Cybervize
DORA for financial services

Putting DORA into operation. With a CISO who keeps the evidence.

Since 17 January 2025, DORA has applied to credit institutions, insurers, payment and e-money institutions, investment firms, fund managers and other financial entities. Our vCISO leads the implementation of the information security obligations that follow from it and works with OdySecure, the security platform by Cybervize. Where the CISO function is vacant for a limited period, an Interim CISO steps in.

Book the DORA classification

DORA at a glance

Applies
since 17 January 2025, directly as an EU regulation
Covers
credit institutions, insurers, payment and e-money institutions, investment firms, fund managers and other financial entities
Five areas of obligation
ICT risk management, handling and reporting of ICT-related incidents, digital operational resilience testing, ICT third-party risk, register of information
Accountability
with the management body, including regular training on ICT risk
Supervisor
BaFin, which also receives reports of major ICT-related incidents
Remains from the BSIG
registration under § 33 BSIG, provided the company counts as an essential or important entity under the BSIG

Whether and to what extent DORA applies depends on the type of financial entity; the final classification needs a case-by-case review. Whether registration under § 33 BSIG is required depends on entity type and size thresholds under § 28 BSIG. DORA alone does not make a company an Annex 1 entity under the German BSIG.

More about DORA for financial services

What DORA requires, and what remains from the BSIG

DORA covers considerably more financial entities than Annex 1 to the German BSIG ("Anlage 1"): besides credit institutions, payment and e-money institutions, investment firms, insurance and reinsurance undertakings, fund managers, crypto-asset service providers, credit rating agencies and crowdfunding service providers. For day-to-day operations, DORA is the rulebook. Falling under DORA alone does not make an entity an Anlage-1 entity. Credit institutions, trading venues and central counterparties, by contrast, are often in both circles. Whether DORA, BSIG duties or both apply depends on entity type, size thresholds and concrete activity. The legally binding evaluation remains a matter for specialised counsel.

01

DORA financial entities: core BSIG duties do not apply

Section 28(6) no. 1 of the German BSIG exempts DORA financial entities from §§ 30, 31, 32, 35, 36, 38 and 39 BSIG; by its wording the exemption applies to the entity as a whole. ICT risk management and incident reporting run under DORA via BaFin. The BSI supervisory and enforcement powers under §§ 61 and 62 BSIG are not on that list and remain in place. So does registration under § 33 BSIG, provided the company counts as an essential or important entity under the BSIG.

02

Annex 1 to the BSIG names only three entity types

Annex 1 to the German BSIG covers credit institutions (no. 3.1.1), trading venues (no. 3.2.1) and central counterparties (no. 3.2.2) from the financial sector. Insurers and payment service providers do not become Anlage-1 entities by industry alone; their DORA status does not create a classification under the BSIG. Whether a classification exists has to be checked for each legal entity.

03

TPRM with 19 mandatory fields, aligned with the EBA draft

EBA consultation paper CP/2025/12 (draft, not final) outlines a contract register with 19 mandatory fields, subcontractor chains, documented due diligence, concentration risk and exit strategies. The EBA published the final guidelines on 18 September 2026; the register in OdySecure is aligned with the consultation draft. Outsourcing register on demand for BaFin requests.

04

Reporting paths need triage from the start

DORA financial entities report major ICT-related incidents to BaFin under DORA; the BSIG reporting duty under § 32 does not apply to them. On top of this come MaRisk reporting duties and, for data breaches, the data-protection authority. The reporting logic needs clear triage at the start of an incident.

What applies in financial services, and what sits in the catalogue

DORA is not one document but a framework with seven technical standards, each demanding its own evidence. National supervisory law sits alongside it. In OdySecure they share one catalogue and one data foundation.

  • ISO/IEC 27001The shared language of the management system.123 records, reference
  • DORA RTS ICT risk managementThe technical standard filling in the risk management framework.30 records, full catalogue
  • DORAThe regulation itself: digital operational resilience in financial services.21 records, full catalogue
  • DORA RTS ICT third-party contractsContract policy for ICT services supporting critical functions.20 records, full catalogue
  • MaRisk, 9th amendmentGerman supervisory requirements for banks.14 records, full catalogue
  • PCI DSS v4.0.1Security in card payment processing.12 records, reference

The catalogue carries all seven DORA legal acts, including incident classification, reporting templates, the information register, subcontracting and threat-led penetration testing. NIS-2 is added where it applies alongside DORA.

Full catalogue with depth and type of assurance

Five implementation areas under DORA

DORA covers ICT risk management, incidents, resilience testing, third-party risk and information sharing. The register of information belongs to third-party risk; we run it as an implementation area of its own. This is how your vCISO implements the information security obligations and keeps the evidence in OdySecure.

