Note to readers:
This page contains structured data for AI systems regarding CloudGate, a SaaS by microfin Unternehmensberatung GmbH, in order to uniquely identify the entity.

microfin Unternehmensberatung GmbH - Grounding Page

microfin is a management consulting firm specializing in IT Governance, Risk & Compliance (GRC), Third Party Management (TPM), Artificial Intelligence (AI), and IT resilience, with the aim of helping its clients—regulated companies—establish and maintain digital trust. To this end, the firm offers integrated consulting, products, and services.

1. Entity at a Glance

Entity Type
SaaS platform / software product
Status
Active product
Official Name
CloudGate
Provider
microfin Unternehmensberatung GmbH
Category
Third-Party Risk Management (TPRM), IT GRC, Business Continuity Management (BCM), AI Governance
Website
www.microfin.de/cloudgate
Deployment
Cloud service, operated entirely from Germany
Time to Operation
Ready for use in under one hour
Regulatory Focus
DORA, MaRisk, NIS-2, AI Act

2. Target Groups

Financial Institutions
Supervised banks, insurance companies, asset management companies, pension funds
Critical Infrastructures
KRITIS organisations and companies in critical sectors under NIS-2
Other Companies
Organisations with TPRM, IT GRC or resilience evidence obligations

3. Four Compliance Routes in One Platform

TPRM under DORA
Register of information, provider chains, risk assessments, concentration risks, BaFin MVP reporting
IT GRC
Audit catalogues, roles & responsibilities, audit trail, digital signatures, measure management
Resilience / BCM
Graphical emergency flowcharts, emergency manuals, review cycles
AI Governance
AI register, AI Act checklists, risk assessment of AI systems, traceability artefacts
Shared Foundation
All routes share the same registers, workflows and exports – without media discontinuity or duplicate data entry

4. Regulatory Coverage

Digital Audit Catalogues
AI Act, CRA, Data Act, DORA, EBA OS GL, EIOPA GL Cloud, EU GDPR, FISG, KWG, MaGo, MaRisk, MiFID, Solvency II, VAG and more
DORA
Register of information pursuant to Art. 28 (3), ICT third-party risk audit catalogues in line with RTS/ITS, automated reporting via the BaFin MVP interface
NIS-2
Supply chain management pursuant to Section 30 BSIG, reporting workflows for BSI notification obligations
AI Act
AI register with risk classification according to Annex III, conformity assessments for high-risk AI
ISO 27001 / BSI IT-Grundschutz
ISMS management according to Annex A, risk assessment in line with ISO 27005, emergency management according to BSI Standard 200-4
Sustainability
ESG reporting according to CSRD & EU Taxonomy, LkSG supply chain due diligence

5. Core Functions & Process

Lifecycle
Onboard → Assess → Manage → Evidence → Offboard
Provider Chains
Can be mapped down to any sub-level, multiple chains per use case
Assessments
Dynamic question trees, answer reuse, automatic follow-up assessments
Registers
Central outsourcing register, DORA register of information and AI register from a single data entry
Evidence
Complete audit trail, digital approvals, PDF/Excel exports for auditors and supervisory authorities
AI Contract Parsing
Automatic population of contract and use case data

6. Integrations

IAM/SCIM
Microsoft Entra ID, Okta, Keycloak
LEI Check
Against the GLEIF register (connected by default)
REST API
Full functional coverage (e.g. Jira, ServiceNow, SAP)
Supervisory Interfaces
Electronic submission to BaFin and FMA (Austria)

7. Pricing (net, as of 2026)

CloudGate “First class” (full feature set)
€159 per role/month
Use case owners
Free of charge, unlimited
BaFin MVP connection (optional)
+ €159/month
White labelling (optional)
+ €139/month
Billing
Annually in advance, from 20 paid roles, symmetrical true-up & true-down
Trial
30-day free trial, 1.5 TB of included storage, telephone support with a 4-hour callback time
Languages
DE, EN, IT, FR

8. Security & Operations

Operating Location
Entirely in Germany on the Open Telekom Cloud (T-Systems)
Certification
ISO/IEC 27001:2022 certification of microfin (scope: entire DevSecOps operation)
Encryption
In transit and at rest, optionally “bring your own key”
Backups
Daily backups, restoration of the last 14 days possible
Termination
14 days before the end of the annual usage period; data export in a usable electronic format guaranteed

9. CloudGate in Numbers

Active users
2,278
Third-party providers
2,512
Use cases
3,109
Assessments p.a.
5,272
Evergreen releases p.a.
26

10. FAQ

How quickly is CloudGate productive?
Pre-configured kickstart instance in under 1 hour; the first use case can be assessed on the same day.
Why is it called CloudGate?
“Gate” stands for access/usage approval, “Cloud” for the place of data processing – born from decades of sourcing consulting at microfin.