{"id":57733,"date":"2022-01-11T16:37:18","date_gmt":"2022-01-11T15:37:18","guid":{"rendered":"https:\/\/www.usd.de\/security-consulting\/information-security-in-finance\/bait\/"},"modified":"2025-04-17T15:46:56","modified_gmt":"2025-04-17T13:46:56","slug":"bafin-requirements","status":"publish","type":"page","link":"https:\/\/www.usd.de\/en\/security-consulting\/information-security-in-finance\/bafin-requirements\/","title":{"rendered":"BaFin's xAIT"},"content":{"rendered":"<p>[et_pb_section fb_built=\"1\" _builder_version=\"4.16\" _module_preset=\"default\" custom_padding=\"0px||0px||true|false\" locked=\"off\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"][et_pb_row _builder_version=\"4.16\" _module_preset=\"default\" width=\"100%\" custom_padding=\"0px||||false|false\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"][et_pb_column type=\"4_4\" _builder_version=\"4.16\" _module_preset=\"default\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"][et_pb_text _builder_version=\"4.27.4\" _module_preset=\"default\" text_text_color=\"#FFFFFF\" text_font_size=\"30px\" text_line_height=\"1.2em\" header_font=\"Roboto||||||||\" header_text_color=\"#F07F1D\" header_font_size=\"50px\" background_color=\"RGBA(0,0,0,0)\" background_image=\"https:\/\/www.usd.de\/wp-content\/uploads\/usd-ag-header-finanzwesen-bait-harmonisierung.jpg\" background_blend=\"multiply\" custom_margin=\"-25px||0px||false|false\" custom_padding=\"95px||60px||false|false\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"]<\/p>\n<h1 style=\"text-align: center;line-height: 120%;font-weight: 400\">BaFin's xAIT<\/h1>\n<p style=\"text-align: center;line-height: 130%\"><span>Harmonization with DORA - We Accompany You<\/span><\/p>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][et_pb_row column_structure=\"1_2,1_2\" _builder_version=\"4.16\" _module_preset=\"default\" custom_padding=\"10px|||||\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"][et_pb_column type=\"1_2\" _builder_version=\"4.16\" _module_preset=\"default\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"][et_pb_image src=\"https:\/\/www.usd.de\/wp-content\/uploads\/usd-pci-security-consulting-dora-bild-1.jpg\" alt=\"Harmonisierung mit BAIT\" title_text=\"usd-pci-security-consulting-dora-bild (1)\" _builder_version=\"4.27.4\" _module_preset=\"default\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"][\/et_pb_image][\/et_pb_column][et_pb_column type=\"1_2\" _builder_version=\"4.16\" _module_preset=\"default\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"][et_pb_text _builder_version=\"4.27.4\" _module_preset=\"default\" background_color=\"RGBA(0,0,0,0)\" custom_margin=\"0px|0px|0px|0px|true|true\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"]<\/p>\n<p>Since 17 January 2025, almost all supervised institutions and companies in the European financial sector have been subject to the <a href=\"https:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/PDF\/?uri=CELEX:32022R2554&amp;from=FR\" target=\"_blank\" rel=\"noopener\">Digital Operational Resilience Act<\/a> (DORA). This aims to improve and harmonize the IT security and operational resilience of banks and financial institutions across Europe.<\/p>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][et_pb_row _builder_version=\"4.16\" _module_preset=\"default\" custom_padding=\"12px||0px|||\" locked=\"off\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"][et_pb_column type=\"4_4\" _builder_version=\"4.16\" _module_preset=\"default\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"][et_pb_text _builder_version=\"4.27.4\" _module_preset=\"default\" background_color=\"RGBA(0,0,0,0)\" custom_margin=\"0px|0px|0px|0px|true|true\" custom_padding=\"||40px|||\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"]<\/p>\n<p>In Germany, institutions were previously regulated by BaFin's IT requirements. Many of the processes and measures required there can now be found in the DORA Regulation. In order to avoid double regulation, BaFin repealed the supervisory requirements for IT in e-money institutions (<strong>ZAIT<\/strong>), insurance undertakings (<strong>VAIT<\/strong>), and German asset managers (<strong>KAIT<\/strong>) in January of 2025. The affected institutions will be fully regulated by DORA in future. The scope of application of supervisory requirements for IT in financial institutions (<strong>BAIT<\/strong>) was initially adjusted. However, the circular will also be repealed in its entirety upon 31 December 2026.