Skip to main content
News & Insights

The Update for
Digital Health.

Technical depth, regulatory updates, and insights into the future of health identities.

6 min read

From Regulation to Code: How azuma nori Translates Between Compliance and Development

azuma Team
Core Team

There's a translation gap between a regulatory requirement and the line of code that satisfies it. On one side stands a regulatory or compliance lead who knows BSI TR-03161 or the EU Cyber Resilience Act. On the other, a development team that wants to ship, but rarely has time to work through several hundred pages of technical guideline. Translating between the two worlds costs time, money, and patience – and is the real friction in the compliance process.

This article describes where that gap comes from, what it costs, and how azuma nori closes it by translating regulatory requirements directly into concrete, verifiable statements about the codebase.

The translation gap between regulation and development

Regulatory documents are written for their own purpose – not for developers. BSI TR-03161, for instance, formulates requirements for secure digital health applications abstractly and normatively. A sentence like "sensitive data must be encrypted according to the state of the art" is regulatorily unambiguous, but requires interpretation for actual implementation: Which algorithm? Which key length? Where in the code? With what evidence?

Today, that interpretation is usually done by a person – an internal compliance lead, a regulatory expert, or an external consultant. They read the requirement, translate it into a technical specification, hand it to the development team, later manually check the implementation, and document the result. Every one of these steps is slow, expensive, and error-prone, because it relies on scarce, point-in-time expert knowledge.

Every digital health team knows the outcome: compliance becomes a bottleneck. Requirements arrive late, often shortly before an audit or a certification. Developers have to rebuild things that could easily have been accounted for earlier. And the scarcest resource – the time of the few people who understand both regulation and technology – gets used up on mechanical translation work instead of the genuinely hard decisions.

What azuma nori does differently

azuma nori is an agentic compliance analysis for your own codebase. Instead of leaving a requirement in a document and waiting for a human to translate it, nori checks the actual code against the concrete requirements of a policy – doing the translation itself.

azuma nori translates regulatory requirements directly into concrete checks against the codebase

The core idea is a shift in perspective: not "read the guideline and implement it somehow," but "here's your code, here's the requirement, and here's the concrete comparison between the two." An abstract normative provision becomes a verifiable statement about the actual state of the product.

azuma nori results screen showing critical findings from an automated comparison of a codebase against a policy

For the roles involved, this fundamentally shifts where the effort goes:

  • Regulatory and compliance leads no longer have to translate every requirement for development individually and manually track implementation. They work with a structured result instead of gut feeling and spot checks.
  • Development teams get concrete, code-level guidance instead of normative prose – right where they already work.
  • External consultants get used for the tasks that genuinely require human judgment (edge cases, interpretation, strategy), instead of mechanically working through checklists.

To the best of our knowledge, this direct translation from policy to codebase is exactly what sets nori apart from generic compliance checklists or pure document-management tools: they work with forms and self-attestations, nori works with the code itself.

Which regulations nori covers

nori isn't limited to a single guideline – it covers several regulatory frameworks relevant to digital health, some fully available, some in beta or in development:

  • BSI TR-03161 (Parts 1–3) – the central security guideline for DiGAs and health applications.
  • BSI TR-02102 (Parts 1–2) – cryptographic requirements and key management.
  • EU Cyber Resilience Act (beta) – the EU's horizontal product cybersecurity regulation (see our CRA article).
  • BSI TR-03107 (in development) – electronic identities and trust levels.
  • EU AI Act (in development) – requirements for AI systems.

You can find the current availability status of each regulation on the azuma nori product page.

What that actually saves

The benefit is easiest to measure in time saved from the most expensive resources. Once the translation from requirement to code no longer has to happen manually, effort shifts from recurring busywork to targeted expert work. Compliance cycles that used to take weeks and tie up external consultants get shorter and repeatable.

For DiGA manufacturers building their product under time and cost pressure while having to satisfy multiple regulations at once, that's a direct lever: less blocking of development, more predictable audit preparation, fewer expensive consulting hours spent on tasks that can be automated.

Frequently asked questions

Does azuma nori replace my compliance leads or consultants?

No. nori takes over the mechanical translation and checking work between policy and code. Interpreting edge cases, strategic decisions, and final responsibility stay with the experts – who gain time for exactly those demanding tasks as a result.

Which guidelines does this work for?

Currently, among others, BSI TR-03161 (Parts 1–3) and BSI TR-02102-1/-2 in regular availability, the EU CRA in beta, and BSI TR-03107 and the EU AI Act in development. The current status is available on the product page.

Do I have to hand over my code to azuma?

No. nori runs locally on the developer's machine; the source code never leaves the device. We explain why that matters for IP protection and data privacy in the article nori never transfers code to azuma.

How do I get started?

You can sign up for a free trial (three selected controls included) or get in touch to discuss your specific use case.


Want to see how nori translates your regulations into concrete checks? Sign up for the free trial (three selected controls included) or get in touch.

As of: July 2026. azuma nori's feature scope and covered regulations are continuously expanding – please check the product page for the current status.