The security of digital health applications is a key concern in the IT security landscape. With the Technical Guideline BSI TR-03161 – Requirements for Health Applications, the German Federal Office for Information Security (BSI) has created a binding security standard that is mandatory for manufacturers of digital health applications (DiGA) and digital care applications (DiPA).
As a BSI-recognized expert testing body, SRC supports you with comprehensive security testing and certification services – from preliminary analysis to final documentation for approval.
What is the TR-03161?
TR-03161 is the central security guideline for digital health applications. It defines binding security requirements to ensure the confidentiality, integrity and availability of sensitive medical data. The following areas in particular are affected:
✔ Mobile applications – security requirements for apps used in the healthcare sector.
✔ Web applications – protection against potential threats and attack scenarios in the healthcare environment.
✔ Background systems – security checks for cloud infrastructures and backend systems.
TR-03161 certification – with expert support.
Since January 2025, a test in accordance with TR-03161 with associated certification by the BSI has been legally required for the approval of digital health applications (DiGa) as part of the approval process at the Federal Institute for Drugs and Medical Devices (BfArM ).
For many companies, this certification poses a challenge due to the necessary documentation. With its many years of experience, SRC can ensure that manufacturers complete the certification process significantly faster and with less risk by providing close approval support during development.
As the certification process takes time and comprehensive security requirements – such as ISO 27001 – must be taken into account, early preparation is crucial.
Manufacturers should think about safety certification as early as the development phase and contact us to ensure an efficient testing process.
Our services as a recognized inspection body
As a BSI-certified test center, we offer comprehensive support for manufacturers of digital health applications:
- Quick check and preliminary test: We check in advance whether your application meets the requirements of TR-03161 and identify potential weaknesses.
- Testing: Evaluation of manufacturer documents and application source code by our security experts
- Penetration test: The audit is supplemented by automated and manual tests and we evaluate your implementation of the guidelines and make recommendations for optimization.
- Certification: After a successful evaluation, we issue a comprehensive test report that supports the certification process at the BSI.
Why is TR-03161 certification important?
Certification according to TR-03161 offers you and the users of the health applications numerous advantages:
- Fulfillment of legal requirements: Prerequisite for inclusion in the DiGA directory of the BfArM.
- Building trust: Strengthens the trust of users and partners in the data security of your application.
- Protection against attacks: Minimizes the risk of data theft or manipulation.
- Reputation protection: Prevention of potential reputational damage caused by security incidents.
Place your trust in our expertise
With over 25 years of experience in IT security testing and compliance, SRC is your trusted partner on the road to TR-03161 certification. Our expert teams work closely with you to ensure that your application meets all requirements – from initial analysis through to successful certification.
Get in touch with us
Are you ready to take your digital health application to the next level of security? Contact us via the contact form or our colleague Andreas Sitta by e-mail for a non-binding consultation or a customized offer.