That's not going to happen because the two toolchains won't be anything alike. You won't be able to make them alike either. Worse, that people often quote Thompson's attack shows that INFOSEC teaches subversion very poorly: it's the least likely attack to affect you and you really need to counter the others. What you have to do is make the software correct, make it secure, and ensure no subversion in lifecycle. That's called high assurance or robustness system design. Links below show you how to do that.
High assurance software design - nice intro http://web.cecs.pdx.edu/~hook/cs491sp08/AssuranceSp08.ppt
FOSS tools for high assurance http://www.dwheeler.com/essays/high-assurance-floss.html
Certified compilation (HW w/ need certified "synthesis") http://compcert.inria.fr/
Original work on subversion http://csrc.nist.gov/publications/history/myer80.pdf
Example of it in action http://www.cisr.us/downloads/theses/02thesis_anderson.pdf
Example of high assurance hardware (AAMP7G version is secure but no public paper...) http://www.csl.sri.com/papers/wift95/wift95.pdf