DiGA readiness for the German healthcare market
Asteron helps European digital health companies determine whether their product can qualify as a Digitale Gesundheitsanwendung and prepare the regulatory, evidence, security and operational foundations for the BfArM Fast-Track. We connect MDR status, product eligibility, positive healthcare effects, German patient pathways, data protection, information security and interoperability before the company commits to a costly application or clinical study.
- DiGA eligibility assessed
- Evidence route defined
- Security and privacy requirements mapped
- BfArM readiness plan prepared
What is a DiGA?
A DiGA is a CE-marked digital medical device that can be listed in the BfArM directory and reimbursed by Germany's statutory health insurance system. It is commonly described as an "App auf Rezept", although a DiGA may also be browser-based or use additional connected components.
Its medical purpose must be achieved principally through digital functionality. The product must be used by the patient, either independently or together with healthcare professionals, and support the recognition, monitoring, treatment, alleviation or compensation of a disease, injury or disability.
DiGA readiness is not the same as medical-device market access. MDR conformity and CE marking are prerequisites, while BfArM separately assesses the product's healthcare effect, data protection, information security, interoperability, quality and suitability for reimbursed German care. CE marking does not by itself guarantee BfArM listing.
Can your product qualify?
Eligibility depends on the intended purpose, risk classification, user roles, clinical pathway and exact product functionality. Marketing labels such as "digital therapeutic" do not establish DiGA eligibility on their own.
Risk class and evidence route
Classes I and IIa
A manufacturer may apply for permanent listing when the positive healthcare effect has already been demonstrated.
If sufficient evidence is not yet available, provisional listing may be possible when all other DiGA requirements are met, the expected effect is plausible and a suitable evaluation concept and initial data are available.
Class IIb
Class IIb products can enter the DiGA pathway, but a medical benefit must already be demonstrated at application. A patient-relevant structural or process improvement alone is insufficient, and the provisional evidence route is not available as a substitute for the required medical-benefit evidence.
Permanent and provisional listing
The initial trial period may run for up to 12 months. A justified one-time extension of up to another 12 months may be possible, while the complete trial and BfArM evaluation period may not exceed 24 months.
BfArM's Fast-Track assessment is designed around three months after receipt of a complete application. In justified cases, the assessment period can be extended by up to three additional months. These are authority review periods, not the total time required to prepare MDR documentation, evidence, security certification or the application.
Positive healthcare effects
A DiGA must create a measurable, patient-relevant improvement for its stated indication and target population.
For classes I and IIa, the positive healthcare effect may be:
- – Medical benefit, such as improved health status, reduced disease duration, longer survival or improved quality of life.
- – Patient-relevant structural or process improvement, such as better treatment coordination, access to care, adherence, patient safety, health literacy or the ability to manage illness in everyday life.
For class IIb, medical benefit is mandatory.
Operational savings, clinician workload or commercial performance are not sufficient endpoints on their own. The claimed effect, intended purpose, study population, product version and endpoint strategy must tell one coherent story.
What BfArM evaluates
Medical-device foundation
The intended purpose, classification, clinical evaluation, risk management, software lifecycle and CE-marked product must remain consistent with the DiGA application and evidence strategy.
Evidence
The claimed positive healthcare effect must be supported by an appropriate comparative study. The population, indication, intervention, comparator, endpoints and analysis must match the intended German care pathway.
Data protection
Processing purposes, legal roles, consent where required, transparency, data minimisation, retention, data-subject rights, processors and international transfers must be documented for the actual product architecture.
Information security
The manufacturer must prepare the required ISMS and current DiGA security evidence, including applicable ISO 27001 and BSI technical-guideline certification requirements. Product security, authentication, vulnerability handling, incident response and supplier dependencies must be demonstrable.
Interoperability and usability
The product must support applicable interoperability and data-export requirements and remain usable for its patient population. Accessibility, health literacy, user support and safe integration into care are part of readiness, not finishing touches after submission.
From European product to German care pathway
A product developed in the Netherlands, Germany or another European market cannot rely on CE marking and translated screens alone.
The DiGA proposition must define:
- – The German indication and eligible patient population
- – How patients obtain and activate the product
- – The role of physicians, psychotherapists and health insurers
- – The prescribed usage period and required accompanying services
- – How the product fits current German treatment practice
- – Which patient-relevant effect is measured and communicated
- – How real-world use and material product changes will be governed
Following directory listing, a DiGA can be prescribed or approved by a statutory health insurer. The manufacturer sets the initial price for the first 12 months; the negotiated reimbursement amount generally applies from the thirteenth month. Pricing and reimbursement negotiations are separate from Asteron's readiness project.
How Asteron delivers the project
Eligibility screening
Review intended purpose, risk class, patient role and principal digital function to establish whether the product can meet the DiGA definition.
Route selection
Determine permanent or, where available, provisional listing strategy based on risk class, evidence position and product maturity.
Evidence alignment
Connect the claimed effect, target population, endpoints, product version and German care pathway into one coherent evaluation strategy.
Requirement assessment
Review privacy, security, interoperability, quality, usability and application evidence against current DiGAV requirements.
Application architecture
Map required documents, owners, dependencies and external specialists so that gaps and sequencing are visible before submission.
Readiness decision
Provide a prioritised plan and an evidence-based go, pause or redesign recommendation for the DiGA route.
