Qualysec
Blog

Is Penetration Testing Mandatory for BaFin Compliance? What Financial Institutions Need to Know

Understand BaFin Compliance requirements, key regulations, penetration testing expectations, and ICT risk controls for financial institutions in Germany.

Published on September 19, 2026
Read Time: 14 min
CONNECT WITH US

Financial organizations in Germany often struggle to decide whether their current security testing meets BaFin regulations. Penetration testing is an important part of BaFin compliance, but the exact requirement depends on the financial institution and the regulatory framework that applies to it. DORA now provides the Information and Communication Technology testing requirements for financial institutions within its scope. 

The DORA regulation became applicable on 17 January 2025 and applies to over 3,600 entities within the financial sector in Germany. The regulation clearly defines the requirements regarding testing digital operational resilience, including penetration testing and Threat-Led Penetration Testing (TLPT).

In this article, we are going to discuss when penetration testing is mandatory under BaFin and DORA. We also cover the systems that require testing, TLPT requirements, and the documentation financial institutions should maintain for regulatory reviews.

What Is BaFin Compliance?

BaFin compliance entails the regulations that must be followed by financial firms in Germany under the supervision of the Federal Financial Supervisory Authority (BaFin). The requirements have been largely defined by the EU Digital Operational Resilience Act (DORA), effective since 17 January 2025.

DORA represents the core framework for risk management in the field of ICT within the finance industry. The compliance of these regulations is made sure by the BaFin authority, which helps banks, insurance, payment, and asset management companies cope with severe cyber events. The BaFin regulator oversees financial institutions and ensures they meet applicable supervisory requirements. 

Why BaFin Mandates Penetration Testing for Financial Entities?

It is necessary to conduct penetration tests under the DORA ICT security testing framework. The testing requirements can vary depending on your organization, the ICT systems that you run, and the services.

BaFin expects you to conduct penetration testing to determine whether your security controls could withstand a real attack, not just check for vulnerabilities. Germany BaFin requirements cover financial-sector organizations under its supervision, alongside applicable EU regulations such as DORA. 

DORA Testing Requirements

According to DORA, financial institutions need a risk-based ICT testing program to test their technology environment. It checks whether the technology can resist cybersecurity attacks and operational disruptions regularly. Testing methodologies that financial institutions may conduct under the DORA law include vulnerability tests, network security tests, penetration testing, among others.

The testing requirements include:

  • Regular testing: ICT systems and applications that support critical functions must be included in the organization’s resilience testing programme. The scope should reflect the risks associated with those systems and their role in critical business operations.
  • Threat-Led Penetration Testing (TLPT): Entities covered by Article 26 must conduct TLPT at least every three years. Unlike a conventional vulnerability assessment, TLPT simulates realistic attacks against live production systems and can cover several or all critical functions.
  • Independent testers: Testing must be performed by qualified and independent testers. TLPT providers are subject to additional requirements covering technical competence, certification, and professional indemnity insurance.

Your organization needs to show that its testing programme has a clear scope, uses appropriate methodologies, produces documented evidence, and leads to remediation when weaknesses are identified.

According to research by Deloitte in 2026, only 7% of surveyed institutions report being fully DORA compliant.  This shows that many organizations are still working to translate DORA’s requirements into effective operational practices.

Evidence-Based Security Validation

A vulnerability scan can tell you that a known weakness exists, but it may not show how that weakness could be exploited when combined with weaknesses in other systems. Penetration testing addresses this gap by attempting to exploit vulnerabilities and examining realistic attack paths through the environment.

TLPT is performed against live production environments; the assessment provides a stronger assessment of whether an attacker could reach and compromise critical functions.

BaFin may therefore assess whether your testing program:

  • Includes the critical functions that require protection
  • Applies a suitable risk-based testing methodology
  • Identifies weaknesses that can actually be exploited and traces the resulting attack paths
  • Produces clear evidence, documented findings, and remediation plans
  • Uses retesting to confirm that identified weaknesses have been properly addressed

Third-Party ICT Risk

DORA also requires financial organizations to consider the security risks created by ICT third-party providers. This is important because critical financial services may depend on technology that the organization does not operate or control directly.

For example, critical functions may rely on cloud platforms, data centres, software providers, APIs, or shared infrastructure. A weakness in one of these dependencies could create an attack path into a critical service.

