18 / 20
Kriterien erfülltCriteria met
2 teilweise: D2 und D52 partly met: D2 and D5
v1.0
Bewertete FassungVersion assessed
Kern v818 · Release-Tag v1.0.818core v818 · release tag v1.0.818
EUPL-1.2
Lizenz der gesamten SoftwareLicence of the entire software
ohne Lizenzvertrag nutzbarusable without a licence agreement
Bezug: ZenDiS, Diskussionspapier „Kriterien zur Bewertung von Digitaler Souveränität – aus messbar wird machbar“, Stand März 2026, Kriterien A1 bis D5. Version 1.0 des Katalogs erscheint laut ZenDiS Mitte Oktober 2026; die Belege werden dann ihr zugeordnet.
Reference: ZenDiS discussion paper “Kriterien zur Bewertung von Digitaler Souveränität – aus messbar wird machbar”, March 2026, criteria A1 to D5. According to ZenDiS, version 1.0 of the catalogue will be published in mid-October 2026; the evidence will then be mapped to it.
A · Organisation und FähigkeitenOrganisation and capabilities
A1 StrategieStrategy
Datensouveränität ist der erste Grundsatz, aus dem die Architektur abgeleitet ist.Data sovereignty is the first principle from which the architecture is derived.
ERFÜLLTMET
A2 IT-Governance und ManagementIT governance and management
Architekturentscheidungen sind als ADRs veröffentlicht, viele davon mit einer maschinell geprüften Probe je Zusage.Architecture decisions are published as ADRs, many of them with a machine-checked test for each commitment.
ERFÜLLTMET
A3 RisikomanagementRisk management
Alle Fremdbestandteile sind eingebettet und verzeichnet; Abhängigkeiten werden laufend gegen die OSV-Datenbank geprüft.All third-party components are embedded and listed; dependencies are checked continuously against the OSV database.
ERFÜLLTMET
A4 Beschaffung und VergabeProcurement
Die gesamte Software steht unter EUPL-1.2. Eine Behörde nutzt, ändert und verbreitet sie ohne Lizenzvertrag.The entire software is licensed under EUPL-1.2. A public body can use, modify and distribute it without a licence agreement.
ERFÜLLTMET
A5 AuftraggeberfähigkeitCapability as a client
Der Quellcode ist vollständig veröffentlicht, und das Produkt lässt sich daraus bauen und betreiben, ohne den Hersteller.The source code is published in full, and the product can be built and run from it independently.
ERFÜLLTMET
A6 KompetenzenSkills
Für den Bau reicht Node.js. Entwicklung, Rechtsräume und Vorlagen sind dokumentiert.Node.js is all the build needs. Development, jurisdictions and templates are documented.
ERFÜLLTMET
B · Digitale Anwendungen und DiensteDigital applications and services
B1 Transparenz und DokumentationTransparency and documentation
Die Kennzahlen stehen in einer Faktenbasis, die maschinell aus dem Code erzeugt wird.Key figures are kept in a fact base generated automatically from the code.
ERFÜLLTMET
B2 LieferketteSupply chain
Stückliste im Format CycloneDX. Herkunft und Lizenz jedes Bestandteils sind verzeichnet, SNOMED CT über das Global Patient Set.Software bill of materials in CycloneDX format. Origin and licence of every component are listed, SNOMED CT via the Global Patient Set.
ERFÜLLTMET
B3 Architektur und ModularitätArchitecture and modularity
Kern und Module sind getrennt. Rechtsräume und Vorlagen kommen als Module hinzu.Core and modules are separate. Jurisdictions and templates are added as modules.
ERFÜLLTMET
B4 StandardsStandards
Export und Import in offenen Standards, darunter HL7 FHIR IPS, SD-JWT VC, vCard und iCalendar.Export and import in open standards, including HL7 FHIR IPS, SD-JWT VC, vCard and iCalendar.
ERFÜLLTMET
B5 Abhängigkeit auf Software-EbeneSoftware-level dependency
Läuft in jedem gebräuchlichen Browser, ohne App-Store und ohne proprietäre Komponente.Runs in any common browser, with no app store and no proprietary component.
