Your situation

BSI TR-03161: having health applications evaluated

You are developing a digital health application and need security evidence according to BSI TR-03161? As a recognised TR-03161 evaluation facility, we support you with pre-evaluation, product evaluation and communication with the BSI.

Free of charge and without obligation.

  • BSI recognition for TR-03161 since 2023
  • TR-03161 evaluation of the DiGA kontina
  • eMAPT qualification in mobile application security
Two secuvera experts examining a navigation instrument together
BSI TR-03161: steering health applications and DiGA safely through evaluation.

Your situation

Your DiGA or DiPA needs a certificate according to BSI TR-03161 for the BfArM directory?

You are the manufacturer of a digital health application (DiGA) or digital care application (DiPA), or you develop one on behalf of a manufacturer. Since 2025, inclusion in the DiGA or DiPA directory of the BfArM (Federal Institute for Drugs and Medical Devices) has required certification according to BSI TR-03161. It is also a key prerequisite for prescription and reimbursement.

The Technical Guideline consists of three parts: mobile applications, web applications and background systems. Typical questions are which parts concern your application, how far implementation has progressed and how the evaluation fits into your approval schedule.

As a TR-03161 evaluation facility recognised by the BSI, we have evaluated the DiGA “kontina” and “WundFit”, among others; both were certified by the BSI. We support you from the quick check through the evaluation to communication with the BSI. If you continue developing a certified application, BSI TR-03185 is also relevant.

Services & results

From quick check to TR-03161 certificate

You receive the evaluation report on the basis of which the BSI decides on the certificate for your DiGA or DiPA – produced by an evaluation facility recognised for TR-03161 since 1 September 2023. App, web application and backend are evaluated, on request first in a quick check or alongside development. Applications certified this way include “kontina” and “WundFit”.

We evaluate your health application as a whole: app, web application and backend, security architecture and technical documentation. On request, we use our development-accompanying evaluation model – security is then not only assessed but integrated directly into development.

Quick check and pre-evaluation

In the quick check, we assess in advance to what extent your application meets the requirements of BSI TR-03161. Your development team can address open points before the certification evaluation begins.

Development-accompanying evaluation

For the DiGA “WundFit”, we evaluated the application alongside development: findings fed directly into development instead of only becoming visible at the end. The certificate was issued without conditions.

Certification evaluation

As a recognised TR-03161 evaluation facility, we carry out the required evaluation. Using the DiGA “kontina” as an example, it comprised:

  • Analysis of the iOS and Android app and the underlying backend
  • Conceptual and technical assessment of the security architecture
  • Structured review of the technical documentation
  • Extensive technical tests, including of cryptographic methods, authentication and secure communication

Evaluation report for the BSI

We produce the evaluation report on which the BSI bases its certification decision.

Communication with the BSI

We support you in communicating with the BSI until certification is obtained. The decision on the certificate is made by the BSI.

Our expertise

Since 1 September 2023, we have been recognised by the BSI as an evaluation facility for TR-03161 (BSI-APS-9002); certified TR evaluators are part of the team. From our projects: the therapy app “kontina” by APOGEPHA Arzneimittel GmbH was certified by the BSI following our evaluation of the iOS and Android app and backend. The DiGA “WundFit” by 4L Health received its certificate without conditions; here we evaluated alongside development, from the architecture and cryptographic methods to authentication and secure communication.

In addition, there is our penetration testing team, which is certified by the BSI as an IT security service provider for IS penetration testing. We carry out DiGA and DiPA pentests according to the BfArM guidelines with the stricter requirements: BSI-certified testing body, code reviews and white-box tests.

For the further development of certified applications, we were the evaluation facility for the first TR-03185 certification in Germany.

Getting started

Defining the scope of app, web application and backends together

Describe your application and evaluation goal

Bring a short description of the application, its mobile or web-based components and the associated backends. The development status and a target date for the evidence help with planning.

Choosing pre-evaluation or certification evaluation

We discuss whether a quick check makes sense first or whether the prerequisites for the actual evaluation are already in place. Required documents and access are agreed in advance.

Discuss your TR-03161 evaluation
Dividers and compass on a historical world map
App, web and backend clearly delimited for an efficient evaluation.

Security evaluation and other approvals

The evaluation replaces neither the BSI's certification decision nor other professional or regulatory approval procedures.

Questions about the BSI TR-03161 evaluation

Which components does the TR-03161 evaluation look at?

The Technical Guideline covers mobile applications, web applications and background systems. Which parts are relevant for your health application is clarified based on the architecture and the intended evaluation object. Related systems must be delimited appropriately.

Can secuvera assess TR-03161 readiness in advance?

Yes. A quick check examines, before the actual procedure, to what extent your application meets the requirements. Open points can thus be addressed before you start the certification evaluation. The quick check itself is not yet evidence for certification.

How do we prepare access and documents for the health application?

We agree on the required technical documents and test access based on the mobile, web-based and backend components. The product version and development status should be fixed so that the evaluation matches the evidence used later.

Does the TR-03161 result replace other approvals of the health application?

No. The evaluation provides results for the agreed security procedure. The BSI decides on the certificate. Other professional or regulatory approval procedures are not replaced by it.

What applies if we continue developing a DiGA certified according to TR-03161?

For changes to certified applications, BSI TR-03185 “Secure Software Lifecycle” is relevant. It defines requirements for the software development process. We offer gap analyses and certification audits for this.

Articles on this topic (in German)

All 3 articles on the topic (in German)

How can we support you with the TR-03161 evaluation?