<\/p>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][et_pb_row _builder_version=\"4.27.4\" _module_preset=\"default\" theme_builder_area=\"post_content\"][et_pb_column _builder_version=\"4.27.4\" _module_preset=\"default\" type=\"4_4\" theme_builder_area=\"post_content\"][et_pb_text _builder_version=\"4.27.4\" _module_preset=\"default\" custom_padding=\"9px|||||\" hover_enabled=\"0\" global_colors_info=\"{}\" theme_builder_area=\"post_content\" sticky_enabled=\"0\"]<\/p>\n<h2>Harmonization with DORA: How Do We Proceed?<\/h2>\n<p>[\/et_pb_text][et_pb_text _builder_version=\"4.27.4\" _module_preset=\"default\" theme_builder_area=\"post_content\" hover_enabled=\"0\" sticky_enabled=\"0\"]<\/p>\n<p>Harmonization with <a href=\"https:\/\/www.eiopa.europa.eu\/digital-operational-resilience-act-dora_en\" target=\"_blank\" rel=\"noopener\">DORA<\/a> requires a detailed implementation project at your institution. Before you start, we recommend that you consider which other security standards have already been implemented in your company and which national regulations place requirements on your company. In most cases, implemented systems and processes for compliance with <a href=\"https:\/\/www.iso.org\/standard\/27001\" target=\"_blank\" rel=\"noopener\">ISO 27001<\/a> or the BaFin's IT requirements (BAIT, KAIT, VAIT, ZAIT) can be used as a good basis. A gap analysis is a good first step to create clarity.<\/p>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][et_pb_row column_structure=\"1_4,3_4\" _builder_version=\"4.27.4\" _module_preset=\"default\" custom_padding=\"0px||15px|||\" hover_enabled=\"0\" global_colors_info=\"{}\" theme_builder_area=\"post_content\" sticky_enabled=\"0\" custom_margin=\"||||false|false\"][et_pb_column type=\"1_4\" _builder_version=\"4.16\" _module_preset=\"default\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"][et_pb_image src=\"https:\/\/www.usd.de\/wp-content\/uploads\/\/finanzwesen-bait-harmonisierung-b.svg\" alt=\"PCI Zertifizierungsprozess Kick-off\" title_text=\"finanzwesen-bait-harmonisierung-b\" align=\"center\" _builder_version=\"4.27.4\" _module_preset=\"default\" background_color=\"RGBA(0,0,0,0)\" width=\"60%\" width_tablet=\"20%\" width_phone=\"30%\" width_last_edited=\"on|tablet\" custom_margin=\"20px||||false|false\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"][\/et_pb_image][\/et_pb_column][et_pb_column type=\"3_4\" _builder_version=\"4.16\" _module_preset=\"default\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"][et_pb_text _builder_version=\"4.27.4\" _module_preset=\"default\" custom_margin=\"0px||0px||false|false\" custom_padding=\"15px|||||\" hover_enabled=\"0\" global_colors_info=\"{}\" theme_builder_area=\"post_content\" sticky_enabled=\"0\"]<\/p>\n<h3>Gap Analysis<\/h3>\n<p>As the requirements have a significant impact on institutions, a mere document review is not sufficient to determine the implementation status of the DORA requirements. We therefore recommend a combination of:<\/p>\n<ul>\n<li><span style=\"font-size: 16px\">Document review<\/span><\/li>\n<li>Interviewing key personnel<\/li>\n<li>Examination of the implementation<\/li>\n<\/ul>\n<p>The result of the <strong>gap analysis<\/strong> is a good picture of the expected effort. It provides implementation options that can be used to set the direction for implementation at the highest management level (<strong>action plan<\/strong>).<\/p>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][et_pb_row _builder_version=\"4.27.4\" _module_preset=\"default\" custom_margin=\"-26px||||false|false\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"][et_pb_column type=\"4_4\" _builder_version=\"4.27.4\" _module_preset=\"default\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"][et_pb_text _builder_version=\"4.27.4\" _module_preset=\"default\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"]<\/p>\n<p>After completing the gap analysis, we work with you on harmonization projects that are tailored to your institution. In these projects, we specifically address the focal points identified in the gap analysis and work closely with you to implement the guidelines.\u00a0<\/p>\n<p>Further information on harmonization with DORA and the procedure can be found <a href=\"https:\/\/www.usd.de\/en\/security-consulting\/dora\/\">here<\/a>.