BSI Compliance

Docuflair TR-RESISCAN

Legally compliant scanning. BSI-certified.

Legally compliant scanning according to BSI TR-RESISCAN for tamper-proof digitisation. Meets the requirements of the Technical Guideline RESISCAN from the German Federal Office for Information Security (BSI).

Docuflair TR-RESISCAN - User Interface

Substitute Scanning with Legal Certainty

With Docuflair TR-RESISCAN, your digital copy receives the same legal evidential value as the paper original.

BSI Conformity

Full compliance with the Technical Guideline TR-RESISCAN from the German Federal Office for Information Security.

Legal Evidential Value

Digital documents receive the same legal standing as the paper original through substitute scanning.

Complete Traceability

Comprehensive audit trail documents every step of the scanning process for maximum transparency.

Quick Setup

A single software installation is all it takes. No complex infrastructure required.

Docuflair TR-RESISCAN in Action

See how simple legally compliant scanning can be

The TR-RESISCAN-Compliant Scanning Process

From authentication to digital signature

1. User Authentication

Login at the device before scanning for clear identification

2. Document Capture

Scanning with preview directly at the multifunction device

3. Web-Based Visual Inspection

Visual verification and quality control in the browser

4. Transfer Note

Automatic documentation of the scanning process with all relevant metadata

5. Digital Signature

Legally binding signature of the PDF/A document

Core Features

Everything for legally compliant and BSI-certified scanning

Automatic Transfer Note

  • Documentation of scan time and date
  • Recording of device data and scan parameters
  • Logging of the performing person
  • Storage of all processing results

Web-Based Visual Inspection

  • Visual quality verification in the browser
  • Comparison with original document
  • Approval or rejection of the scan
  • Documented confirmation of verification

Digital Signature

  • Legally binding digital signing
  • PDF/A format for long-term archiving
  • Tamper protection through cryptography
  • Integration with certificate infrastructure

Additional Benefits

User Authentication

Secure login at the device before each scan for unambiguous attribution.

Preview at Device

Immediate verification of scan results directly at the multifunction device.

Metadata Capture

Automatic logging of scan time, device data and processing results.

PDF/A Format

Archive-ready format for long-term storage and readability.

Complete Audit Trail

Comprehensive documentation of all steps for compliance and auditing.

Easy Installation

One software, quick setup, no complex infrastructure required.

BSI Technical Guideline

What is BSI TR-03138 (TR-RESISCAN)?

The Technical Guideline from the German Federal Office for Information Security for substitute scanning

Definition & Purpose

BSI TR-03138 (Technical Guideline for Substitute Scanning - RESISCAN) defines security-relevant technical and organisational measures for scanning processes where the paper original is to be destroyed after digitisation.

The aim is to ensure the evidential value of the scan product is as close as possible to that of the original.

  • Current version: 1.5 (December 2024)
  • Publisher: German Federal Office for Information Security (BSI)
  • Legal references: Section 7 EGovG, Section 371b ZPO

Structure of the Guideline

TR-RESISCAN consists of the main document and several annexes:

  • Main document: All requirements and measures
  • Annex P: Normative test specification for conformity assessment
  • Annex A: Results of risk analysis
  • Annex R: Non-binding legal notes
  • Annex V: Sample procedure instruction
  • Annex F: Frequently asked questions (FAQ)

NEW in Version 1.5: Mobile Substitute Scanning

Version 1.5 extends TR-RESISCAN to include the option of mobile substitute scanning. This enables the substitute digitisation of paper originals using mobile devices (smartphone, tablet) with a suitable scanning app.

Module Concept

Modular Requirements Structure

TR-RESISCAN uses a modular system of base and extension modules

Base Module

Basic requirements for all protection categories

  • Basic process requirements
  • Minimum scanner requirements
  • Documentation and logging
  • Quality assurance and visual inspection
  • Transfer note creation
Mandatory for all protection levels

Extension Module Integrity

Additional measures for high protection needs

  • Extended integrity protection
  • Cryptographic hash values
  • Digital signatures
  • Tamper protection
  • Four-eyes principle for approval
When integrity is "high" or "very high"

Extension Module Confidentiality

Measures to protect sensitive data

  • Encrypted transmission
  • Access controls
  • Secure storage
  • Authorisation concept
  • Audit logging
When confidentiality is "high" or "very high"
Protection Needs Assessment

Protection Requirement Categories

The protection requirement determines the necessary modules and measures

Legal Basis

Legal Framework References

TR-RESISCAN as "state of the art" in German legislation

Conformity Evidence

Paths to TR-RESISCAN Conformity

Various options for demonstrating guideline conformity

BSI Certification

Official confirmation by the BSI

Comprehensive assessment of all requirements in Annex P by accredited test centres. Highest level of evidence.

  • Complete conformity assessment
  • On-site audit required
  • Regular recertification
Highest level of evidence

TR-RESISCAN Ready

Practice-oriented VOI-CERT certification

Alternative to BSI certification with reduced effort. Assessment based on Annex P of TR-RESISCAN.

  • More cost-effective than BSI certification
  • Practice-oriented assessment
  • Suitable for SMEs and mid-market
Ideal for enterprises

Self-Declaration

Self-responsible conformity declaration

The organisation declares TR-RESISCAN compliance on its own responsibility. Sufficient for many tenders.

