Financial industry: DORA-ready operations
Operational continuity and outsourcing management need evidence, not promises – from German data centres, with a BSI certificate and C5 attestation.
- Separated backup systems – backup environments independent of the production system.
- Geo-redundancy since 2016 – distributed operations across several locations in Germany.
- Audit-ready evidence – certificates with scope and TOM documentation.
- Certified to the BSI standard – ISO 27001 based on IT-Grundschutz.
What the financial sector needs from the cloud
DORA has applied directly since January 2025. That shifts the requirement from policy to technology: recovery and restoration must demonstrably work.
Evidence for your outsourcing file
ISO 27001 based on IT-Grundschutz (BSI certificate BSI-IGZ-0773) and an unqualified BSI C5:2020 Type 1 attestation – including scope, technical measures and the data processing agreement in the Trust Center.
German company, German locations
centron GmbH, based in Hallstadt near Bamberg, with no foreign parent company. Customer data is processed exclusively in German data centres, with no transfer to third countries.
Separated backup environment
Backups independent of the production system, immutable via the object lock function of S3 Object Storage, with a dedicated permission and network concept for the backup path.
Named contacts instead of ticket numbers
Fixed contacts who answer questions from internal audit, outsourcing management and supervisory authorities – without escalation chains across time zones.
Four requirements that hit the infrastructure directly
DORA has applied directly since January 2025 – four requirements decide whether the infrastructure passes the review.
Backup systems separated from production
DORA requires that backup systems are not directly connected to the production system. Anyone who can reach the backups through production loses both at once in an incident – exactly the pattern ransomware exploits. The implementation: a separated backup environment, immutable backups via object lock, a dedicated permission and network concept.
Recovery objectives with technical backing
The business impact analysis yields RTO and RPO – you define these values, not the service provider. From them follow the backup frequency, the retention and whether a second environment runs permanently. centron’s cloud architects work through that calculation with you before a quote is made.
Tests that are documented
DORA requires a programme for testing digital operational resilience. In the cloud this works without spare hardware: restore an environment from backup, measure the actual recovery time, document the result, delete the environment. Only the time it exists is billed.
A second site with its own risk profile
A fallback environment is of little use if the same event hits it as the primary one. DORA therefore requires considering the geographic risk of the secondary site. centron has operated geo-redundancy since 2016 – Hallstadt, Nuremberg and Frankfurt am Main lie within the certification scope.
Infrastructure that withstands the audit
You define the recovery objectives – RTO and RPO determine how often backups run, how long they are retained and whether a second environment runs permanently or is only built in an emergency. centron provides the infrastructure and the documentation: certificates with scope, an overview of technical and organisational measures, and the data processing agreement. You classify the outsourcing as material or not; we supply a reliable service description for it – covered in detail on IT outsourcing under BAIT and MaRisk.
- DORA-ready – separated backups, testable recovery
- BAIT & MaRisk – documents for your outsourcing file
- Geo-redundancy – distributed operations at German sites
- Audit-proof – certificates with scope in the Trust Center
ISO 22301 or BSI standard 200-4: which framework fits?
DORA prescribes neither framework; for the infrastructure the choice is secondary, since both demand the same technical capabilities. DORA itself requires policies and procedures for backing up data and for its retrieval and restoration – the responsibility stays with the financial company, even when operations are outsourced. The contractual side of outsourcing is covered by IT outsourcing under BAIT and MaRisk.
| Criterion | ISO 22301 | BSI standard 200-4 |
|---|---|---|
| Character | international, certifiable standard for BCM systems | nationally shaped, closely interlocked with IT-Grundschutz |
| Strength | robust evidence towards supervisors, parent companies and business partners | stage model for step-by-step build-up, extensive set of templates |
| Suits | internationally active institutions | institutions already working to IT-Grundschutz |
| Technical requirements | separated backups, defined recovery objectives, tested restoration, a second site | identical – both frameworks demand the same capabilities |
| Task | With you | With centron |
|---|---|---|
| Business impact analysis, RTO and RPO | in full | — |
| Recovery plans and BCM documentation | creation and maintenance | supply of operating details |
| Applications and operating systems | configuration, patching, application recovery | managed service on request |
| Backup and restoration | definition of interval and retention | execution and provision |
| Platform and data centres | — | redundancy, monitoring, operational emergency management |
| Resilience tests | planning, execution, evaluation, reporting | provision of the test environment |
| Reporting serious incidents to the supervisor | in full | information about incidents in operations |
The right centron products
Banks, insurers and financial service providers typically implement operational resilience with these modules – combinable and extensible at any time.
- Independent of production
- Retention to your schedule
- Restores are testable
- Immutable backups
- €0.02 per GB per month
- Outbound traffic free
- 15-minute replication
- Failover in seconds
- Separate fire compartment
Which cloud infrastructure suits the financial industry?
Cloud for the financial industry: DORA-ready infrastructure in German data centres with a separated backup environment, immutable backups and documented evidence for your outsourcing file. The core building block is a backup separated from the production system using cBacks and S3 Object Storage with object lock; cProtect adds fast recovery. The infrastructure runs in our own German data centres, certified to ISO 27001 based on IT-Grundschutz (BSI certificate BSI-IGZ-0773) and with an unqualified BSI C5:2020 Type 1 attestation. New accounts receive €200 in starting credit.
| Module | Price |
|---|---|
| cBacks Backup | on request |
| S3 Object Storage | from €5.00 / month |
| cProtect | from €0.03 / month |
Frequently asked questions
What is business continuity management?
What does DORA require for recovery and restoration?
What is the difference between ISO 22301 and BSI standard 200-4?
Why must backups be separated from the production system?
How does centron meet the DORA requirement for separated backup systems?
Who defines RTO and RPO?
How often must restoration tests take place?
Is centron an ICT third-party provider within the meaning of DORA?
Is centron suitable as an outsourcing provider under BAIT and MaRisk?
What evidence do we receive for supervisors and internal audit?
Is data processed outside Germany?
More on compliance & operations
Get expert advice
Tell us about your project. Our sales team will get back to you within one business day.
The consultation is free of charge and without obligation.