Your testing programme should therefore address:

  • Outsourced ICT services: Identify the third-party ICT services that support critical functions and determine which of those dependencies need to be included in the testing scope.
  • Supply-chain exposure: Examine integrations, APIs, shared infrastructure, and data flows to identify attack paths that could originate from or pass through third-party environments.
  • Contractual requirements: Make sure contracts and SLAs give your organization appropriate testing rights and establish responsibilities for incident cooperation and remediation.

This means penetration testing should not be treated as a test of individual internal systems alone. The objective is to understand whether the entire technology chain supporting critical services can withstand an attack or disruption.

Transition From Germany’s Earlier IT Rules

DORA has also changed the regulatory framework that German financial entities use for ICT security and operational resilience. BaFin has removed several national requirements that overlapped with DORA so that firms subject to the regulation can operate primarily under the common EU-wide digital operational resilience framework.

The transition includes:

  • KAIT, VAIT, and ZAIT: These circulars were repealed on 16 January 2025.
  • BAIT: Firms subject to DORA have been excluded from BAIT since 17 January 2025. BAIT is scheduled for complete repeal by 31 December 2026.
  • EU-wide framework: DORA establishes a common framework for managing digital operational resilience across EU member states.

For entities covered by DORA, penetration testing should be planned according to the applicable DORA testing requirements rather than relying on the former national IT rules. 

Which Core Regulatory Frameworks Demand Penetration Testing Under BaFin Compliance?

Financial institutions regulated by BaFin may be required to carry out penetration testing according to various regulations depending on the institution and its regulatory scope.

The regulations are as follows:

  • DORA: The current EU-wide framework for ICT security and digital operational resilience.
  • BAIT: Germany’s IT requirements for certain banking institutions.
  • VAIT: IT requirements that previously applied to insurance and reinsurance undertakings.
  • KAIT: IT requirements that previously applied to capital-management companies.
  • ZAIT: IT requirements that previously applied to payment and electronic-money institutions.
  • MaRisk: The broader framework for risk management and internal controls.

All of these frameworks cover key financial industries regulated by BaFin. These industries include banking, insurance, asset management, payment services, and electronic money.

1. Digital Operational Resilience Act (DORA) 

DORA is the current EU-wide framework for ICT security and digital operational resilience. It applies to most BaFin-supervised financial entities. Which are banks, insurance companies, investment firms, payment institutions, electronic money institutions, and capital-management companies.

DORA requires financial entities to maintain a comprehensive and risk-based ICT testing programme. The programme must cover systems supporting critical functions.

The recognised testing methods include:

  • Penetration testing
  • Vulnerability assessments
  • Vulnerability scans
  • Network-security assessments
  • Source-code reviews
  • Scenario-based exercises

DORA also requires Threat-Led Penetration Testing for selected financial entities. TLPT uses threat intelligence to simulate realistic cyberattacks against live production systems.

2. BAIT (Bankaufsichtliche Anforderungen an die IT)

BAIT applies to certain banks and financial-services institutions. These institutions remain subject to Germany’s national IT-supervisory framework. BAIT recognises penetration testing as a method for assessing and protecting information. It also identifies other testing methods such as gap analyses, vulnerability scans, simulated attacks, and penetration testing.

The choice of testing method depends on your institution’s risks and the systems being assessed. Penetration testing may be appropriate for systems such as:

  • Internet-facing banking applications.
  • Payment and transaction systems.
  • Customer portals and mobile applications.
  • Systems processing confidential customer information.
  • Privileged-access infrastructure.
  • Critical applications before deployment.
  • Critical applications after significant changes.
  • Interfaces connecting banks with external service providers.

BAIT does not demand that all banks carry out identical annual penetration tests. It adopts a risk-based approach. This is no longer an additional framework for financial institutions covered by DORA. It continues to be adopted by certain institutions not within the scope of DORA, depending on the transition arrangement.

3. VAIT (Versicherungsaufsichtliche Anforderungen an die IT)

VAIT applies to insurance and reinsurance undertakings supervised by BaFin. It requires penetration testing where such testing is necessary to protect information. This created a risk-based expectation for insurers.

Penetration testing is relevant where other testing methods could not sufficiently assess important systems.

Relevant systems could include:

  • Policy-administration platforms.
  • Claims-management systems.
  • Underwriting applications.
  • Customer and broker portals.
  • Insurance APIs.
  • Identity and access-management systems.
  • Cloud-based insurance services.
  • Systems supporting critical insurance operations.