<\/p>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][et_pb_row _builder_version=\"4.16\" _module_preset=\"default\" custom_margin=\"-8px||||false|false\" custom_padding=\"||2px|||\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"][et_pb_column type=\"4_4\" _builder_version=\"4.16\" _module_preset=\"default\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"][et_pb_divider color=\"#d8d8d8\" _builder_version=\"4.16\" _module_preset=\"default\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"][\/et_pb_divider][\/et_pb_column][\/et_pb_row][et_pb_row _builder_version=\"4.16\" _module_preset=\"default\" custom_padding=\"0px||0px|||\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"][et_pb_column type=\"4_4\" _builder_version=\"4.16\" _module_preset=\"default\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"][et_pb_text _builder_version=\"4.27.4\" _module_preset=\"default\" custom_padding=\"9px|||||\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"]<\/p>\n<h2>Harmonization with BAIT: How Do We Proceed?<\/h2>\n<p>[\/et_pb_text][et_pb_text _builder_version=\"4.27.4\" _module_preset=\"default\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"]<\/p>\n<p>With the introduction of DORA on 17 January 2025, the scope of application of BAIT was adjusted. Institutions that are required to operate ICT risk management in accordance with Art. 5-15 or Art. 16 DORA are excluded from the BAIT scope of application. The circular will still apply to all other regulated institutions before it is completely repealed on 31 December 2026.<\/p>\n<p>We are pleased to provide you with further support in harmonizing with BAIT:<\/p>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][et_pb_row column_structure=\"1_4,3_4\" _builder_version=\"4.16\" _module_preset=\"default\" custom_padding=\"0px||15px|||\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"][et_pb_column type=\"1_4\" _builder_version=\"4.16\" _module_preset=\"default\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"][et_pb_image src=\"https:\/\/www.usd.de\/wp-content\/uploads\/\/finanzwesen-vait-harmonisierung-c.svg\" alt=\"VAIT Harmonisierung Umsetzungsprojekt\" title_text=\"finanzwesen-vait-harmonisierung-c\" align=\"center\" _builder_version=\"4.27.4\" _module_preset=\"default\" background_color=\"RGBA(0,0,0,0)\" width=\"60%\" width_tablet=\"20%\" width_phone=\"30%\" width_last_edited=\"on|tablet\" custom_margin=\"20px||||false|false\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"][\/et_pb_image][\/et_pb_column][et_pb_column type=\"3_4\" _builder_version=\"4.16\" _module_preset=\"default\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"][et_pb_text _builder_version=\"4.27.4\" _module_preset=\"default\" custom_margin=\"20px||0px||false|false\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"]<\/p>\n<h3>Harmonization Measures<\/h3>\n<p>Implementation of harmonization with BAIT in a comprehensive <strong>implementation project<\/strong> tailored to the institution. We support you at all levels, from defining the strategy and formulating guidelines to the operational implementation of the requirements in the organization.<\/p>\n<ul><\/ul>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][et_pb_row _builder_version=\"4.16\" _module_preset=\"default\" custom_margin=\"-8px||||false|false\" custom_padding=\"||2px|||\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"][et_pb_column type=\"4_4\" _builder_version=\"4.16\" _module_preset=\"default\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"][et_pb_divider color=\"#d8d8d8\" _builder_version=\"4.16\" _module_preset=\"default\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"][\/et_pb_divider][\/et_pb_column][\/et_pb_row][et_pb_row _builder_version=\"4.16\" _module_preset=\"default\" custom_margin=\"|auto|18px|auto||\" custom_padding=\"0px||1px|||\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"][et_pb_column type=\"4_4\" _builder_version=\"4.16\" _module_preset=\"default\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"][et_pb_text _builder_version=\"4.27.4\" _module_preset=\"default\" custom_padding=\"9px|||||\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"]<\/p>\n<h2>More Information on the Digital Operational Resilience Act<\/h2>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][et_pb_row