fiskaly SIGN DE uses a TSS that is fully certified according to BSI requirements. This page lists the certificates for the TSS versions used in the SIGN DE v2 LIVE environment.
Overview
Section titled “Overview”This page provides:
- Links to the certificates and compliance reports issued by the BSI
- Security documentation of the SMAERS and CSPL components (Security Target)
- Secure Platform Concepts for the SMAERS operational environment
- Information on the PKI used by the fiskaly TSS
A TSS has to be certified by the BSI — the German Federal Office for Information Security — in order to meet the requirements of KassenSichV. The aim of certification is to ensure a standard minimum level of trust and security for all TSS components and compliance with the necessary interoperability requirements.
The following certificates have to be achieved:
TSS Application — The composite TSS application certification
Logging Unit — Security Module Application for Electronic Record-Keeping Systems
Signature Creation Unit — Cryptographic Service Provider for digital signature creation
For an overview on how the fiskaly SIGN DE system is structured, and how the requirements are met, consult fiskaly SIGN DE architecture and certified components
Official document downloads
Section titled “Official document downloads”The sections below contain certificates for versions used in the SIGN DE v2 LIVE environment and are not an exhaustive list of all certificates achieved by fiskaly.
Public Key Infrastructure
Section titled “Public Key Infrastructure”All certified TSS need to have certificates issued by a Public Key Infrastructure certified towards TR-03145. All fiskaly TSS are using the DARZ TSE-PKI, with the Root-CA DARZ-TSE-ROOT-CA-01 and the Sub-CA DARZ-TSE-SUB-CA-01.
The full certificate chain of Root-CA, Sub-CA, and TSS signing key certificate are always included in the TAR exports of a TSS for verification purposes.
Below we provide the PKI Concept that is generated as part of the TSS certification process. It details how the PKI is used by the fiskaly TSS and how the TSS certificates can be verified.
Download PKI Concept
For the PKI Certificate Policy, please refer to the DARZ TSE-PKI homepage.
TR-03153 — “TSS Application”
Section titled “TR-03153 — “TSS Application””fiskaly sign Cloud-TSE 1.0.15-1.5.0
Section titled “fiskaly sign Cloud-TSE 1.0.15-1.5.0”This is the current version used in SIGN DE v2 LIVE, since 24.08.2025.
- BSI-K-TR-0717-2025 — BSI certificate webpage
- Certificate — issued 31.03.2025
- Certificate of Conformity — issued 31.03.2025
- Compliance Report — issued 31.03.2025
- Secure Platform Concept — “Umgebungsschutzkonzept” — version 2.0.6, released 23.01.2025
fiskaly sign Cloud-TSE 1.0.5–1.2.0
Section titled “fiskaly sign Cloud-TSE 1.0.5–1.2.0”This version was used in SIGN DE v2 LIVE between 2021–2025. No active instance with this version exists after 02.11.2025.
- BSI-K-TR-0403-2021 — BSI certificate webpage
- Certificate — issued 27.05.2021
- Certificate of Conformity — issued 27.05.2021
- Compliance Report — issued 27.05.2021
CSPL — “Signature Unit”
Section titled “CSPL — “Signature Unit””fiskaly Cloud Crypto Service Provider (BSI-DSZ-CC-1153) certification history
fiskaly Cloud Crypto Service Provider 1.5.0
Section titled “fiskaly Cloud Crypto Service Provider 1.5.0”This is the current version used in SIGN DE v2 LIVE, since 24.08.2025.
- Certificate — issued 03.07.2025
- Certification Report — issued 03.07.2025
- Security Target — version 1.4.5, released 02.06.2025
fiskaly Cloud Crypto Service Provider 1.2.0
Section titled “fiskaly Cloud Crypto Service Provider 1.2.0”This version was used in SIGN DE v2 LIVE between 2021–2025. No active instance with this version exists after 02.11.2025.
- Certificate — issued 20.05.2021
- Certification Report — issued 20.05.2021
- Security Target — version 1.2.1, released 21.04.2021
SMAERS — “Logging Unit”
Section titled “SMAERS — “Logging Unit””fiskaly Security Module Application for Electronic Record-keeping Systems 1.0.15
Section titled “fiskaly Security Module Application for Electronic Record-keeping Systems 1.0.15”This is the current version used in SIGN DE v2 LIVE, since 24.08.2025.
- Certificate — issued 31.03.2025
- Certification Report — issued 31.03.2025
- Security Target — version 1.4.4, released 23.01.2025
fiskaly Security Module Application for Electronic Record-keeping Systems 1.0.5
Section titled “fiskaly Security Module Application for Electronic Record-keeping Systems 1.0.5”This version was used in SIGN DE v2 LIVE between 2021–2025. No active instance with this version exists after 02.11.2025.
- Certificate — issued 17.05.2021
- Certification Report — issued 17.05.2021
- Security Target — version 1.1.6, released 11.05.2021