What the opportunity means
Develop, trial and publish security test catalogues and best practices for LLM-based agentic AI, including OSCAL output and two trials on real systems.
Bundesamt für Sicherheit in der Informationstechnik
Tier C with excellent subject fit but a hard evidence gate. The package is complete. Company evidence is partial or unknown for four external reference minima, technical equipment, the degree-qualified named team and independent stakeholder access to two real agentic-AI systems. Bid only if those proofs already exist and can be committed within days.
Develop, trial and publish security test catalogues and best practices for LLM-based agentic AI, including OSCAL output and two trials on real systems.
Strong thematic fit through Perspectify and Forseti patterns; external references, technical equipment, named team and real-system stakeholder evidence are incomplete.
The study and assurance contract matches demonstrated LLM-agent, auditable evaluation, regulated-evidence and secure-delivery competencies, but it does not procure an existing Digital David product.
Portfolio evidence
Decision gates
German legal identity is verified, but ownership, control and supply-chain facts needed for the tender declaration are not evidenced.
Agent and MCP products are demonstrated, but no admissible external reference with buyer, period, value and scope is packaged.
No documented qualifying project, publication, standard contribution or testing report is in the evidence pack.
No external work evidences AI-specific attacks, protections or implemented security measures.
Secure regulated SaaS delivery is demonstrated, but the formal external reference is missing.
No hardware, compute, software or testing-tool inventory is in the qualification evidence.
The team needs at least two people plus PL, deputy and QM with the PL separate; expert-team evidence is deferred and headcount is not inferred.
Named degrees and coverage of complex systems, enterprise AI, agentic LLMs, attacks, testing and scientific writing are deferred.
No named project lead or comparable leadership reference is evidenced.
No named market stakeholders, written interest or real production/test systems exist in the pack; this is also a high-weight quality criterion.
No certification or tender-ready social and environmental evidence is available, although reasoned declarations are accepted.
Legal facts and 2024/2025 turnover are verified; 2023 and relevant-field headcount remain unknown. No turnover or headcount minimum is stated.
Official clarifications · selected by AI relevance
Name a primary project lead, deputy project lead and quality-management representative. Deputy and QM may also be project-team members, but the primary lead cannot hold either role; every offered person must actually be deployed.
Evidence status: unknown. Expert-team evidence is deferred, so named availability and role separation are not established.
Comparable tests with documented methods and reports qualify, supplemented by publications, standards, disclosures, tools or classic security-testing qualifications only where AI specialisation and threat models are explicit.
Evidence status: unknown. No qualifying external AI-test project, publication, standard contribution or report is in the pack.
References should show secure design, hardening or protection of agentic AI, implemented measures, relevant publications, standards or tools; documented real application is stronger than theory.
Evidence status: unknown. Portfolio fit exists, but no formal external AI-security reference is evidenced.
The bidder provides suitable hardware, software and test tools. BSI supplies no compute and separately reimburses neither bidder compute nor stakeholder token or compute cost.
Evidence status: unknown. No technical-equipment inventory is in the company pack and all compute must be priced into rates.
No. The shared cap is fixed upward; effort may only move between work packages.
Unknown use cases must fit a hard commercial ceiling, creating material fixed-cap discovery risk.
Yes. Each of the two use cases requires a practical trial on a real agentic-AI system in production or test.
Evidence status: unknown. No two committed external systems are evidenced.
No. The criterion demonstrates market participation and cooperation outside the bid consortium.
A consortium partner cannot close the high-weight stakeholder criterion; separate market stakeholders are needed.
Yes. BSI will change the obligation to five years after project completion.
This removes a perpetual obligation; the Q&A annex overrides the base wording.
No. BSI treats every work package as a work requiring formal acceptance under contract clause 13.
Every milestone is acceptance-gated; schedule, cash flow and remediation risk must reflect that.
No. Internal projects are not admissible as company references, although they may contribute to personal evidence under Q5.
Digital David products alone do not close company gates unless there are qualifying external buyer projects with period, value and scope.
Interpreted scope
Bid package
Commercial reading
Evidence trail
Authoritative e-Vergabe package checked 16 August 2026 at 16:43 CEST. It contains 42 Q&A PDFs covering 135 answered questions numbered 1–136; Q9 never existed and no Q108 file is published. All PDFs through 11 August were read and ten decision-relevant answers are selected.
Package reviewed 16 Aug 2026, 17:03
Research files