Runtime Application Self-Protection (RASP) Lösung für EUDI Wallet Apps
Was wird ausgeschrieben
Die SPRIND GmbH beschafft eine Runtime Application Self-Protection (RASP) Lösung zur Absicherung der deutschen EUDI Wallet Anwendungen für iOS und Android. Der Auftrag umfasst die Beschaffung und Integration der RASP-Software mit Funktionen zum Schutz vor Runtime-Bedrohungen, Code-Obfuskierung sowie Privacy-Provisioning und Telemetrie. Die Vertragslaufzeit beträgt 900 Tage (ca. 2,5 Jahre). Die Beschaffung ist Teil der deutschen Umsetzung der eIDAS-Verordnung und des European Digital Identity Wallet.
Vollständige Beschreibung anzeigen
The implementation of the revised eIDAS regulation (electronic Identification, Authentication and Trust Services) requires the creation of a secure and user-friendly ecosystem. As a milestone for Europe's digital sovereignty, its core element is the European Digital Identity Wallet (EUDI Wallet), which serves as the regulation's central instrument. By the start of 2027, all EU citizens and residents should have access to a trustworthy, interoperable, and non-discriminatory digital wallet for identification, attribute attestations, electronic signatures, and more. The EUDI Wallet aims to simplify users' daily lives while enabling companies and administrations to benefit from faster, more secure, and more efficient digital processes. In Germany, the rollout of the EUDI Wallet is a joint effort by the Federal Ministry for Digital and State Modernization (BMDS) and SPRIN-D - the Federal Agency for Breakthrough Innovation. Since June 2023, the initiative has followed an open architecture and consultation process involving business, civil society, and science, with a focus on security, privacy, user-friendliness, and innovation. Germany"s dual strategy supports both a national EUDI Wallet as well as alternative EUDI Wallets. The roadmap includes a sandbox rollout of the identity (PID) function by the end of 2025 and further enhancements and production rollout throughout 2026. In this tender, the client is seeking a Runtime Application Self-Protection (RASP) solution to provide an additional layer of runtime security for its wallet applications on iOS and Android. The objective is to enhance protection against runtime threats, obfuscate the code and support privacy provisioning and telemetry. The scope covers the procurement and integration of the RASP solution with the described functionality.
Die Bundesagentur für Sprunginnovation (SPRIND) in Leipzig beschafft eine Sicherheitssoftware namens RASP (Runtime Application Self-Protection) für die deutsche EUDI Wallet – die App, die ab 2027 allen EU-Bürgern für digitale Identifikation, Signaturen und Attestierungen zur Verfügung stehen soll. Die Software soll die mobilen Apps auf iOS und Android vor Angriffen zur Laufzeit schützen, den Programmcode unkenntlich machen (Obfuskierung) und Funktionen für Datenschutz und Telemetrie bieten. Da die EUDI Wallet ein zentrales Element der europäischen digitalen Souveränität ist und bis Anfang 2027 flächendeckend verfügbar sein soll, handelt es sich um ein strategisch wichtiges IT-Sicherheitsprojekt im öffentlichen Sektor. Bewerber müssen die gesetzlichen Eignungsnachweise nach GWB, AEntG, AufenthG, MiLoG, SchwarzArbG und LkSG vorweisen.
Zentrale Anforderungen
6 Punkte- Nachweis der gesetzlichen Eignung gemäß §§ 123, 124 GWB
- Erfüllung der AEntG-Anforderungen (Arbeitnehmerentsendegesetz)
- Einhaltung des Mindestlohngesetzes (MiLoG)
- Konformität mit dem Lieferkettensorgfaltspflichtengesetz (LkSG)
- RASP-Lösung muss für iOS und Android verfügbar sein
- Fähigkeit zur Code-Obfuskierung und Runtime-Bedrohungsschutz
KI-zusammengefasst aus den offiziellen Eignungsanforderungen. Verbindlich ist der Originaltext unten.
Eignungskriterien (Volltext)
In accordance with Sections 123,124 GWB (Act Against Restraints of Competition), Section 21 AEntG (Posted Workers Act), Section 98c AufenthG (Residence Act), Section 19 MiLoG (Minimum Wage Act), Section 21 SchwarzArbG ( Act to Combat Illegal Employment) and Section 22 LkSG (Supply Chain Due Diligence Act) In accordance with Sections 123,124 GWB (Act Against Restraints of Competition), Section 21 AEntG (Posted Workers Act), Section 98c AufenthG (Residence Act), Section 19 MiLoG (Minimum Wage Act), Section 21 SchwarzArbG ( Act to Combat Illegal Employment) and Section 22 LkSG (Supply Chain Due Diligence Act). SPRIND GmbH asks - within its discretion - the bidder to submit, complete or correct documents, within the framework laid down by law (Section 56 (2) VgV).
Aufteilung in Lose
1 LotThe implementation of the revised eIDAS regulation (electronic Identification, Authentication and Trust Services) requires the creation of a secure and user-friendly ecosystem. As a milestone for Europe's digital sovereignty, its core element is the European Digital Identity Wallet (EUDI Wallet), which serves as the regulation's central instrument. By the start of 2027, all EU citizens and residents should have access to a trustworthy, interoperable, and non-discriminatory digital wallet for identification, attribute attestations, electronic signatures, and more. The EUDI Wallet aims to simplify users' daily lives while enabling companies and administrations to benefit from faster, more secure, and more efficient digital processes. In Germany, the rollout of the EUDI Wallet is a joint effort by the Federal Ministry for Digital and State Modernization (BMDS) and SPRIN-D - the Federal Agency for Breakthrough Innovation. Since June 2023, the initiative has followed an open architecture and consultation process involving business, civil society, and science, with a focus on security, privacy, user-friendliness, and innovation. Germany"s dual strategy supports both a national EUDI Wallet as well as alternative EUDI Wallets. The roadmap includes a sandbox rollout of the identity (PID) function by the end of 2025 and further enhancements and production rollout throughout 2026. In this tender, the client is seeking a Runtime Application Self-Protection (RASP) solution to provide an additional layer of runtime security for its wallet applications on iOS and Android. The objective is to enhance protection against runtime threats, obfuscate the code and support privacy provisioning and telemetry. The scope covers the procurement and integration of the RASP solution with the described functionality.
Zeitplan
- 7. Mai 2026Bekanntmachung veröffentlichtAuf TED publiziert
- 5. Juni 2026EinreichungsfristElektronische Einreichung