Navigation and service

Certification to technical guidelines

Alongside the certification of IT (information technology) products and IT systems in terms of their security functionality, the Federal Office for Information Security (BSI) also offers certification according to technical guidelines (TR). This is necessary in cases where, apart from the implementation of certain security properties, the fulfilment of functional requirements is necessary for the operation of an IT product or system. In particular, this applies to IT products and systems that are envisaged for use in the public sector/in relation to state-issued documents, and therefore in security-critical areas within the Federal Republic of Germany. Requirements in relation to electronic security against counterfeiting, operational reliability or interoperability are priorities here.

Technical Guidelines that describe these requirements are developed and published by the BSI. This, in turn, results solely from the identification of concerns in relation to national security or the public interest. One example of this process has been the creation of various technical guidelines in the context of the introduction of the electronic passport.

The conformity of an IT product or system to a Technical Guideline can be confirmed by the BSI with a certificate. In the course of this procedure, a conformity test is carried out by a neutral testing laboratory on the basis of the test specifications defined in the Technical Guideline. The test is monitored by the responsible certification body within the BSI, and confirmed on completion with a notice of conformity and a certificate.

Testing laboratories that perform technical conformity testing are private enterprises and are accredited for this purpose by the BSI. The requirements that must be met by laboratories testing in accordance with technical guidelines are set out in the technical guidelines themselves. Since there are many different kinds of technical guidelines, domain expertise needs to be demonstrated for each Technical Guideline individually. Testing authorisations are issued and monitored by the accreditation body in the BSI.

All of the laboratories and bodies involved in certification according to technical guidelines are bound to maintain confidentiality.