column_structure=\"1_2,1_2\" use_custom_gutter=\"on\" gutter_width=\"2\" make_equal=\"on\" _builder_version=\"4.27.4\" _module_preset=\"default\" background_color=\"RGBA(0,0,0,0)\" custom_margin=\"4px|auto||auto||\" custom_padding=\"0px|7px|40px|7px|false|true\" border_radii=\"on|5px|5px|5px|5px\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"][et_pb_column type=\"1_2\" _builder_version=\"4.27.4\" _module_preset=\"default\" background_color=\"#707070\" background_image=\"https:\/\/www.usd.de\/wp-content\/uploads\/news-usd-ag-dora-vorbereitung.jpg\" background_blend=\"multiply\" background_enable_video_mp4=\"off\" custom_padding=\"0px|0px|0px|0px|false|true\" link_option_url=\"https:\/\/www.usd.de\/en\/dora-preparation-in-3-steps\/\" background_last_edited=\"off|desktop\" border_radii=\"on|5px|5px|5px|5px\" border_width_all=\"1px\" border_color_all=\"#F6F6F6\" global_colors_info=\"{}\" background__hover_enabled=\"off|hover\" background_enable_color__hover=\"off\" background_image__hover=\"https:\/\/www.usd.de\/wp-content\/uploads\/news-success-story-cashpoint.jpeg\" background_enable_image__hover=\"on\" theme_builder_area=\"post_content\"][et_pb_text _builder_version=\"4.27.4\" _module_preset=\"51ae1141-d3aa-4d8e-88be-0448f8284f54\" background_color=\"RGBA(0,0,0,0)\" custom_margin=\"80px||58px||false|false\" custom_padding=\"6px|30px|0px|30px|false|true\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"]<\/p>\n<h3><span style=\"color: #ffffff\">Setting off for DORA \u2013 Your Preparation in 3 Steps<\/span><\/h3>\n<p>[\/et_pb_text][\/et_pb_column][et_pb_column type=\"1_2\" _builder_version=\"4.27.4\" _module_preset=\"default\" background_color=\"rgba(46,53,61,0.86)\" background_image=\"https:\/\/www.usd.de\/wp-content\/uploads\/usd-ag-dora.jpg\" background_blend=\"multiply\" background_enable_video_mp4=\"off\" custom_padding=\"0px|0px|0px|0px|true|true\" link_option_url=\"https:\/\/www.usd.de\/en\/dora-5-tips-on-what-to-consider-during-planning\/\" background_last_edited=\"off|desktop\" border_radii=\"on|5px|5px|5px|5px\" border_width_all=\"1px\" border_color_all=\"#F6F6F6\" global_colors_info=\"{}\" background__hover_enabled=\"off|hover\" background_enable_color__hover=\"off\" background_image__hover=\"https:\/\/www.usd.de\/wp-content\/uploads\/news-success-story-cashpoint.jpeg\" background_enable_image__hover=\"on\" theme_builder_area=\"post_content\"][et_pb_text _builder_version=\"4.27.4\" _module_preset=\"51ae1141-d3aa-4d8e-88be-0448f8284f54\" background_color=\"RGBA(0,0,0,0)\" custom_margin=\"80px||58px||false|false\" custom_padding=\"6px|30px|0px|30px|false|true\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"]<\/p>\n<h3><span style=\"color: #ffffff\">5 Tips on What to Consider during Planning<\/span><\/h3>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][\/et_pb_section]<\/p>\n","protected":false},"excerpt":{"rendered":"<p>BaFin's xAIT Harmonization with DORA - We Accompany YouSince 17 January 2025, almost all supervised institutions and companies in the European financial sector have been subject to the Digital Operational Resilience Act (DORA). This aims to improve and harmonize the IT security and operational resilience of banks and financial institutions across Europe.In Germany, institutions were [&hellip;]<\/p>\n","protected":false},"author":92,"featured_media":23498,"parent":11714,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"_et_pb_use_builder":"on","_et_pb_old_content":"","_et_gb_content_width":"","inline_featured_image":false,"footnotes":""},"class_list":["post-57733","page","type-page","status-publish","has-post-thumbnail","hentry"],"_links":{"self":[{"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/pages\/57733","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/users\/92"}],"replies":[{"embeddable":true,"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/comments?post=57733"}],"version-history":[{"count":5,"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/pages\/57733\/revisions"}],"predecessor-version":[{"id":57864,"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/pages\/57733\/revisions\/57864"}],"up":[{"embeddable":true,"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/pages\/11714"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/media\/23498"}],"wp:attachment":[{"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/media?parent=57733"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}