DiGA Penetration Testing for BfArM Directory Listing
Test the application, backend, APIs, and cloud components in your DiGA scope with white-box testing, manual code review, and clear evidence for BfArM security requirements.

DiGA penetration testing for BfArM readiness
Assess the full technical scope of your Digital Health Application and turn validated findings into evidence your security, engineering, and regulatory teams can use.
Find security gaps before your DiGA submission
Test the DiGA version and technical components in scope, document validated findings, and address security issues before BfArM review.

Test the full DiGA attack surface
Assess the patient-facing app, backend services, APIs, identity flows, third-party integrations, and cloud infrastructure handling health data.

Verify fixes before they become submission blockers
Track validated findings, remediation owners, and agreed fix validation so your team can document the updated security state.

Where penetration testing fits into DiGA security
Support relevant DiGAV information-security requirements with technical testing aligned to BSI guidance and current OWASP methods. A pentest supports the process; it does not replace the broader BfArM assessment.
Basis
How Blaze helps support it
Penetration testing of all components
BfArM DiGA guidance (incl. backend, since Feb 2024)
Full-scope pentest of app, backend, APIs, and infrastructure with manual code review and white-box testing.
BSI TR-03161
Technical security requirements for health apps
Testing aware of TR-03161 requirements; note the Dec 2025 guideline allows TR-03161 certification to replace the separate pentest.
OWASP (MASVS / ASVS / Top 10)
Application security baseline
Manual testing beyond the OWASP Top 10 across mobile, web, and API surfaces.
§139e SGB V
Legal basis for the DiGA directory
Evidence supporting the security requirements for directory listing and reimbursement.
GDPR Art. 32 / ISO 27001
Data protection & ISMS
Security-of-processing evidence and ISMS-aligned reporting (ISO 27000 series or BSI 200-2).
Technical evidence for DiGA security assurance
Get a clear test scope, validated findings, code-review evidence, remediation guidance, and reporting your security team can use alongside the broader BfArM and BSI assurance process.
DiGA-focused reporting
Document scope, methodology, validated findings, and remediation status against the DiGA security requirements relevant to the engagement.
White-box testing & code review
Combine hands-on penetration testing with source-code analysis where the agreed DiGA scope and applicable BSI audit depth call for deeper implementation review.
Assurance-ready documentation
Receive technical reports and executive summaries that document the tested DiGA version, scope, findings, risk, and remediation status.
Experienced security testing team
Work directly with named testers experienced in web, mobile, API, cloud, source-code, and regulated digital-health security assessments.
Reusable technical evidence
Reuse relevant findings in GDPR, ISO 27001, customer assurance, and other security work where the tested scope and requirements genuinely overlap.
Fix validation
Re-verify agreed fixes and document the updated state when validation is included in the selected package or program.
Reuse relevant DiGA security findings
Where scope and requirements overlap, the same technical findings may support GDPR, ISO 27001, HIPAA, or DiPA work. Each framework still has its own obligations.
GDPR
Use relevant findings when demonstrating or improving security of processing for health data under GDPR.
ISO 27001
Use relevant findings in ISMS risk treatment, vulnerability management, and control-improvement work.
DiGA penetration testing questions
Security services for digital health teams
Complement DiGA penetration testing with broader product security validation, adversary simulation, or security program guidance.

Penetration Testing
Test web apps, APIs, mobile, cloud, and networks for exploitable weaknesses with validated findings and clear remediation guidance.
.avif)
Adversary Simulation
Red team and purple team exercises that test how your organization detects, responds to, and contains realistic attack scenarios.

vCISO & Advisory
Build the security roadmap, remediation program, and assurance process around BfArM, GDPR, and broader customer requirements.
Ready to scope your DiGA pentest?
Share your DiGA architecture, current version, submission timeline, and testing needs. We’ll help shape the right technical scope.