CCapability-led route

Projekt 1000 – Agentic AI: Prüfanforderungen für LLM-basierte agentische künstliche Intelligenz (PRAKI)

Bundesamt für Sicherheit in der Informationstechnik

Deadline
24 Aug 2026, 16:00
Value
480 person-days / 3,840 hours for AP2–AP8; AP1/AP9 fixed price; AP7 travel cap EUR 5,000 net
Region
Bonn, Germany
Reviewed
16 Aug 2026
Portfolio verdict

Capability-led route

Tier C with excellent subject fit but a hard evidence gate. The package is complete. Company evidence is partial or unknown for four external reference minima, technical equipment, the degree-qualified named team and independent stakeholder access to two real agentic-AI systems. Bid only if those proofs already exist and can be committed within days.

Recommended actionPursue only if four external company-reference gates, the degree-qualified PL/deputy/QM team and two independent real-system stakeholders can be evidenced immediately; otherwise no-bid.

What the opportunity means

Develop, trial and publish security test catalogues and best practices for LLM-based agentic AI, including OSCAL output and two trials on real systems.

Portfolio thesis

Strong thematic fit through Perspectify and Forseti patterns; external references, technical equipment, named team and real-system stakeholder evidence are incomplete.

Qualification reality

The study and assurance contract matches demonstrated LLM-agent, auditable evaluation, regulated-evidence and secure-delivery competencies, but it does not procure an existing Digital David product.

Portfolio evidence

Products and reusable delivery strengths

Products

PerspectifyForsetiKuebikoKURT

Competencies

LLM and agent workflowsauditable evaluationregulated evidence researchsecure cloud deliveryobservability

Decision gates

Eligibility and delivery gates

  • Company matchUnknown
    Article 5k sanctions declaration
    MustRequired

    German legal identity is verified, but ownership, control and supply-chain facts needed for the tender declaration are not evidenced.

  • Company matchPartially met
    External agentic-AI reference
    MustRequired

    Agent and MCP products are demonstrated, but no admissible external reference with buyer, period, value and scope is packaged.

  • Company matchUnknown
    External AI-system testing reference
    MustRequired

    No documented qualifying project, publication, standard contribution or testing report is in the evidence pack.

  • Company matchUnknown
    External AI-security reference
    MustRequired

    No external work evidences AI-specific attacks, protections or implemented security measures.

  • Company matchPartially met
    External IT-security reference
    MustRequired

    Secure regulated SaaS delivery is demonstrated, but the formal external reference is missing.

  • Company matchUnknown
    Technical equipment
    MustRequired

    No hardware, compute, software or testing-tool inventory is in the qualification evidence.

  • Company matchUnknown
    Minimum team and role separation
    MustRequired

    The team needs at least two people plus PL, deputy and QM with the PL separate; expert-team evidence is deferred and headcount is not inferred.

  • Company matchUnknown
    Degrees and collective expertise
    MustRequired

    Named degrees and coverage of complex systems, enterprise AI, agentic LLMs, attacks, testing and scientific writing are deferred.

  • Company matchUnknown
    Comparable project leadership
    MustRequired

    No named project lead or comparable leadership reference is evidenced.

  • Company matchUnknown
    Independent stakeholder access
    ScoredNot required

    No named market stakeholders, written interest or real production/test systems exist in the pack; this is also a high-weight quality criterion.

  • Company matchUnknown
    Sustainability evidence
    ScoredNot required

    No certification or tender-ready social and environmental evidence is available, although reasoned declarations are accepted.

  • Company matchPartially met
    Firm profile, headcount and turnover
    DeliveryNot required

    Legal facts and 2024/2025 turnover are verified; 2023 and relevant-field headcount remain unknown. No turnover or headcount minimum is stated.

Official clarifications · selected by AI relevance

Relevant bidder questions

  1. Q6Which minimum roles and profiles must be offered?
    Buyer answer

    Name a primary project lead, deputy project lead and quality-management representative. Deputy and QM may also be project-team members, but the primary lead cannot hold either role; every offered person must actually be deployed.

    Portfolio impact

    Evidence status: unknown. Expert-team evidence is deferred, so named availability and role separation are not established.

  2. Q8What qualifies as proof of AI-system testing expertise?
    Buyer answer

    Comparable tests with documented methods and reports qualify, supplemented by publications, standards, disclosures, tools or classic security-testing qualifications only where AI specialisation and threat models are explicit.

    Portfolio impact

    Evidence status: unknown. No qualifying external AI-test project, publication, standard contribution or report is in the pack.

  3. Q10What qualifies as proof of AI-security expertise?
    Buyer answer

    References should show secure design, hardening or protection of agentic AI, implemented measures, relevant publications, standards or tools; documented real application is stronger than theory.