VAIT did not require every insurer to conduct the same penetration test at a fixed interval. Testing instead depended on system criticality, exposure, and protection requirements. Also, risks associated with the relevant systems. Insurance undertakings covered by DORA must now assess their testing obligations under DORA. This includes DORA’s resilience-testing and TLPT requirements.

4. KAIT (Kapitalverwaltungsaufsichtliche Anforderungen an die IT)

KAIT applies to capital-management companies and asset-management activities. It established IT security and control expectations for systems used in several areas. These areas included portfolio management, fund administration, trading and order management, valuation and accounting, risk management, investor reporting, and outsourced ICT services.

Penetration testing is needed to verify system protection. It can also help determine whether identified ICT risks could be exploited.

Typical testing service targets could include:

  • Investment portals.
  • Trading interfaces.
  • Application programming interfaces.
  • Privileged-access systems.
  • Cloud platforms.

KAIT followed a risk-based approach rather than requiring one annual penetration test for every application. KAIT was repealed when DORA became applicable. Capital-management companies within DORA’s scope must now use DORA as their primary framework. This applies to ICT security and digital-resilience testing.

5. ZAIT (Zahlungsdiensteaufsichtliche Anforderungen an die IT)

ZAIT applies to payment institutions and electronic-money institutions. It was particularly relevant to penetration testing because these institutions process financial transactions, authentication information, and customer data. Testing could cover:

  • Payment applications.
  • Mobile and online payment platforms.
  • Strong customer-authentication systems.
  • Open-banking interfaces.
  • Payment APIs.
  • Fraud-detection systems.
  • Transaction-processing infrastructure.
  • Cryptographic and tokenization services.
  • Third-party payment processors.

Penetration testing could assess whether attackers could bypass authentication, manipulate payment instructions, escalate privileges, and access transaction data. Like the other xAIT frameworks, ZAIT followed a risk-based testing approach. 

6. MaRisk (Minimum Requirements for Risk Management)

Minimum Requirements for Risk Management provide the broader governance and internal-control framework for German financial institutions. It supports penetration-testing requirements through its focus on risk management and internal controls.

The framework requires institutions to:

  • Identify, assess, manage, and monitor material risks.
  • Maintain effective internal controls.
  • Define clear responsibilities.
  • Maintain appropriate documentation.
  • Use independent control functions.
  • Provide appropriate management reporting.

Penetration testing can help validate whether ICT and operational-risk controls work effectively. You can use penetration testing to assess:

  • Access management.
  • Network segmentation.
  • Vulnerability remediation.
  • Secure application development.
  • Security monitoring controls.

However, MaRisk should not be described as independently imposing a universal penetration-testing schedule. Its role is to establish the broader risk-management basis for testing. More direct testing requirements come from DORA or the applicable IT-supervisory framework, such as BAIT.

What Systems Must Be Tested?

Financial institutions should test ICT systems that support their Critical or Important Functions (CIFs). The scope should include both core financial systems and the infrastructure that supports them. Under DORA Articles 24 and 25, testing should cover the assets and connections that could affect critical financial services. This also supports a broader financial compliance audit by helping institutions identify security and resilience gaps across systems supporting critical functions.

Key systems may include:

  • Core Banking and Transaction Platforms: Test mainframes, ledger databases, payment gateways, and transaction-processing engines. This includes interfaces used for systems such as TARGET2 and SWIFT.
  • Customer-Facing Interfaces: Test mobile banking applications, customer portals, online onboarding APIs, and authentication systems. Testing should also consider multi-factor authentication flows.
  • Treasury and Trading Systems: Assess high-frequency trading infrastructure, settlement systems, and liquidity-management platforms. These systems can directly support critical financial operations.
  • Supporting ICT Infrastructure: Test infrastructure that provides access to CIF environments. This can include Active Directory domains, enterprise virtualization layers, internal cloud configurations, and administrative jump hosts.
  • Third-Party and Cloud Dependencies: Include external services that connect to critical operations. These may include APIs, shared SaaS platforms, and outsourced data-centre connections.

Identify the systems, dependencies, and access paths that could affect critical functions. BaFin-supervised institutions should also maintain an accurate Register of Information.

How Qualysec Helped a Regulated Fintech Strengthen Security: A Qualysec Case Study

Qualysec helped a regulated cryptocurrency exchange identify and address security weaknesses in its trading platform. The engagement focused on finding exploitable vulnerabilities, assessing their impact, and verifying that the issues were fixed. 

How Did Qualysec Test the Platform?

