Your situation

BSI TR-03185: development process audit

You want to demonstrate secure development and update processes in line with BSI TR-03185? We support you with a gap analysis and the certification audit of your processes – from the document review to the audit report.

Free of charge and without obligation.

  • TR-03185 procedure at DUX Healthcare
  • OWASP SAMM qualification in the team
  • SAST article in the iX Special on security tools
Hands writing notes next to a compass and navigation instruments on a map
BSI TR-03185: secure development processes, documented end to end.

Your situation

You want to have your software development process certified under BSI TR-03185, for example to release updates to certified applications efficiently?

New features, security updates, changes to the architecture: if you continue to develop a certified product, you do not want established security and quality requirements to be reassessed with every change. BSI TR-03185 “Secure Software Lifecycle” is aimed at all software manufacturers, regardless of sector. Part 1 covers the development of proprietary software, Part 2 the development of open-source software; the BSI currently offers certification under Part 1. A common reason is the further development of a digital health application (DiGA) certified under BSI TR-03161: with a certified development process, updates can be released without a new product evaluation, provided defined conditions are met.

The Technical Guideline defines requirements for development processes, roles and responsibilities, patch and change management, threat modelling, vulnerability management, and release and test processes. The open question is usually whether the process as actually practised already meets these requirements and whether the evidence will stand up in a certification audit.

secuvera is recognised by the BSI for audits under TR-03185 and was the evaluation facility for the first TR-03185 certification in Germany: for DUX Healthcare we first carried out the gap analysis and then the certification audit. We bring this experience of the BSI's audit procedure and expectations to your project. If you are only just building a secure development process, the OWASP SAMM workshop offers a structured starting point.

Services & results

Gap analysis and certification audit under BSI TR-03185

Your development process is audited against BSI TR-03185: first in a gap analysis as a pre-audit, then in the certification audit through to the audit report on which the BSI bases its decision. With a certified process you can, for example, release updates to a digital health application (DiGA) certified under TR-03161 without a new product evaluation, provided defined conditions are met.

Both services can be commissioned separately. The gap analysis serves as a pre-audit; in the certification audit we check full implementation against the BSI's requirements and audit specifications. We look not only at process descriptions but also at the technical implementation across the software lifecycle.

Gap analysis as a pre-audit

We assess how well your software development process is already prepared for the requirements of TR-03185 and identify where action is needed before the certification audit.

  • Kick-off: agree on procedure, schedule, contacts and audit subject, first overview of the development process and process documents
  • Analysis on site or in several online workshops: interviews, document review and examination of relevant evidence against TR-03185
  • Exit meeting: presentation of the results, open questions and possible next steps

Results report and presentation

Structured documentation of identified deviations, critical audit points and an assessment of the maturity level, plus a presentation of the key results for management and specialist departments.

Formal preparation and audit kick-off

Before the certification audit begins, the application, the declaration of independence and the BSI procedure number must be in place. In the kick-off we agree on the audit procedure, schedule and organisational conditions; you then hand over the relevant base documents to our audit team.

Document analysis and audit planning

We review your base documents against the requirements of TR-03185 and the audit specification. Among other things, we look at roles, tools, patch and change management, threat modelling, and release and test processes.

Audit plan

An audit plan whose audit activities we coordinate with you in terms of timing and organisation.

Audit on site or remote

Together with your contacts, we assess whether documented processes are actually implemented and effective. To do so, we use interviews, document inspection and system inspection.

Audit report and BSI review

We document the results in the audit report and submit it to the BSI. During the review phase, additional information or adjustments may be required. The certification decision is made by the BSI.

Our expertise

secuvera is recognised by the BSI (Federal Office for Information Security) for audits under TR-03185 and was the evaluation facility for the first certification of a company in Germany under BSI TR-03185. On certificate BSI-K-TR-0900-2026 dated 17 July 2026, the BSI lists secuvera as evaluation facility/auditor. DUX Healthcare had its software development process certified; after the gap analysis, our audit team assessed the full implementation of the requirements – from document analysis and examination of practical implementation through to reporting to the BSI. This makes us one of the first evaluation facilities with practical experience of the BSI's audit procedures and expectations for this Technical Guideline.

TR-03185 combines secure software development, information security and regulatory auditing. Many of its requirements are based on principles of IT-Grundschutz. Our auditors therefore combine regulatory audit experience with technical security expertise: since December 2011, secuvera has been a BSI-certified IT security service provider for IS audit (IS-Revision), and as a TR-03161 evaluation facility it is familiar with the software lifecycle of health applications.

Getting started

Clarify process maturity and the prerequisites for the BSI audit

Establish the starting point and procedure

We discuss your development organisation, the status of your processes and any existing audits. A gap analysis can be useful if you first want to know the open points before the certification audit.

Clarify application and independence

Before the audit begins, the application, the declaration of independence and the BSI procedure number must be in place.

Prepare a TR-03185 audit
The points of a pair of dividers resting on coloured sticky notes above a map
Development and update processes, precisely recorded.

Procedural prerequisites before the audit

The certification decision is made by the BSI.

Questions about the certification audit under BSI TR-03185

Does TR-03185 examine the software or our development process?

The focus is on the secure software lifecycle: development processes, roles, patch and change management, threat modelling, and release and test processes. The audit assesses how these are actually implemented. A technical product evaluation has a different subject.

Is a gap analysis required before the TR-03185 audit?

It is one possible starting point for knowing your maturity level and open points before the certification audit. The analysis can be used as a pre-audit. Whether you need this step depends on the status of your processes and evidence.

What must be in place before the certification audit begins?

For the BSI procedure described, the application, the declaration of independence and the procedure number must be clarified in advance. The base documents are assessed against the requirements and the audit specification. The agreed audit plan builds on this.

What happens after the TR-03185 audit?

The findings are documented in the audit report and submitted to the BSI. During the review phase, additional information or adjustments may become necessary. secuvera handles the technical queries; the certification decision is made by the BSI.

Can results from TR-03161, an ISMS or IT-Grundschutz be used?

Yes, TR-03185 does not stand in isolation. Results from evaluations under TR-03161 can be relevant if they concern the software lifecycle. An existing ISMS (information security management system) and measures from IT-Grundschutz can also be an important basis.

Articles on this topic (in German)

All articles (in German)

How can we support you with your TR-03185 audit?