Source Siglum Registry
The registry orders its sources by decreasing regulatory bindingness — from directly applicable EU law through European and national supervisory instruments to voluntary standards.
As of 2026-08-25 — 39 entries, 288 attestations. Curated and growing; the registry makes no promise of completeness. EU acts appear under their official English designations; German statutes and supervisory circulars keep their German names, having none. Remaining record content is given in the language of the sources it describes, and the field names of the machine-readable data are German as well and are explained in the README.
EU Regulations
Directly applicable EU law — no national transposition required.
| Siglum | Official reference | Full title | Rank | Hardness | Identity | Version | Source | Aliases | Attested by |
|---|---|---|---|---|---|---|---|---|---|
| AI Act | Regulation (EU) 2024/1689 | Regulation (EU) 2024/1689 (Artificial Intelligence Act) | 1 | common usage | celex:32024R1689 | konsolidiert Stand 27.07.2026, CELEX 02024R1689-20260727 | EUR-Lex EN · EUR-Lex EN (konsolidiert) | — | — |
| CRR | Regulation (EU) No 575/2013 | Regulation (EU) No 575/2013 | 1 | common usage | celex:32013R0575 | i. d. F. CRR III, konsolidiert Stand 26.06.2026, CELEX 02013R0575-20260626 | EUR-Lex EN · EUR-Lex EN (konsolidiert) | — | BBK, BaFin, EBA, ESAs |
| CRR II | Regulation (EU) 2019/876 | Regulation (EU) No 575/2013 as amended by Regulation (EU) 2019/876 (CRR II) | 1 | common usage | celex:32013R0575 | Verordnung (EU) Nr. 575/2013 in der Fassung der Änderungsverordnung (EU) 2019/876 | EUR-Lex EN | — | — |
| CRR III | Regulation (EU) 2024/1623 | Regulation (EU) No 575/2013 as amended by Regulation (EU) 2024/1623 (CRR III) | 1 | common usage | celex:32013R0575 | Verordnung (EU) Nr. 575/2013 in der Fassung der Änderungsverordnung (EU) 2024/1623 | EUR-Lex EN | — | — |
| DORA | Regulation (EU) 2022/2554 | Regulation (EU) 2022/2554 (Digital Operational Resilience Act) | 1 | common usage | celex:32022R2554 | Ursprungsfassung, CELEX 02022R2554-20221227 | EUR-Lex EN · EN · EUR-Lex EN (konsolidiert) | — | BBK, BaFin, EBA, ESAs, EZB |
| DSGVO | Regulation (EU) 2016/679 | Regulation (EU) 2016/679 (General Data Protection Regulation) | 1 | common usage | celex:32016R0679 | Ursprungsfassung, CELEX 02016R0679-20160504 | EUR-Lex EN · EUR-Lex EN (konsolidiert) | GDPR | BaFin, EBA, ESAs, EZB |
EU Directives
Take effect only through national transposition — for institutions, the transposing statute governs (CRD → KWG).
| Siglum | Official reference | Full title | Rank | Hardness | Identity | Version | Source | Aliases | Attested by |
|---|---|---|---|---|---|---|---|---|---|
| CRD | Directive 2013/36/EU | Directive 2013/36/EU | 1 | common usage | celex:32013L0036 | i. d. F. CRD VI, konsolidiert, CELEX 02013L0036-20260711 | EUR-Lex EN · EUR-Lex EN (konsolidiert) | — | BaFin, EBA, ESAs, EZB |
| CRD IV | Directive 2013/36/EU | Directive 2013/36/EU (original 2013 act, CRD IV) | 1 | common usage | celex:32013L0036 | Stammfassung der Richtlinie 2013/36/EU (CRD IV) | EUR-Lex EN | — | BaFin, EBA |
| CRD V | Directive (EU) 2019/878 | Directive 2013/36/EU as amended by Directive (EU) 2019/878 (CRD V) | 1 | common usage | celex:32013L0036 | Richtlinie 2013/36/EU in der Fassung der Änderungsrichtlinie (EU) 2019/878 | EUR-Lex EN | — | EBA |
| CRD VI | Directive (EU) 2024/1619 | Directive 2013/36/EU as amended by Directive (EU) 2024/1619 (CRD VI) | 1 | common usage | celex:32013L0036 | Richtlinie 2013/36/EU in der Fassung der Änderungsrichtlinie (EU) 2024/1619 | EUR-Lex EN | — | BaFin |
German Statutes
Binding national law — applies alongside the EU framework and transposes EU directives.
