The software development life cycle (SDLC) is the structured series of stages that software moves through, from the first idea to release and ongoing maintenance. A typical version covers planning, requirements, design, development, testing, deployment and maintenance, though organizations name and divide the stages differently. The SDLC describes what has to happen; methods such as Agile and Waterfall describe how the stages are organized and repeated.
At a glance
- The SDLC breaks software work into stages, each with a purpose, owners and outputs.
- Common stages are planning, requirements, design, development, testing, release and maintenance; some models add retirement.
- Waterfall runs the stages largely in sequence; Agile and DevOps run them in short, repeated cycles, often automated.
- A secure SDLC adds security activities to each stage rather than only testing at the end.
- Buyers meet the SDLC in vendor due diligence, security questionnaires and custom development contracts.
What problem it solves
Building software without a shared process leads to familiar problems: requirements that change without anyone agreeing, code that reaches users without being tested, releases that break what already worked, and security flaws found only after customers do. Nobody can say where a piece of work stands or who signed off on it.
The SDLC gives teams a common map. Each stage has entry and exit points, so work is reviewed before it moves on and problems are caught earlier, when they are usually cheaper to fix. It also creates a record of decisions and tests that auditors, customers and security reviewers can examine, and it makes the cost of shortcuts, often called technical debt, easier to see.
How it works
Planning. Define the goal, scope, budget, timeline and risks of the work.
Requirements. Capture what the software must do and how well it must do it, including security, performance and compliance needs.
Design. Decide the architecture, data model, interfaces and integrations. In a secure SDLC this is where threat modeling usually happens.
Development. Write the code, typically with peer review and automated checks such as static application security testing (SAST).
Testing. Verify that the software works as intended through unit, integration, user acceptance, performance and application security testing.
Deployment. Release to users, often through an automated pipeline using continuous integration and continuous delivery (CI/CD), with a way to roll back if something goes wrong.
Maintenance. Fix defects, apply security patches, monitor performance and add improvements. This stage often lasts far longer than the build. Eventually the software is retired and its data archived or migrated.
How these stages are run depends on the method. In Scrum and other Agile approaches, small pieces of work pass through all the stages every few weeks. In DevSecOps, much of the testing and security checking is automated and runs on every change.
When it matters for buyers
- When hiring a development firm. Ask how they run each stage, who approves releases and how testing is evidenced.
- When assessing a software vendor’s security. Security questionnaires and frameworks commonly ask about secure development practices.
- When your own customers ask. If you sell software, buyers and auditors may request evidence of your SDLC.
- When choosing development, testing or monitoring tools. Each tool covers part of the cycle; knowing the stages shows where the gaps are.
- When releases keep causing outages. Weak testing or deployment stages are a common cause.
For tools that find security flaws during development and testing, see our application security testing solutions overview.
Questions to ask vendors
- Which SDLC model or method do you follow, and is it documented?
- How are requirements, including security requirements, captured and approved?
- What testing happens before each release, and which parts are automated?
- How do you scan code and third-party components for vulnerabilities, and how quickly are findings fixed?
- Who can approve a release to production, and how is that recorded?
- How do you handle security patches after release, and how are customers notified?
- Can you provide evidence, such as audit reports or test summaries, rather than only a description?
How it differs from Agile and Waterfall
The SDLC is the set of stages that software development has to cover. Agile and Waterfall are methods for working through those stages. Waterfall runs them largely once, in order, with each stage mostly complete before the next begins. Agile runs them in short, repeated iterations so working software reaches users early and plans can change. Asking “which SDLC do you use?” usually means “which method do you use to run it?”, and the useful follow-up is how each stage is actually carried out and checked.
