For the two financial verticals here — MiCA and DORA — Germany’s regulator is the same body: BaFin, the country’s all-in-one financial supervisor. It licenses the crypto firms (CASPs) that want to operate from Germany, and it supervises how German banks and insurers meet DORA’s IT-resilience rules. Germany also happens to lead the EU in authorised crypto providers, which makes BaFin one of the busiest crypto regulators in the bloc. This is a profile of the body. Every fact is sourced.
Quick facts
- Full name: Bundesanstalt für Finanzdienstleistungsaufsicht (BaFin) — Federal Financial Supervisory Authority
- What it is: Germany’s integrated financial regulator — a single authority for banking, insurance, securities/markets and now crypto-asset supervision
- MiCA role: Germany’s national competent authority under MiCA — crypto-asset service providers (CASPs) authorise with BaFin; the rules have applied since 30 December 2024 (BaFin)
- National crypto law: the Kryptomärkteaufsichtsgesetz (KMAG) — Germany’s MiCA companion act, published in the Federal Law Gazette on 27 December 2024, giving BaFin its supervisory powers (BaFin)
- DORA role: the national competent authority supervising DORA’s application by German financial entities
- President: Mark Branson — President of BaFin since August 2021 (BaFin)
- Headquarters: Bonn and Frankfurt am Main
- Website: bafin.de
What BaFin is
BaFin is Germany’s integrated financial supervisor: where some countries split banking, insurance and markets across separate regulators, Germany puts them under one roof. It supervises banks (with the Bundesbank, and under the ECB’s Single Supervisory Mechanism for the largest banks), insurers, investment firms and the securities markets — and, since MiCA, crypto-asset service providers. It operates under the oversight of the Federal Ministry of Finance.
For a compliance hub, BaFin matters in two of the four verticals at once: it is the German face of both the crypto regime (MiCA) and the financial-sector operational-resilience regime (DORA).
BaFin and MiCA
BaFin is Germany’s national competent authority under MiCA. Any firm that wants to provide crypto-asset services from Germany — running an exchange, custody, brokerage, advice, transfers — must be authorised by BaFin as a CASP; that authorisation then passports across the EEA. The CASP rules have applied since 30 December 2024 (BaFin).
Germany backed MiCA with a national act — the Kryptomärkteaufsichtsgesetz (KMAG), published on 27 December 2024 — which equips BaFin with the supervisory and enforcement powers to run the regime domestically (BaFin). Germany set its national transitional window for existing operators to 31 December 2025 — shorter than the EU-level backstop of 1 July 2026.
The result: by April 2026 Germany led the EU by number of MiCA-authorised CASPs (55, the most of any member state — ESMA MiCA Register). BaFin is therefore one of the most active crypto authorisers in the bloc — see our MiCA stablecoins register for how the wider market reshaped.
What BaFin is not: it does not supervise the EU’s significant stablecoin issuers — that job moves to the EBA once a token crosses the significance threshold. BaFin authorises and supervises CASPs and ordinary token issuers at national level.
BaFin and DORA
Under DORA, BaFin is the German national competent authority supervising operational resilience for the financial entities it already regulates — banks, insurers, investment firms, payment institutions and CASPs. It enforces DORA’s ICT-risk, incident-reporting and third-party-risk obligations through Germany’s existing sectoral supervisory framework. The EU-level oversight of the largest tech suppliers (the CTPP regime) sits with the three ESAs jointly — see the DORA CTPP register — while BaFin supervises the German financial firms that use them.
Leadership
- President: Mark Branson. A former Director of Switzerland’s financial regulator FINMA, he has been President of BaFin since August 2021 (BaFin). Under his tenure BaFin has flagged the growing crypto market as a focus area for financial-crime risk.
What this means for you
- If you run a crypto business targeting the EU from Germany: BaFin is your MiCA authorisation authority, and a German CASP licence passports across the EEA. Budget for the KMAG-specific supervisory expectations on top of the MiCA baseline.
- If you are a German bank, insurer or investment firm: BaFin supervises your DORA compliance through the existing sectoral channels — the ICT register, the Article 30 contractual clauses, incident reporting.
- If you map EU regulators: BaFin is the German counterpart to bodies like France’s ACPR/AMF and Ireland’s Central Bank — but uniquely integrated, covering banking, insurance, markets and crypto in one authority. For data protection in Germany, that is a different family entirely — the BfDI and the state DPAs.
TL;DR
BaFin is Germany’s integrated financial supervisor — banking, insurance, securities and crypto under one authority, seated in Bonn and Frankfurt, led by President Mark Branson since August 2021. It is Germany’s national competent authority for both MiCA (it authorises CASPs; the national companion law is the KMAG of 27 December 2024) and DORA (it supervises operational resilience for German financial entities). By April 2026 Germany led the EU with the most MiCA-authorised CASPs (55). Significant stablecoin issuers move up to the EBA; the EU-level oversight of critical tech suppliers sits with the three ESAs.
Sources
- BaFin — MiCAR (official) — CASP authorisation, MiCA application from 30 December 2024
- BaFin — CASPs under MiCAR: simplifications and challenges — the KMAG and BaFin’s powers
- BaFin — President (official) — Mark Branson, President since August 2021
- ESMA MiCA Register — authorised CASPs by member state
- bafin.de — official site
- Related: MiCA pillar · DORA pillar · EBA · MiCA stablecoins register · DORA CTPP register