Financial Supervision | Compliance
BaFin Compliance:
BAIT, MaRisk and DORA
BaFin (Bundesanstalt fur Finanzdienstleistungsaufsicht) is Germany's integrated financial supervisory authority - comparable to the FCA in the UK or the SEC/OCC in the US. Banks and financial institutions in Germany are subject to the strictest IT security requirements: BAIT, MaRisk and since January 2025 DORA define binding standards for IT governance, information security and digital operational resilience.
Last updated: March 2026
Overview
BaFin Regulatory Framework: Who Must Comply With What
BaFin has issued several IT-specific circulars applying to different institution types. Since January 2025, DORA has fundamentally changed the regulatory landscape.
| Framework | Scope | Status (as of 2025) |
|---|---|---|
| BAIT Supervisory Requirements for IT in Financial Institutions | Credit institutions under the KWG (German Banking Act) | Still valid (alongside DORA) |
| MaRisk Minimum Requirements for Risk Management | Credit institutions under the KWG | Still valid (IT sections supplemented by DORA) |
| DORA Digital Operational Resilience Act (EU 2022/2554) | Broad range of financial institutions (directly applicable) | In force since 17 Jan 2025 - takes precedence as EU regulation |
| VAIT Supervisory IT Requirements for Insurance Companies | (formerly insurance companies) | Repealed since 17 Jan 2025 - replaced by DORA |
| KAIT Requirements for Capital Management Companies | (formerly capital management companies) | Repealed since 17 Jan 2025 - replaced by DORA |
| ZAIT IT Supervisory Requirements for Payment Service Providers | (formerly payment service providers) | Repealed since 17 Jan 2025 - replaced by DORA |
Transition
What Applies Under DORA: The New Legal Framework Since January 2025
With effect from 17 January 2025, DORA (Digital Operational Resilience Act, EU 2022/2554) applies directly to a broad range of financial institutions. As an EU regulation, DORA is directly applicable - without national implementing legislation.
DORA has fully repealed three of the previous BaFin IT circulars: VAIT (insurance companies), KAIT (capital management companies) and ZAIT (payment service providers) are no longer in force. For credit institutions, BAIT continues alongside DORA but loses practical significance where DORA governs the same requirements directly.
For more detail on DORA requirements, scope and the ICT risk management framework, see our DORA topic page.
DORA Core Obligations at a Glance
§44 KWG
BaFin IT Audits: What Is Examined
BaFin special audits under §44 KWG can be ordered at any time. The IT audit focus areas are clearly defined - structured preparation is possible and advisable.
IT Governance
- IT strategy and documentation (BAIT AT 1)
- IT organisational structures and responsibilities
- IT reporting to management bodies
- IT budget management and resource planning
Information Risk Management
- Complete risk register for all IT systems
- Risk classification by criticality
- Regular risk assessment and updates
- Risk reports to board and supervisory board
Information Security Management
- ISMS documentation and policies
- Regular penetration tests (BAIT AT 7.3)
- Vulnerability scans and patch management
- Security awareness training
Outsourcing Management
- Complete outsourcing register (§25b KWG)
- Risk classification of all IT outsourcing
- Contractual minimum requirements (exit, audit, SLA)
- Ongoing outsourcing monitoring
Contingency & Business Continuity
- Contingency plan for critical IT systems
- Regular BCP/DR tests and documentation
- Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO)
- Communication plans for IT disruptions
Access Rights Management
- Role-based access control (RBAC)
- Privileged Access Management (PAM)
- Regular access rights reviews
- Full audit trail of privileged access
Threat Landscape
Cyber Threats in the Financial Sector: ENISA Data
The financial sector is the primary target of cybercriminals worldwide. According to the ENISA Threat Landscape for the Finance Sector 2024, 488 significant security incidents in the EU financial sector were documented - with a clearly rising trend.
BaFin reporting obligations capture only a fraction of actual incidents. Financial institutions are attractive targets not only for direct financial damage but also for systemic risk: a successful attack on a major bank can destabilise the entire financial system.
DORA has therefore significantly tightened reporting obligations and response times - 4-hour early warnings and 24-hour initial notifications are the new reality for all DORA-obligated institutions.
