AIS acceptance process
At a glance
FWU Institut für Film und Bild in Wissenschaft und Unterricht gGmbH (Grünwald, Germany) is tendering: AIS acceptance process. Offers are due 13 Oct 2026, 17:00 CEST. 3 lots. Bidders must show, among other things: ISO 27001, ISTQB, references, key people, minimum turnover, insurance.
- 13 Oct 2026, 17:00 CEST
- Deadline
- Restricted procedure
- Procedure
- Software testing (72254000)
- Main CPV
- 14 Sept 2026
- Published
Translated from the official notice. The original text is the legally binding one.
What the buyer wants
The advertised services are divided into three branches. A tender may be submitted for one lot, for several lots or for all lots. There is therefore no obligation to tender for all lots. The lots shall be assessed independently. The contract may be awarded to different contractors per lot. Lot 1: acceptance tests Lot 2: security tests Lot 3: code reviews The contractor provides his services independently and without instructions with regard to the evaluation of the examination results. The services are based on the documents, information, software statuses, source codes, test environments, test data, accesses and other resources required for the respective service. The scope of the documents and resources to be provided by the client depends on the requirements of the respective lots.
Gegenstand der Ausschreibung sind Leistungen der unabhängigen Qualitätssicherung für die Softwarelösung AIS (Adaptives Intelligentes System). Die Leistungen dienen der objektiven und nachvollziehbaren Bewertung der bereitgestellten Software hinsichtlich der in den jeweiligen Losen definierten fachlichen, technischen und sicherheitsrelevanten Anforderungen. Ziel der Leistungen ist die Ermittlung und Dokumentation des Qualitätsstands der Software sowie die Identifikation von Abweichungen, Mängeln, Risiken und Verbesserungspotenzialen. Die im Rahmen der Qualitätssicherung erstellten Ergebnisse bilden eine wesentliche Grundlage für die Entscheidung des Auftraggebers über die Abnahme der Software. Die Verantwortung für die Abnahmeentscheidung verbleibt ausschließlich beim Auftraggeber.
Lots (3)
Lot 1Abnahmetests
The advertised services are divided into three branches. A tender may be submitted for one lot, for several lots or for all lots. There is therefore no obligation to tender for all lots. The lots shall be assessed independently. The contract may be awarded to different contractors per lot. Lot 1: acceptance tests Lot 2: security tests Lot 3: code reviews The contractor provides his services independently and without instructions with regard to the evaluation of the examination results. The services are based on the documents, information, software statuses, source codes, test environments, test data, accesses and other resources required for the respective service. The scope of the documents and resources to be provided by the client depends on the requirements of the respective lots.
Lot 2Security-Tests
The advertised services are divided into three branches. A tender may be submitted for one lot, for several lots or for all lots. There is therefore no obligation to tender for all lots. The lots shall be assessed independently. The contract may be awarded to different contractors per lot. Lot 1: acceptance tests Lot 2: security tests Lot 3: code reviews The contractor provides his services independently and without instructions with regard to the evaluation of the examination results. The services are based on the documents, information, software statuses, source codes, test environments, test data, accesses and other resources required for the respective service. The scope of the documents and resources to be provided by the client depends on the requirements of the respective lots.
Lot 3Code Reviews
The advertised services are divided into three branches. A tender may be submitted for one lot, for several lots or for all lots. There is therefore no obligation to tender for all lots. The lots shall be assessed independently. The contract may be awarded to different contractors per lot. Lot 1: acceptance tests Lot 2: security tests Lot 3: code reviews The contractor provides his services independently and without instructions with regard to the evaluation of the examination results. The services are based on the documents, information, software statuses, source codes, test environments, test data, accesses and other resources required for the respective service. The scope of the documents and resources to be provided by the client depends on the requirements of the respective lots.
Can you bid? Your readiness check
These are the conditions this notice asks bidders to prove. In SalesDots each one is checked against your company profile: certificates with their validity dates, delivered references and your people.
