BLIK
Poland · blik.com/en · 14 vendors
Resilience scores
- Digital Sovereignty: 29
- Digital Resilience: 7
- Financial Resilience: 8
Technology vendors
- GoDaddy Inc. — Technology — United States
- Looker — Technology — United States
- Meta Platforms, Inc. — Technology — United States
- and 11 more
Services catalogue
1 service in catalogue across 1 category; runs on 14 sub-vendors.
- Mobile Payment System
Insights
Last updated 2026-08-15 · revision 2
14 direct vendors, 159 subvendors
Direct vendors by controlling owner country (sample)
- Norway: 1
- Denmark: 1
- United States: 9
Subvendors by controlling owner country (sample)
- Ireland: 2
- Norway: 2
- Greece: 1
Migration Readiness: 6/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
BLIK shows moderate migration readiness. The company's engagement with DXC Technology for "central system engineering & modernization" suggests an ongoing effort to update its core infrastructure, which is a positive step towards potential migration. Its reliance on modern payment technologies, real-time processing, and bank API integration indicates a potentially modular architecture that could facilitate migration. Furthermore, ISO/IEC 27001 certification implies robust security practices that would be beneficial during a migration process. However, significant challenges and unknowns exist. There is no explicit information on whether their current architecture is cloud-native, containerized, or based on microservices, which are key indicators of high migration readiness. Crucially, data on the regulatory environment and data residency requirements is missing, which are critical factors for planning and executing a migration, especially for a financial services company operating across multiple countries. Financial stability data is also absent, making it difficult to assess the company's capacity to fund a large-scale migration. While vendor geographic diversity is present, the specific number of distinct vendors and the associated lock-in risk remain unknown, posing a potential hurdle for migration flexibility.
Compliance
10 in-scope frameworks identified; showing 3.
EBA Guidelines on Outsourcing Arrangements — Assessment Required
The EBA Guidelines on Outsourcing Arrangements apply to credit institutions and investment firms, but also create indirect obligations for BLIK as a critical service provider to 21 regulated banks. Risk is Medium because: (1) BLIK's partner banks (PKO Bank Polski, mBank, ING, Millennium, etc.) are subject to EBA outsourcing guidelines and must ensure adequate controls at BLIK as a material outsourcing provider; (2) this creates contractual and audit obligations flowing down to BLIK; (3) BLIK's partnership with DXC Technology for system modernization creates a sub-outsourcing chain that must be managed; (4) BLIK's ISO 27001 certification partially satisfies partner bank audit requirements. Risk is not High because BLIK is the service provider (not the regulated entity) under these guidelines.
Evidence: https://www.blik.com/en/about-us, https://www.blik.com/en/polish-mobile-payment-system-blik-to-modernize-and-expand-into-romania-and-slovakia-with-dxc-technology-1
NIS2 (source) — Assessment Required
NIS2 is almost certainly applicable to BLIK with very high probability, making the risk of non-compliance or incomplete compliance High. Reasoning: (1) BLIK operates a payment system classified by the National Bank of Poland (NBP) as a 'significant retail payment system' in March 2023 — this directly maps to the NIS2 'financial market infrastructures' Essential Entity category under Annex I; (2) BLIK processes billions of transactions annually across Poland, Romania, and Slovakia, clearly exceeding the medium enterprise threshold (50+ employees, €10M+ turnover); (3) NIS2 was transposed into Polish law (Act on the National Cybersecurity System, with NIS2 amendments) and Romanian/Slovak law; (4) As a payment system operator, BLIK is a critical digital infrastructure provider whose disruption would have systemic financial consequences; (5) The Polish KNF (financial supervisory authority) and NBP are the likely competent authorities for NIS2 oversight of BLIK. The 'Assessment Required' status reflects that while applicability is near-certain, the specific NIS2 compliance posture (incident reporting procedures, supply chain security measures, governance documentation) has not been publicly disclosed. High risk is assigned because NIS2 penalties can reach €10M or 2% of global annual turnover for Essential Entities, and the financial sector faces intense regulatory scrutiny.