| Siglum | Official reference | Full title | Rank | Hardness | Identity | Version | Source | Aliases | Attested by |
|---|---|---|---|---|---|---|---|---|---|
| AO | Abgabenordnung | Abgabenordnung | 1 | official | jurabk:ao_1977 | § 147 (Aufbewahrung); Fassung [nachzutragen] | gesetze-im-internet | — | — |
| HGB | Handelsgesetzbuch | Handelsgesetzbuch | 1 | official | jurabk:hgb | § 257 (Aufbewahrung); Fassung [nachzutragen] | gesetze-im-internet | — | BaFin |
| KWG | Kreditwesengesetz | Kreditwesengesetz | 1 | official | jurabk:kredwg | §§ 25a–25c, Fassung 09.04.2026 (BGBl-Fundstelle [nachzutragen]) | gesetze-im-internet | — | BBK, BaFin |
| ZAG | Zahlungsdiensteaufsichtsgesetz | Zahlungsdiensteaufsichtsgesetz | 1 | official | jurabk:zag_2018 | §§ 53, 54; Fassung FinmadiG 27.12.2024, m. W. v. 30.12.2024 | gesetze-im-internet | — | BaFin |
Delegated and Implementing Acts under DORA
RTS and ITS, adopted as delegated and implementing regulations — as directly binding as the base regulation.
| Siglum | Official reference | Full title | Rank | Hardness | Identity | Version | Source | Aliases | Attested by |
|---|---|---|---|---|---|---|---|---|---|
| ITS RoI | Commission Implementing Regulation (EU) 2024/2956 | Commission Implementing Regulation (EU) 2024/2956 (register of information) | 2 | publisher usage | doc_ref:Durchführungsverordnung (EU) 2024/2956 | konsolidiert Stand 02.12.2024 | EUR-Lex EN (konsolidiert) | ITS Informationsregister, ITS Register, ITS-INFOREG, ITS-RoI | BaFin |
| ITS TIR | Commission Implementing Regulation (EU) 2025/302 | Commission Implementing Regulation (EU) 2025/302 (templates for incident reporting) | 2 | publisher usage | celex:32025R0302 | konsolidiert Stand 20.02.2025, CELEX 02025R0302-20250220 | EUR-Lex EN · EUR-Lex EN (konsolidiert) | ITS Vorfallmeldung, ITS-TIR, ITS-INCREP | BaFin |
| RTS CCI | Commission Delegated Regulation (EU) 2024/1772 | Commission Delegated Regulation (EU) 2024/1772 (classification criteria for ICT incidents) | 2 | publisher usage | celex:32024R1772 | 13.03.2024, ABl. 25.06.2024 | EUR-Lex EN | — | BaFin |
| RTS CTIR | Commission Delegated Regulation (EU) 2025/301 | Commission Delegated Regulation (EU) 2025/301 (content and time limits for incident reporting) | 2 | publisher usage | celex:32025R0301 | 23.10.2024, ABl. 20.02.2025 | EUR-Lex EN | — | BaFin |
| RTS RMF | Commission Delegated Regulation (EU) 2024/1774 | Commission Delegated Regulation (EU) 2024/1774 (ICT Risk Management Framework) | 2 | publisher usage | celex:32024R1774 | 13.03.2024, ABl. 25.06.2024, CELEX 02024R1774-20240625 | EUR-Lex EN · EN · EUR-Lex EN (konsolidiert) | RTS Risikomanagement, RTS-RMF | BaFin |
| RTS SUB | Commission Delegated Regulation (EU) 2025/532 | Commission Delegated Regulation (EU) 2025/532 (subcontracting) | 2 | publisher usage | doc_ref:Delegierte Verordnung (EU) 2025/532 | 24.03.2025 | EUR-Lex EN | RTS Subcontracting, RTS-SUB, RTS-SUBCON | BaFin |
| RTS TPPol | Commission Delegated Regulation (EU) 2024/1773 | Commission Delegated Regulation (EU) 2024/1773 (ICT Third-Party Policy) | 2 | publisher usage | doc_ref:Delegierte Verordnung (EU) 2024/1773 | 13.03.2024, ABl. 25.06.2024 | EUR-Lex EN | RTS-TPPOL | BaFin |
European Supervisory Guidelines
Guidelines of the EU authorities — not directly legally binding; they operate through comply-or-explain and supervisory practice.
| Siglum | Official reference | Full title | Rank | Hardness | Identity | Version | Source | Aliases | Attested by |
|---|---|---|---|---|---|---|---|---|---|
| EBA/GL/2019/02 | EBA/GL/2019/02 | EBA, Guidelines on outsourcing arrangements | 3 | official | doc_ref:EBA/GL/2019/02 | 25.02.2019 | EBA PDF (DE) | — | BaFin, EBA, ESAs, EZB |
| EBA/GL/2019/04 | EBA/GL/2019/04 | EBA, Guidelines on ICT and security risk management | 3 | official | doc_ref:EBA/GL/2019/04 | konsolidierte Fassung; IKT-Abschnitte seit 20.05.2025 gestrichen | EBA PDF (EN) | — | EBA, ESAs |
| EBA/GL/2021/05 | EBA/GL/2021/05 | EBA, Guidelines on internal governance under CRD | 3 | official | doc_ref:EBA/GL/2021/05 | Final Report 02.07.2021, anwendbar ab 31.12.2021 | EBA (Publikationsseite) | — | BaFin, EBA |
| EBA/GL/2022/03 | EBA/GL/2022/03 | EBA, SREP-Guidelines | 3 | official | doc_ref:EBA/GL/2022/03 | Final Report 18.03.2022, anwendbar ab 01.01.2023 (Ablösung durch EBA/GL/2026/06 ab 01.01.2027) | EBA Final Report (EN) | — | — |
| EDSA 07/2020 | EDPB Guidelines 07/2020 | EDPB, Guidelines 07/2020 on the concepts of controller and processor | 3 | official | doc_ref:Leitlinien 07/2020 | Version 2.0, angenommen 07.07.2021 | EDSA (DE) | — | — |
German Supervisory Practice
BaFin's administrative interpretation — decisive in supervisory practice, without the rank of statute.
