DORA
Financial entities, AIFMs, crypto service providers
ICT third-party risk (Art. 28–30) must be documented at closing. SPA clauses on DORA compliance becoming standard.
Bußgeldrahmen
up to 2 % of global group turnover
Private Equity & M&A
Mid-market PE and strategic acquirers can't treat cyber due diligence as nice-to-have from 2025 onward. It's a closing condition. Kopexa scans targets against DORA, NIS2 and ISO 27001 in 14 days instead of 6 weeks, SPA-ready and multi-entity-capable for post-merger integration.
Example: cyber-DD score
Hohes RisikoPlanned acquisition · closing Q3
DORA
In scope (via AIFM relationship)
NIS2
Essential entity
ISO 27001
No ISMS, no DPO designated
Closing-Empfehlung
SPA clauses on cyber-compliance required. Risk reserve to be calculated.
Current regulatory drivers
Cyber-DD is no longer optional. Buying a target without DORA/NIS2 check means inheriting open fine risk and personal executive liability.
Financial entities, AIFMs, crypto service providers
ICT third-party risk (Art. 28–30) must be documented at closing. SPA clauses on DORA compliance becoming standard.
Bußgeldrahmen
up to 2 % of global group turnover
30,000+ German companies (essential + important entities)
From 50 employees / EUR 10M turnover potentially in scope. § 38 BSIG: personal executive liability. Buyer checks threshold status in target.
Bußgeldrahmen
up to EUR 7M / 1.4 % turnover
All companies processing personal data
Check target's fine backlog, verify DPO designation, inspect ROPA and TOM documentation. Rep & Warranty insurance requires evidence.
Bußgeldrahmen
up to 4 % of global group turnover
Sources: regulations, BSI activity reports, German Data Protection Conference (DSK).
Full deal lifecycle
Cyber compliance is no longer a one-off DD point. It's continuous oversight across the investment cycle. Here is what Kopexa delivers per phase.
Scan target against DORA, NIS2, ISO 27001 and (where applicable) TISAX. Check thresholds, quantify fine risk, surface missing structures (DPO, ISMS, vendor management).
Mit Kopexa
Standardised DD template on Pro plan. OSCAL import of target docs. SPA-ready findings report with risk score and concrete recommendations.
After closing, compliance standards must apply to the new subsidiary, alongside existing portfolio companies. Painful manually, chaotic with n separate tools.
Mit Kopexa
Multi-entity platform (Enterprise plan): define group frameworks once, instantiate n times. Cross-framework mapping avoids duplicate work.
Before exit, sellers want a clean cyber story. Documented ISMS / DORA / NIS2 compliance justifies higher multiples and disarms vendor DD findings.
Mit Kopexa
Audit trail over multiple quarters, exportable compliance dossiers for the data room, auditor workspace for external confirmation.
LPs ask for ESG, cyber and governance quarterly. An aggregated view across portfolio companies isn't possible with n separate compliance stacks.
Mit Kopexa
Aggregated dashboard across portfolio. Cyber-health score per company. Quarterly export for LP reports. Escalation workflow on incidents via § 38 BSIG / DORA reporting.
Killer argument vs DD boutiques
NCC, KPMG Cyber and other DD houses sell DORA, NIS2 and ISO-DD as separate workstreams. Kopexa maps them automatically: one scan, one findings report, four regulations covered.
| Control area | DORA | NIS2 | ISO 27001 | TISAX 6.0 |
|---|---|---|---|---|
| ICT third-party risk / supply chain | Art. 28–30 | Art. 21(2)(d) | A.5.19–5.23 | 8.x |
| Risk management & governance | Art. 5–15 | Art. 21(1) | A.5.7, A.6.x | 1.x |
| Incident reporting & notification | Art. 17–18 | Art. 23 | A.5.24–5.25 | 5.x |
| Executive responsibility | Art. 5 | Art. 20 (BSIG § 38) | A.5.1 | 1.1 |
| Resilience testing / pen testing | Art. 24–27 | Art. 21(2)(f) | A.8.29 | 5.2 |
| Asset & configuration management | Art. 9 | Art. 21(2)(c) | A.5.9, A.8.9 | 1.4 |
Mapping based on Kopexa cross-framework engine. Full 200+ mapping points in the Pro and Enterprise plans.
Multi-entity
In the Enterprise plan you build group frameworks once and roll them out n times. Each portfolio company has its own workspace, the holding dashboard aggregates for LP reports.
Maintain group policies once
Holding defines cyber standards, all subsidiaries inherit automatically. No n Excel graveyards.
Aggregated LP reports
Cyber-health score across portfolio companies, exportable as PDF for quarterly LP calls.
Escalation workflow
Incidents per § 38 BSIG / DORA Art. 17 are automatically escalated to holding oversight.
Holding · Aggregated view
5 Portfolio-Companies
Ø Cyber-Score
71/100
Portfolio companies
PortCo A
SaaS · 80 employees
PortCo B
Fintech · 240 employees
PortCo C
Industrial · 450 employees
PortCo D
Maritime · 120 employees
PortCo E
Healthcare · 95 employees
Pay once, use forever
Move the slider to your portfolio size. The comparison shows traditional DD boutique per target plus separate platform per portfolio company against an Enterprise plan covering DD and ongoing compliance.
Portfolio size
5 portfolio companies
Time horizon
3 years
DD boutique setup
593.000 EUR
Kopexa Enterprise
52 % günstiger285.000 EUR
Difference over 3 years
308.000 EUR
Plus soft factor: documentation outlives closing, findings live outside the PDF graveyard.
Assumptions: mid-market complexity, 1 acquisition per year over the horizon. Specific Enterprise pricing on request.
Two entry points
Single-target DD is the fastest entry, portfolio rollout the biggest lever. Both run on the same platform.
Single workspace with unlimited frameworks, OSCAL import, SPA-ready findings report. Right for buy-side DD before LOI or pre-sale vendor DD.
Define group frameworks once, instantiate n times. Aggregated dashboard for LP reporting. SSO/SAML, dedicated success manager, SLA.