Skip to main content
News & Insights

The Update for
Digital Health.

Technical depth, regulatory updates, and insights into the future of health identities.

5 min read

BSI TR-03185: Updates Without Re-Certification for DiGAs

azuma Team
Core Team

On 22 September 2026, the BSI (German Federal Office for Information Security) handed over the first certificate under BSI TR-03185 to our partner DUX Healthcare from Karlsruhe. Manufacturers who have their development process certified under TR-03185 can ship updates to a TR-03161-certified health application without having every version re-assessed.

This article explains what BSI TR-03185 requires, how the update procedure works, and why DiGA manufacturers already have a good starting point with their ISO 27001 ISMS.

What is BSI TR-03185?​

BSI TR-03185 "Secure Software Lifecycle" is a Technical Guideline issued by the BSI. It sets requirements for a manufacturer's development process, from project management through development and testing to vulnerability management and decommissioning. What gets certified is the process, not the product.

Part 1, for proprietary software, has been available since 6 August 2024 and is the basis for certification. Part 2, for open-source software, followed in November 2025; the BSI does not currently certify against it. The requirements are drawn from the IT-Grundschutz Compendium, DIN EN IEC 62443-4-1, GSMA NESAS and NIST SP 800-218.

The update procedure for TR-03161​

A certificate under BSI TR-03161 applies to one specific product. Since the start of 2026, a pilot procedure has been running for health applications: with a valid TR-03185 certificate, according to the BSI, "re-certifications, maintenance procedures and change notifications for product updates" are no longer required (our translation). The certificate is valid for three years, with annual surveillance audits.

Core requirements for development​

  • Threat model (PROD.DEV.C): created during design and kept up to date
  • Third-party components (PROD.DEV.G): trusted sources, integrity checks, no outdated versions
  • Builds (PROD.DEV.I): automated and reproducible from the version control system
  • SBOM (PROD.DEV.L): provenance records for components per release
  • Regression tests (PROD.TEST.D): check whether updates change security mechanisms
  • Vulnerability management (PROD.FIX): reporting channel, active research, assessment e.g. via CVSS

What this means for DiGA manufacturers​

Every DiGA manufacturer already needs an ISO 27001-certified ISMS and the data security attestation under TR-03161. As of today, TR-03185 is not mandatory, but it builds on that foundation: it is based on IT-Grundschutz, and it is audited by BSI-certified audit team leaders for ISO 27001 on the basis of IT-Grundschutz. Evidence from your existing ISMS can therefore be reused.

Our assessment: the process certificate pays off mainly for frequent releases and several certified platforms. If you rarely ship updates, you save little and still carry the annual audits.

TR-03185 mentions the Cyber Resilience Act as context, but there is no official mapping. The CRA does not apply to medical devices under the MDR in any case.

How azuma nori helps​

Comparison of two update flows: without TR-03185, every new version goes through a change notification or re-certification. With TR-03185, the development process is certified for three years with an annual audit, updates go to release without re-certification, and azuma nori checks against TR-03161 and TR-03185 for every release.

azuma nori checks your codebase locally against BSI TR-03161, TR-02102 and BSI TR-03185 (currently in preview), either as a gap analysis or with every release in your CI/CD pipeline. Before the audit, you see where the gaps are. After certification, nori shows for every release that the requirements are still met. Your source code never leaves your infrastructure. nori does not replace process documentation or the audit.

Five steps to certification​

  1. Gap analysis against TR-03185, e.g. with the BSI test specification or azuma nori
  2. Map evidence from your ISO 27001 ISMS via the source references in the guideline
  3. Close the gaps, typically threat model, SBOM, reproducible builds
  4. Automate checks in your CI/CD pipeline
  5. Commission the audit and plan for the annual surveillance audits; the BSI answers questions at tr03185@bsi.bund.de

Frequently asked questions​

Is BSI TR-03185 mandatory for DiGAs?​

No, not as of today. What is mandatory is an ISO 27001-certified ISMS and the attestation under BSI TR-03161.

Does TR-03185 replace TR-03161 certification?​

No. The product remains certified under TR-03161; the process certificate saves you re-certifications for updates.

How long is a TR-03185 certificate valid?​

Three years, with annual surveillance audits.

Does TR-03185 apply to open-source software?​

Part 1 does not. Open source is covered by Part 2, which the BSI does not currently certify against.


Want to know where your codebase stands against TR-03161 and TR-03185? Sign up for the free trial of azuma nori (three selected controls included) or get in touch.

As of: 5 October 2026. The update procedure is in its pilot phase. The BSI's current publications are authoritative.