| Siglum | Official reference | Full title | Rank | Hardness | Identity | Version | Source | Aliases | Attested by |
|---|---|---|---|---|---|---|---|---|---|
| BAIT | Rundschreiben 10/2017 (BA) | Bankaufsichtliche Anforderungen an die IT | 3 | publisher usage | doc_ref:Rundschreiben 10/2017 | BaFin-Rundschreiben 10/2017, Fassung 16.12.2024; Aufhebung zum 31.12.2026 | BaFin (PDF) | — | BBK, BaFin |
| MaRisk | Rundschreiben 06/2026 (BA) | BaFin, Mindestanforderungen an das Risikomanagement | 3 | publisher usage | doc_ref:Rundschreiben 06/2026 (BA) | Rundschreiben 06/2026 (BA) vom 30.06.2026 (9. Novelle; löst RS 06/2024 ab) | BaFin PDF | — | BaFin, EBA |
| ZAG-MaRisk | Rundschreiben 07/2024 (ZAG) | BaFin-Rundschreiben 07/2024 (ZAG) | 3 | publisher usage | doc_ref:Rundschreiben 07/2024 (ZAG) | PDF-Fassung v=6 | BaFin (PDF) | — | BaFin |
Standards and Leading Practices
Not legally binding — independent standards and practice frameworks used as reference.
| Siglum | Official reference | Full title | Rank | Hardness | Identity | Version | Source | Aliases | Attested by |
|---|---|---|---|---|---|---|---|---|---|
| BSI C5 | BSI C5:2026 | BSI, Cloud Computing Compliance Criteria Catalogue | — | publisher usage | version:C5:2026 | C5:2020 und C5:2026 v1.0.1 (verpflichtend ab 01.06.2027) | BSI, Kriterienkatalog C5 | — | — |
| CIS Controls | CIS Controls v8.1 | CIS Critical Security Controls | — | publisher usage | version:v8.1 | v8.1 | cisecurity.org | — | — |
| CVSS | CVSS v4.0 | FIRST, Common Vulnerability Scoring System | — | publisher usage | version:v4.0 | v4.0, Spezifikation v1.2 | first.org | — | CISA, FIRST, NIST |
| ENISA TIG | ENISA NIS2 Technical Implementation Guidance v1.0 | ENISA, NIS2 Technical Implementation Guidance | — | publisher usage | version:v1.0 | v1.0, 26.06.2025 | enisa.europa.eu | — | — |
| EPSS | EPSS v5 | FIRST, Exploit Prediction Scoring System | — | publisher usage | version:v5 | v5 seit 15.06.2026 | first.org | — | — |
| ISO/IEC 27001:2022 | ISO/IEC 27001:2022 | ISO/IEC 27001:2022, ISMS-Anforderungen | — | official | doc_ref:ISO/IEC 27001:2022 | deutsche Übernahme: DIN EN ISO/IEC 27001:2024-01 (kostenpflichtig) | iso.org | — | ISO |
| ISO/IEC 27002:2022 | ISO/IEC 27002:2022 | ISO/IEC 27002:2022, Informationssicherheits-Controls | — | official | doc_ref:ISO/IEC 27002:2022 | deutsche Übernahme: DIN EN ISO/IEC 27002:2024-01 (kostenpflichtig) | iso.org | — | ISO |
| NIST SP 800-40r4 | NIST SP 800-40 Rev. 4 | NIST SP 800-40 Rev. 4, Guide to Enterprise Patch Management Planning | — | official | doc_ref:NIST SP 800-40r4 | 04/2022 | csrc.nist.gov | — | NIST |
| PCI DSS | PCI DSS v4.0.1 | Payment Card Industry Data Security Standard | — | publisher usage | version:v4.0.1 | v4.0.1 (Volltext zugriffsbeschränkt) | pcisecuritystandards.org | — | PCI SSC |
| SDM | SDM V3.1a | Standard-Datenschutzmodell (DSK) | — | publisher usage | version:V3.1a | Methodenhandbuch V3.1a, 14.05.2024 | DSK, SDM-Methode V3.1 (PDF) | — | — |