{"id":73414,"date":"2026-08-05T22:34:23","date_gmt":"2026-08-05T20:34:23","guid":{"rendered":"http:\/\/adiumento.local\/?page_id=73414"},"modified":"2026-08-05T22:34:23","modified_gmt":"2026-08-05T20:34:23","slug":"sichere-softwarebereitstellung","status":"publish","type":"page","link":"https:\/\/adiumento.de\/en\/themen\/regulatorik-sicher-umsetzen\/sichere-softwarebereitstellung\/","title":{"rendered":"Secure software delivery"},"content":{"rendered":"<div class=\"wp-block-cover alignfull is-position-center-left service-page-hero is-light alignfull\" style=\"min-height:420px;aspect-ratio:unset;\"><img loading=\"lazy\" decoding=\"async\" width=\"1536\" height=\"1024\" class=\"wp-block-cover__image-background wp-image-73455\" alt=\"Sichere Softwarebereitstellung\" src=\"https:\/\/adiumento.de\/wp-content\/uploads\/2026\/08\/adiumento-themen-software.png\" data-object-fit=\"cover\" srcset=\"https:\/\/adiumento.de\/wp-content\/uploads\/2026\/08\/adiumento-themen-software.png 1536w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/08\/adiumento-themen-software-300x200.png 300w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/08\/adiumento-themen-software-1024x683.png 1024w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/08\/adiumento-themen-software-768x512.png 768w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/08\/adiumento-themen-software-18x12.png 18w\" sizes=\"auto, (max-width: 1536px) 100vw, 1536px\" \/><span aria-hidden=\"true\" class=\"wp-block-cover__background has-dark-background-color has-background-dim-50 has-background-dim\"><\/span><div class=\"wp-block-cover__inner-container\"><p class=\"service-page-back is-layout-flow wp-block-cover-is-layout-flow\"><a href=\"https:\/\/adiumento.de\/en\/?page_id=73410\">\u2190 Implement regulatory requirements securely<\/a><\/p><h1 class=\"wp-block-heading\">Secure software delivery<\/h1><p class=\"has-medium-font-size wp-block-paragraph\"><strong>Transfer security requirements from the start of planning to operation into a repeatable delivery process.<\/strong><\/p><\/div><\/div>\n\n\n\n<div class=\"wp-block-group is-style-section-light service-page-orientation adiumento-passage is-layout-flow wp-block-group-is-layout-flow\"><p class=\"has-text-align-center service-orientation__text wp-block-paragraph\">Secure software delivery controls risks along a traceable delivery route: <strong>Source \u2192 Dependencies \u2192 Build \u2192 Artifact \u2192 Release \u2192 Deployment \u2192 Operation<\/strong>. DevSecOps, SBOM and signing are not isolated tools, but controls for transparency, integrity and understandable decisions.<\/p>\n<\/div>\n\n\n<div class=\"wp-block-group is-style-section-neutral adiumento-passage adiumento-themen-section is-layout-flow wp-block-group-is-layout-flow\"><h2 class=\"wp-block-heading has-text-align-center\">Background<\/h2>\n\n<div class=\"wp-block-media-text is-stacked-on-mobile has-media-on-the-right service-media-text adiumento-themen-media\"><figure class=\"wp-block-media-text__media\"><img loading=\"lazy\" decoding=\"async\" width=\"1536\" height=\"1024\" src=\"https:\/\/adiumento.de\/wp-content\/uploads\/2026\/08\/adiumento-themen-software.png\" alt=\"Sichere Softwarebereitstellung\" class=\"wp-image-73455 size-full\" srcset=\"https:\/\/adiumento.de\/wp-content\/uploads\/2026\/08\/adiumento-themen-software.png 1536w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/08\/adiumento-themen-software-300x200.png 300w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/08\/adiumento-themen-software-1024x683.png 1024w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/08\/adiumento-themen-software-768x512.png 768w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/08\/adiumento-themen-software-18x12.png 18w\" sizes=\"auto, (max-width: 1536px) 100vw, 1536px\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p class=\"wp-block-paragraph\">Modern applications are created from your own code, open source components, build systems and external services. Scheduling security checks before a release leads to late conflicts and unclear exceptions. Likewise, a generated SBOM is not sufficient if no one assesses vulnerabilities or secures an artifact on its way into production.