Financial Supervision | Compliance
BaFin Compliance: BAIT, MaRisk and DORA
BaFin (Bundesanstalt fur Finanzdienstleistungsaufsicht) is Germany's integrated financial supervisory authority - comparable to the FCA in the UK or the SEC/OCC in the US. Banks and financial institutions in Germany are subject to the strictest IT security requirements: BAIT, MaRisk and since January 2025 DORA define binding standards for IT governance, information security and digital operational resilience.
Last updated: March 2026
- BaFin IT Circulars
- 5
- BAIT, MaRisk + DORA since 01/2025
- VAIT repealed
- 17 Jan 2025
- KAIT and ZAIT also repealed
- ENISA Finance Incidents
- 488
- Reported incidents in EU financial sector (2023)
- Banks with cyber incident
- 61%
- According to EBA/ENISA Threat Landscape
Overview
BaFin Regulatory Framework: Who Must Comply With What
BaFin has issued several IT-specific circulars applying to different institution types. Since January 2025, DORA has fundamentally changed the regulatory landscape.
| Framework | Scope | Status (as of 2025) |
|---|---|---|
| BAIT Supervisory Requirements for IT in Financial Institutions | Credit institutions under the KWG (German Banking Act) | Still valid (alongside DORA) |
| MaRisk Minimum Requirements for Risk Management | Credit institutions under the KWG | Still valid (IT sections supplemented by DORA) |
| DORA Digital Operational Resilience Act (EU 2022/2554) | Broad range of financial institutions (directly applicable) | In force since 17 Jan 2025 - takes precedence as EU regulation |
| VAIT Supervisory IT Requirements for Insurance Companies | (formerly insurance companies) | Repealed since 17 Jan 2025 - replaced by DORA |
| KAIT Requirements for Capital Management Companies | (formerly capital management companies) | Repealed since 17 Jan 2025 - replaced by DORA |
| ZAIT IT Supervisory Requirements for Payment Service Providers | (formerly payment service providers) | Repealed since 17 Jan 2025 - replaced by DORA |
Transition
What Applies Under DORA: The New Legal Framework Since January 2025
With effect from 17 January 2025, DORA (Digital Operational Resilience Act, EU 2022/2554) applies directly to a broad range of financial institutions. As an EU regulation, DORA is directly applicable - without national implementing legislation.
DORA has fully repealed three of the previous BaFin IT circulars: VAIT (insurance companies), KAIT (capital management companies) and ZAIT (payment service providers) are no longer in force. For credit institutions, BAIT continues alongside DORA but loses practical significance where DORA governs the same requirements directly.
For more detail on DORA requirements, scope and the ICT risk management framework, see our DORA topic page.
DORA Core Obligations at a Glance
Complete ICT risk register, risk classification, control mechanisms and reporting to management bodies. Management bodies bear personal responsibility for adequate DORA compliance.
4-hour early warning, 24-hour initial notification, 72-hour detailed report and 1-month final report for significant ICT incidents to the competent authority.
For significant institutions: regulatory mandated advanced penetration tests (Threat-Led Penetration Testing, TLPT) every 3 years following the TIBER-EU methodology.
Complete register of all ICT third-party service providers, risk classification, contractual DORA minimum requirements, exit strategies. Critical ICT service providers are supervised directly by EBA/ESMA/EIOPA.
§44 KWG
BaFin IT Audits: What Is Examined
BaFin special audits under §44 KWG can be ordered at any time. The IT audit focus areas are clearly defined - structured preparation is possible and advisable.
IT Governance
- IT strategy and documentation (BAIT AT 1)
- IT organisational structures and responsibilities
- IT reporting to management bodies
- IT budget management and resource planning
Information Risk Management
- Complete risk register for all IT systems
- Risk classification by criticality
- Regular risk assessment and updates
- Risk reports to board and supervisory board
Information Security Management
- ISMS documentation and policies
- Regular penetration tests (BAIT AT 7.3)
- Vulnerability scans and patch management
- Security awareness training
Outsourcing Management
- Complete outsourcing register (§25b KWG)
- Risk classification of all IT outsourcing
- Contractual minimum requirements (exit, audit, SLA)
- Ongoing outsourcing monitoring
Contingency & Business Continuity
- Contingency plan for critical IT systems
- Regular BCP/DR tests and documentation
- Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO)
- Communication plans for IT disruptions
Access Rights Management
- Role-based access control (RBAC)
- Privileged Access Management (PAM)
- Regular access rights reviews
- Full audit trail of privileged access
Threat Landscape
Cyber Threats in the Financial Sector: ENISA Data
The financial sector is the primary target of cybercriminals worldwide. According to the ENISA Threat Landscape for the Finance Sector 2024, 488 significant security incidents in the EU financial sector were documented - with a clearly rising trend.
BaFin reporting obligations capture only a fraction of actual incidents. Financial institutions are attractive targets not only for direct financial damage but also for systemic risk: a successful attack on a major bank can destabilise the entire financial system.
