of certification may cost you the contract.
- Vendor risk management in enterprise sales. Major corporate clients use extensive security questionnaires and vendor risk assessments as a prerequisite for doing business. Failing to answer questions about incident management, data access policies, or business continuity plans will block the procurement process.
- SOC 2 in international business relationships. For Polish SaaS companies selling in US markets, a SOC 2 report is becoming the expected evidence that security controls are operating effectively. In domestic business relationships, ISO 27001 remains the primary benchmark.
Regulators are increasingly taking a preventive approach – rather than waiting for complaints, they analyze the market and intervene based on their own findings. For your company, this means that compliance must be maintained continuously rather than treated as a response to an inspection.
Contact us – we will help you determine which guidelines apply to your company and how to turn them into effective processes.
How to distinguish a legal obligation from an industry recommendation
One of the most common questions I hear from founders is: “How do I know which guidelines I have to comply with and which ones I can ignore for now?" The answer requires dividing requirements into three categories:
| Category | What it means | Examples | Consequences of non-compliance |
|---|---|---|---|
| Legal obligation | Arises directly from an act or regulation; a breach may result in an administrative or criminal penalty | GDPR, DORA, AI Act, AML Act, Labor Code | Financial penalties, personal liability of management board members, prohibition on conducting business |
| Regulatory recommendation | Issued by a supervisory authority; formally non-binding, but treated as a standard of due care | KNF recommendations, UODO guidelines, CSIRT positions | Negative supervisory assessment, additional requirements, rating downgrade |
| Market standard | Expected by counterparties, investors, or auditors; there is no formal penalty, but there are real business consequences | ISO 27001, SOC 2, enterprise security questionnaires | Loss of contracts, lower valuation during due diligence, blocked funding round |
This distinction has operational significance. A legal obligation must always be implemented. A regulatory recommendation should be implemented if you operate in a regulated sector or your clients expect it. A market standard should be implemented if you want to sell to enterprise clients or attract an investor.
At the scaleup stage of a technology company, these three categories overlap. A fintech startup is subject to KNF licensing and PSD2 requirements from day one – it must meet the same security standards as traditional banks despite operating on a much smaller scale. A SaaS company selling to the financial sector becomes indirectly subject to DORA as an ICT provider – even if it is not a financial institution itself.
That is why the first step is not to implement everything at once, but to conduct an inventory: what applies to your company, on what basis, and with what priority.
Four steps to a predictable compliance model
Step 1: inventory the guidelines – create a single table
Start by collecting all the requirements that apply to your company in one place. Do not try to cover everything – focus on the 5-7 most important areas. Here is a template you can adapt:
| No. | Area / process | Basis (law / recommendation / market standard) | Requirement description | Compliance status | Risk level | Process owner |
|---|---|---|---|---|---|---|
| 1 | Personal data protection | GDPR (legal obligation) | Record of processing activities, data processing agreements, DPIA | Partially compliant | High | Head of Legal |
| 2 | Information security | ISO 27001 (market standard) | Information security management system | Not implemented | High | CTO |
| 3 | Anti-money laundering | AML Act (legal obligation) | KYC procedures, risk assessment, reporting | Compliant | Medium | Compliance Officer |
| 4 | Digital resilience | DORA (legal obligation – if an ICT provider to the financial sector) | ICT risk management, incident reporting | Not implemented | High | CTO |
| 5 | Use of AI | AI Act (legal obligation) | AI literacy, prohibition on emotion recognition, risk assessment of HR systems | Undetermined | Medium | HR + CTO |
This type of table gives management visibility into what has been implemented, what requires action, and who is responsible. Without it, risk builds up quietly – management does not see the growing problem until an inspection or dispute occurs.
Step 2: compare documentation with practice – gap analysis
An inventory alone is not enough. The next step is to compare what the documents say with how the company actually operates.
Typical discrepancies we find during audits include:
- A data protection policy exists, but has not been updated for 3 years and does not cover new processes (e.g. marketing automation or AI tools).
- Data processing agreements have been signed with key suppliers, but are missing for 40% of subcontractors.
- An incident reporting procedure is documented, but no one on the team knows whom to notify of a breach or by what deadline.
- Workplace regulations include provisions on working time, but the actual model of working with B2B contractors differs from the documentation.
- The company claims compliance with ISO 27001 in its sales materials, but has not undergone certification or an internal audit.
Law firm clients and their operational teams report that the “flood of legal changes" – constant amendments to the GDPR, e-commerce directives, AI regulations, and tax law – causes documents to become outdated faster than anyone can update them. The result: documents say one thing, processes work differently, and employees rely on intuition instead of following a consistent standard.
