DORA and the Financial Center: Why Security
3,600 financial institutions in Germany now operate under a new regulation with no grace period: the Digital Operational Resilience Act (DORA). In force since January 17, 2025, DORA demands a level of digital operational resilience that many banks, insurers, and asset managers are still building from scratch. According to Advisori, 44% of German financial firms face significant implementation hurdles. McKinsey estimates implementation costs for large institutions at €25-150 million. And Germany’s Federal Financial Supervisory Authority (BaFin) has announced systematic audits beginning in 2026. For Germany’s financial center, DORA is a litmus test: meeting its requirements demonstrates digital maturity; failing them risks not only fines but trust itself.
TL;DR
- 3,600 financial institutions in Germany affected: Out of 22,000 across the EU. DORA has applied fully since January 17, 2025 – with no transition period and no exemptions.
- €25-150 million implementation cost: For large institutions – five to ten times their initial program budget. Seventy percent anticipate permanently higher operating costs for technology and oversight (McKinsey).
- 44% facing significant implementation challenges: The average compliance level among German financial institutions stands at roughly two-thirds of DORA’s full requirements (Advisori).
- 19 critical ICT third-party providers under direct EU supervision: Including Deutsche Telekom and SAP. For the first time, European Supervisory Authorities (ESAs) are auditing cloud providers directly.
- BaFin launches systematic audits in 2026: Reporting window for the Information Register runs March 9-30, 2026. BAIT will be fully repealed by December 31, 2026.
What DORA Requires from Financial Institutions
DORA rests on five pillars that together form a comprehensive framework for digital operational resilience. It’s not enough to implement isolated measures – the BaFin expects an integrated system.
Pillar 1: ICT Risk Management. A holistic framework covering asset identification, risk analysis, protective controls, threat detection, incident response, and disaster recovery. No financial institution may operate without documented ICT risk management. That sounds obvious – but in practice, it isn’t: many smaller asset managers and payment service providers have relied on informal processes until now.
Pillar 2: Incident Management and Reporting. Mandatory reporting of major ICT incidents. While timelines draw inspiration from NIS2, they’re DORA-specific: early warning, incident notification, and final report. Any institution lacking a functional reporting process violates the law from its very first incident.
Pillar 3: Digital Operational Resilience Testing. Regular stress tests and scenario-based exercises. Systemically important institutions must also conduct Threat-Led Penetration Testing (TLPT): simulated attacks by external red teams replicating real-world threat scenarios. This marks a quantum leap beyond traditional annual penetration tests.
Pillar 4: Third-Party Risk Management. All ICT third-party contracts must include DORA-compliant clauses: service-level agreements (SLAs), audit rights, termination rights, exit strategies, and incident notification obligations. For a bank with hundreds of IT contracts, this means a complete review – and likely renegotiation – of its entire contract portfolio.
Pillar 5: Cyber Threat Information Sharing. Voluntary but strongly encouraged exchange of threat intelligence among financial institutions. The DCSO (backed by Allianz, BASF, Bayer, and VW) leads here – but the financial sector needs its own dedicated formats.
Sources: EU DORA Regulation 2022/2554, BaFin
What BaFin Has Planned for 2026
Jens Obermoeller, Head of IT Supervision at BaFin, has laid out the agency’s direction clearly. In a recent expert interview, he noted: “Concentration on just a few vendors on one side – and a fragmented value chain on the other – makes it harder to control critical processes. An incident at a systemically important IT provider could trigger a domino effect impacting the entire financial market.”
In February 2026, BaFin hosted workshops for the second round of Information Register submissions. The reporting window runs March 9-30, 2026. For 2026 and 2027, BaFin has announced systematic audits and follow-up reviews – focused squarely on the quality and completeness of those registers. This marks the shift from rollout to enforcement.
Of particular significance for the market: BAIT (the Bank Supervisory Requirements for IT), Germany’s central IT regulatory framework since 2017, will be fully repealed as of December 31, 2026. DORA replaces BAIT not only substantively but formally. Institutions that previously aligned with BAIT now face a completely new regulatory reference framework. BAIT compliance does not guarantee DORA compliance – because DORA goes significantly further in several areas.