DORA has therefore significantly tightened reporting obligations and response times - 4-hour early warnings and 24-hour initial notifications are the new reality for all DORA-obligated institutions.
Financial Sector Cybersecurity in Numbers
BaFin-reported ICT incidents per year (estimate, actual figure likely higher)
Significant ENISA incidents in EU financial sector (2023)
DDoS attacks as the most common attack type against financial institutions
Banks that experienced a significant cyber incident in the last 3 years
Ransomware share in successful attacks on financial institutions
DORA early warning deadline from detection of a major ICT incident
Sources: ENISA Threat Landscape for the Finance Sector 2024; EBA Risk Assessment Report 2024; BaFin Annual Report 2024.
„BaFin IT audits are not a surprise - the audit focus areas are well known. What I consistently see in practice: institutions that carry out penetration tests and documentation reviews regularly pass these audits without issue. The effort for continuous compliance is a fraction of the effort required for reactive crisis remediation.“
Oskar Braun
ISO 27001 Lead Auditor (IRCA certified) · AWARE7 GmbH
Why AWARE7 for BaFin Compliance
What sets us apart from other providers
Pure awareness platforms don't test systems. Pure consulting firms are too far removed. AWARE7 combines both: we hack your infrastructure and train your employees: tailored to mid-sized companies, personal, without enterprise overhead.
Research and teaching as our foundation
20 %Around 20% of our revenue comes from research projects for the BSI and the BMBF. Our studies, published at ACM and Springer conferences, analyse millions of websites and tens of thousands of phishing emails. Three of our executives are professors at German universities at the same time.
Digital sovereignty: no compromises
100 %From first contact to final report, your data is stored on our own servers in Germany - no US cloud providers, no third-country transfers. Our AI also runs on our own hardware in Germany - with locally operated open-source models. Client and project data never reach external AI services. All staff are permanently employed, covered by social insurance and bound by uniform legal obligations.
More on digital sovereigntyFixed price within 24h: predictable project timelines
24 hWithin 24 hours you receive a binding fixed-price quote without hourly rate risk. A well-practised team and standardised processes ensure a clear schedule with a defined start and end date.
Your dedicated contact
1:1A personal project manager accompanies you from the first meeting to the retest. You book appointments directly with your contact person and keep the same contact throughout the project.
Peer-reviewed publications
Different Seas, Different Phishes - Large-Scale Analysis of Phishing Simulations
ACM AsiaCCS 2025
Oskar Braun, Jan Hörnemann, Norbert Pohlmann, Matteo Große-Kampmann
A Platform for Physiological and Behavioral Security
NSPW 2025
Jan Hörnemann
Privacy from 5 PM to 6 AM: Tracking and Transparency in the HbbTV Ecosystem
IEEE/IFIP DSN 2025
Jan Hörnemann, Norbert Pohlmann, Matteo Große-Kampmann
Understanding Regional Filter Lists: Efficacy and Impact
PoPETS 2025
Jan Hörnemann, Norbert Pohlmann, Matteo Große-Kampmann
Who is AWARE7 the right partner for?
Mid-sized companies with 50-2,000 employees
Companies that need real security, without paying for a DAX-corporation provider. Fixed price, clear scope, one point of contact.
IT managers & CISOs
Who have to argue convincingly in-house and need a report in boardroom language for that, not just technical findings.
Regulated industries
Critical infrastructure, healthcare, financial services: NIS-2, ISO 27001, DORA. We know the requirements and deliver evidence that auditors accept.
FAQ
Frequently Asked Questions about BaFin Compliance
Answers to the most common questions about BAIT, MaRisk, DORA transition and BaFin IT audits for financial institutions.
What is BAIT and is it still valid?
What is MaRisk and how does it relate to IT security?
Which BaFin circulars concern IT security?
What changed for BAIT/VAIT/KAIT/ZAIT when DORA came into force?
What does BaFin examine in a §44 KWG special audit?
How do I prepare for a BaFin IT audit?
Do I need BAIT or DORA?
How does AWARE7 support BaFin compliance?
Aus dem Blog
Weiterführende Artikel
Datenbanksicherheit: PostgreSQL, MySQL und MSSQL richtig absichern
Datenbank-Härtung für PostgreSQL, MySQL und MSSQL: Least-Privilege-Rollen, Audit-Logging, Verschlüsselung und SQL-Injection-Prävention.
Der Informationssicherheitsbeauftragte - Zuständigkeiten und Aufgaben!
Der Informationssicherheitsbeauftragte ist der Ansprechpartner für Informationssicherheit im Unternehmen. Diese Aufgaben hat er!
PCI DSS: Der Sicherheitsstandard für Kreditkartenzahlungen erklärt
Erfahren Sie, warum PCI DSS für Unternehmen, die Kreditkartenzahlungen akzeptieren, unverzichtbar ist und schützt.
Approach BaFin Compliance Systematically
AWARE7 supports financial institutions with BAIT gap analyses, DORA readiness assessments and regulatory-grade penetration tests. Fixed-price proposal after a free initial assessment.
Free · 30 minutes · No obligation