- In your profile
Certificates
ISO 27001 · ISTQB
- In your profile
References
Similar contracts delivered before
- Not in your profile yet
Key people
Named roles, CVs or minimum team
- In your profile
Minimum turnover
Minimum annual turnover or financial standing
- Expires before the deadline
Insurance
Professional or liability insurance
Detected automatically in the published notice. Always confirm against the tender documents.
Check it against my companyShow the notice text (8)
- Presentation of the company (if possible with indication of name, registered office, postal address, legal form, object of the company, number of registration in a public register, legal representative, contact person, telephone, fax, e-mail address, if applicable, competent establishment or Location, range of services and core business of the company) as well as - if applicable - detailed description of the group affiliated / affiliated to other companies. - self-declaration about the absence of grounds for exclusion according to §§ 123, 124 GWB. - Current extract from the commercial register or comparable extract from the register (not older than 6 months at the time of submission of the application for participation, copy sufficient). Foreign tenderers shall provide equivalent certificates in accordance with the rules of their country of origin. These must be translated into German. - Self-declaration on Article 5 k of Regulation (EU) 833/2014 concerning restrictive measures in view of Russia's actions destabilising the situation in Ukraine - Declaration of Scientology protection - Declaration of commitment to collective labour standards and ILO core labour standards - Neutrality clause
This insurance must have the following minimum amounts of cover per damage event: - Personal injury: 2,000,000.00 Euro (per damage event) - Property, property and other damage: 2,000,000.00 Euro (per damage event) The coverage sums must be available at least twice in each insurance year (2-fold maximization).
Minimum standard: total turnover of the applicant/tenderer in the last three years on average of at least 1.000.000,00 Euro net p.a.
Indicate the turnover of the applicant/tenderer in the field of activity of the contract with comparable services over the last three years. Minimum standard for all lots: turnover on average at least. Lot 1 - Acceptance tests: Comparable services are services for the planning, creation, implementation and documentation of software tests in AI projects, in particular acceptance tests, functional and non-functional tests, API and E2E tests, usability and accessibility tests, performance and load tests, recovery and regression tests. This includes, in particular, testing of AI-based applications, web applications and complex software systems including interfaces, data processing and role and authorization functions. Also comparable are services for the detection and evaluation of defects as well as for the implementation of retests. Lot 2 - Security tests: Comparable services are services for the independent testing of the security of software applications and IT systems in the context of AI projects, in particular security assessments, penetration tests and vulnerability analyses. This includes in particular the testing of AI-based applications, APIs, authentication and authorization mechanisms, roles and permissions, data processing and interfaces. In particular, security tests of AI functionalities and agentic harnesses or agentic systems are comparable, including adversarial testing and Red Team tests for testing manipulation, abuse, prompt injection, tool and authorization risks. Also comparable are services for assessing, documenting and reviewing identified vulnerabilities as well as evaluating the effectiveness of implemented security measures. Lot 3 - Code Review: Comparable services are services for the independent testing and evaluation of software source code in the context of AI projects. This includes in particular the evaluation of code quality, architecture, maintainability, expandability, error handling, technical risks, code smells and technical debt as well as the examination of compliance with coding guidelines. Also comparable are code reviews of AI-/LLM-based applications, agent harnesses or agentic systems and their technical components as well as the documentation, prioritization and evaluation of the identified defects and risks.
Number of persons employed (full-time equivalents) by the applicant/tenderer in the last three years: minimum requirement: lot 1: 20 FTE for software acceptance tests lot 2: 15 FTE for software security tests lot 3: 15 FTE for code review
Lot 1 Acceptance tests For each lot, three references comparable in content must be shown. For each reference max. 9 points Comparability of the company references rating with 1 point each when meeting the respective criterion: The reference project involved conducting acceptance tests (functional, API, E2E) for a system with at least 100,000 users. The reference project was carried out using recognised test management standards (e.g. ISTQB, ISO/IEC/IEEE 29119); The reference project was delivered using test automation tools for E2E/API testing (e.g. Cucumber, Playwright, Selenium); The reference project involved WCAG 2.1 accessibility testing of a publicly available application. The reference project included performance/load and recovery/failover tests for a system with load scaling of at least 500,000 users. The reference project involved the parallel implementation of several test types (functional, API, E2E, usability, performance) within a defined time period by a test team. The reference project involved testing AI/LLM-based application functions (e.g. tutor/assistance functions) for functional correctness and response quality. The reference project was carried out in the school/public educational context or public/official context. The reference project included the verification of data protection-relevant functions within the framework of the acceptance tests (e.g. rectification, deletion, restriction of the processing of personal data) for compliance with the relevant data protection requirements.
