Solid Documentation for Secure VS-NFD Compliance

VS-NfD Documentation & Security Concept

Comprehensive documentation and a well-conceived security concept are essential for successful VS-NFD implementation. We develop customized concepts with you that meet regulatory requirements while ensuring operational security.

  • Complete fulfillment of all VS-NFD documentation requirements
  • Solid IT security concepts for confidential reporting data
  • Practical procedure documentation for sustainable implementation
  • Continuous updates for changing requirements

Your strategic success starts here

Our clients trust our expertise in digital transformation, compliance, and risk management

30 Minutes • Non-binding • Immediately available

For optimal preparation of your strategy session:

  • Your strategic goals and objectives
  • Desired business outcomes and ROI
  • Steps already taken

Or contact us directly:

Certifications, Partners and more...

ISO 9001 CertifiedISO 27001 CertifiedISO 14001 CertifiedBeyondTrust PartnerBVMW Bundesverband MitgliedMitigant PartnerGoogle PartnerTop 100 InnovatorMicrosoft AzureAmazon Web Services

What Does a VS-NfD Security Concept Include?

Why ADVISORI for Your VS-NfD Security Concept?

  • Hands-on experience with VS-NfD projects at classified-information-handling companies and government agencies
  • Current knowledge of requirements: VSA, GHB, BSI CON.11.1, self-accreditation
  • Holistic approach: IT security, classified information protection, and documentation from one source
  • ISO 27001 & ISO 9001 certified — proven competence in information security

Important: Self-Accreditation Mandatory Since 01.09.2025

Companies handling classified information must self-accredit their VS-NfD IT systems since September 1, 2025. The VS-NfD officer must confirm in writing to management every three years that all requirements of the VS-NfD memorandum are fully implemented.

ADVISORI in Numbers

11+

Years of Experience

120+

Employees

520+

Projects

In five structured steps, we develop a VS-NfD security concept that meets BSI, VSA, and Classified Information Handbook requirements while securing your self-accreditation.

Our Approach:

Assessment: Analysis of your IT systems, facilities, and processes against the VS-NfD memorandum

Gap Analysis: Identifying deviations from BSI IT-Grundschutz and VSA requirements

Concept Development: Documenting all security measures in the concept per CON.11.1

Implementation Support: Deploying technical and organizational measures

Accreditation: Preparing self-accreditation and documentation for contracting authorities

"Well-conceived documentation and a solid security concept are the foundation of successful VS-NFD implementation. With our expertise, we create the basis for sustainable compliance success."
Sarah Richter

Sarah Richter

Head of Information Security, Cyber Security

Expertise & Experience:

10+ years of experience, CISA, CISM, Lead Auditor, DORA, NIS2, BCM, Cyber and Information Security

Our Services

We offer you tailored solutions for your digital transformation

Complete Procedure Documentation

We create comprehensive documentation of all VS-NFD-relevant procedures that meets regulatory requirements while ensuring practical applicability.

  • Structured documentation of all VS-NFD processes and procedures
  • Clear description of roles, responsibilities, and workflows
  • Practical work instructions and checklists
  • Version control and systematic change management

IT Security Concept and Data Protection

We develop solid security concepts for VS-NFD systems and data that meet the highest security standards while enabling operational efficiency.

  • Comprehensive IT security architecture for VS-NFD systems
  • Data protection concepts and confidentiality measures
  • Emergency and business continuity planning
  • Continuous monitoring and updating of security measures

Our Competencies in VS-NFD Readiness

Choose the area that fits your requirements

VS-NFD Define Roles & Responsibilities

Successful implementation of VS-NFD requirements requires precise definition of roles and responsibilities. We support you in developing an optimal organizational structure for sustainable regulatory reporting.

VS-NfD Classification and Marking of Classified Information

Proper classification and marking of classified information is a critical building block of information security. We support you in implementing solid classification systems and compliant handling of confidential information.

Frequently Asked Questions about VS-NfD Documentation & Security Concept

What must a VS-NfD security concept include?

A VS-NfD security concept per the VS-NfD memorandum (Annex

4 to the Classified Information Handbook) must document all technical and organizational measures that ensure the protection of classified information at the VS-NfD level.The concept covers three core areas:1. Physical Security: Access controls, security zones, secure storage in steel cabinets or security rooms2. Personnel Security: Security clearance checks per the Security Clearance Act (SÜG), commitment declarations, classified information briefings3. IT and Information Security: Use of BSI-approved IT systems, hard drive encryption, access control, logging, and network segmentationFor networked IT systems (compound systems), an additional information security concept per BSI IT-Grundschutz is required, documenting all communication relationships. ADVISORI creates this concept to be both audit-proof and practical.

What does VS-NfD self-accreditation mean since September 2025?

Since September 1, 2025, self-accreditation is mandatory for all companies handling classified information that process VS-NfD on IT systems. The VS-NfD officer must confirm in writing to management every three years that all VS-NfD memorandum requirements are fully implemented.The confirmation covers three areas:- Implementation of all IT requirements from the memorandum- Compliance with operating conditions for BSI-approved IT security products- Evidence of an ISMS through BSI IT-Grundschutz (with IT-Grundschutz check, risk analysis, and implementation plan) or ISO 27001 certificationThis confirmation must be presented to the VS-NfD contracting authority or the BMWK upon request. ADVISORI guides you through the entire accreditation process.

What IT requirements does the VS-NfD memorandum impose on companies?