<\/p>\n<\/div><\/div>\n\n\n<\/div>\n\n\n<div class=\"wp-block-group is-style-section-light adiumento-passage adiumento-themen-section is-layout-flow wp-block-group-is-layout-flow\"><h2 class=\"wp-block-heading has-text-align-center\">The delivery route as a security model<\/h2>\n\n<p class=\"wp-block-paragraph\">Each stage of the delivery journey needs a verifiable handover: source code and changes, known dependencies, protected build environments, clearly assigned artifacts, approved releases, controlled deployments and operational feedback. The model helps to clarify responsibilities and evidence not just for each tool, but across the entire delivery route.<\/p>\n<\/div>\n\n\n<div class=\"wp-block-group is-style-section-neutral adiumento-passage adiumento-themen-section is-layout-flow wp-block-group-is-layout-flow\"><h2 class=\"wp-block-heading has-text-align-center\">Technical context<\/h2>\n\n<div class=\"wp-block-media-text is-stacked-on-mobile has-media-on-the-left service-media-text adiumento-themen-media\"><figure class=\"wp-block-media-text__media\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"768\" src=\"https:\/\/adiumento.de\/wp-content\/uploads\/2025\/08\/adiumento-cloud-hub-outcomes-2.png\" alt=\"Abstrakte Illustration: Cloud-Roadmap und Umsetzungsplanung in Blau.\" class=\"wp-image-73220 size-full\" srcset=\"https:\/\/adiumento.de\/wp-content\/uploads\/2025\/08\/adiumento-cloud-hub-outcomes-2.png 1024w, https:\/\/adiumento.de\/wp-content\/uploads\/2025\/08\/adiumento-cloud-hub-outcomes-2-300x225.png 300w, https:\/\/adiumento.de\/wp-content\/uploads\/2025\/08\/adiumento-cloud-hub-outcomes-2-768x576.png 768w, https:\/\/adiumento.de\/wp-content\/uploads\/2025\/08\/adiumento-cloud-hub-outcomes-2-16x12.png 16w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p class=\"wp-block-paragraph\">A <strong>Secure Software Lifecycle (SSLC)<\/strong> anchors security decisions in planning, development, testing, release and operation. <strong>DevSecOps<\/strong> makes these steps in the delivery flow repeatable. One <strong>SBOM<\/strong> creates transparency about components and dependencies; <strong>Code and Artifact Signing<\/strong> helps verify the provenance and integrity of artifacts. Deepen the implementation <a href=\"\/en\/themen\/regulatorik-sicher-umsetzen\/sichere-softwarebereitstellung\/secure-software-lifecycle-devsecops\/\">Secure Software Lifecycle \/ DevSecOps<\/a>, <a href=\"\/en\/themen\/regulatorik-sicher-umsetzen\/sichere-softwarebereitstellung\/sbom-dependency-management\/\">SBOM &amp; Dependency Management<\/a> and <a href=\"\/en\/themen\/regulatorik-sicher-umsetzen\/sichere-softwarebereitstellung\/code-signing-microsoft-artifact-signing\/\">Code Signing \/ Artifact Signing<\/a>.<\/p>\n<\/div><\/div>\n\n\n<\/div>\n\n\n<div class=\"wp-block-group is-style-section-light adiumento-passage adiumento-themen-section is-layout-flow wp-block-group-is-layout-flow\"><h2 class=\"wp-block-heading has-text-align-center\">What companies need to clarify specifically<\/h2>\n\n<ul class=\"wp-block-list\">\n<li>Which applications, components, repositories and delivery routes are within the scope.<\/li>\n<li>Who is responsible for security requirements, risks, exceptions and approvals.<\/li>\n<li>Which tests will be automated and where professional assessment remains necessary.<\/li>\n<li>How dependencies and vulnerabilities are tracked during operations.<\/li>\n<li>How build identities, keys and production access are protected.