The exchange handled sensitive customer information and financial transactions. We conducted penetration testing across key areas of the platform, including:

  • Authentication and session management
  • Access controls and authorization
  • Wallet and transaction functionality
  • Account-management features
  • APIs and application endpoints
  • Input validation and information disclosure

The assessment identified 18 security issues that required remediation.

What Vulnerabilities Were Identified?

The assessment uncovered several vulnerabilities that could affect the security of the financial platform:

  • IDOR
  • Session-management weakness
  • CSRF
  • Open redirect
  • Information disclosure

These findings showed how application-level weaknesses could create security risks for users and financial operations.

How Does This Experience Support BaFin and DORA Requirements?

It shows how we assess security risks in regulated financial environments. If you are preparing for BaFin compliance and DORA testing requirements, you can use the same approach to assess the systems within your testing scope. 

We can help you identify exploitable vulnerabilities, understand their impact, support remediation, and retest the fixes. This gives you more than a list of vulnerabilities. 

How Qualysec Delivers Audit-Ready BaFin Pentesting

Qualysec is a CREST-accredited specialized penetration testing company offering VAPT across multiple countries. Meeting BaFin compliance and DORA requirements demands more than basic vulnerability scans. It requires defensible technical evidence from trusted security experts. We can help your institution bridge the gap between complex regulatory mandates and practical cybersecurity execution through:

  • Independent Expert Validation: We provide certified, objective testing that satisfies the strict independence criteria mandated under DORA Article 25 and regulatory frameworks.
  • Compliance-Driven Mapping: We align every engagement directly with European resilience standards, linking discovered technical weaknesses straight to Article 9 controls and critical business functions.
  • Advanced Adversarial Simulation: We move beyond automated tools by deploying skilled human testers and threat-intelligence-driven scenarios to evaluate your real-world production risks.
  • Audit-Ready Reporting: We deliver clear, structured documentation outlining exploited paths, control failures, and actionable remediation steps designed for seamless review by supervisory authorities.

By partnering with Qualysec, your organization ensures its security posture stands up to BaFin compliance while protecting critical banking infrastructure.

Conclusion

Penetration testing is one of the major components of BaFin compliance for all financial institutions falling under the purview of DORA and relevant German regulations. It allows organizations to detect potential vulnerabilities and ensure the integrity of systems carrying out crucial financial services.

With the transformation that is being brought about by DORA, financial institutions need to implement a risk-based testing strategy backed by evidence and prompt remediation of identified vulnerabilities.

Speak Directly With Qualysec’s Certified Security Experts

Discover vulnerabilities before attackers exploit them

Schedule Free Consultation

Security Expert

FAQs

1. Is penetration testing mandatory under BaFin and DORA compliance?

Penetration testing is required for most financial institutions operating under BaFin supervision. Under DORA Articles 24 and 25, organizations must conduct regular, risk-based digital operational resilience tests, including annual penetration tests on all systems supporting critical functions.

2. What is the difference between standard penetration testing and TLPT under DORA?

Standard penetration testing evaluates baseline security controls and application vulnerabilities. Threat-Led Penetration Testing is an advanced, triennial simulation of realistic cyberattacks using threat intelligence against live production systems for systemically important entities.

3. Which financial institutions in Germany are affected by DORA testing rules?

DORA impacts over 3,600 financial entities in Germany, including banks, insurance companies, investment firms, payment service providers, and crypto-asset service providers. It is largely replacing older national regulations like BAIT, VAIT, KAIT, and ZAIT.

4. What core systems must be included in a BaFin-compliant penetration test scope?

Testing must cover all ICT systems supporting Critical or Important Functions (CIFs). This includes core banking mainframes, payment gateways like SWIFT and TARGET2, customer-facing mobile apps, trading infrastructure, and supporting layers like Active Directory and cloud supply chains.

5. What documentation do financial institutions need for BaFin regulatory reviews?

Institutions must provide audit-ready evidence showing their testing scope and methodologies used. They also need a complete Register of Information mapping critical assets, detailed vulnerability findings, and documented remediation or retesting plans.

Chandan Sahoo

About Chandan Sahoo

Chandan Kumar Sahoo is the Co-Founder and Chief Executive Officer (CEO) at Qualysec. With over 8 years of experience in security testing and software quality assurance, he leads corporate strategy and expansion, helping organizations globally secure their web, mobile, and cloud environments.

Leave a Comment.

Your email address will not be published. Required fields are marked *

Related Blogs

Subscribe to Newsletter

Get the latest cybersecurity insights, compliance tips, and vulnerability reports delivered directly to your inbox.