The VS-NfD memorandum distinguishes between technically isolated IT systems and networked compound systems:Isolated Systems (Air-Gapped):- Restrictive user permissions and role-based access- Prohibition of wireless interfaces (WiFi, Bluetooth)- BSI-approved hard drive encryption- No private software or storage mediaNetworked Systems (Compound Systems):- Project-specific access controls- Physical securing of central components- Information security concept per BSI IT-Grundschutz- Documentation of all communication relationships- Encryption with BSI-approved productsAdditionally, all systems must meet requirements for data backup, controlled data destruction, and logging. ADVISORI documents these requirements in your individual security concept.

How does a VS-NfD security concept differ from BSI IT-Grundschutz?

BSI IT-Grundschutz and the VS-NfD security concept complement each other but are not identical:BSI IT-Grundschutz is a general information security framework with building blocks, threats, and measures. It provides the methodological foundation.The VS-NfD security concept builds on this but adds specific requirements:- Specific provisions from the Classified Information Directive (VSA)- Requirements from the Classified Information Handbook (GHB)- Mandatory use of BSI-approved products (not just recommended ones)- Personnel security clearances per the Security Clearance Act (SÜG)- BSI building block CON.11.1 'Classified Information Protection VS-NfD' specifies the requirementsFor compound systems, the VS-NfD memorandum requires at least the basic requirements of BSI IT-Grundschutz. An ISO 27001 certification based on IT-Grundschutz can facilitate self-accreditation.

Who needs a VS-NfD security concept?

A VS-NfD security concept is required by all organizations that work with classified information at the VS-NfD level (For Official Use Only):- Companies handling classified information: Suppliers to the Bundeswehr and defense industry with access to VS-NfD information- Government agencies: Federal, state, and municipal institutions that create or process VS-NfD- Critical infrastructure operators: KRITIS operators with access to classified information- IT service providers: Companies that provide or operate IT systems for processing VS-NfDThe obligation stems from the Classified Information Directive (VSA) and the Classified Information Handbook (GHB). Without a valid security concept and successful self-accreditation, companies may not process VS-NfD on IT systems since September 2025.

How long does it take to create a VS-NfD security concept?

The duration depends on the complexity of your IT landscape and the maturity of your existing security measures:- Small companies with isolated IT systems: 4–8 weeks- Medium companies with compound systems: 8–16 weeks- Large organizations with complex IT infrastructure: 3–6 monthsThe main factors affecting duration:1. Number and complexity of VS-NfD-processing IT systems2. Existence of an ISMS (ISO 27001 or BSI IT-Grundschutz)3. Status of physical and personnel security measures4. Availability of required BSI-approved productsADVISORI accelerates the process through proven templates and structured methodologies. If an ISMS is already in place, the VS-NfD-specific security concept can be completed in significantly less time.

What role does BSI building block CON.11.1 play for the VS-NfD security concept?

BSI building block CON.11.1 'Classified Information Protection VS-NUR FÜR DEN DIENSTGEBRAUCH (VS-NfD)' is the central reference module for VS-NfD security concepts in the IT-Grundschutz Compendium.It defines:- Basic requirements: Minimum measures for every VS-NfD workstation, including awareness training, access control, and document management- Standard requirements: Extended measures such as logging, contingency planning, and regular reviews- Enhanced requirements: Additional measures for particularly sensitive environmentsThe building block supports classified information officers in systematically implementing VSA requirements for electronic processing of VS-NfD. It bridges the gap between general IT-Grundschutz and specific VS-NfD requirements.ADVISORI uses CON.11.1 as the foundation for structuring your security concept and ensures that all basic, standard, and enhanced requirements are addressed.

Success Stories

Discover how we support companies in their digital transformation

Digitalization in Steel Trading

Klöckner & Co

Digital Transformation in Steel Trading

Case Study
Digitalisierung im Stahlhandel - Klöckner & Co

Results

Over 2 billion euros in annual revenue through digital channels
Goal to achieve 60% of revenue online by 2022
Improved customer satisfaction through automated processes

AI-Powered Manufacturing Optimization

Siemens

Smart Manufacturing Solutions for Maximum Value Creation

Case Study
Case study image for AI-Powered Manufacturing Optimization

Results

Significant increase in production performance
Reduction of downtime and production costs
Improved sustainability through more efficient resource utilization

AI Automation in Production

Festo

Intelligent Networking for Future-Proof Production Systems

Case Study
FESTO AI Case Study

Results

Improved production speed and flexibility
Reduced manufacturing costs through more efficient resource utilization
Increased customer satisfaction through personalized products

Generative AI in Manufacturing

Bosch

AI Process Optimization for Improved Production Efficiency

Case Study
BOSCH KI-Prozessoptimierung für bessere Produktionseffizienz

Results

Reduction of AI application implementation time to just a few weeks
Improvement in product quality through early defect detection
Increased manufacturing efficiency through reduced downtime

Let's

Work Together!

Is your organization ready for the next step into the digital future? Contact us for a personal consultation.

Your strategic success starts here

Our clients trust our expertise in digital transformation, compliance, and risk management

Ready for the next step?

Schedule a strategic consultation with our experts now

30 Minutes • Non-binding • Immediately available

For optimal preparation of your strategy session:

Your strategic goals and challenges
Desired business outcomes and ROI expectations
Current compliance and risk situation
Stakeholders and decision-makers in the project

Prefer direct contact?

Direct hotline for decision-makers

Strategic inquiries via email

Detailed Project Inquiry

For complex inquiries or if you want to provide specific information in advance