<\/li>\n<\/ul>\n<\/div>\n\n\n<div class=\"wp-block-group is-style-section-neutral adiumento-passage adiumento-themen-section is-layout-flow wp-block-group-is-layout-flow\"><h2 class=\"wp-block-heading has-text-align-center\">From requirements to implementation<\/h2>\n\n<div class=\"wp-block-media-text is-stacked-on-mobile has-media-on-the-right service-media-text adiumento-themen-media\"><figure class=\"wp-block-media-text__media\"><img loading=\"lazy\" decoding=\"async\" width=\"1708\" height=\"2560\" src=\"https:\/\/adiumento.de\/wp-content\/uploads\/2026\/07\/adiumento-cloud-computing-microsoft-365-azure-zusammenarbeit-scaled.jpg\" alt=\"Team arbeitet gemeinsam an Cloud-L\u00f6sungen und digitalen Arbeitspl\u00e4tzen.\" class=\"wp-image-73299 size-full\" srcset=\"https:\/\/adiumento.de\/wp-content\/uploads\/2026\/07\/adiumento-cloud-computing-microsoft-365-azure-zusammenarbeit-scaled.jpg 1708w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/07\/adiumento-cloud-computing-microsoft-365-azure-zusammenarbeit-200x300.jpg 200w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/07\/adiumento-cloud-computing-microsoft-365-azure-zusammenarbeit-683x1024.jpg 683w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/07\/adiumento-cloud-computing-microsoft-365-azure-zusammenarbeit-768x1151.jpg 768w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/07\/adiumento-cloud-computing-microsoft-365-azure-zusammenarbeit-1025x1536.jpg 1025w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/07\/adiumento-cloud-computing-microsoft-365-azure-zusammenarbeit-1367x2048.jpg 1367w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/07\/adiumento-cloud-computing-microsoft-365-azure-zusammenarbeit-8x12.jpg 8w\" sizes=\"auto, (max-width: 1708px) 100vw, 1708px\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<div class=\"wp-block-group wp-block-coblocks-accordion adiumento-accordion is-layout-flow wp-block-group-is-layout-flow\">\n\n<details class=\"wp-block-details wp-block-coblocks-accordion-item\"><summary class=\"wp-block-coblocks-accordion-item__title is-layout-flow wp-block-details-is-layout-flow\">secure lifecycle<\/summary><p class=\"wp-block-paragraph\"><strong>Risk:<\/strong> late recognition<br><strong>Organisational measure:<\/strong> Security Gates and Roles<br><strong>Technical implementation:<\/strong> Checks in pipeline and repository<br><strong>Possible evidence:<\/strong> Requirements, approvals<\/p><\/details>\n\n<details class=\"wp-block-details wp-block-coblocks-accordion-item\"><summary class=\"wp-block-coblocks-accordion-item__title is-layout-flow wp-block-details-is-layout-flow\">Dependencies<\/summary><p class=\"wp-block-paragraph\"><strong>Risk:<\/strong> unknown components<br><strong>Organisational measure:<\/strong> Evaluation and update process<br><strong>Technical implementation:<\/strong> SBOM generation, dependency scanning<br><strong>Possible evidence:<\/strong> SBOM, Tickets<\/p><\/details>\n\n<details class=\"wp-block-details wp-block-coblocks-accordion-item\"><summary class=\"wp-block-coblocks-accordion-item__title is-layout-flow wp-block-details-is-layout-flow\">Build integrity<\/summary><p class=\"wp-block-paragraph\"><strong>Risk:<\/strong> manipulated artifacts<br><strong>Organisational measure:<\/strong> Separation of tasks<br><strong>Technical implementation:<\/strong> protected runners, minimal permissions<br><strong>Possible evidence:<\/strong> Pipeline and access logs<\/p><\/details>\n\n<details class=\"wp-block-details wp-block-coblocks-accordion-item\"><summary class=\"wp-block-coblocks-accordion-item__title is-layout-flow wp-block-details-is-layout-flow\">Release<\/summary><p class=\"wp-block-paragraph\"><strong>Risk:<\/strong> unclear origin<br><strong>Organisational measure:<\/strong> Release approval<br><strong>Technical implementation:<\/strong> Signing and Verifying Artifacts<br><strong>Possible