Deutsch

Source Siglum Registry

The registry orders its sources by decreasing regulatory bindingness — from directly applicable EU law through European and national supervisory instruments to voluntary standards.

As of 2026-08-25 — 39 entries, 288 attestations. Curated and growing; the registry makes no promise of completeness. EU acts appear under their official English designations; German statutes and supervisory circulars keep their German names, having none. Remaining record content is given in the language of the sources it describes, and the field names of the machine-readable data are German as well and are explained in the README.

EU Regulations

Directly applicable EU law — no national transposition required.

SiglumOfficial referenceFull titleRankHardnessIdentityVersionSourceAliasesAttested by
AI ActRegulation (EU) 2024/1689Regulation (EU) 2024/1689 (Artificial Intelligence Act)1common usagecelex:32024R1689konsolidiert Stand 27.07.2026, CELEX 02024R1689-20260727EUR-Lex EN · EUR-Lex EN (konsolidiert)
CRRRegulation (EU) No 575/2013Regulation (EU) No 575/20131common usagecelex:32013R0575i. d. F. CRR III, konsolidiert Stand 26.06.2026, CELEX 02013R0575-20260626EUR-Lex EN · EUR-Lex EN (konsolidiert)BBK, BaFin, EBA, ESAs
CRR IIRegulation (EU) 2019/876Regulation (EU) No 575/2013 as amended by Regulation (EU) 2019/876 (CRR II)1common usagecelex:32013R0575Verordnung (EU) Nr. 575/2013 in der Fassung der Änderungsverordnung (EU) 2019/876EUR-Lex EN
CRR IIIRegulation (EU) 2024/1623Regulation (EU) No 575/2013 as amended by Regulation (EU) 2024/1623 (CRR III)1common usagecelex:32013R0575Verordnung (EU) Nr. 575/2013 in der Fassung der Änderungsverordnung (EU) 2024/1623EUR-Lex EN
DORARegulation (EU) 2022/2554Regulation (EU) 2022/2554 (Digital Operational Resilience Act)1common usagecelex:32022R2554Ursprungsfassung, CELEX 02022R2554-20221227EUR-Lex EN · EN · EUR-Lex EN (konsolidiert)BBK, BaFin, EBA, ESAs, EZB
DSGVORegulation (EU) 2016/679Regulation (EU) 2016/679 (General Data Protection Regulation)1common usagecelex:32016R0679Ursprungsfassung, CELEX 02016R0679-20160504EUR-Lex EN · EUR-Lex EN (konsolidiert)GDPRBaFin, EBA, ESAs, EZB

EU Directives

Take effect only through national transposition — for institutions, the transposing statute governs (CRD → KWG).

SiglumOfficial referenceFull titleRankHardnessIdentityVersionSourceAliasesAttested by
CRDDirective 2013/36/EUDirective 2013/36/EU1common usagecelex:32013L0036i. d. F. CRD VI, konsolidiert, CELEX 02013L0036-20260711EUR-Lex EN · EUR-Lex EN (konsolidiert)BaFin, EBA, ESAs, EZB
CRD IVDirective 2013/36/EUDirective 2013/36/EU (original 2013 act, CRD IV)1common usagecelex:32013L0036Stammfassung der Richtlinie 2013/36/EU (CRD IV)EUR-Lex ENBaFin, EBA
CRD VDirective (EU) 2019/878Directive 2013/36/EU as amended by Directive (EU) 2019/878 (CRD V)1common usagecelex:32013L0036Richtlinie 2013/36/EU in der Fassung der Änderungsrichtlinie (EU) 2019/878EUR-Lex ENEBA
CRD VIDirective (EU) 2024/1619Directive 2013/36/EU as amended by Directive (EU) 2024/1619 (CRD VI)1common usagecelex:32013L0036Richtlinie 2013/36/EU in der Fassung der Änderungsrichtlinie (EU) 2024/1619EUR-Lex ENBaFin

German Statutes

Binding national law — applies alongside the EU framework and transposes EU directives.

