What Is SDLC (Software Development Life Cycle)?

Related problems: Software releases keep slipping and nobody knows what stage the work is in; Security issues found only after the product ships; Can't tell whether a development vendor follows a disciplined process; Customers asking how we build and test our software

The software development life cycle (SDLC) is the structured series of stages that software moves through, from the first idea to release and ongoing maintenance. A typical version covers planning, requirements, design, development, testing, deployment and maintenance, though organizations name and divide the stages differently. The SDLC describes what has to happen; methods such as Agile and Waterfall describe how the stages are organized and repeated.

At a glance

  • The SDLC breaks software work into stages, each with a purpose, owners and outputs.
  • Common stages are planning, requirements, design, development, testing, release and maintenance; some models add retirement.
  • Waterfall runs the stages largely in sequence; Agile and DevOps run them in short, repeated cycles, often automated.
  • A secure SDLC adds security activities to each stage rather than only testing at the end.
  • Buyers meet the SDLC in vendor due diligence, security questionnaires and custom development contracts.

What problem it solves

Building software without a shared process leads to familiar problems: requirements that change without anyone agreeing, code that reaches users without being tested, releases that break what already worked, and security flaws found only after customers do. Nobody can say where a piece of work stands or who signed off on it.

The SDLC gives teams a common map. Each stage has entry and exit points, so work is reviewed before it moves on and problems are caught earlier, when they are usually cheaper to fix. It also creates a record of decisions and tests that auditors, customers and security reviewers can examine, and it makes the cost of shortcuts, often called technical debt, easier to see.

How it works

Planning. Define the goal, scope, budget, timeline and risks of the work.

Requirements. Capture what the software must do and how well it must do it, including security, performance and compliance needs.

Design. Decide the architecture, data model, interfaces and integrations. In a secure SDLC this is where threat modeling usually happens.

Development. Write the code, typically with peer review and automated checks such as static application security testing (SAST).

Testing. Verify that the software works as intended through unit, integration, user acceptance, performance and application security testing.

Deployment. Release to users, often through an automated pipeline using continuous integration and continuous delivery (CI/CD), with a way to roll back if something goes wrong.

Maintenance. Fix defects, apply security patches, monitor performance and add improvements. This stage often lasts far longer than the build. Eventually the software is retired and its data archived or migrated.

How these stages are run depends on the method. In Scrum and other Agile approaches, small pieces of work pass through all the stages every few weeks. In DevSecOps, much of the testing and security checking is automated and runs on every change.

When it matters for buyers

  • When hiring a development firm. Ask how they run each stage, who approves releases and how testing is evidenced.
  • When assessing a software vendor’s security. Security questionnaires and frameworks commonly ask about secure development practices.
  • When your own customers ask. If you sell software, buyers and auditors may request evidence of your SDLC.
  • When choosing development, testing or monitoring tools. Each tool covers part of the cycle; knowing the stages shows where the gaps are.
  • When releases keep causing outages. Weak testing or deployment stages are a common cause.

For tools that find security flaws during development and testing, see our application security testing solutions overview.

Questions to ask vendors

  • Which SDLC model or method do you follow, and is it documented?
  • How are requirements, including security requirements, captured and approved?
  • What testing happens before each release, and which parts are automated?
  • How do you scan code and third-party components for vulnerabilities, and how quickly are findings fixed?
  • Who can approve a release to production, and how is that recorded?
  • How do you handle security patches after release, and how are customers notified?
  • Can you provide evidence, such as audit reports or test summaries, rather than only a description?

How it differs from Agile and Waterfall

The SDLC is the set of stages that software development has to cover. Agile and Waterfall are methods for working through those stages. Waterfall runs them largely once, in order, with each stage mostly complete before the next begins. Agile runs them in short, repeated iterations so working software reaches users early and plans can change. Asking “which SDLC do you use?” usually means “which method do you use to run it?”, and the useful follow-up is how each stage is actually carried out and checked.

Frequently Asked Questions

What are the stages of the SDLC?
Models vary, but most include planning, requirements, design, development, testing, deployment or release, and maintenance. Some add retirement as a final stage. The names and number of stages differ between organizations; what matters is that each stage has a clear purpose and output.
Is Agile an SDLC?
Agile is an approach to running the SDLC, not a replacement for it. In Agile, the same stages happen in short, repeated cycles instead of once in sequence. Waterfall runs them largely one after another. Both are ways of organizing the life cycle.
What is a secure SDLC?
A secure SDLC builds security activities into each stage: threat modeling during design, secure coding standards and code scanning during development, security testing before release and vulnerability management after. The aim is to find and fix security issues earlier, when they are usually cheaper to fix.
Does SDLC mean the same as systems development life cycle?
The two share an acronym and a similar sequence of stages. The systems development life cycle is the older, broader term and can cover hardware, people and processes as well as software. In most software discussions today, SDLC means the software development life cycle.
Why should a buyer care about a vendor's SDLC?
A vendor's development process affects the quality, security and reliability of what you buy. Security questionnaires and customer contracts increasingly ask how software is designed, tested, released and patched, and a vendor with a documented, consistently followed SDLC can usually answer with evidence.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.