Financial Sector Cybersecurity in Numbers
„BaFin IT audits are not a surprise - the audit focus areas are well known. What I consistently see in practice: institutions that carry out penetration tests and documentation reviews regularly pass these audits without issue. The effort for continuous compliance is a fraction of the effort required for reactive crisis remediation.“
Oskar Braun
ISO 27001 Lead Auditor (IRCA certified) · AWARE7 GmbH
Why AWARE7 for BaFin Compliance
Was uns von anderen Anbietern unterscheidet
Reine Awareness-Plattformen testen keine Systeme. Reine Beratungskonzerne sind zu weit weg. AWARE7 verbindet beides: Wir hacken Ihre Infrastruktur und schulen Ihre Mitarbeiter - mittelstandsgerecht, persönlich, ohne Enterprise-Overhead.
Forschung und Lehre als Fundament
Rund 20% unseres Umsatzes stammen aus Forschungsprojekten für BSI und BMBF. Unsere Studien analysieren Millionen von Websites und Zehntausende Phishing-E-Mails - publiziert auf ACM- und Springer-Konferenzen. Drei unserer Führungskräfte sind gleichzeitig Professoren an deutschen Hochschulen.
Digitale Souveränität - keine Kompromisse
Alle Daten werden ausschließlich in Deutschland gespeichert und verarbeitet - ohne US-Cloud-Anbieter. Keine Freelancer, keine Subunternehmer in der Wertschöpfung. Alle Mitarbeiter sind sozialversicherungspflichtig angestellt und einheitlich rechtlich verpflichtet. Auf Anfrage VS-NfD-konform.
Festpreis in 24h - planbare Projektzeiträume
Innerhalb von 24 Stunden erhalten Sie ein verbindliches Festpreisangebot - kein Stundensatz-Risiko, keine Nachforderungen, keine Überraschungen. Durch eingespieltes Team und standardisierte Prozesse erhalten Sie einen klaren Zeitplan mit definiertem Starttermin und Endtermin.
Ihr fester Ansprechpartner - jederzeit erreichbar
Ein persönlicher Projektleiter begleitet Sie vom Erstgespräch bis zum Re-Test. Sie buchen Termine direkt bei Ihrem Ansprechpartner - keine Ticket-Systeme, kein Callcenter, kein Wechsel zwischen wechselnden Beratern. Kontinuität schafft Vertrauen.
Für wen sind wir der richtige Partner?
Mittelstand mit 50–2.000 MA
Unternehmen, die echte Security brauchen - ohne einen DAX-Konzern-Dienstleister zu bezahlen. Festpreis, klarer Scope, ein Ansprechpartner.
IT-Verantwortliche & CISOs
Die intern überzeugend argumentieren müssen - und dafür einen Bericht mit Vorstandssprache brauchen, nicht nur technische Findings.
Regulierte Branchen
KRITIS, Gesundheitswesen, Finanzdienstleister: NIS-2, ISO 27001, DORA - wir kennen die Anforderungen und liefern Nachweise, die Auditoren akzeptieren.
Mitwirkung an Industriestandards
OWASP · 2023
OWASP Top 10 for Large Language Models
Prof. Dr. Matteo Große-Kampmann als Contributor im Core-Team des international anerkannten OWASP LLM-Sicherheitsstandards.
BSI · Allianz für Cyber-Sicherheit
Management von Cyber-Risiken
Prof. Dr. Matteo Große-Kampmann als Mitwirkender des offiziellen BSI-Handbuchs für die Unternehmensleitung (dt. Version).
Frequently Asked Questions about BaFin Compliance
Answers to the most common questions about BAIT, MaRisk, DORA transition and BaFin IT audits for financial institutions.
What is BAIT and is it still valid?
What is MaRisk and how does it relate to IT security?
Which BaFin circulars concern IT security?
What changed for BAIT/VAIT/KAIT/ZAIT when DORA came into force?
What does BaFin examine in a §44 KWG special audit?
How do I prepare for a BaFin IT audit?
Do I need BAIT or DORA?
How does AWARE7 support BaFin compliance?
Aus dem Blog
Weiterführende Artikel
Alle ArtikelApproach BaFin Compliance Systematically
AWARE7 supports financial institutions with BAIT gap analyses, DORA readiness assessments and regulatory-grade penetration tests. Fixed-price proposal after a free initial assessment.
Kostenlos · 30 Minuten · Unverbindlich