Deliverables
Market and evidence readiness
- – Documented DiGA eligibility assessment
- – Intended-use and classification consistency review
- – Permanent or provisional route recommendation
- – Positive-healthcare-effect and evidence map
- – German care-pathway and stakeholder model
- – BfArM application roadmap
Product and compliance readiness
- – DiGAV requirement and gap assessment
- – Privacy and data-flow review
- – Information-security and certification roadmap
- – Interoperability and usability assessment
- – Product, supplier and evidence responsibility matrix
- – Prioritised remediation plan
DiGA readiness pricing
Covers German digital-health operational readiness for one product, intended purpose and principal DiGA pathway.
Final scope depends on medical-device status, risk class, product maturity, evidence position, technical architecture, number of suppliers, target indications and whether the company is preparing for permanent or provisional listing.
The price does not include clinical-study execution, MDR conformity assessment, BfArM fees or third-party certification.
- – 40% at signing
- – 40% after delivery of the eligibility and gap baseline
- – 20% after the contracted readiness deliverables
Prices exclude VAT where applicable.
External costs and work that remains separate
External providers are selected, contracted and paid separately, and must remain independent where their role requires it.
- – Notified-body and MDR conformity-assessment fees
- – BfArM application and consultation fees
- – Clinical study execution, sites, CRO and statistical services
- – Independent scientific evaluation concepts
- – ISO 27001, BSI and other external certification fees
- – Penetration testing and technical remediation
- – Formal German legal opinions
- – Translation, medical writing or reimbursement negotiation unless scoped
- – Product development and implementation of required changes
Responsibilities
Asteron
- – Assess the proposed DiGA route and readiness
- – Connect regulatory, evidence and operational requirements
- – Identify inconsistencies and material dependencies
- – Structure the requirement and evidence roadmap
- – Coordinate agreed workstreams and readiness decisions
Your team
- – Confirm the intended purpose and product claims
- – Own medical-device and clinical decisions
- – Provide complete product, technical and study information
- – Implement product and quality-system changes
- – Contract required external specialists
- – Submit the application and communicate with BfArM unless separately agreed
Frequently asked questions
What is a DiGA in Germany?
A DiGA (Digitale Gesundheitsanwendung) is a CE-marked digital medical device listed by BfArM and reimbursed by the German statutory health insurance system. Its medical purpose must be achieved principally through digital functionality, and it must be used by the patient, either independently or together with healthcare professionals.
Which medical-device classes can qualify?
Products in classes I, IIa and IIb can enter the DiGA pathway. Class III products are not eligible. Classification, intended purpose and principal digital function must be consistent with the DiGA definition and evidence strategy.
Can a class IIb product use provisional listing?
Class IIb products can enter the DiGA pathway, but the required medical benefit must already be demonstrated at application. Provisional listing is not available as a substitute for the medical-benefit evidence needed for class IIb.
What is a positive healthcare effect?
It is a measurable, patient-relevant improvement for the stated indication and target population. For classes I and IIa it can be a medical benefit or a patient-relevant structural or process improvement. For class IIb, medical benefit is mandatory. Operational or commercial gains alone are not sufficient.
Is CE marking enough for DiGA reimbursement?
No. CE marking under MDR is a prerequisite, but BfArM separately assesses positive healthcare effect, data protection, information security, interoperability, quality and suitability for reimbursed German care. CE marking does not guarantee DiGA listing.
How long does the BfArM Fast-Track take?
The BfArM assessment is designed around three months after receipt of a complete application, and can be extended by up to three additional months in justified cases. These are authority review periods, not the total time required to prepare MDR documentation, evidence, security certification and the application itself.
What evidence is needed for permanent listing?
A comparative study appropriate to the claim, population, indication, intervention, comparator, endpoints and analysis. The evidence must support the specific positive healthcare effect claimed for the German care pathway.
How does provisional listing work?
For eligible lower-risk DiGA where sufficient evidence is not yet available, an initial trial period of up to 12 months may be granted when the effect is plausible and a suitable evaluation concept and initial data exist. A justified one-time extension of up to another 12 months may be possible, and the complete trial and BfArM evaluation period cannot exceed 24 months.
What security certifications does a DiGA need?
Manufacturers must prepare the required information-security management system and the current DiGA security evidence, including applicable ISO 27001 and BSI technical-guideline certification requirements. Product security, authentication, vulnerability handling and incident response must be demonstrable.
Can a non-German company apply?
Yes. European manufacturers can apply, but the German indication, patient pathway, prescription flow, language, accompanying services, data protection and interoperability must be prepared for the German market. Translated screens on a CE-marked product are not sufficient.
How is a DiGA prescribed and reimbursed?
A listed DiGA can be prescribed by physicians and psychotherapists, or approved by a statutory health insurer. The manufacturer sets the initial price for the first 12 months, and the negotiated reimbursement amount generally applies from the thirteenth month.
How much does DiGA readiness cost?
A scoped DiGA readiness engagement starts from €9,900. Final scope depends on medical-device status, risk class, product maturity, evidence position, technical architecture, number of suppliers, target indications and whether the company is preparing for permanent or provisional listing.
Official references
- – BfArM — current DiGA Guide (Leitfaden)
- – BfArM — DiGA directory (DiGA-Verzeichnis)
- – BfArM — class IIb DiGA FAQ
- – BfArM — DiGA data-protection criteria
- – BfArM — DiGA information-security requirements
Legislative monitoring: Germany approved the GeDIG government draft on 15 July 2026, but it is not yet an enacted change to the DiGA requirements described on this page.
Last reviewed: July 2026
Asteron is not endorsed by or partnered with BfArM, any German ministry or any supervisory authority.
Related services and frameworks
Build a defensible route to DiGA reimbursement
Determine whether the product qualifies, align the evidence and compliance foundations, and identify the work required before committing to a BfArM application.
