DORA regulation in Germany
This page explains how the Digital Operational Resilience Act works in Germany: what BaFin and the Bundesbank expect, how the register of information and threat-led penetration tests run, and where the people who carry DORA duties at banks, insurers and IT providers meet. Dates are in the calendar below.
What DORA means for a financial firm in Germany
DORA is the Digital Operational Resilience Act, Regulation (EU) 2022/2554. It is one EU rulebook for how banks, insurers, asset managers, payment institutions and crypto-asset service providers keep their IT running, report failures and control their IT suppliers. As an EU regulation it is law in Germany without a German act of transposition, and every firm in its scope applies the same text as a firm in Vienna or Paris.
For German compliance teams the bigger change was the end of the national IT circulars they had worked with for years. BaFin withdrew the circulars for insurers (VAIT), fund managers (KAIT) and payment institutions (ZAIT) on the day before DORA took effect, and it is phasing out BAIT for banks. A bank under DORA no longer applies BAIT. The German Financial Market Digitalization Act (FinmadiG) pulls further institutions in: according to the Deutsche Bundesbank, promotional banks apply DORA from the start and financial services institutions such as leasing and factoring firms follow later. When the last of them has moved, BAIT is gone.
Who supervises DORA in Germany
BaFin is the competent authority for DORA in Germany. It takes the incident reports and the register of information, and it selects the firms that must run threat-led penetration tests. BaFin describes the rules as proportional and risk-based, so a small payment institution documents less than a large bank, but both follow the same regulation. The Bundesbank supports the tests and carries out on-site examinations at banks.
Above the national level, the three European Supervisory Authorities oversee the IT providers themselves. One of them, the insurance authority EIOPA, has its seat in Frankfurt. The authorities designated the first critical ICT third-party providers in a list of 19 names. According to PwC Legal, the list includes two German companies, Deutsche Telekom and SAP, next to Amazon Web Services, Google Cloud and Microsoft. For a German bank this means its cloud provider now has its own supervisor, while the bank stays fully responsible for its own compliance.
The register of information and incident reporting
Every firm under DORA keeps a register of information. It lists all contracts with ICT third-party service providers and, for services that support critical or important functions, the subcontractors behind them. BaFin collects the register once a year, only through its reporting platform MVP, with contract data as of December 31 of the previous year. The filing has to pass BaFin's checks without errors by March 31; a rejected file comes back with an error log and goes in again.
The old outsourcing notices did not disappear. BaFin still wants ICT outsourcing reported through the MVP procedure "Anzeige von Auslagerungen", and it wants to hear in advance when a firm plans a contract for a critical or important function. Major ICT-related incidents go to BaFin in three steps: an initial notification, an intermediate report and a final report, as set out in Article 19 of DORA.
Threat-led penetration testing and TIBER-DE
A threat-led penetration test (TLPT) is a controlled attack on the critical live production systems of a financial firm. An external red team plans it from current threat intelligence and attacks the way a real group of hackers would. BaFin decides which firms must test and tells each one whether it tests every three years or at another rhythm. The Bundesbank accompanies every test.
The method is older than DORA. The Bundesbank introduced the European TIBER framework in Germany as TIBER-DE, and banks took part on a voluntary basis. Under DORA the most critical firms must now run these tests, and the revised framework allows internal testers under certain conditions. The Bundesbank unit that runs the tests is its TIBER Cyber Team.
What DORA teams in Germany work on now
Much of the daily work sits between three departments. IT security owns the ICT risk management framework, procurement and legal own the contracts with IT suppliers, and the ICT risk control function checks the work of both. Under DORA the management body bears the ultimate responsibility for ICT risk, so board members now sign off on topics that used to stay in the IT department.
The register comes back every year with strict data checks. BaFin tests every file and returns an error log, so contract data from purchasing, IT and legal has to match down to the subcontractor. Concentration risk is the second topic: the designation of critical providers reflects, in the words of PwC Legal, "systemic reliance on a small set of providers". A third is the link to other laws. A bank that scores consumer credit with AI also answers to the EU AI Act, and a crypto-asset service provider licensed under MiCA applies DORA as well. Someone new to the field should start with the register of information and the incident classification criteria, because both are yearly or daily routines with a direct line to BaFin.
Upcoming events on risk and compliance in Germany
DORA at Finance Loop
Finance Loop is the meeting place for IT risk managers, information security officers and compliance staff at banks, insurers, asset managers and their IT providers. It connects the finance, IT and AI communities in Frankfurt and holds events in Munich, Berlin and Hamburg as well.
Finance Loop announced KI Exchange 2026 in Hamburg, a conference by Payment & Banking whose program listed AI governance and DORA compliance, with speakers expected from BaFin. At the AI Week Frankfurt side event, presented by Finance Loop with Frankfurt Main Finance and Sopra Financial Technology, revel8 spoke on deepfake awareness. Finance Loop co-organized the Frankfurt Quantum Finance Forum with Frankfurt School, the Deutsche Bundesbank and IBM, where quantum risk to cryptography is on the agenda. Many evenings take place at TechQuartier, with which Finance Loop is built in collaboration. Related pages: cybersecurity in finance in Germany, the EU AI Act in finance, risk management in Frankfurt and crypto regulation in Germany.
Investment & Digital Assets
Payments & Digital Money
What is DORA in banking?
In banking, DORA is the set of EU rules for ICT risk. A bank must run an ICT risk management framework, classify and report major IT incidents, test its systems, keep a register of all IT service contracts and manage the risk of its IT suppliers. The DORA answer in the knowledge hub goes through the five chapters.
Does DORA apply to banks in Germany?
Yes. Every credit institution in Germany applies DORA directly, and BaFin supervises it. The national BAIT circular no longer applies to banks under DORA. Some institutions outside the CRR, such as leasing and factoring firms, move into DORA later under FinmadiG, as the Bundesbank explains.
What are the DORA requirements for ICT providers?
An ICT provider needs no DORA license, but its customers carry duties toward it: before they sign, they assess whether the service supports a critical or important function and check concentration risk, and afterwards they list the provider in the register of information. Providers that the European Supervisory Authorities designate as critical, such as Deutsche Telekom and SAP, come under direct EU oversight, with a Lead Overseer that can impose daily penalty payments.
Is there a DORA conference in Germany?
BaFin runs its own conference on IT supervision in the financial sector, which has reviewed the first year of DORA. Conferences on AI in finance, such as KI Exchange in Hamburg, put DORA compliance on their agenda as well. Dates of events that Finance Loop runs or supports are in the calendar on this page.
About Finance Loop: DORA in Germany
Finance Loop brings people who answer for ICT risk at financial firms together with the IT providers and supervisors they work with, at Finance Loop events across Germany, Austria and Switzerland.
Finance Loop is a professional network and has the goal of driving the adoption of emerging technologies in finance, such as AI, tokenization, stablecoins, and DeFi. Finance Loop helps its members build skills and personal networks in these fields: Investment & Digital Assets, Payments & Digital Money, and Risk & Compliance.