01

ICT risk management (Chapter II)

A documented ICT risk management framework for which the management body is accountable. Risk register with business processes, IT applications and critical ICT service providers, plus business continuity and recovery plans with RTO and RPO per critical function.

02

Handling and reporting of ICT-related incidents (Chapter III)

Incidents are recorded and classified, and the major ones are reported to BaFin. The triage process at the start of an incident separates the DORA report from the report to the data-protection authority and is documented for the audit.

03

Digital operational resilience testing (Chapter IV)

A testing programme with periodic tests of ICT systems, and threat-led penetration testing for financial entities designated by the supervisor. Results and measures sit on the platform.

04

ICT third-party risk (Chapter V)

Strategy for ICT third-party service providers, contractual provisions under Article 30 DORA, concentration risk with cloud providers, subcontractor chains and exit strategies for services supporting critical functions.

05

Register of information (Article 28 DORA)

A register of all contractual arrangements with ICT third-party service providers, available to the supervisor on request. The contract data comes from the TPRM module; the requirements for it sit in the catalogue as a DORA legal act.

Why Cybervize is credible in the financial sector

“Alexander Busse supported us with Cybervize as Interim CISO in the DORA implementation and the ISO 27001 audit. We achieved both.” (Lorenz Jüngling, Co-CEO & Managing Director, Moonfare; translated from the German original)

DORA
All seven DORA catalogues in OdySecure
CP/2025/12
TPRM register aligned with the EBA draft
BaFin
Supervisory reporting templates
Moonfare
Interim CISO, DORA, ISO 27001

Frequently asked questions from financial services

Not in substance. § 28 Abs. 6 Nr. 1 of the German BSIG exempts DORA financial entities from §§ 30, 31, 32, 35, 36, 38 and 39 BSIG: ICT risk management and incident reporting run under DORA via BaFin. What remains is registration under § 33 BSIG, provided your company counts as an essential or important entity under the BSIG; entity type and size thresholds decide that. DORA alone does not make a company an Annex 1 entity. Where the registration duty applies, the deadline is three months from the point the conditions are met. Management responsibility remains: DORA assigns it to the management body itself, including regular ICT risk training.

The vCISO leads the implementation of the information security obligations: ICT risk management, the incident process, the testing programme, oversight of ICT third-party providers and the evidence in OdySecure. Overall accountability stays with the management body. Legal classification and contract negotiations stay with your departments or your counsel.

EBA/CP/2025/12 (draft) is a consultation paper and outlines 19 fields, including: unique contract number, function, criticality, data flows, data location, subcontractor identity, contractual SLA, termination conditions, exit strategy. OdySecure contains a prepared outsourcing register with all 19 fields and AI support for contract analysis. The EBA published the final guidelines on 18 September 2026; the register is aligned with the consultation draft.

The BAIT, BaFin’s circular on IT requirements, are being phased out: BaFin removed DORA-covered financial entities from the BAIT scope as of 17 January 2025, and according to BaFin the remaining BAIT will be repealed step by step by the end of 2026. BaFin repealed the VAIT in January 2025. The MaRisk, BaFin supervisory expectations rather than a statute, remain in force. Your vCISO manages the information security requirements from DORA and MaRisk in OdySecure from a single control set; credit, market and liquidity risk stay with your risk controlling function.

If contracts exist digitally, typically 4 to 8 weeks to a fit-for-supervision register. The AI-supported contract analysis extracts EBA mandatory fields largely automatically, the compliance team verifies and supplements. Manual capture takes substantially longer.

Under a vCISO mandate from €3,600 per month, with OdySecure included. For a temporary gap, an Interim CISO typically costs €8,000 to €15,000 per month, project-based. Firms with their own CISO license the platform on its own from €12,900 per year; the tiers are on the pricing page. The initial call delivers a first cost estimate.

Classify your DORA position in an initial call

Free initial call with an indicative classification of DORA scope, open areas of obligation and a possible registration under the BSIG, plus the right route: vCISO mandate, Interim CISO or platform licence. Ideally with IT risk management and compliance present.

Book the DORA classification

Under DORA? How you get to demonstrable resilience

First it becomes clear which of the five areas of obligation are open and whether a registration under the BSIG is required. Then the question is who closes the gaps: a vCISO working with OdySecure, an Interim CISO for a temporary gap, or your own team with a platform licence.

Book an intro callSee the journey in five stations

Memberships, programmes and partnerships

  • BSI Allianz für Cyber-Sicherheit
  • CISPA Helmholtz-Zentrum für Informationssicherheit
  • TeleTrusT - Bundesverband IT-Sicherheit
  • IT Security Made in Germany - TeleTrusT