evidence:<\/strong> Signature and release evidence<\/p><\/details>\n<\/div>\n\n<\/div><\/div>\n\n\n<\/div>\n\n\n<div class=\"wp-block-group is-style-section-light adiumento-passage adiumento-themen-section is-layout-flow wp-block-group-is-layout-flow\"><h2 class=\"wp-block-heading has-text-align-center\">Working with ADIUMENTO<\/h2>\n\n<p class=\"wp-block-paragraph\">This page is a technical topic hub, not a service promise for DevSecOps, SBOM or signing. The <a href=\"https:\/\/digital-strategy.ec.europa.eu\/en\/policies\/cyber-resilience-act\">Cyber Resilience Act<\/a> can create relevant context for products with digital elements; Applicability and obligations must be assessed on a product and role basis. Whether an architectural clarification or implementation fits the confirmed portfolio will only be clarified in the specific project.<\/p>\n<\/div>\n\n\n<div class=\"wp-block-group is-style-section-neutral adiumento-passage adiumento-themen-section is-layout-flow wp-block-group-is-layout-flow\"><h2 class=\"wp-block-heading has-text-align-center\">Typical deliverables<\/h2>\n\n<div class=\"wp-block-media-text is-stacked-on-mobile has-media-on-the-left service-media-text adiumento-themen-media\"><figure class=\"wp-block-media-text__media\"><img loading=\"lazy\" decoding=\"async\" width=\"1344\" height=\"768\" src=\"https:\/\/adiumento.de\/wp-content\/uploads\/2025\/08\/adiumento-cloud-hub-architecture-2.png\" alt=\"Abstrakte Illustration: Cloud-Architektur als vernetzte Plattform-Landschaft in Blau.\" class=\"wp-image-73219 size-full\" srcset=\"https:\/\/adiumento.de\/wp-content\/uploads\/2025\/08\/adiumento-cloud-hub-architecture-2.png 1344w, https:\/\/adiumento.de\/wp-content\/uploads\/2025\/08\/adiumento-cloud-hub-architecture-2-300x171.png 300w, https:\/\/adiumento.de\/wp-content\/uploads\/2025\/08\/adiumento-cloud-hub-architecture-2-1024x585.png 1024w, https:\/\/adiumento.de\/wp-content\/uploads\/2025\/08\/adiumento-cloud-hub-architecture-2-768x439.png 768w, https:\/\/adiumento.de\/wp-content\/uploads\/2025\/08\/adiumento-cloud-hub-architecture-2-18x10.png 18w\" sizes=\"auto, (max-width: 1344px) 100vw, 1344px\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<ul class=\"wp-block-list\">\n<li>Lifecycle target image with roles, security gates and exceptions;<\/li>\n<li>prioritised roadmap for pipeline, dependency and release protection;<\/li>\n<li>comprehensible artifact and evidence structure;<\/li>\n<li>Operational process for vulnerabilities and updates.<\/li>\n<\/ul>\n<\/div><\/div>\n\n\n<\/div>\n\n\n<div class=\"wp-block-group is-style-section-light adiumento-passage adiumento-themen-section is-layout-flow wp-block-group-is-layout-flow\"><h2 class=\"wp-block-heading has-text-align-center\">Limitations and dependencies<\/h2>\n\n<p class=\"wp-block-paragraph\">The measures do not replace product approval, legal advice or certification and do not constitute a certification guarantee. Their impact depends on the toolchain, development model, suppliers and consistent application in everyday life. Obligations under the CRA must be assessed separately by role and product.<\/p>\n<\/div>\n\n\n<div class=\"wp-block-group is-style-section-light service-page-topics adiumento-passage adiumento-themen-faq is-layout-flow wp-block-group-is-layout-flow\"><p class=\"has-text-align-center service-section-kicker wp-block-paragraph\">Orientation<\/p>\n<h2 class=\"wp-block-heading has-text-align-center\">Frequently asked questions<\/h2>\n\n<div class=\"wp-block-group wp-block-coblocks-accordion adiumento-accordion is-layout-flow wp-block-group-is-layout-flow\">\n\n<details class=\"wp-block-details wp-block-coblocks-accordion-item\"><summary class=\"wp-block-coblocks-accordion-item__title is-layout-flow wp-block-details-is-layout-flow\">Is an SBOM enough as a protective measure?