Under TR-03161, DiGA manufacturers must submit every planned update to the BSI for assessment.
In current discussions, the BSI is bringing another technical guideline into play, published only in August of this year: TR-03185 Secure Software Lifecycle for Proprietary and Open Source Software.
It is intended to solve the problem that manufacturers currently have to report every change to the product to the BSI, which then decides on the effect of the change on the validity of the existing TR-03161 certification. This could cease to apply in future if the manufacturer demonstrates compliance with the new TR-03185. On the one hand this would be a relief for DiGA manufacturers. On the other hand, it would further increase the regulatory burden.
Details are expected to be announced by the BSI in Q1/2026, when the revision of TR-03161 is likely to be published. In the meantime, the BSI has already invited a number of DiGA manufacturers to pilot TR-03185.