Lot 2 Security tests There are three references comparable in content for each lot. For each reference max. 11 points Comparability of the company references Rating with 1 point each when meeting the respective criterion: The reference project involved conducting security/penetration tests for a system with at least 100,000 active users. The reference project meets information security standards according to ISO 27001 The reference project was tested by a CREST or equivalent accredited penetration test company The reference project was tested using recognized testing methods and standards (OWASP Testing Guide, OWASP Top 10, OWASP API Security Top 10). The reference project was delivered using modern test infrastructure (e.g. automated scanning pipelines, CI/CD-integrated security testing). The reference project involved testing open and documented interfaces (APIs) for their secure integration into existing system landscapes (e.g. ERP, identity, cloud systems). The reference project involved parallel testing of several components, interfaces or system areas within a defined period by a test team. The reference project included security tests of AI/LLM-based components and agentic harnesses or agentic systems, in particular with regard to prompt injection, impermissible tool or function calls, authorization escalation, data outflow and agent behavior manipulation. The reference project included security tests in the public/official or school education context. The reference project included security tests in the public/official or school educational context. The reference project involved examining data protection-relevant aspects of the processing of personal data (e.g. access protection, session management, data transmission) within the framework of the security tests.
Lot 3 Code review Three references comparable in content must be shown for each lot. For each reference max. 8 points Comparability of the company references Rating with 1 point each when meeting the respective criterion: The reference project involved reviewing a code base with high complexity (e.g. microservice architecture, multiple programming languages/frameworks, or involvement of multiple development teams). The reference project was carried out in compliance with recognized principles of software development as well as project-specific coding guidelines and clean code principles, verifiable by documented review results. The reference project was delivered using automated static code analysis tools (e.g. SonarQube, Checkmarx, ESLint, Codacy) in combination with expert evaluation by the reviewers. The reference project involved reviewing open and documented interfaces (APIs) in terms of structure, maintainability and consistency when integrating into existing system landscapes (e.g. ERP, identity, cloud systems). The reference project involved the parallel examination of several components, modules or system areas within a defined period by a review team. The reference project was carried out within the framework of an established DevOps approach with the integration of code review activities into automated build, test and deployment processes (continuous code quality). The reference project involved reviewing AI/ML specific components (data pipelines, model integration, prompt engineering) and agentic harnesses in terms of code quality, architecture and technical risks. The reference project involved reviewing open source licensed components or applications for license compliance and code quality.
How offers are scored
- The qualification and experience of performing the contract..60%
- The submitted prize is awarded using the linear interpolation method40%
What this buyer bought before
Recent IT contracts awarded by the same buyer, from published award notices.
LC Lizenzmanager
Winner: SINC GmbH
€2.3m
18 Jun 2026
Germany-Grünwald: Secondary education services
Winner: C.C.Buchner Verlag GmbH & Co. KG
€975,400
Win it with SalesDots
Read the documents for you
SalesDots fetches the tender documents (or takes your upload when a platform does not allow it) and answers the two questions that matter first: what the buyer wants built, and what you must prove to take part, each with the exact quote and page.
Analyse documentsMatch it with your profile
Every certificate, reference and role is checked against your company: green when you have it, amber when it expires before the deadline, grey when it needs a look.
Check my fitPrepare your response
Turn the conditions into a bid checklist with owners and due dates, draft the questions to the buyer and keep the team on one plan.
Start a responseNever miss a change
Track the deadline, amendments and answers to clarification questions, and get similar tenders and re-tenders before they are published.
Track this tenderSource: Tenders Electronic Daily (TED), Official Journal of the EU. SalesDots is not the contracting authority; offers are submitted only through the buyer's platform.