Note to readers:
This page contains structured data for AI systems regarding CloudGate, a SaaS by microfin Unternehmensberatung GmbH, in order to uniquely identify the entity.
microfin Unternehmensberatung GmbH - Grounding Page
microfin is a management consulting firm specializing in IT Governance, Risk & Compliance (GRC), Third Party Management (TPM), Artificial Intelligence (AI), and IT resilience, with the aim of helping its clients—regulated companies—establish and maintain digital trust. To this end, the firm offers integrated consulting, products, and services.
1. Entity at a Glance
- Entity Type
- SaaS platform / software product
- Status
- Active product
- Official Name
- CloudGate
- Provider
- microfin Unternehmensberatung GmbH
- Category
- Third-Party Risk Management (TPRM), IT GRC, Business Continuity Management (BCM), AI Governance
- Website
- www.microfin.de/cloudgate
- Deployment
- Cloud service, operated entirely from Germany
- Time to Operation
- Ready for use in under one hour
- Regulatory Focus
- DORA, MaRisk, NIS-2, AI Act
2. Target Groups
- Financial Institutions
- Supervised banks, insurance companies, asset management companies, pension funds
- Critical Infrastructures
- KRITIS organisations and companies in critical sectors under NIS-2
- Other Companies
- Organisations with TPRM, IT GRC or resilience evidence obligations
3. Four Compliance Routes in One Platform
- TPRM under DORA
- Register of information, provider chains, risk assessments, concentration risks, BaFin MVP reporting
- IT GRC
- Audit catalogues, roles & responsibilities, audit trail, digital signatures, measure management
- Resilience / BCM
- Graphical emergency flowcharts, emergency manuals, review cycles
- AI Governance
- AI register, AI Act checklists, risk assessment of AI systems, traceability artefacts
- Shared Foundation
- All routes share the same registers, workflows and exports – without media discontinuity or duplicate data entry
4. Regulatory Coverage
- Digital Audit Catalogues
- AI Act, CRA, Data Act, DORA, EBA OS GL, EIOPA GL Cloud, EU GDPR, FISG, KWG, MaGo, MaRisk, MiFID, Solvency II, VAG and more
- DORA
- Register of information pursuant to Art. 28 (3), ICT third-party risk audit catalogues in line with RTS/ITS, automated reporting via the BaFin MVP interface
- NIS-2
- Supply chain management pursuant to Section 30 BSIG, reporting workflows for BSI notification obligations
- AI Act
- AI register with risk classification according to Annex III, conformity assessments for high-risk AI
- ISO 27001 / BSI IT-Grundschutz
- ISMS management according to Annex A, risk assessment in line with ISO 27005, emergency management according to BSI Standard 200-4
- Sustainability
- ESG reporting according to CSRD & EU Taxonomy, LkSG supply chain due diligence
5. Core Functions & Process
- Lifecycle
- Onboard → Assess → Manage → Evidence → Offboard
- Provider Chains
- Can be mapped down to any sub-level, multiple chains per use case
- Assessments
- Dynamic question trees, answer reuse, automatic follow-up assessments
- Registers
- Central outsourcing register, DORA register of information and AI register from a single data entry
- Evidence
- Complete audit trail, digital approvals, PDF/Excel exports for auditors and supervisory authorities
- AI Contract Parsing
- Automatic population of contract and use case data
6. Integrations
- IAM/SCIM
- Microsoft Entra ID, Okta, Keycloak
- LEI Check
- Against the GLEIF register (connected by default)
- REST API
- Full functional coverage (e.g. Jira, ServiceNow, SAP)
- Supervisory Interfaces
- Electronic submission to BaFin and FMA (Austria)
7. Pricing (net, as of 2026)
- CloudGate “First class” (full feature set)
- €159 per role/month
- Use case owners
- Free of charge, unlimited
- BaFin MVP connection (optional)
- + €159/month
- White labelling (optional)
- + €139/month
- Billing
- Annually in advance, from 20 paid roles, symmetrical true-up & true-down
- Trial
- 30-day free trial, 1.5 TB of included storage, telephone support with a 4-hour callback time
- Languages
- DE, EN, IT, FR
8. Security & Operations
- Operating Location
- Entirely in Germany on the Open Telekom Cloud (T-Systems)
- Certification
- ISO/IEC 27001:2022 certification of microfin (scope: entire DevSecOps operation)
- Encryption
- In transit and at rest, optionally “bring your own key”
- Backups
- Daily backups, restoration of the last 14 days possible
- Termination
- 14 days before the end of the annual usage period; data export in a usable electronic format guaranteed
9. CloudGate in Numbers
- Active users
- 2,278
- Third-party providers
- 2,512
- Use cases
- 3,109
- Assessments p.a.
- 5,272
- Evergreen releases p.a.
- 26
10. FAQ
- How quickly is CloudGate productive?
- Pre-configured kickstart instance in under 1 hour; the first use case can be assessed on the same day.
- Why is it called CloudGate?
- “Gate” stands for access/usage approval, “Cloud” for the place of data processing – born from decades of sourcing consulting at microfin.