Industries & sectors – Cloud for banks & insurers · DORA & C5

Financial industry: DORA-ready operations

Operational continuity and outsourcing management need evidence, not promises – from German data centres, with a BSI certificate and C5 attestation.

centron Console · resilience test
eu-de · Hallstadt Data Centre
Last test
passed
Backups
separated
Compliance
C5 / ISO
BIA Recovery objectives · RTO/RPO recorded
● Defined
BK S3 Object Lock · immutable
● Active
RST Restoration · time measured
● Documented
GEO Second site · distinct risk profile
● Ready
Resilience test completedrecovery · within RTO
  • Separated backup systems – backup environments independent of the production system.
  • Geo-redundancy since 2016 – distributed operations across several locations in Germany.
  • Audit-ready evidence – certificates with scope and TOM documentation.
  • Certified to the BSI standard – ISO 27001 based on IT-Grundschutz.
Why centron

What the financial sector needs from the cloud

DORA has applied directly since January 2025. That shifts the requirement from policy to technology: recovery and restoration must demonstrably work.

Evidence for your outsourcing file

ISO 27001 based on IT-Grundschutz (BSI certificate BSI-IGZ-0773) and an unqualified BSI C5:2020 Type 1 attestation – including scope, technical measures and the data processing agreement in the Trust Center.

German company, German locations

centron GmbH, based in Hallstadt near Bamberg, with no foreign parent company. Customer data is processed exclusively in German data centres, with no transfer to third countries.

Separated backup environment

Backups independent of the production system, immutable via the object lock function of S3 Object Storage, with a dedicated permission and network concept for the backup path.

Named contacts instead of ticket numbers

Fixed contacts who answer questions from internal audit, outsourcing management and supervisory authorities – without escalation chains across time zones.

DORA in practice

Four requirements that hit the infrastructure directly

DORA has applied directly since January 2025 – four requirements decide whether the infrastructure passes the review.

Backup systems separated from production

DORA requires that backup systems are not directly connected to the production system. Anyone who can reach the backups through production loses both at once in an incident – exactly the pattern ransomware exploits. The implementation: a separated backup environment, immutable backups via object lock, a dedicated permission and network concept.

Recovery objectives with technical backing

The business impact analysis yields RTO and RPO – you define these values, not the service provider. From them follow the backup frequency, the retention and whether a second environment runs permanently. centron’s cloud architects work through that calculation with you before a quote is made.

Tests that are documented

DORA requires a programme for testing digital operational resilience. In the cloud this works without spare hardware: restore an environment from backup, measure the actual recovery time, document the result, delete the environment. Only the time it exists is billed.

A second site with its own risk profile

A fallback environment is of little use if the same event hits it as the primary one. DORA therefore requires considering the geographic risk of the secondary site. centron has operated geo-redundancy since 2016 – Hallstadt, Nuremberg and Frankfurt am Main lie within the certification scope.

From risk analysis to recovery

Infrastructure that withstands the audit

You define the recovery objectives – RTO and RPO determine how often backups run, how long they are retained and whether a second environment runs permanently or is only built in an emergency. centron provides the infrastructure and the documentation: certificates with scope, an overview of technical and organisational measures, and the data processing agreement. You classify the outsourcing as material or not; we supply a reliable service description for it – covered in detail on IT outsourcing under BAIT and MaRisk.

Made in GermanyCompany · Data centres · Support
Calculate costs in the price calculator
  • DORA-ready – separated backups, testable recovery
  • BAIT & MaRisk – documents for your outsourcing file
  • Geo-redundancy – distributed operations at German sites
  • Audit-proof – certificates with scope in the Trust Center
Frameworks & responsibility

ISO 22301 or BSI standard 200-4: which framework fits?

DORA prescribes neither framework; for the infrastructure the choice is secondary, since both demand the same technical capabilities. DORA itself requires policies and procedures for backing up data and for its retrieval and restoration – the responsibility stays with the financial company, even when operations are outsourced. The contractual side of outsourcing is covered by IT outsourcing under BAIT and MaRisk.

ISO 22301 and BSI standard 200-4 compared
CriterionISO 22301BSI standard 200-4
Characterinternational, certifiable standard for BCM systemsnationally shaped, closely interlocked with IT-Grundschutz
Strengthrobust evidence towards supervisors, parent companies and business partnersstage model for step-by-step build-up, extensive set of templates
Suitsinternationally active institutionsinstitutions already working to IT-Grundschutz
Technical requirementsseparated backups, defined recovery objectives, tested restoration, a second siteidentical – both frameworks demand the same capabilities
Who is responsible for what
TaskWith youWith centron
Business impact analysis, RTO and RPOin full—
Recovery plans and BCM documentationcreation and maintenancesupply of operating details
Applications and operating systemsconfiguration, patching, application recoverymanaged service on request
Backup and restorationdefinition of interval and retentionexecution and provision
Platform and data centres—redundancy, monitoring, operational emergency management
Resilience testsplanning, execution, evaluation, reportingprovision of the test environment
Reporting serious incidents to the supervisorin fullinformation about incidents in operations
Recommended modules

The right centron products

Banks, insurers and financial service providers typically implement operational resilience with these modules – combinable and extensible at any time.

cBacks Backup
Price
on request
Separated backup environment
  • Independent of production
  • Retention to your schedule
  • Restores are testable
S3 Object Storage
From
€5.00 / month
Object lock
  • Immutable backups
  • €0.02 per GB per month
  • Outbound traffic free
cProtect
From
€0.03 / month
Recovery in seconds
  • 15-minute replication
  • Failover in seconds
  • Separate fire compartment
In brief

Which cloud infrastructure suits the financial industry?

