B2B Software Consulting in Frankfurt
DORA has bound Frankfurt financial entities since 17 January 2025, and BaFin closed the register of information on 30 March 2026 against a 31 December 2025 reference date. ERPStack engineers custom ERP and CRM systems remotely, deploying into AWS eu-central-1, the region sitting on Frankfurt's own DE-CIX peering fabric.
Quick Answer
In short: DORA has bound Frankfurt financial firms since 17 January 2025, and BaFin's register of information closed on 30 March 2026. ERPStack builds custom ERP for that audit: MaRisk-mapped controls, GoBD immutability with Z1, Z2 and Z3 tax data access, XRechnung output, in AWS eu-central-1 under 2 ms from the metro.
Regional Compliance
- DORA (Regulation (EU) 2022/2554), applicable 17 January 2025
- BaFin MaRisk — Rundschreiben 05/2023 (BA) of 29 June 2023
- EU GDPR and BDSG, supervised in Frankfurt by the HBDI
- GoBD immutability with Z1, Z2 and Z3 tax data access
- Hessische E-Rechnungsverordnung — XRechnung since 18 April 2024
Security & Compliance Architecture
In Frankfurt the auditor arrives before the customer. DORA has applied since 17 January 2025, BaFin’s MaRisk sits on top, and the Hessian commissioner supervises the personal data underneath — finance and insurance buyers feel all three.
Critical or important is a column, not an opinion
BaFin collected the DORA register of information between 9 and 30 March 2026 against a 31 December 2025 reference date. ERPStack stores criticality as a versioned enum on the provider contract, so the flag driving exit planning and audit rights keeps a history a Frankfurt examiner can replay — including which AWS region, and which Microsoft Azure fallback, held the data.Four hours, 24 hours, 72 hours, one month
Major-incident reporting leaves a Frankfurt entity no room for a single timestamp. ERPStack keeps detection, classification and notification as distinct PostgreSQL columns with the acting user attached, guards retries with Idempotency in API Design, and starts the countdown at classification — the moment the four-hour window opens.In Hessen, employee logs need a works agreement
The Court of Justice struck down Hessen’s § 23 HDSIG in C-34/21 on 30 March 2023 as too unspecific for Article 88 GDPR, and § 26 BDSG reads almost identically. A Frankfurt employer therefore rests on a § 87 Abs. 1 Nr. 6 BetrVG works agreement while DORA still demands user-attributable trails; RBAC over Postgres row-level security is how both survive one multi-tenant schema.One ledger, two examiners
A Frankfurt bank’s books are read twice: by a tax auditor under the GoBD, amended 11 March 2024 and 14 July 2025, and by BaFin under DORA. ERPStack serves both from one PostgreSQL Immutable Audit Trail with write-once archives, AWS Key Management Service envelope encryption under Zero-Trust Security, and Z1, Z2 and Z3 extracts on request.
Engineering Blueprint
Frankfurt is the one German city where the cloud region, the internet exchange and the supervisor share a postcode. ERPStack runs Frankfurt ERP and CRM workloads — Next.js and TypeScript over PostgreSQL — in AWS eu-central-1 (3 availability zones) and Microsoft Azure Germany West Central, both on the fabric that carried DE-CIX Frankfurt’s 19.636 Tbit/s peak on 7 July 2026.
The register of information is a query
DORA Article 28 makes every Frankfurt financial entity register each contractual arrangement with an ICT third-party provider, mapped to the function it supports and flagged critical or important. ERPStack owns that in PostgreSQL through Drizzle ORM — provider, region, sub-processor, criticality — so the BaFin submission is a REST query over live data rather than a hand-built spreadsheet.
export const ictProviders = pgTable('ict_providers', {
functionCriticality: criticality('function_criticality').notNull(),
hostingRegion: varchar('hosting_region').default('eu-central-1'),
});Two clocks, because DORA has two
Frankfurt incident reporting runs on four-hour, 24-hour, 72-hour and one-month deadlines, so the system must separate detection from classification. ERPStack writes both timestamps and the classifying user into an append-only PostgreSQL table, and an Event-Driven Architecture fans the same incident id out to Redis consumers and OpenTelemetry Observability spans.
