In Germany, BaFin enforces DORA for banking, insurance, and investment firms. German financial entities must reconcile DORA with existing BaFin requirements (MaRisk, BAIT, VAIT, KAIT).
BaFin (Federal Financial Supervisory Authority) + BSI for cybersecurity aspects
BaFin can impose fines, require remediation measures, restrict business activities, or revoke licenses. Criminal liability possible under KWG (Banking Act).
What DORA requires from organizations operating in Germany.
Germany's MaRisk and BAIT frameworks already impose strict IT risk requirements. BaFin has indicated it will align these with DORA rather than create parallel obligations. The BSI provides TLPT testing standards for the German market.
In Germany, BaFin enforces DORA for banking, insurance, and investment firms. German financial entities must reconcile DORA with existing BaFin requirements (MaRisk, BAIT, VAIT, KAIT).
BaFin (Federal Financial Supervisory Authority) + BSI for cybersecurity aspects
BaFin can impose fines, require remediation measures, restrict business activities, or revoke licenses. Criminal liability possible under KWG (Banking Act).

Run a free scan to see your risk score and applicable obligations.