  • Lowest effort
  • Process documentation required
  • No external assessment
Sufficient for many cases

No Certification Obligation

TR-RESISCAN serves as a practice-oriented guideline for proper scanning processes - without mandatory certification. Docuflair supports you on all three paths to conformity.

Docuflair Solution

How Docuflair Fulfils TR-RESISCAN Requirements

Automated compliance for all modules of the technical guideline

Base Module Requirements

  • User authentication before each scan
  • Automatic capture of all scan parameters
  • Web-based visual inspection with approval workflow
  • Complete transfer note according to BSI specification
  • Logging and audit trail

Extension Module Integrity

  • Cryptographic hash calculation (SHA-256)
  • Digital signature for PDF/A documents
  • Tamper protection through integrity verification
  • Four-eyes principle for approvals configurable
  • Timestamps for traceability

Extension Module Confidentiality

  • TLS-encrypted transmission of all data
  • Granular authorisation concept
  • Active Directory integration
  • On-premises operation without cloud dependency
  • Complete audit logging

Legal Certainty According to BSI Standard

The Technical Guideline RESISCAN defines binding standards for substitute scanning

BSI TR-RESISCAN Requirements

Full compliance with all requirements of the Technical Guideline for substitute scanning.

Tamper-Proof Digitisation

Cryptographically secured document capture prevents subsequent modifications.

Evidential Digital Copies

Digital documents receive the same legal evidential value as the paper original.

Audit-Proof Long-Term Archiving

PDF/A format and digital signature ensure permanent storage.

Complete Traceability

Comprehensive audit trail documents every step of the scanning process.

Digital Signing

Legally binding digital signature guarantees integrity and authenticity.

What is TR-RESISCAN?

Understanding the German standard for legally compliant substitute scanning

German BSI Standard

TR-RESISCAN is a Technical Guideline issued by the German Federal Office for Information Security (BSI). It establishes requirements for the legally compliant digitisation of paper documents.

Substitute Scanning

The guideline enables "substitute scanning" - a process where paper documents are digitised with full legal evidential value, allowing the original to be safely destroyed.

International Recognition

While originating in Germany, TR-RESISCAN represents best practice for legally compliant document digitisation applicable to organisations handling German documents or operating in German-speaking markets.

Who is TR-RESISCAN For?

Organisations with high compliance requirements

Government Agencies

Public administrations requiring legally compliant digitisation according to BSI specifications.

Enterprises

Companies with high compliance requirements and the need for substitute scanning.

Archives

Institutions that wish to digitise and archive paper collections in a legally compliant manner.

Frequently Asked Questions

TR-RESISCAN is a Technical Guideline from the German Federal Office for Information Security (BSI). It defines requirements for legally compliant substitute scanning, where paper documents are digitised and the originals can subsequently be destroyed whilst maintaining full legal evidential value.

TR-RESISCAN is particularly relevant for government agencies, public institutions, companies with high compliance requirements, and all organisations that wish to legally destroy paper documents after scanning whilst retaining full evidential value.

The transfer note documents the scanning process and confirms the correspondence between original and digital copy. It contains information such as scan date, scan operator, settings used and verification results - essential for the evidential value of the digital document.

Visual inspection is an essential part of the TR-RESISCAN process. After scanning, the digital document is compared with the original on screen. The inspector confirms completeness and legibility - this is documented in the transfer note.

For TR-RESISCAN-compliant scanning, you need a suitable scanner, the Docuflair TR-RESISCAN software, and optionally a screen for visual inspection at the device. The software guides you through the entire process and ensures compliance with all requirements.

Yes, when the TR-RESISCAN process is carried out correctly, the original document can subsequently be destroyed. The digital document with transfer note then has the same evidential value as the original.

All documents are stored in PDF/A format, an ISO standard for long-term archiving. Additionally, they are digitally signed and tagged with metadata. This ensures that documents remain readable and verifiable for many years to come.

Implementation is very quick: by installing a single piece of software, legally compliant scanning according to TR-RESISCAN is available to you within minutes. Integration with existing systems is seamless through standardised interfaces.

The base module contains the minimum requirements for all protection categories - from user authentication to the transfer note. The extension modules (Integrity and Confidentiality) apply when there is increased protection need and define additional measures such as digital signatures, encryption and extended access controls.

No, certification is generally not mandatory. TR-RESISCAN serves as a practice-oriented guideline for proper scanning processes. There are three paths to conformity: official BSI certification, the "TR-RESISCAN ready" certificate (VOI-CERT), or a self-declaration with process documentation.

Version 1.5 (December 2024) introduces mobile substitute scanning. This enables TR-RESISCAN-compliant digitisation using mobile devices such as smartphones or tablets with a suitable scanning app. Particularly relevant for field service and decentralised locations.

The German E-Government Act (Section 7 EGovG) requires federal agencies to maintain electronic records and references TR-RESISCAN as state of the art. The Code of Civil Procedure (Section 371b ZPO) governs the evidential value of scanned public documents. The GoBD (principles of proper accounting) also complements TR-RESISCAN for tax-relevant documents.

The protection requirement is assessed separately for the three protection goals: Integrity, Confidentiality, and Availability. The categories are: Normal (limited damage impact), High (considerable impact), and Very High (existential impact). Depending on the classification, the base module and/or extension modules are required.

Ready for Legally Compliant Scanning?

Contact us for a personal consultation or request a demo of Docuflair TR-RESISCAN.