A gap analysis does not have to take months. For a company with 50-200 employees, it can be completed with the support of a law firm in 2-3 weeks – provided that you focus on priorities rather than “perfection."
Step 3: prioritize gaps and create a remediation plan
Not all gaps carry the same weight. Divide the identified shortcomings into three groups and present them to management in a decision-oriented format:
| Priority | Time frame | Examples |
|---|---|---|
| Critical | Implement within 30 days | No data processing agreements with suppliers; no incident reporting procedure; use of prohibited AI practices (emotion recognition in HR) |
| Important | Schedule within 90 days | Update the data protection policy; implement AI literacy procedures; review B2B agreements for DORA compliance |
| Improvements | Implement in stages | ISO 27001 certification; preparation of a compliance one-pager for the sales department; implementation of periodic compliance reviews |
This division allows management to decide how many resources to allocate, in what order to act, and when to engage external legal support. Without prioritization, companies either try to implement everything at once (and finish nothing) or create overly burdensome procedures that look good on paper but that no one follows.
Step 4: appoint owners and implement a review cycle
The most common problem we see in multi-department organizations is that compliance, operations, sales, IT, and HR all deal with the same area of the guidelines. No one knows who is responsible for updating documents or who reports risks.
The solution:
- Appoint one person responsible for each area covered by the guidelines – not a “department," but a specific named individual. This person is responsible for keeping documents up to date, monitoring regulatory changes, and escalating risks to management.
- Establish a review cycle – quarterly, for example. During the review, process owners report on compliance status, new guidelines or interpretations, and identified risks.
- Provide brief training to operational teams – not on the guidelines as a whole, but on specific changes to their day-to-day work: what is changing, why, who is responsible, and when to escalate.
- Every compliance document should state the date of its last review and its owner – regulations, policies, and internal instructions must reflect the company’s actual practices rather than being copies of templates.
The binding corporate rules (BCR) model required by the GDPR (Article 47) provides a ready-made organizational framework: audits, remediation mechanisms, procedures for reporting changes, staff training, and the appointment of a person responsible for monitoring. You can adapt the same framework to manage compliance with any industry guidelines.
Compliance at different stages of company growth
The scope and method of managing compliance depend on your company’s stage of development. Here is what the compliance profile looks like at each level:
| Aspect | Startup | Scaleup | Corporation |
|---|---|---|---|
| Who is responsible for compliance | Founder + accountant + possibly an external lawyer | Head of Legal / Compliance Officer (often the first person in this role) | Dedicated compliance department, DPO, risk team |
| Scope of requirements | GDPR (basic), employment law, IP, tax obligations; in fintech – PSD2 and AML from day 1 | All of the above + ISO 27001, DORA (if an ICT provider), NIS2, AI Act, ESG/CSRD (from 250 employees) | Full scope of sector-specific regulations, BCR, non-financial reporting, supply chain risk management |
| Typical problem | No formalized procedures; everything is “in people’s heads" | Documents exist, but are scattered and outdated; practice differs from documentation | Excessive formalization; procedures slow down the business |
| Priority | Secure the essentials: agreements, IP, GDPR, employment model | Organize and professionalize: gap analysis, process owners, review cycle | Optimize: automation, system integration, continuous compliance |
If your company is at the scaleup stage and preparing for a funding round, due diligence will reveal every discrepancy between stated and actual compliance. Scattered, outdated documents and a lack of designated process owners may reduce the valuation or block the transaction.
The good news is that getting organized does not have to take months. By focusing on priorities and working with a law firm that understands the realities of technology companies, you can move from chaos to a predictable model in 2-4 weeks.
Compliance one-pager – a document that accelerates sales
One of the most practical tools you can prepare is a compliance one-pager – a one-page document showing:
- Which industry standards your company meets (e.g. GDPR, ISO 27001, AI Act compliance).
- How you manage compliance (review cycle, process owners, incident reporting procedure).
- Who in the company is responsible for each area (name, position, contact details).
- Which certifications or audits the company has completed (with dates).
This document is useful in three situations:
- Enterprise sales – you can complete security questionnaires faster and more efficiently because the information is readily available.
- Due diligence – an investor or buyer can see that the company has an organized compliance management model rather than a collection of scattered documents.
- Partnerships and tenders – you can attach the compliance one-pager to your proposal as proof of credibility.
How we can help you
Organizing compliance with industry guidelines does not require building a large in-house compliance department. It does, however, require an accurate assessment of which requirements apply to your company, where the gaps are, and in what order they should be addressed.