SiglumOfficial referenceFull titleRankHardnessIdentityVersionSourceAliasesAttested by
AOAbgabenordnungAbgabenordnung1officialjurabk:ao_1977§ 147 (Aufbewahrung); Fassung [nachzutragen]gesetze-im-internet
HGBHandelsgesetzbuchHandelsgesetzbuch1officialjurabk:hgb§ 257 (Aufbewahrung); Fassung [nachzutragen]gesetze-im-internetBaFin
KWGKreditwesengesetzKreditwesengesetz1officialjurabk:kredwg§§ 25a–25c, Fassung 09.04.2026 (BGBl-Fundstelle [nachzutragen])gesetze-im-internetBBK, BaFin
ZAGZahlungsdiensteaufsichtsgesetzZahlungsdiensteaufsichtsgesetz1officialjurabk:zag_2018§§ 53, 54; Fassung FinmadiG 27.12.2024, m. W. v. 30.12.2024gesetze-im-internetBaFin

Delegated and Implementing Acts under DORA

RTS and ITS, adopted as delegated and implementing regulations — as directly binding as the base regulation.

SiglumOfficial referenceFull titleRankHardnessIdentityVersionSourceAliasesAttested by
ITS RoICommission Implementing Regulation (EU) 2024/2956Commission Implementing Regulation (EU) 2024/2956 (register of information)2publisher usagedoc_ref:Durchführungsverordnung (EU) 2024/2956konsolidiert Stand 02.12.2024EUR-Lex EN (konsolidiert)ITS Informationsregister, ITS Register, ITS-INFOREG, ITS-RoIBaFin
ITS TIRCommission Implementing Regulation (EU) 2025/302Commission Implementing Regulation (EU) 2025/302 (templates for incident reporting)2publisher usagecelex:32025R0302konsolidiert Stand 20.02.2025, CELEX 02025R0302-20250220EUR-Lex EN · EUR-Lex EN (konsolidiert)ITS Vorfallmeldung, ITS-TIR, ITS-INCREPBaFin
RTS CCICommission Delegated Regulation (EU) 2024/1772Commission Delegated Regulation (EU) 2024/1772 (classification criteria for ICT incidents)2publisher usagecelex:32024R177213.03.2024, ABl. 25.06.2024EUR-Lex ENBaFin
RTS CTIRCommission Delegated Regulation (EU) 2025/301Commission Delegated Regulation (EU) 2025/301 (content and time limits for incident reporting)2publisher usagecelex:32025R030123.10.2024, ABl. 20.02.2025EUR-Lex ENBaFin
RTS RMFCommission Delegated Regulation (EU) 2024/1774Commission Delegated Regulation (EU) 2024/1774 (ICT Risk Management Framework)2publisher usagecelex:32024R177413.03.2024, ABl. 25.06.2024, CELEX 02024R1774-20240625EUR-Lex EN · EN · EUR-Lex EN (konsolidiert)RTS Risikomanagement, RTS-RMFBaFin
RTS SUBCommission Delegated Regulation (EU) 2025/532Commission Delegated Regulation (EU) 2025/532 (subcontracting)2publisher usagedoc_ref:Delegierte Verordnung (EU) 2025/53224.03.2025EUR-Lex ENRTS Subcontracting, RTS-SUB, RTS-SUBCONBaFin
RTS TPPolCommission Delegated Regulation (EU) 2024/1773Commission Delegated Regulation (EU) 2024/1773 (ICT Third-Party Policy)2publisher usagedoc_ref:Delegierte Verordnung (EU) 2024/177313.03.2024, ABl. 25.06.2024EUR-Lex ENRTS-TPPOLBaFin

European Supervisory Guidelines

Guidelines of the EU authorities — not directly legally binding; they operate through comply-or-explain and supervisory practice.

SiglumOfficial referenceFull titleRankHardnessIdentityVersionSourceAliasesAttested by
EBA/GL/2019/02EBA/GL/2019/02EBA, Guidelines on outsourcing arrangements3officialdoc_ref:EBA/GL/2019/0225.02.2019EBA PDF (DE)BaFin, EBA, ESAs, EZB
EBA/GL/2019/04EBA/GL/2019/04EBA, Guidelines on ICT and security risk management3officialdoc_ref:EBA/GL/2019/04konsolidierte Fassung; IKT-Abschnitte seit 20.05.2025 gestrichenEBA PDF (EN)EBA, ESAs
EBA/GL/2021/05EBA/GL/2021/05EBA, Guidelines on internal governance under CRD3officialdoc_ref:EBA/GL/2021/05Final Report 02.07.2021, anwendbar ab 31.12.2021EBA (Publikationsseite)BaFin, EBA
EBA/GL/2022/03EBA/GL/2022/03EBA, SREP-Guidelines3officialdoc_ref:EBA/GL/2022/03Final Report 18.03.2022, anwendbar ab 01.01.2023 (Ablösung durch EBA/GL/2026/06 ab 01.01.2027)EBA Final Report (EN)
EDSA 07/2020EDPB Guidelines 07/2020EDPB, Guidelines 07/2020 on the concepts of controller and processor3officialdoc_ref:Leitlinien 07/2020Version 2.0, angenommen 07.07.2021EDSA (DE)

