You have received a contract that incorporates the VS-NfD guideline (Merkblatt) and now have to demonstrate that your IT meets its requirements. Or you are building a VS-NfD environment from scratch and want to scope it correctly from the start. We know both situations from our own practice, because we operate a VS-NfD environment ourselves.
Handling classified information
The German Security Clearance Check Act (Sicherheitsüberprüfungsgesetz, SÜG) defines four classification levels: VS-NUR FÜR DEN DIENSTGEBRAUCH (VS-NfD, roughly RESTRICTED), VS-VERTRAULICH (CONFIDENTIAL), GEHEIM (SECRET) and STRENG GEHEIM (TOP SECRET). Handling classified information is subject to specific organizational, personnel and technical requirements that increase markedly with the classification level.
Organizations have to translate these requirements into their actual workflows and IT systems. This includes, among other things, assigning responsibilities, formally obliging staff to secrecy, separating project data, controlling access and transmission paths, and a robust information security concept.
Personnel security: VS-NfD does not require a security clearance check under the SÜG. Before being granted access, staff are briefed and formally obliged to secrecy, evidenced through part 5 of the VS-NfD guideline. A clearance check is added only from VS-VERTRAULICH upwards, as a rule the simple security clearance check (Ü1), with more extensive checks at higher levels. The roles differ as well: for VS-NfD the company appoints a person responsible for VS-NfD, whereas from VS-VERTRAULICH the security officer (Sicherheitsbevollmächtigter) under section 25 SÜG takes over. In public authorities, responsibility rests with the classified-protection officers (Geheimschutzbeauftragte).
Which classification levels we support
We support organizations in processing classified information up to the German national level VS-VERTRAULICH (CONFIDENTIAL), including VS-NfD, in each case within the prerequisites required for it.
We work in VS-NfD environments today, on the basis of the VS-NfD guideline requirements included in the respective contract. For this we operate a self-accredited VS-NfD environment built from BSI-approved security products.
Support at VS-VERTRAULICH requires additional prerequisites: admission into the classified-information protection program (Geheimschutzbetreuung) of the Federal Ministry for Economic Affairs and Energy (BMWE) including the security clearance certificate, plus security-cleared staff. We stand ready for this as soon as a classified contracting authority applies for our admission. The procedure does not provide for a self-application.
Advice on implementing the VS-NfD guideline
The VS-NfD guideline is annex 4 to the classified-protection manual for industry (Geheimschutzhandbuch, GHB) issued by the BMWE, and it is attached to your contract. It applies in its own right: a full classified-protection procedure and the remaining GHB provisions only come into play from VS-VERTRAULICH. We support the implementation on the basis of BSI IT-Grundschutz, for which our consultants hold personal certification from the German Federal Office for Information Security (BSI).
We support you with, among other things:
- identifying the requirements that apply to your VS-NfD contract,
- defining the information domain (Informationsverbund) and the affected workflows,
- assessing existing IT systems, networks, cloud services and project platforms,
- designing isolated or segmented VS-NfD environments,
- applying the principle of need-to-know,
- separating different VS-NfD contracts and project areas,
- selecting and integrating suitable and, where required, BSI-approved security products,
- drawing up an information security concept based on BSI IT-Grundschutz,
- performing the IT-Grundschutz check, the risk analysis and the implementation planning,
- governing administration, mobile working, data exchange, maintenance, deletion and emergency processes,
- preparing and documenting the self-accreditation.
The self-accreditation under part 3 of the VS-NfD guideline is the evidence everything leads up to: at least every three years, the person responsible for VS-NfD confirms in writing to the management that the IT requirements are implemented. This explicitly includes an established information security management system, either based on BSI IT-Grundschutz with an information security concept, IT-Grundschutz check, risk analysis and implementation planning, or through an ISO 27001 certification. These are exactly the building blocks we put in place with you.
We combine the formal requirements of classified-information protection with the practical demands of collaboration, project delivery and IT operations. That way the requirements do not just end up in the documentation, but in day-to-day work.
Penetration tests for verifying the effectiveness of your classified IT
A security concept on paper is not enough. Once the security concepts are finalized and the classified IT is in place, you have to verify that the defined measures are actually implemented effectively. For federal authorities and federal public-law institutions subject to the VSA, this effectiveness verification is a prerequisite for releasing the classified IT under section 50 VSA. Companies are not subject to the VSA: for them the contractually included requirements of the VS-NfD guideline apply, and they confirm their implementation through self-accreditation. In both cases, a penetration test is a suitable way to demonstrate technical implementation.
The BSI describes the approach for the public-authority setting in its German-language guidance document Handreichung zur Wirksamkeitsprüfung von VS-IT. The starting point is the result of the IT-Grundschutz check for the applicable module, CON.11.1 (VS-NfD) or CON.11.2 (VS-VERTRAULICH or higher). The verification combines interviews, written self-assessments, on-site inspections, document reviews and penetration tests, because no single method can capture multi-layered security on its own.
We cover the penetration testing part of this verification. It specifically reveals what is neither visible in the documentation nor noticed during an on-site inspection. Depending on your needs, we assess the entire classified IT or individual components, either classically as an intrusion attempt or analytically, by reviewing configurations and settings together with your administrators.
We test where VS-NfD is processed. Because we meet the requirements of the VS-NfD guideline ourselves and operate a self-accredited VS-NfD environment built from BSI-approved security products, we can work in the classified environment.
In the public-authority setting, your classified-protection officers draw up the test plan. Responsibility for the effectiveness verification also stays with them. It cannot be outsourced in full. We take on the partial assessment you commission from us and document it so that the results are traceable for third parties and the tests performed are reproducible. On that basis, your classified-protection officers can add the evidence to the classified IT documentation. One practical note, which the BSI makes as well: commission the penetration test early so that it fits into the test plan and the project schedule.
What we bring
- Implementation advice for VS-NfD from consultants holding BSI personal certification in IT-Grundschutz.
- Information security concepts and risk analyses based on BSI IT-Grundschutz, as the basis for the self-accreditation.
- Secure processing of classified project data in our self-accredited VS-NfD environment.
- Penetration tests in the classified environment as a contribution to verifying the effectiveness of your classified IT, delivered by a BSI-certified IS penetration testing service provider (registration ID BSI-APS-9080, listed in the BSI register).
- Practical experience from operating our own VS-NfD environment and the special requirements for operation, administration and data transmission.
- Support from requirements analysis to documented operation, including measures planning and preparation of the self-accreditation.
We do not name references from the classified domain publicly, as that is part of the assignment. On request we discuss them in an appropriate setting. You can find our certifications and qualifications on our About us page.
