VS-NfD Documentation & Security Concept
Comprehensive documentation and a well-conceived security concept are essential for successful VS-NFD implementation. We develop customized concepts with you that meet regulatory requirements while ensuring operational security.
- ✓Complete fulfillment of all VS-NFD documentation requirements
- ✓Solid IT security concepts for confidential reporting data
- ✓Practical procedure documentation for sustainable implementation
- ✓Continuous updates for changing requirements
Your strategic success starts here
Our clients trust our expertise in digital transformation, compliance, and risk management
30 Minutes • Non-binding • Immediately available
For optimal preparation of your strategy session:
- Your strategic goals and objectives
- Desired business outcomes and ROI
- Steps already taken
Or contact us directly:
Certifications, Partners and more...










What Does a VS-NfD Security Concept Include?
Why ADVISORI for Your VS-NfD Security Concept?
- Hands-on experience with VS-NfD projects at classified-information-handling companies and government agencies
- Current knowledge of requirements: VSA, GHB, BSI CON.11.1, self-accreditation
- Holistic approach: IT security, classified information protection, and documentation from one source
- ISO 27001 & ISO 9001 certified — proven competence in information security
Important: Self-Accreditation Mandatory Since 01.09.2025
Companies handling classified information must self-accredit their VS-NfD IT systems since September 1, 2025. The VS-NfD officer must confirm in writing to management every three years that all requirements of the VS-NfD memorandum are fully implemented.
ADVISORI in Numbers
11+
Years of Experience
120+
Employees
520+
Projects
In five structured steps, we develop a VS-NfD security concept that meets BSI, VSA, and Classified Information Handbook requirements while securing your self-accreditation.
Our Approach:
Assessment: Analysis of your IT systems, facilities, and processes against the VS-NfD memorandum
Gap Analysis: Identifying deviations from BSI IT-Grundschutz and VSA requirements
Concept Development: Documenting all security measures in the concept per CON.11.1
Implementation Support: Deploying technical and organizational measures
Accreditation: Preparing self-accreditation and documentation for contracting authorities
"Well-conceived documentation and a solid security concept are the foundation of successful VS-NFD implementation. With our expertise, we create the basis for sustainable compliance success."