ERFÜLLTMET
C · DatenData
C1 DatenlokationData location
Die Daten liegen auf dem Gerät der Person. Die Anwendung baut keine Netzverbindung auf (
connect-src 'none').The data stays on the person’s device. The application opens no network connection (connect-src 'none').ERFÜLLTMET
C2 DatensicherheitData security
AES-256-GCM, Schlüssel aus dem Passwort abgeleitet. Geprüft gegen NIST- und Wycheproof-Testvektoren.AES-256-GCM, key derived from the password. Tested against NIST and Wycheproof test vectors.
ERFÜLLTMET
C3 DatenschutzData protection
Jede Herausgabe ist eine Handlung der Person. Sensible Felder werden dabei zurückgehalten, bis sie sie einzeln freigibt.Every disclosure is an action by the person. Sensitive fields are held back until they release each one.
ERFÜLLTMET
C4 DatenstrukturenData structures
Die Depot-Datei liegt bei der Person und lässt sich kopieren und mitnehmen. Ältere Fassungen werden über geprüfte Migrationsstufen gelesen.The depot file stays with the person and can be copied and taken anywhere. Older versions are read through tested migration steps.
ERFÜLLTMET
D · Betrieb und InfrastrukturOperations and infrastructure
D1 Abhängigkeit auf Betriebs- und Provider-EbeneOperator and provider dependency
Kein Betreiber und kein Cloud-Anbieter: Die Anwendung läuft als Datei im Browser, auch offline.No operator and no cloud provider: the application runs as a file in the browser, offline too.
ERFÜLLTMET
D2 KundenverhältnisCustomer relationship
Kein Vertrag, keine Registrierung. Jede Fassung bekommt mindestens fünf Jahre Sicherheitsaktualisierungen und trägt einen Release-Tag.No contract, no registration. Every version receives at least five years of security updates and carries a release tag.Offen: Release-Planung und signierte Release-Tags kommen mit der nächsten Fassung.Open: A release plan and signed release tags come with the next version.
TEILWEISEPARTLY
D3 Exit-FähigkeitExit capability
Wer die Datei hat, arbeitet ohne Anbieter weiter. Sie lässt sich aus dem Quellcode neu bauen.Whoever has the file can carry on without a provider. It can be rebuilt from the source code.
ERFÜLLTMET
D4 Resilienz und Business ContinuityResilience and business continuity
Es gibt keinen zentralen Dienst, der ausfallen kann. Die Daten liegen verteilt bei den Menschen, die sie führen.There is no central service that can fail. The data is spread across the people who keep it.
ERFÜLLTMET
D5 Sicherheit und Compliance im BetriebOperational security and compliance
Meldeweg für Schwachstellen und Meldeprozess nach dem Cyber Resilience Act sind festgelegt; Prüfsummen je Fassung sind veröffentlicht. Eine interne Sicherheitsprüfung läuft: Bedrohungsmodell, statische Codeanalyse und ein Sicherheitsscan des Auslieferungsdienstes.A vulnerability reporting route and a Cyber Resilience Act reporting process are in place; checksums are published for every version. An internal security review is under way: threat model, static code analysis and a security scan of the delivery service.Offen: Eine externe Prüfung ist vorgesehen.Open: An external review is planned.
TEILWEISEPARTLY
Unsere Empfehlungen an ZenDiSOur recommendations to ZenDiS
- Bürgeranwendungen in den Katalog aufnehmen: Souveränität entscheidet sich auch dort, wo Menschen ihre eigenen Unterlagen führen.Include citizen applications in the catalogue: sovereignty is also decided where people keep their own records.
- Offline-Fähigkeit als eigenes Kriterium.Offline capability as a criterion in its own right.
- EUPL-1.2 als bevorzugte Lizenz für souveräne Anwendungen empfehlen.Recommend EUPL-1.2 as the preferred licence for sovereign applications.
- Kryptografische Vertrauensketten für Vertretung: Bevollmächtigte und Betreuende handeln nachweisbar im Auftrag, ohne Vermittler.Cryptographic chains of trust for representation: attorneys and carers act verifiably on someone’s behalf, without an intermediary.
- Kompatibilität mit der EUDI-Wallet als Kriterium.Compatibility with the EUDI Wallet as a criterion.
- Contextual Custody als Prüfgesichtspunkt: Wo hält die Person die Verbindung zwischen ihren Lebensbereichen, und werden selbst verfasste Unterlagen wie Vollmachten als eigene Kategorie behandelt? (Klessen 2026)Contextual custody as an assessment point: where does the person hold the link between the areas of their life, and are self-authored records such as powers of attorney treated as a category of their own? (Klessen 2026)
