The BSI TR-03185 “Secure Software Lifecycle” defines requirements for secure software development processes across the entire product lifecycle. It is relevant for DiGA manufacturers because of the obligations arising from the BSI guideline: anyone who can demonstrate TR-03185 certification faces considerably less assessment effort for subsequent versions of their TR-03161-certified products. Specifically, the obligation to notify the BSI of every product change in advance no longer applies. Instead, the development process itself is certified, which means software updates can be released without a further BSI assessment. The BSI provided details in a press release dated February 4, 2026.
On February 4, 2026, the BSI officially started piloting TR-03185.
The BSI has also published the list of certified auditors who can carry out TR-03185 conformity assessments.
To the BSI page with the list of assessors and further information: BSI TR-03185