BSI and ZenDiS publish strategy for securing administrative software supply chains
In a joint strategy paper, the German Federal Office for Information Security (BSI) and ZenDiS set out their concept for securing software supply chains for public administration.
Bochum/Bonn, April 10, 2025 - In times of increasing geopolitical tensions, ensuring the security and stability of digital infrastructures is becoming a central component of public services. With a joint initiative, the Center for Digital Sovereignty in Public Administration (ZenDiS) and the German Federal Office for Information Security (BSI) are now focusing more attention on the importance of secure and sovereign software supply chains.
Nearly all software today relies on hundreds or even thousands of existing individual components, libraries and tools. The entirety of these components forms the software supply chain. If a part of this chain is compromised or fails, considerable risks arise for all users.
Complex software supply chains require new, standardized testing procedures
Complete testing of software supply chains has hardly been feasible for individual software providers to date due to their complexity. This requires a fundamentally new approach that goes beyond the capabilities of individual organizations and bundles the expertise of security experts, developers and authorities in a targeted manner, establishes standardized testing procedures and enables joint security analyses.
openCode as a core building block for a secure digital infrastructure
The central building block is the openCode platform. It establishes binding security standards, makes dependencies transparent and creates traceable proof of origin for critical software components. Thanks to the transparency of open source, many of the previous manual testing processes can be automated, significantly improving the scalability of security checks in the software supply chain.
With its recently launched badge program, ZenDiS demonstrates in concrete terms how such a check can be implemented. There, quality features of software running on openCode - for example, maintenance and reuse - are automatically derived from the code.
Paradigm shift from reaction to prevention
Current approaches to software security are largely reactive. openCode can enable a preventative approach through continuous, automated security checks and transparent software supply chains: In the event of a security incident, artifacts and affected parties can be reliably identified and real-time situation pictures can be created so that targeted warnings can be issued. This makes openCode a key element of a resilient digital infrastructure in Germany.
Claudia Plattner, President of the BSI, emphasizes the importance of cooperation: "Secure software supply chains are a decisive factor for functioning digitalization. They make dependencies clear and therefore manageable. We are also creating an offering that gives us the scalability we urgently need to implement cyber security effectively. The successful interaction of many players is crucial for this, just as we would like it to be for Germany as a cyber nation."
Leonhard Kugler, Head of Open Source Platform at ZenDiS, emphasizes the strategic importance: "The development of a sovereign digital infrastructure is essential for our public services in the 21st century. With openCode, we are putting in place an essential building block to strengthen the security of our software supply chains and thus preserve the state's digital ability to act even in a complex geopolitical landscape."
Strategy paper invites participation
The BSI and ZenDiS have set out their concept for a secure and sovereign software supply chain in a joint strategy paper including an implementation plan. The paper is available for download at: opencode.de/en/ssdlc
Feedback from the expert community is expressly welcome. Contact details can be found at opencode.de.
About ZenDiS
The Center for Digital Sovereignty in Public Administration (ZenDiS) was founded in 2022 by the Federal Ministry of the Interior and for Home Affairs (BMI). As a competence and service center, ZenDiS supports public administration at federal, state and municipal level in securing its ability to act in the digital space in the long term - above all by eliminating critical dependencies on individual technology providers. To this end, ZenDiS is concentrating on promoting the use of open source software in public administration in the first expansion phase. ZenDiS is a limited liability company and is currently wholly owned by the federal government. A participation of the federal states is in preparation. ZenDiS is based in Bochum.
About the BSI
The BSI is the federal government's cyber security authority and shaper of secure digitalization in Germany. It makes Germany resilient against cyber threats - and cyber security a success factor for digitalization. Together with its partners, the BSI is driving the development of Germany as a cyber nation - for a resilient, innovative and secure digital future. Cybersecurity is becoming a success factor for digitalization - nationally and in Europe.
ZenDiS Contact
Downloads
BSI and ZenDiS publish strategy for securing administrative software supply chains