VS-NFD Ongoing Compliance
Ensure your company continuously meets VS-NfD requirements for handling German classified information. We establish systematic processes for monitoring, training, and documentation so your security measures always comply with the Verschlusssachenanweisung (VSA) and BSI standards.
- ✓Systematic VS-NfD monitoring with regular compliance reviews
- ✓Employee training and briefings per VS-NfD memorandum requirements
- ✓Audit-ready documentation for classified information inspections
- ✓Proactive adaptation to updated Verschlusssachenanweisung requirements
Your strategic success starts here
Our clients trust our expertise in digital transformation, compliance, and risk management
30 Minutes • Non-binding • Immediately available
For optimal preparation of your strategy session:
- Your strategic goals and objectives
- Desired business outcomes and ROI
- Steps already taken
Or contact us directly:
Certifications, Partners and more...










Ongoing VS-NfD Compliance for Companies
Our Strengths
- Hands-on experience with Geheimschutz management and VS-NfD audits at critical infrastructure and government contractor companies
- Deep knowledge of VSA, SÜG, Geheimschutzhandbuch, and BSI guidelines
- Structured approach: gap analysis, action plan, implementation, monitoring
- Experience with both physical and personnel security requirements
Important Note
The Verschlusssachenanweisung (VSA) was fundamentally revised in 2023. Companies under Geheimschutz must adapt their processes to the new requirements. Digital processing of VS-NfD documents in particular requires updated IT security concepts. Check now whether your ongoing VS-NfD compliance meets current standards.
ADVISORI in Numbers
11+
Years of Experience
120+
Employees
520+
Projects
We follow a structured approach for ongoing VS-NfD compliance based on the concrete requirements of the Verschlusssachenanweisung, the Geheimschutzhandbuch, and BSI guidelines.
Our Approach:
Assessment: Analysis of current VS-NfD compliance status and gap identification
Action plan: Prioritized measures to close identified compliance gaps
Implementation: Training, process adjustments, and IT security measures
Monitoring: Regular review and reporting on VS-NfD compliance status
Audit support: Preparation and assistance during official Geheimschutz inspections
"Sustainable compliance with VS-NFD requirements is not a one-time project, but a continuous process that must be integrated into the DNA of the non-financial service provider. Our Ongoing Compliance approach creates the structures, processes, and cultural prerequisites for this integration and enables our clients not only to meet VS-NFD requirements but to utilize them as a strategic advantage. The combination of automated monitoring, proactive change management, and integrated control systems not only reduces compliance risks but also significantly optimizes resource utilization."