The Cost Question: €25-150 Million
The McKinsey analysis of DORA implementation costs is sobering. Just for strategy, planning, and orchestration, consultants estimate €5-15 million. Total implementation costs for large institutions range from €25-150 million – five to ten times their original program budget. Seventy percent of respondents expect permanently higher operating costs for technology and controls.
Forty percent of financial institutions and ICT providers assign more than seven full-time staff to their DORA compliance programs. Only one-third expressed confidence in meeting all requirements by the January 2025 deadline. Fifty percent expected full compliance by end-2025; 38% not until 2026.
For mid-sized financial institutions – regional banks, specialized insurers, and payment service providers – Advisori estimates six to twelve months for substantial compliance and twelve to eighteen months for full compliance. As noted earlier, 44% of German financial institutions face significant implementation challenges, with average progress standing at about two-thirds of DORA’s full scope.
Fines for noncompliance are steep: up to 10% of annual turnover or €10 million for serious violations. Individual executives face penalties of up to €1 million – making DORA compliance a personal liability issue at board level.
19 Critical Third Parties Under Direct EU Oversight
On November 18, 2025, the European Supervisory Authorities (EBA, ESMA, EIOPA) published – for the first time – a list of 19 critical ICT third-party providers (CTPPs). For the first time in financial supervision history, cloud providers and IT service firms fall under direct EU oversight.
On the list are names including Amazon Web Services, Microsoft, Google Cloud, IBM, Oracle, Accenture, Capgemini, and NTT DATA. Two German companies appear: Deutsche Telekom AG and SAP SE. Criteria for designation include systemic impact if the provider fails, importance to dependent financial institutions, concentration risk, and substitutability.
This has two key implications for Germany’s financial center: First, Deutsche Telekom and SAP – as service providers to banks and insurers – will now undergo direct scrutiny by the ESAs. That raises expectations around governance, security standards, and incident reporting. Second, German financial institutions using these providers must still demonstrate their own third-party oversight. EU supervision of CTPPs doesn’t relieve institutions of their duty to assess and document vendor compliance themselves.
AWS confirmed its designation on its Security Blog and pledged cooperation with supervisory authorities. Key audit areas include incident reporting, subcontracting practices, ICT security, and governance.
DORA vs. NIS2: Which Applies When?
The most common practical question: Must financial institutions comply with both DORA and NIS2? The answer is clearer than often assumed.
DORA is an EU regulation (directly applicable); NIS2 is a directive (requiring national transposition). The legal principle of lex specialis applies: DORA takes precedence over NIS2 for ICT risks in the financial sector. Banks and credit institutions fall under DORA – not NIS2. So do financial market infrastructures (trading venues, central counterparties).
Key differences in detail: NIS2 recommends vulnerability assessments; DORA mandates Threat-Led Penetration Testing (significantly more demanding). On third parties, DORA introduces direct supervision of CTPPs, while NIS2 requires only risk management – not direct oversight. And while NIS2 regulates 18 sectors across industries, DORA focuses exclusively on finance – applying more specific and stringent requirements.
For organizations delivering both financial services and operating critical infrastructure (e.g., an insurer running its own data centers), both regulations may apply: DORA governs financial activities; NIS2 covers infrastructure operations.
The Counterargument: Overregulation of the Financial Sector?
Criticism of DORA is real – and comes from within the industry itself. Implementation costs of €25-150 million for a regulation with no transition period place enormous strain on institutions – especially smaller ones. Regional savings banks and cooperative banks, which operated successfully under BAIT, now face EU-wide standards designed for global megabanks.
Compounding the pressure is regulatory overlap: DORA, NIS2, and the AI Act collectively create a density of rules unmatched anywhere in the world. A financial services firm using AI for credit decisions may find itself subject to all three simultaneously. Compliance departments grow – but core business value creation does not.
And the CTPP oversight creates a paradox: If the EU directly supervises major cloud providers, consolidation may follow. Smaller cloud vendors unable to bear the regulatory burden may exit the financial sector entirely – increasing dependence on the largest players rather than reducing it.
Why DORA Is Still a Strategic Advantage
The counterbalance makes a strong case for DORA: A single severe cyber incident at a German bank could cause billions in losses, shake confidence in the country’s financial hub, and trigger regulatory consequences far exceeding DORA fines.
Frankfurt’s financial center competes with London, Paris, and Amsterdam. In an environment where international investors treat cybersecurity maturity as a quality signal, DORA compliance becomes a location advantage. A financial center that demonstrably delivers resilience attracts more capital than one that merely claims it.