Evidence a MaRisk examiner can pull
BaFin’s MaRisk, Rundschreiben 05/2023 (BA) of 29 June 2023, and § 25b KWG leave the Frankfurt institution accountable for what it outsources. ERPStack exports Terraform state, GitHub Actions history, Kubernetes manifests and Sentry error budgets as evidence, and builds to the controls an ISO 27001 or SOC 2 audit asks for, so the examiner watches them operate.
Evaluate Your Stack
Take our interactive audit to see if your architecture is ready for operational scale.
Start Free AuditRegional Infrastructure
Infrastructure Region
Latency Metrics
Primary Datacenter
Success Stories in Frankfurt
Real-Time Fraud Detection Platform
Real-time fraud detection and risk scoring platform
Read Case StudyTarget Industries in Frankfurt
Frequently Asked Questions
Extend SAP S/4HANA where the Frankfurt bank's core ledger already lives — reimplementing general ledger and regulatory reporting is rarely worth the risk. Build custom where DORA bites: incident classification clocks, the register of information feed, and evidence a BaFin examiner can query. ERPStack ships those beside SAP S/4HANA, Oracle NetSuite or Microsoft Dynamics 365, never instead of them.
Under DORA Article 28 a Frankfurt financial entity records every contractual arrangement with an ICT third-party provider and marks whether the supported function is critical or important. A multi-tenant ERP or SaaS CRM carrying payments, positions or client onboarding usually is. That one flag then drives exit planning, contractual audit rights and BaFin's supervisory attention.
Frankfurt is simply where the traffic already is. DE-CIX Frankfurt peaked at 19.636 Tbit/s on 7 July 2026, and AWS eu-central-1 and Microsoft Azure Germany West Central both sit on that metro fabric — so counterparties, market-data feeds and payment rails are one peering hop away rather than one country away.
DORA did. BaFin withdrew VAIT, KAIT and ZAIT with effect from 16 January 2025 and repealed BAIT Chapter 11 from 17 January 2025 for institutions inside DORA's ICT risk-management scope, the remainder falling away by 31 December 2026. For a Frankfurt ERP build the controls did not soften — they became directly applicable EU law.
DORA splits the clock. A Frankfurt financial entity notifies its authority within four hours of classifying an incident as major and no later than 24 hours after becoming aware, then reports at 72 hours and again at one month. So the ERP holds detection time and classification time as separate PostgreSQL columns inside one Immutable Audit Trail — a single created_at cannot serve both.
Frankfurt sits in Hessen, so its supervisor is Der Hessische Beauftragte für Datenschutz und Informationsfreiheit under Prof. Dr. Alexander Roßnagel — not Berlin's authority. His 54th activity report, presented 14 April 2026, logged complaints rising from 3,839 to 6,070, with credit-agency complaints up 221 percent: directly relevant to any scoring feature in a Frankfurt CRM.
Not on a general statutory clause. In C-34/21 of 30 March 2023 the Court of Justice held Hessen's § 23 HDSIG was not a more specific rule under Article 88 GDPR, and § 26 BDSG reads almost identically. A Frankfurt employer needs a § 87 Abs. 1 Nr. 6 BetrVG works agreement naming the fields that Role-Based Access Control (RBAC) then enforces, while DORA still demands user-attributable audit trails.
DORA Article 26 requires threat-led penetration testing at least every three years for the financial entities authorities designate, run against live production systems supporting critical functions under TIBER-EU. ERPStack therefore builds Frankfurt systems behind a Bastion Host inside a Virtual Private Cloud (VPC), with Semgrep SAST and OWASP ZAP wired into the CI/CD Deployment Pipelines.