AI in Secure Software Development Life Cycle (KISDL) | Tenderlake

AI in Secure Software Development Life Cycle (KISDL)

Contract Value:
-
Notice Type:
Contract Notice
Published Date:
10 September 2026
Closing Date:
24 September 2026
Location(s):
DEA22 Bonn, Kreisfreie Stadt (DE Germany/DEUTSCHLAND)
Description:
The project aims to explore the beneficial use of AI in the Secure Software Development Life Cycle, focusing on current practices, evaluation criteria updates, and integration strategies for AI tools.

Methods of Artificial Intelligence (AI) demonstrate remarkable performance in many application areas and are increasingly being used in fields that affect daily life. The area of cybersecurity has also not remained untouched by AI. New AI tools are being released nearly daily in this context, and especially Large Language Models (LLMs) are already being used for various application purposes. At the same time, the threat landscape is also changing significantly, as models intended for benign use are being misused for attack purposes (dual use). Consequently, it must sometimes be assumed that vulnerabilities will be discovered and exploited increasingly faster with the advancing capabilities of AI in the future. Against this background, the defensive side must also take active measures, which is why this project aims to investigate how AI can be profitably used in the SSDLC and what effects the ongoing developments have on software security. The project is divided into three parts with related but distinct deliverables:

In work packages (WP) 1-4 [HM1.1], a study on the current state of the art and science in the area of AI in the Secure Software Development Life Cycle is to be created. Additionally, best practices for the use of identified AI tools shall be developed. The results are to be published.
In WPs 5-6 [HM2.1], based on the study and in cooperation with the BSI, the contractor shall review the evaluation criteria for AVA scoring in Common Criteria certification and update them in light of new circumstances. Furthermore, an implementation plan for the use of AI tools for testing bodies is to be created.
In WP 7, a reference architecture will be created for the Open CoDE platform, which illustrates how AI tools can be integrated into the Secure Software Development Life Cycle and the software environment of Open CoDE. Suitable tools are to be proposed here.


LOT-0000
BSI_07_26 P1008
AI in Secure Software Development Life Cycle (KISDL).
Methods of Artificial Intelligence (AI) demonstrate remarkable performance in many application areas and are increasingly being used in fields that affect daily life. The area of cybersecurity has also not remained untouched by AI. New AI tools are being released nearly daily in this context, and especially Large Language Models (LLMs) are already being used for various application purposes. At the same time, the threat landscape is also changing significantly, as models intended for benign use are being misused for attack purposes (dual use). Consequently, it must sometimes be assumed that vulnerabilities will be discovered and exploited increasingly faster with the advancing capabilities of AI in the future. Against this background, the defensive side must also take active measures, which is why this project aims to investigate how AI can be profitably used in the SSDLC and what effects the ongoing developments have on software security. The project is divided into three parts with related but distinct deliverables:

In work packages (WP) 1-4 [HM1.1], a study on the current state of the art and science in the area of AI in the Secure Software Development Life Cycle is to be created. Additionally, best practices for the use of identified AI tools shall be developed. The results are to be published.
In WPs 5-6 [HM2.1], based on the study and in cooperation with the BSI, the contractor shall review the evaluation criteria for AVA scoring in Common Criteria certification and update them in light of new circumstances. Furthermore, an implementation plan for the use of AI tools for testing bodies is to be created.
In WP 7, a reference architecture will be created for the Open CoDE platform, which illustrates how AI tools can be integrated into the Secure Software Development Life Cycle and the software environment of Open CoDE. Suitable tools are to be proposed here.

The Buyer:
Bundesamt für Sicherheit in der Informationstechnik
Additional information:
Link:
Additional document: 865505-1
Link:
View Full Notice
Link:
Download Full Notice as PDF
CPV Code(s):
72000000 - IT services: consulting, software development, Internet and support