Sarah Richter
Head of Information Security, Cyber Security
Expertise & Experience:
10+ years of experience, CISA, CISM, Lead Auditor, DORA, NIS2, BCM, Cyber and Information Security
Our Services
We offer you tailored solutions for your digital transformation
VS-NFD Compliance Governance & Monitoring
We establish solid governance structures and automated monitoring systems specifically for VS-NFD requirements that ensure continuous compliance, identify risks early, and signal the need for action.
- Development of a tailored VS-NFD compliance governance framework
- Implementation of automated VS-NFD compliance monitoring systems
- Establishment of clear responsibilities and escalation paths for VS-NFD
- Integration of KPI-based VS-NFD compliance reporting
VS-NFD Regulatory Change Management
We implement proactive processes for identifying, evaluating, and implementing VS-NFD changes that protect your company from regulatory surprises and minimize adaptation efforts.
- Establishment of a VS-NFD regulatory early warning system
- Development of structured impact analysis processes for VS-NFD changes
- Implementation of standardized VS-NFD change management procedures
- Integration of stakeholder management and communication for VS-NFD
Our Competencies in VS-NfD Implementierung
Choose the area that fits your requirements
Highly secure access control systems for VS-NFD compliant collective custody and nominee accounts. We implement solid Identity & Access Management solutions with multi-factor authentication and continuous monitoring.
Ensure permanent compliance with VS-NFD provisions through systematic monitoring and regular checks. We support you in implementing proactive monitoring systems.
Practical training programmes for handling classified information at the VS-NfD (Restricted) level. We provide your employees with the knowledge required for classification, marking, secure transmission and storage of classified documents in accordance with the German Classified Information Instruction (VSA) and the Security Clearance Act (SÜG).
Frequently Asked Questions about VS-NFD Ongoing Compliance
What does ongoing VS-NfD compliance involve for companies?
Ongoing VS-NfD compliance covers all measures a company must continuously implement to handle classified information at the VS-NfD (Nur für den Dienstgebrauch / For Official Use Only) level in a compliant manner. This includes regular employee training per the VS-NfD memorandum, maintaining security clearances (SÜG) for all personnel with access to classified materials, updating IT security concepts per BSI requirements, and preparing for classified information audits by the BMWK. Without ongoing compliance measures, companies risk losing their Geheimschutz status and the ability to participate in classified contracts.
What obligations do companies have under the Verschlusssachenanweisung (VSA)?
The Verschlusssachenanweisung (VSA) requires companies with access to VS-NfD material to implement comprehensive protective measures. These include physical security (secure storage, access controls, transport regulations), personnel security (security clearances under the SÜG, commitment declarations), classification and management of classified documents, and IT security (encrypted transmission, BSI-approved systems). Since the
2023 VSA revision, stricter requirements apply for digital processing of classified information.
How often must VS-NfD training be conducted?
All employees with access to VS-NfD classified information must receive an initial briefing per the VS-NfD memorandum (GHB Annex 4) and sign a commitment declaration before starting work. Regular refresher training is then required, typically at least annually in practice. All training must be documented and archived in an audit-ready manner. ADVISORI supports the design, delivery, and documentation of these training sessions.
What does the BMWK examine during a classified information audit?
During a Geheimschutz audit, the Federal Ministry for Economic Affairs and Climate Action (BMWK) or the responsible security authority examines whether the company fully meets the requirements of the Geheimschutzhandbuch (GHB) and the Verschlusssachenanweisung (VSA). Key audit areas include the organization of classified information protection (Geheimschutzbeauftragter), secure storage of classified materials, IT security measures, currency of security clearances, training records, and documentation of classified document inventory. ADVISORI prepares companies specifically for these audits.
What role does the BSI play in VS-NfD compliance?
The Federal Office for Information Security (BSI) defines technical requirements for processing VS-NfD information on IT systems. This includes approval of encryption products, specifications for VPN infrastructure, multi-factor authentication requirements, and review of IT security concepts. Companies must use exclusively BSI-approved or BSI-recommended solutions for digital processing of VS-NfD materials and demonstrate this as part of ongoing compliance.
What is the difference between physical and personnel security in classified information protection?
Physical security (materieller Geheimschutz) covers all technical and organizational measures for protecting classified materials: secure storage (e.g., steel cabinets, security rooms), access control systems, transport and destruction procedures, and IT security measures. Personnel security (personeller Geheimschutz) concerns the individuals who receive access to classified information: security clearances under the SÜG, commitment declarations, regular training, and monitoring of access authorizations. Both areas must be continuously maintained as part of ongoing VS-NfD compliance.
What are the consequences of violating VS-NfD regulations?
Violations of VS-NfD regulations can have severe consequences. At the corporate level, companies face withdrawal of their Geheimschutz status, which means exclusion from classified contracts. For individuals, criminal prosecution under sections
93 ff. of the German Criminal Code (treason, endangering external security) is possible, as even VS-NfD material can constitute a state secret. Additional risks include contractual penalties and reputational damage. Ongoing compliance measures with regular monitoring prevent such violations from occurring.
Success Stories
Discover how we support companies in their digital transformation
Digitalization in Steel Trading
Klöckner & Co
Digital Transformation in Steel Trading

Results
AI-Powered Manufacturing Optimization
Siemens
Smart Manufacturing Solutions for Maximum Value Creation

Results
AI Automation in Production
Festo
Intelligent Networking for Future-Proof Production Systems

Results
Generative AI in Manufacturing
Bosch
AI Process Optimization for Improved Production Efficiency

Results
Let's
Work Together!
Is your organization ready for the next step into the digital future? Contact us for a personal consultation.
Your strategic success starts here
Our clients trust our expertise in digital transformation, compliance, and risk management
Ready for the next step?
Schedule a strategic consultation with our experts now
30 Minutes • Non-binding • Immediately available
For optimal preparation of your strategy session:
Prefer direct contact?
Direct hotline for decision-makers
Strategic inquiries via email
Detailed Project Inquiry
For complex inquiries or if you want to provide specific information in advance