<\/summary><p class=\"wp-block-paragraph\">No. It creates inventory transparency. Only with ownership, assessment, updates and a process for new vulnerabilities does it become effective.<\/p><\/details>\n\n<details class=\"wp-block-details wp-block-coblocks-accordion-item\"><summary class=\"wp-block-coblocks-accordion-item__title is-layout-flow wp-block-details-is-layout-flow\">Is signing only relevant for external releases?<\/summary><p class=\"wp-block-paragraph\">No. Signatures can also help internally to distinguish trusted artifacts from unauthorized builds. The appropriate strategy depends on the delivery model.<\/p><\/details>\n<\/div>\n\n<\/div>\n\n\n<div class=\"wp-block-group is-style-section-light adiumento-passage adiumento-themen-section is-layout-flow wp-block-group-is-layout-flow\"><h2 class=\"wp-block-heading has-text-align-center\">Next sensible step<\/h2>\n\n<div class=\"wp-block-media-text is-stacked-on-mobile has-media-on-the-right service-media-text adiumento-themen-media\"><figure class=\"wp-block-media-text__media\"><img loading=\"lazy\" decoding=\"async\" width=\"1707\" height=\"2560\" src=\"https:\/\/adiumento.de\/wp-content\/uploads\/2026\/07\/adiumento-daten-ki-digitale-datenanalyse-scaled.jpg\" alt=\"Digitaler Datenraum als Symbol f\u00fcr Datenanalyse und k\u00fcnstliche Intelligenz.\" class=\"wp-image-73304 size-full\" srcset=\"https:\/\/adiumento.de\/wp-content\/uploads\/2026\/07\/adiumento-daten-ki-digitale-datenanalyse-scaled.jpg 1707w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/07\/adiumento-daten-ki-digitale-datenanalyse-200x300.jpg 200w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/07\/adiumento-daten-ki-digitale-datenanalyse-683x1024.jpg 683w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/07\/adiumento-daten-ki-digitale-datenanalyse-768x1152.jpg 768w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/07\/adiumento-daten-ki-digitale-datenanalyse-1024x1536.jpg 1024w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/07\/adiumento-daten-ki-digitale-datenanalyse-1365x2048.jpg 1365w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/07\/adiumento-daten-ki-digitale-datenanalyse-8x12.jpg 8w\" sizes=\"auto, (max-width: 1707px) 100vw, 1707px\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p class=\"wp-block-paragraph\">First, make delivery routes, build identities, and critical dependencies transparent. Bid for architectural clarification as part of the confirmed portfolio <a href=\"https:\/\/adiumento.de\/en\/loesungen\/\">IT Security &amp; Compliance<\/a> and <a href=\"https:\/\/adiumento.de\/en\/leistungen\/\">Services<\/a> the right entry points.<\/p>\n<\/div><\/div>\n\n\n<\/div>","protected":false},"excerpt":{"rendered":"<p>Secure software across its lifecycle: classify the Secure Software Lifecycle, DevSecOps, dependencies, SBOM, secure builds and signing.<\/p>","protected":false},"author":3,"featured_media":0,"parent":73410,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"class_list":["post-73414","page","type-page","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/adiumento.de\/en\/wp-json\/wp\/v2\/pages\/73414","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/adiumento.de\/en\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/adiumento.de\/en\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/adiumento.de\/en\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/adiumento.de\/en\/wp-json\/wp\/v2\/comments?post=73414"}],"version-history":[{"count":4,"href":"https:\/\/adiumento.de\/en\/wp-json\/wp\/v2\/pages\/73414\/revisions"}],"predecessor-version":[{"id":73500,"href":"https:\/\/adiumento.de\/en\/wp-json\/wp\/v2\/pages\/73414\/revisions\/73500"}],"up":[{"embeddable":true,"href":"https:\/\/adiumento.de\/en\/wp-json\/wp\/v2\/pages\/73410"}],"wp:attachment":[{"href":"https:\/\/adiumento.de\/en\/wp-json\/wp\/v2\/media?parent=73414"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}