Cloud for the financial industry: DORA-ready infrastructure in German data centres with a separated backup environment, immutable backups and documented evidence for your outsourcing file. The core building block is a backup separated from the production system using cBacks and S3 Object Storage with object lock; cProtect adds fast recovery. The infrastructure runs in our own German data centres, certified to ISO 27001 based on IT-Grundschutz (BSI certificate BSI-IGZ-0773) and with an unqualified BSI C5:2020 Type 1 attestation. New accounts receive €200 in starting credit.

Modules and prices
ModulePrice
cBacks Backupon request
S3 Object Storagefrom €5.00 / month
cProtectfrom €0.03 / month
Industries & sectors FAQ

Frequently asked questions

What is business continuity management?

Business continuity management is the regulated handling of events that interrupt business operations. It covers the analysis of critical processes, the definition of permissible downtimes, the recovery plans, the technical precautions and regular rehearsal. In the financial sector it has not been voluntary since DORA – it is required by supervisory law.

What does DORA require for recovery and restoration?

DORA requires policies and procedures for backing up data and for its retrieval and restoration. Backup systems must not be directly connected to the production system. Added to this are response and recovery plans and a programme for testing digital operational resilience. The responsibility remains with the financial company, even when operations are outsourced.

What is the difference between ISO 22301 and BSI standard 200-4?

ISO 22301 is the international, certifiable standard for business continuity management systems; it particularly suits internationally active institutions and evidence towards third parties. BSI standard 200-4 is nationally shaped, closely interlocked with IT-Grundschutz, and offers a stage model for step-by-step build-up. DORA prescribes neither; technically both demand the same.

Why must backups be separated from the production system?

Because an attacker who takes over the production system would otherwise reach the backups too. That is exactly what ransomware aims at: first the backups are encrypted or deleted, then the production system. A separated backup environment with its own permission and network concept and immutable backups prevents this. DORA picks up this requirement expressly.

How does centron meet the DORA requirement for separated backup systems?

With a backup environment that is not attached to the production system: backups run through cBacks into a separate environment, immutable via the object lock function of S3 Object Storage, with a dedicated permission and network concept for the backup path. Anyone who can reach the backups through the production system loses both in an incident – separation prevents exactly that.

Who defines RTO and RPO?

You do. Your institution's impact analysis determines the acceptable downtime (RTO) and acceptable data loss (RPO). From those follow how often backups run, how long they are retained and whether a second environment runs permanently or is only built in an emergency. We work through that calculation with you – but you set the values.

How often must restoration tests take place?

DORA requires a programme for testing digital operational resilience whose scope and frequency depend on size, risk profile and the criticality of the function. For significant companies, threat-led penetration tests are added. Independently of that: a recovery plan that has never been rehearsed is no evidence in an audit. In practice, at least one documented restoration per year per critical function has proven itself.

Is centron an ICT third-party provider within the meaning of DORA?

Yes. If you run infrastructure with centron, we are an ICT third-party provider. This entails requirements for you regarding the contractual arrangements, the entry in your information register and an exit strategy. We provide the details you need for this; the contractual side is covered by IT outsourcing under BAIT and MaRisk.

Is centron suitable as an outsourcing provider under BAIT and MaRisk?

Yes – you classify the outsourcing as material or not, based on your own risk analysis; responsibility towards the supervisory authority remains with the institution. Classification, the information register, the exit strategy and provider oversight, including all documents, are covered in detail on IT outsourcing under BAIT and MaRisk.

What evidence do we receive for supervisors and internal audit?

The certificates with their stated scope, the BSI C5 attestation, the documentation of technical and organisational measures under Art. 32 GDPR and the data processing agreement. Plus the operating details that belong in your recovery plans: locations, backup procedures, reporting channels and availability. Everything is in the Trust Center.

Is data processed outside Germany?

No. Customer data is processed exclusively in German data centres, with no transfer to third countries – by default in our own data centre in Hallstadt near Bamberg, with Nuremberg and Frankfurt am Main additionally within the certification scope. centron is a German company based in Hallstadt with no foreign parent company – a point that comes up regularly in outsourcing reviews.

Get expert advice

Tell us about your project. Our sales team will get back to you within one business day.

The consultation is free of charge and without obligation.