PTB TR 5 – Discovered and Expl
IT security assessment in accordance with Section 12(3) of the Gaming Ordinance (SpielV)
Technical Guideline 5.0 of the Physikalisch-Technische Bundesanstalt requires manufacturers of gaming machines, amongst other things, to provide an IT security assessment report drawn up by a BSI-accredited testing body for Common Criteria (ISO 15408) or ITSEC. The Technical Guideline is based on Section 12(3) of the Gaming Ordinance (SpielV).

PTB Technical Guideline 5.0 (PTB TR 5.0) defines the mandatory technical requirements for the type approval of gaming machines in accordance with the German Gaming Ordinance. It serves as the basis for the development, testing and approval of machines that comply with the law and ensures adherence to regulatory requirements.
The focus is on tamper resistance, data integrity, transparent game processes and the protection of security-relevant hardware and software components. Furthermore, PTB TR 5.0 supports player and consumer protection through clearly defined technical standards.
Manufacturers, testing organisations and operators are thus provided with a uniform framework for conformity assessment, safe operation and long-term legal compliance of modern gaming machines.
The security assessment must take into account all attack scenarios identified in the threat analysis (Annex 4) and assessed as critical, and demonstrate that these have been adequately addressed as part of the security assessment. It must also be based on the state of the art in the field of IT security technology (e.g. ISO/IEC 15408).
The PTB may request supplementary reports if the security report submitted is insufficient for the assessment of a type. This applies in particular to cases where eligibility for approval cannot be conclusively assessed using the test procedures applied by the PTB and additional evidence is required.
Security assessments generally contain the following statements:

The TÜVIT testing centre is a testing laboratory accredited by DakkS in accordance with DIN EN ISO/IEC 17025:2018. We are recognised by the BSI for testing in accordance with ITSEC/ITSEM and Common Criteria/CEM, as well as for many other procedures.
The Technical Guideline for Gaming Machines, Version 5.0 (TR 5.0), is intended for manufacturers of gaming machines and is required in order to apply for type approval for a gaming machine from the Physikalisch-Technische Bundesanstalt (PTB).
A safety assessment in accordance with TR 5.0 is required for commercial gaming machines offering the chance to win money, as, under Section 33c of the Trade Regulation Act (GewO), such machines may only be installed if they have type approval, which is granted by the PTB.
The requirements set out in TR 5.0 must be met by all manufacturers and developers of gaming machines intended for commercial installation in Germany.
TR 5.0 sets out a wide range of requirements regarding the approval of gaming machines. These include, amongst other things, the design, labelling, permitted playing times and breaks, stake and win limits, and the IT security of the gaming machine.
The Gaming Ordinance (SpielV) is a federal regulation issued by the Federal Ministry for Economic Affairs and Energy for the territory of Germany, pursuant to the Trade Regulation Act (a federal law). The Physikalisch-Technische Bundesanstalt (PTB) decides, in accordance with Section 11 of the Gaming Ordinance, on applications for type approval within the meaning of the Trade Regulation Act. Section 12 of the Gaming Ordinance also stipulates that the PTB may issue and apply technical guidelines. TR 5.0 is one such technical guideline for the approval of gaming machines; it provides technical specifications, sets out requirements and gives guidance on the application and approval procedures. TR 5.0 also specifies the security assessment and corresponding attack scenarios in the context of IT security.
PTB approval: The PTB approves gaming machines for commercial use; the documentation requirements are set out in TR 5.0. Manufacturers can carry out and provide much of the work themselves, but an external body is mandatory for security assessments. TÜVIT is a partner that is capable of carrying out such work and has extensive experience in the field of IT security.
All commercial gaming machines require PTB certification.
Any changes to the design of a gaming machine necessitate re-approval by the PTB. The design includes, amongst other things, the hardware, software and configuration of a gaming machine. A relevant security assessment may, in certain circumstances, be reused or, in most cases – for example, where the changes are minor – be updated by means of supplementary IT security tests.
Starting the safety assessment at an early stage allows manufacturers of gaming machines to respond to any findings from the testing body even before production or development is finalised. As soon as in-house development is complete and the first prototypes are available, documents can be reviewed and tests carried out. It is then still possible to rectify security vulnerabilities by adjusting configurations, software or hardware before a planned market launch is imminent.
TÜVIT is a testing body which, amongst other things, has been recognised by the BSI (Federal Office for Information Security) since 1993 for certifications in accordance with the Common Criteria and ITSEC at the highest security level (Assurance).
Thanks to decades of experience in testing IT security products, TÜVIT possesses in-depth expert knowledge that manufacturers can rely on when the assessment report is drawn up. Combined with numerous, technologically advanced test benches, the assessment is always carried out in accordance with the latest state of the art.
The security assessment required as part of the approval process for a gaming machine ensures that the machine to be approved is designed in such a way as to prevent any tampering. This security requirement relates in particular to the current state of the art in the field of IT security.
The security assessment, which is mandatory as part of the approval process for a gaming machine by the PTB, covers various components of the machine and is intended to evaluate their IT security. These include software, data collected, means of identification, hardware and its connections, processes, interfaces and the cryptographic mechanisms used.
The security assessment relating to IT security must be carried out by a Common Criteria or ITSEC testing laboratory accredited by the BSI (Federal Office for Information Security). Unlike the other requirements of TR 5.0, the security assessment cannot be provided by the device manufacturer itself. Nationally recognised bodies in European countries that have signed the SOGIS Agreement, or in other countries that have signed the CC-MRA Agreement, are also authorised to do so. Other testing bodies that do not meet these criteria must first demonstrate, in writing, that they are equivalent to the PTB as part of an accreditation process, be recognised by the PTB, and renew this recognition regularly.