We combine corporate law with contract law and an understanding of the business context of technology companies. We work with founders, COOs, and Heads of Legal at SaaS, fintech, and e-commerce companies – we understand time pressure, parallel projects, and limited resources.
Our support includes:
- Inventory of industry guidelines – we identify which requirements arise from legislation, which from regulatory expectations, and which from the requirements of the market and counterparties. You get a single table instead of dozens of scattered documents.
- Gap analysis – we compare the documentation with the company’s actual practices. We identify specific discrepancies and assess the risk.
- Prioritized remediation plan – we divide gaps into critical, important, and improvement-related categories. Management receives a decision-oriented report rather than a multi-page legal opinion.
- Updating or creating compliance documents – regulations, policies, instructions, data processing agreements, and incident reporting procedures – tailored to the company’s actual operating model.
- Appointing process owners and implementing a review cycle – so that compliance becomes a predictable model rather than a one-off project.
- Preparing a compliance one-pager – for enterprise sales, due diligence, or funding rounds.
Industry guidelines are a prerequisite for growth – not a barrier
In 2026, industry guidelines are not a formality to tick off a checklist. They are a prerequisite for selling to major clients, achieving a successful due diligence outcome, and securing funding. Companies that treat compliance as a “project for later" lose contracts, pay higher penalties, and reduce their valuation.
The four steps described in this article – inventory, gap analysis, prioritization, and appointment of owners – allow you to move from regulatory chaos to a predictable model. You do not have to implement everything at once. Start with what is holding your business back today.
If you need support mapping requirements, conducting an audit, or preparing your company for due diligence, contact us. We will help you organize compliance in weeks, not months.
Frequently asked questions
How do I know which industry guidelines apply to my company if I am not a lawyer?
Start with three questions: (1) which sector do you operate in and who is your regulator (e.g. KNF for fintech, UODO for every company processing personal data), (2) who are your clients – if you sell to the financial sector, DORA applies to you indirectly as an ICT provider, and (3) what requirements do your counterparties set out in security questionnaires or agreements? Based on this, you can create an initial requirements map. If you have any doubts, consult a law firm that understands the realities of technology companies.
Can non-compliance with guidelines that are not formally binding law really block my sales or funding round?
Yes. Major corporate clients use vendor risk management as a prerequisite for doing business. A lack of ISO 27001 certification, outdated data protection policies, or no incident reporting procedure are all reasons why procurement departments freeze or reject proposals. During due diligence, an investor verifies whether stated compliance is supported by documents and processes. Scattered, outdated documents and discrepancies between procedures and practice reduce the valuation or block the transaction.
How much time and how many resources does it realistically take to organize sector-specific compliance in a company with 50-200 employees?
With support from a law firm and a focus on priorities, the inventory and gap analysis take 2-3 weeks. A prioritized remediation plan takes another week. Implementation of critical changes takes 30 days. Fully organizing compliance – updating documents, appointing owners, and implementing a review cycle – takes 2-3 months. You do not have to do everything at once. Start with the gaps that block sales or expose the company to the greatest risk.
Can I implement compliance in stages, starting with the minimum?
Yes – and this is the recommended approach. Divide the requirements into three groups: critical (implement within 30 days), important (schedule within 90 days), and improvements (implement in stages). Critical requirements are those that expose the company to an administrative penalty or block current sales. Important requirements are those that affect valuation or audit readiness. Improvements are those that build long-term credibility. This division allows management to allocate resources consciously.
Who in my company should be responsible for monitoring industry guidelines if I do not have a compliance department?
Appoint one person for each area – not a “department," but a specific individual. In a company with 50-200 employees, the typical division looks like this: the CTO is responsible for information security and technical requirements (ISO 27001, DORA), the Head of Legal or COO for GDPR and contract law, the HR Manager for employment law and the AI Act as it relates to HR, and the CFO for AML and tax obligations. Each of these people reports on compliance status as part of a quarterly review. If you do not have a Head of Legal, this role can be performed by an external law firm under an ongoing support arrangement.
What specifically do auditors or investors check regarding compliance with industry guidelines during due diligence?
They primarily verify: (1) whether the company has identified the regulatory and industry requirements that apply to it, (2) whether compliance documents exist (policies, regulations, data processing agreements, procedures) and whether they are up to date, (3) whether the documents reflect actual practice – for example, whether the incident reporting procedure is known to the team, (4) who in the organization is responsible for each compliance area, (5) whether the company has undergone audits or certifications (ISO 27001, SOC 2), and (6) whether there is a mechanism for periodic compliance reviews. Discrepancies between statements and the actual situation are the most common reason for a lower valuation or a longer transaction process.