German institutions also hold a head start: BAIT experience since 2017 has built a foundational layer of compliance upon which DORA can build. The German Banking Industry Committee emphasizes that German financial institutions are widely regarded as “pioneers in security and compliance.” DORA elevates requirements to EU-wide standards – but Germany isn’t starting from zero.
Five Steps Toward DORA Compliance
1. Build and submit your Information Register. BaFin’s reporting window for the second submission runs March 9-30, 2026. The register must include all ICT third-party contracts, along with SLAs, criticality assessments, and exit strategies. Institutions that missed Round One must catch up now.
2. Formalize your ICT risk management framework. Documented processes for asset identification, risk analysis, protective controls, and incident response. The framework must be approved by the board and reviewed regularly. Existing BAIT documentation provides a solid foundation – but must be expanded to meet DORA’s broader scope.
3. Review contracts with ICT third-party providers. Every contract must contain DORA-compliant clauses: audit rights, SLAs with measurable KPIs, termination rights, exit strategies, and incident notification obligations. With hundreds of contracts, this is a multi-month undertaking.
4. Plan Threat-Led Penetration Testing (TLPT). TLPT is mandatory for systemically important institutions. It requires qualified external red teams capable of simulating realistic threat scenarios. Tests require BaFin approval and formal reporting. Start early – qualified TLPT providers are scarce.
5. Establish board-level reporting. DORA makes ICT risk management a board responsibility. Regular reports to the board and supervisory board must cover ICT risk profiles, incidents, and compliance status. Delegating this solely to IT – without active board involvement – violates both the spirit and likely the letter of the regulation.
Conclusion
DORA represents the most stringent ICT regulation the European financial sector has ever seen. Three thousand six hundred institutions in Germany face implementation costs up to €150 million. Forty-four percent struggle with significant hurdles. BaFin shifts into enforcement mode in 2026. And 19 critical ICT third-party providers now face direct EU supervision for the first time. For Germany’s financial center, this is both a challenge and an opportunity: Demonstrating DORA compliance proves digital resilience in a market where trust is the hardest currency.
Frequently Asked Questions
Every question is locked. A tap unlocks the answer.
Does DORA apply to small financial institutions?
Yes – but proportionally. Small institutions must fulfill core obligations (ICT risk management, incident reporting, third-party oversight) but may use simplified frameworks. Threat-Led Penetration Testing is mandatory only for systemically important institutions. BaFin has stated it will consider an institution’s size and complexity during audits.
What happens to BAIT?
The Bank Supervisory Requirements for IT will be fully repealed as of December 31, 2026. DORA replaces BAIT as the official regulatory reference. Institutions already compliant with BAIT have a strong foundation – but must enhance it in several areas: TLPT, third-party oversight, and the formalized Information Register all go beyond BAIT’s scope.
How does DORA differ from NIS2?
DORA serves as lex specialis for the financial sector and takes precedence over NIS2 for ICT risks. DORA is stricter: it mandates Threat-Led Penetration Testing instead of basic vulnerability assessments, introduces direct supervision of critical third parties (not just risk management), and imposes more precise incident reporting requirements. Banks fall under DORA – not NIS2.
What does the CTPP list mean for cloud customers?
Financial institutions using AWS, Azure, Google Cloud, SAP, or Deutsche Telekom benefit from additional EU oversight of those providers. But: CTPP supervision does not replace an institution’s own due diligence. Each institution must still independently verify and document whether its cloud provider meets DORA’s requirements.
What does DORA compliance cost a mid-sized institution?
According to Advisori: six to twelve months for substantial compliance, twelve to eighteen months for full compliance. Direct costs depend heavily on starting position. Institutions with existing BAIT compliance begin from a stronger footing than those without. McKinsey estimates total costs for large institutions at €25-150 million. For mid-sized institutions – regional banks, specialized insurers – the realistic range is €1-5 million, depending on complexity.
Further Reading
NIS2 in Germany: What Companies Need to Implement Now (SecurityToday)
Incident Response Made in Germany: BSI and DCSO (SecurityToday)
NIS2 as a Competitive Advantage (SecurityToday)
Reboot Germany: €735 Billion Investments (MyBusinessFuture)
Header Image Source: Pexels / Pixabay (px:210574)