On August 21, 2026, the BSI published Technical Guideline TR-03185, “Secure Software Lifecycle,” as a consolidated English-language document in version 1.1.1, merging the previous section on proprietary software with the section on open-source software, including 20 open-source requirements in six categories, seven of which include a reference to Annex I or II of the Cyber Resilience Act.
A new addition is the introductory section 0.1, which states that code assistants, vulnerability scanners, and large language models fall within the scope of the guideline as resources and tools, their additional risks arising from probabilistic behavior must be taken into account, and the BSI strongly recommends the use of AI-based vulnerability scanners for software testing.
This is a guideline, not yet a requirement: This section appears in the introduction and is not listed as a numbered requirement; the German version and the certification basis still refer to Version 1.0, and even the list of sources for the new open-source requirements still cites TR-03185 in Version 1.0.