    Portfolio impact

    Evidence status: unknown. Portfolio fit exists, but no formal external AI-security reference is evidenced.

  4. Q37What equipment and compute must the bidder provide?
    Buyer answer

    The bidder provides suitable hardware, software and test tools. BSI supplies no compute and separately reimburses neither bidder compute nor stakeholder token or compute cost.

    Portfolio impact

    Evidence status: unknown. No technical-equipment inventory is in the company pack and all compute must be priced into rates.

  5. Q75Can the 480-person-day cap rise if use cases prove more expensive?
    Buyer answer

    No. The shared cap is fixed upward; effort may only move between work packages.

    Portfolio impact

    Unknown use cases must fit a hard commercial ceiling, creating material fixed-cap discovery risk.

  6. Q87Must both selected use cases be tested on real systems?
    Buyer answer

    Yes. Each of the two use cases requires a practical trial on a real agentic-AI system in production or test.

    Portfolio impact

    Evidence status: unknown. No two committed external systems are evidenced.

  7. Q90Can a subcontractor also count as the practice stakeholder under award criterion 1.4?
    Buyer answer

    No. The criterion demonstrates market participation and cooperation outside the bid consortium.

    Portfolio impact

    A consortium partner cannot close the high-weight stakeholder criterion; separate market stakeholders are needed.

  8. Q98Can unlimited confidentiality be time-limited?
    Buyer answer

    Yes. BSI will change the obligation to five years after project completion.

    Portfolio impact

    This removes a perpetual obligation; the Q&A annex overrides the base wording.

  9. Q110Are the study work packages services without acceptance?
    Buyer answer

    No. BSI treats every work package as a work requiring formal acceptance under contract clause 13.

    Portfolio impact

    Every milestone is acceptance-gated; schedule, cash flow and remediation risk must reflect that.

  10. Q128Can internal projects prove company-reference gates?
    Buyer answer

    No. Internal projects are not admissible as company references, although they may contribute to personal evidence under Q5.

    Portfolio impact

    Digital David products alone do not close company gates unless there are qualifying external buyer projects with period, value and scope.

Interpreted scope

Delivery shape

  • Run virtual kickoff and establish a binding collaboration, quality and project plan.
  • Identify at least three agentic-LLM use cases, analyse risks and recommend two for full treatment.
  • Create use-case-specific security test criteria, requirements, workflows, tools and best practices in human-readable and OSCAL-compatible forms.
  • Trial both procedures on two real production or test agentic-AI systems with independent stakeholders and incorporate feedback.
  • Generalise both catalogues, perform gap analysis and produce reusable test catalogues and best practices.
  • Prepare publications and possible conference presentations, an accessible English final study of about 90 pages and a half-day expert presentation.
  • Use biweekly video meetings and reports, German working communication, encrypted signed email and accessible publication-ready documents.

Bid package

Required submissions

  • Machine-readable unscanned offer form, kept separate and completed in text form.
  • Central ordered annex covering every criterion and a firm profile with legal, organisation, relevant-field employee and three-year turnover data if available.
  • Article 5k declaration and four external company-reference sections with buyer, department, period, volume and detailed scope; internal products are excluded.
  • Equipment, compute and testing-tool overview.
  • Threat analysis and exemplar test flow, each maximum five A4 pages, plus stakeholder, workshop, involvement and project-risk concepts.
  • Real profiles for every offered person, maximum two pages each, with PL and deputy named and project/publication mapping.
  • AP1/AP9 fixed-price calculations; AP2–AP8 role and day-rate allocation totaling exactly 480 person-days; milestone/payment plan and Gantt.
  • Consortium, subcontractor and eligibility-lending declarations where used.

Commercial reading

Contract and pricing terms

  • AP1 and AP9 are fixed price; AP2–AP8 are quarter-hour actuals under one exact 480-person-day cap after written call-off approval.
  • Token, compute and other operating costs are included in rates. Only AP7 travel has a separate EUR 5,000 net cap and requires preapproval.
  • Milestone invoices require formal acceptance; every work package is a work and there is no deemed acceptance.
  • Delay penalty is 0.5% per completed week of relevant value, capped at 5%, without excluding further damages.
  • New outputs, software and results carry full exclusive worldwide perpetual rights for BSI; pre-existing and third-party components require disclosure and approval.
  • Confidentiality lasts five years after project completion under Q98.
  • The effort cap cannot increase for harder use cases; budget may only shift between work packages.

Evidence trail

Sources and bidder information

Authoritative e-Vergabe package checked 16 August 2026 at 16:43 CEST. It contains 42 Q&A PDFs covering 135 answered questions numbered 1–136; Q9 never existed and no Q108 file is published. All PDFs through 11 August were read and ten decision-relevant answers are selected.

Package reviewed 16 Aug 2026, 17:03

Research files

Documents used for this evaluation