Evidence: https://www.blik.com/en/about-us, https://www.blik.com/en/blik-keeps-up-the-pace-nearly-half-a-billion-transactions-in-q3-2023
ISAE 3000 (source) — Assessment Required
ISAE 3000 is the international standard for assurance engagements other than audits or reviews of historical financial information, commonly used for third-party assurance reports on controls (e.g., ISAE 3402 for service organizations, analogous to SOC 1). As a payment system operator processing transactions on behalf of 21 banks and millions of consumers, BLIK's partner banks may require ISAE 3402 (or equivalent) assurance reports to satisfy their own audit and regulatory requirements. Risk is Medium because: (1) partner banks (PKO Bank Polski, mBank, ING, Millennium, etc.) are themselves subject to strict banking regulations and may contractually require assurance reports from BLIK; (2) the KNF may expect assurance reporting as part of outsourcing oversight requirements; (3) no public evidence of ISAE 3000/3402 reports has been found, creating uncertainty. Risk is not High because BLIK's ISO 27001 certification may partially satisfy partner assurance requirements.
Evidence: https://www.blik.com/en/about-us, https://www.blik.com/en/blik-for-business
Financials
Three-year financials
- 2024:
- 2023:
- 2022:
Financial Resilience Score: 8/10
BLIK / Polski Standard Płatności is a bank-owned, systemically important payment scheme with a dominant domestic franchise in Poland. It benefits from strong network effects (~90%+ of Polish mobile-banking users can access BLIK from within their existing bank apps) and is owned by Poland's largest retail banks (PKO BP, mBank, Millennium, ING BŚ, Alior, Santander/Erste) plus Mastercard, providing capital access, distribution, and stability. In March 2023, the National Bank of Poland classified BLIK as a 'significant retail payment system,' strengthening its systemic status. Transaction volumes have grown rapidly — BLIK crossed 1 billion transactions in only 8 months in 2023, with nearly 500 million transactions in Q3 2023 alone. The product mix is diversifying from online e-commerce into contactless POS, P2P, ATM, BNPL (BLIK Pay Later, launched 2024) and cross-border transfers via EuroPA. However, precise revenue, EBIT and equity figures are not publicly disclosed on the corporate website and must be pulled from KRS filings (KRS 0000493783). Key risks include heavy geographic concentration in Poland (~100% of revenue during FY2022–FY2024), regulatory pressure on payment scheme fees (PSD3, Instant Payments Regulation, Digital Euro), and rising competition from Apple Pay, Google Pay, Visa/Mastercard, the future Digital Euro, and the pan-European Wero/EPI scheme. Execution risk exists in the early-stage Slovakia and Romania expansions, and shareholder-bank dynamics can make pricing decisions politically sensitive.
Key strengths: Dominant domestic market share in Poland across e-commerce, ATM, P2P and POS, Bank-consortium ownership (PKO BP, mBank, Millennium, ING BŚ, Alior, Santander/Erste) plus Mastercard as strategic shareholder, Strong network effects — ~90%+ of Polish mobile-banking users can access BLIK via existing bank apps, Product diversification: online, contactless POS, ATM, P2P, BNPL, cross-border (EuroPA), Classified as a 'significant retail payment system' by the National Bank of Poland (March 2023), ISO/IEC 27001 certification, Rapid transaction growth — 1 billion transactions in only 8 months in 2023, Recognized by Deloitte Technology Fast 50 CE and CNBC/Statista World's Top Fintechs 2023
Risk factors: Geographic concentration — overwhelmingly Poland-based revenue, exposed to Polish macro and PLN, Regulatory pressure on interchange / payment-scheme fees (PSD3, Instant Payments Regulation, Digital Euro), Competition from Apple Pay, Google Pay, Visa/Mastercard, future Digital Euro and Wero/EPI, Execution risk of international expansion into Slovakia and Romania (early-stage, pre-profitability), Shareholder-bank dynamics — owners are also largest distribution partners, making pricing politically sensitive
Revenue by geography
- Poland: 100%
- Romania: 0%
- Slovakia: 0%
Revenue by product/service
- P2P transfers: 0%
- BLIK Pay Later (BNPL): 0%
- BLIK contactless (POS): 0%
- Online e-commerce payments: 0%
- ATM cash withdrawals/deposits: 0%
Workforce by country
- Poland: 0
- Romania: 0
- Slovakia: 0
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.