German Supervisory Practice

BaFin's administrative interpretation — decisive in supervisory practice, without the rank of statute.

SiglumOfficial referenceFull titleRankHardnessIdentityVersionSourceAliasesAttested by
BAITRundschreiben 10/2017 (BA)Bankaufsichtliche Anforderungen an die IT3publisher usagedoc_ref:Rundschreiben 10/2017BaFin-Rundschreiben 10/2017, Fassung 16.12.2024; Aufhebung zum 31.12.2026BaFin (PDF)BBK, BaFin
MaRiskRundschreiben 06/2026 (BA)BaFin, Mindestanforderungen an das Risikomanagement3publisher usagedoc_ref:Rundschreiben 06/2026 (BA)Rundschreiben 06/2026 (BA) vom 30.06.2026 (9. Novelle; löst RS 06/2024 ab)BaFin PDFBaFin, EBA
ZAG-MaRiskRundschreiben 07/2024 (ZAG)BaFin-Rundschreiben 07/2024 (ZAG)3publisher usagedoc_ref:Rundschreiben 07/2024 (ZAG)PDF-Fassung v=6BaFin (PDF)BaFin

Standards and Leading Practices

Not legally binding — independent standards and practice frameworks used as reference.

SiglumOfficial referenceFull titleRankHardnessIdentityVersionSourceAliasesAttested by
BSI C5BSI C5:2026BSI, Cloud Computing Compliance Criteria Cataloguepublisher usageversion:C5:2026C5:2020 und C5:2026 v1.0.1 (verpflichtend ab 01.06.2027)BSI, Kriterienkatalog C5
CIS ControlsCIS Controls v8.1CIS Critical Security Controlspublisher usageversion:v8.1v8.1cisecurity.org
CVSSCVSS v4.0FIRST, Common Vulnerability Scoring Systempublisher usageversion:v4.0v4.0, Spezifikation v1.2first.orgCISA, FIRST, NIST
ENISA TIGENISA NIS2 Technical Implementation Guidance v1.0ENISA, NIS2 Technical Implementation Guidancepublisher usageversion:v1.0v1.0, 26.06.2025enisa.europa.eu
EPSSEPSS v5FIRST, Exploit Prediction Scoring Systempublisher usageversion:v5v5 seit 15.06.2026first.org
ISO/IEC 27001:2022ISO/IEC 27001:2022ISO/IEC 27001:2022, ISMS-Anforderungenofficialdoc_ref:ISO/IEC 27001:2022deutsche Übernahme: DIN EN ISO/IEC 27001:2024-01 (kostenpflichtig)iso.orgISO
ISO/IEC 27002:2022ISO/IEC 27002:2022ISO/IEC 27002:2022, Informationssicherheits-Controlsofficialdoc_ref:ISO/IEC 27002:2022deutsche Übernahme: DIN EN ISO/IEC 27002:2024-01 (kostenpflichtig)iso.orgISO
NIST SP 800-40r4NIST SP 800-40 Rev. 4NIST SP 800-40 Rev. 4, Guide to Enterprise Patch Management Planningofficialdoc_ref:NIST SP 800-40r404/2022csrc.nist.govNIST
PCI DSSPCI DSS v4.0.1Payment Card Industry Data Security Standardpublisher usageversion:v4.0.1v4.0.1 (Volltext zugriffsbeschränkt)pcisecuritystandards.orgPCI SSC
SDMSDM V3.1aStandard-Datenschutzmodell (DSK)publisher usageversion:V3.1aMethodenhandbuch V3.1a, 14.05.2024DSK, SDM-Methode V3.1 (PDF)