On May 21, the BSI updated its FAQ on TR-03161. It now lists different authentication methods for DiGA that are permissible within TR certification, for example. It also distinguishes which methods count as “suitably secure” and which methods require consent from the user. This is good news for DiGA manufacturers, who had so far been left in the dark as to whether the methods they implemented would be recognised.

The FAQ can be reached at this link: FAQ zur TR-03161