Sarah Richter
Head of Information Security, Cyber Security
Expertise & Experience:
10+ years of experience, CISA, CISM, Lead Auditor, DORA, NIS2, BCM, Cyber and Information Security
Our Services
We offer you tailored solutions for your digital transformation
Complete Procedure Documentation
We create comprehensive documentation of all VS-NFD-relevant procedures that meets regulatory requirements while ensuring practical applicability.
- Structured documentation of all VS-NFD processes and procedures
- Clear description of roles, responsibilities, and workflows
- Practical work instructions and checklists
- Version control and systematic change management
IT Security Concept and Data Protection
We develop solid security concepts for VS-NFD systems and data that meet the highest security standards while enabling operational efficiency.
- Comprehensive IT security architecture for VS-NFD systems
- Data protection concepts and confidentiality measures
- Emergency and business continuity planning
- Continuous monitoring and updating of security measures
Our Competencies in VS-NFD Readiness
Choose the area that fits your requirements
Successful implementation of VS-NFD requirements requires precise definition of roles and responsibilities. We support you in developing an optimal organizational structure for sustainable regulatory reporting.
Proper classification and marking of classified information is a critical building block of information security. We support you in implementing solid classification systems and compliant handling of confidential information.
Frequently Asked Questions about VS-NfD Documentation & Security Concept
What must a VS-NfD security concept include?
A VS-NfD security concept per the VS-NfD memorandum (Annex
4 to the Classified Information Handbook) must document all technical and organizational measures that ensure the protection of classified information at the VS-NfD level.The concept covers three core areas:1. Physical Security: Access controls, security zones, secure storage in steel cabinets or security rooms2. Personnel Security: Security clearance checks per the Security Clearance Act (SÜG), commitment declarations, classified information briefings3. IT and Information Security: Use of BSI-approved IT systems, hard drive encryption, access control, logging, and network segmentationFor networked IT systems (compound systems), an additional information security concept per BSI IT-Grundschutz is required, documenting all communication relationships. ADVISORI creates this concept to be both audit-proof and practical.
What does VS-NfD self-accreditation mean since September 2025?
Since September 1, 2025, self-accreditation is mandatory for all companies handling classified information that process VS-NfD on IT systems. The VS-NfD officer must confirm in writing to management every three years that all VS-NfD memorandum requirements are fully implemented.The confirmation covers three areas:- Implementation of all IT requirements from the memorandum- Compliance with operating conditions for BSI-approved IT security products- Evidence of an ISMS through BSI IT-Grundschutz (with IT-Grundschutz check, risk analysis, and implementation plan) or ISO 27001 certificationThis confirmation must be presented to the VS-NfD contracting authority or the BMWK upon request. ADVISORI guides you through the entire accreditation process.
What IT requirements does the VS-NfD memorandum impose on companies?
The VS-NfD memorandum distinguishes between technically isolated IT systems and networked compound systems:Isolated Systems (Air-Gapped):- Restrictive user permissions and role-based access- Prohibition of wireless interfaces (WiFi, Bluetooth)- BSI-approved hard drive encryption- No private software or storage mediaNetworked Systems (Compound Systems):- Project-specific access controls- Physical securing of central components- Information security concept per BSI IT-Grundschutz- Documentation of all communication relationships- Encryption with BSI-approved productsAdditionally, all systems must meet requirements for data backup, controlled data destruction, and logging. ADVISORI documents these requirements in your individual security concept.
How does a VS-NfD security concept differ from BSI IT-Grundschutz?
BSI IT-Grundschutz and the VS-NfD security concept complement each other but are not identical:BSI IT-Grundschutz is a general information security framework with building blocks, threats, and measures. It provides the methodological foundation.The VS-NfD security concept builds on this but adds specific requirements:- Specific provisions from the Classified Information Directive (VSA)- Requirements from the Classified Information Handbook (GHB)- Mandatory use of BSI-approved products (not just recommended ones)- Personnel security clearances per the Security Clearance Act (SÜG)- BSI building block CON.11.1 'Classified Information Protection VS-NfD' specifies the requirementsFor compound systems, the VS-NfD memorandum requires at least the basic requirements of BSI IT-Grundschutz. An ISO 27001 certification based on IT-Grundschutz can facilitate self-accreditation.
Who needs a VS-NfD security concept?
A VS-NfD security concept is required by all organizations that work with classified information at the VS-NfD level (For Official Use Only):- Companies handling classified information: Suppliers to the Bundeswehr and defense industry with access to VS-NfD information- Government agencies: Federal, state, and municipal institutions that create or process VS-NfD- Critical infrastructure operators: KRITIS operators with access to classified information- IT service providers: Companies that provide or operate IT systems for processing VS-NfDThe obligation stems from the Classified Information Directive (VSA) and the Classified Information Handbook (GHB). Without a valid security concept and successful self-accreditation, companies may not process VS-NfD on IT systems since September 2025.
How long does it take to create a VS-NfD security concept?
The duration depends on the complexity of your IT landscape and the maturity of your existing security measures:- Small companies with isolated IT systems: 4–8 weeks- Medium companies with compound systems: 8–16 weeks- Large organizations with complex IT infrastructure: 3–6 monthsThe main factors affecting duration:1. Number and complexity of VS-NfD-processing IT systems2. Existence of an ISMS (ISO 27001 or BSI IT-Grundschutz)3. Status of physical and personnel security measures4. Availability of required BSI-approved productsADVISORI accelerates the process through proven templates and structured methodologies. If an ISMS is already in place, the VS-NfD-specific security concept can be completed in significantly less time.
What role does BSI building block CON.11.1 play for the VS-NfD security concept?
BSI building block CON.11.1 'Classified Information Protection VS-NUR FÜR DEN DIENSTGEBRAUCH (VS-NfD)' is the central reference module for VS-NfD security concepts in the IT-Grundschutz Compendium.It defines:- Basic requirements: Minimum measures for every VS-NfD workstation, including awareness training, access control, and document management- Standard requirements: Extended measures such as logging, contingency planning, and regular reviews- Enhanced requirements: Additional measures for particularly sensitive environmentsThe building block supports classified information officers in systematically implementing VSA requirements for electronic processing of VS-NfD. It bridges the gap between general IT-Grundschutz and specific VS-NfD requirements.ADVISORI uses CON.11.1 as the foundation for structuring your security concept and ensures that all basic, standard, and enhanced requirements are addressed.
Success Stories
Discover how we support companies in their digital transformation
Digitalization in Steel Trading
Klöckner & Co
Digital Transformation in Steel Trading

Results
AI-Powered Manufacturing Optimization
Siemens
Smart Manufacturing Solutions for Maximum Value Creation

Results
AI Automation in Production
Festo
Intelligent Networking for Future-Proof Production Systems

Results
Generative AI in Manufacturing
Bosch
AI Process Optimization for Improved Production Efficiency

Results
Let's
Work Together!
Is your organization ready for the next step into the digital future? Contact us for a personal consultation.
Your strategic success starts here
Our clients trust our expertise in digital transformation, compliance, and risk management
Ready for the next step?
Schedule a strategic consultation with our experts now
30 Minutes • Non-binding • Immediately available
For optimal preparation of your strategy session:
Prefer direct contact?
Direct hotline for decision-makers
Strategic inquiries via email
Detailed Project Inquiry
For complex inquiries or if you want to provide specific information in advance