The defence sector opens up new growth opportunities for industrial and technology companies, but also presents new market entrants with specific regulatory requirements. In addition to procurement and pricing law, export controls and the law on the control of weapons of war, state secrecy and the establishment of the necessary security clearance capabilities may also be relevant to securing a contract. Particularly in the case of contracts involving classified information, the establishment of security clearance capabilities, security vetting in accordance with the Security Vetting Act (SÜG) and further organisational and technical security measures may be required. A confidentiality agreement or an established information security management (ISM) system alone is not sufficient.
Ready to talk?
Five key questions for affected businesses
Not every company that supplies the Bundeswehr or a defence contractor automatically requires a security organisation. Many stakeholders, particularly within the wider defence ecosystem, are unlikely ever to come into contact with government classified information. This applies, for example, to suppliers of standard products available on the open market, known as commercial-off-the-shelf (COTS) products (such as office equipment, standard tools or standard personal protective equipment), or to service providers who (such as canteen operations, grounds maintenance, building cleaning or general upkeep) outside classified areas.
The prerequisite in each case is that they neither receive classified information nor require access to classified areas, items or IT systems. Whilst contractual and/or statutory confidentiality, access or cybersecurity requirements may also apply to these companies, However, formal security clearance support is not automatically required. Rather, security clearance applies only to a narrower group within the defence sector: companies that, for a specific contract, require access to state-classified information or items, are required to generate or process such information or items themselves, or are required to pass them on to subcontractors.
For example, a product may be subject to export or arms control regulations without the associated information being classified. Conversely, design documents, system architectures, software, information on vulnerabilities or maintenance data may be protected as classified information, even though the contracted company itself does not manufacture defence equipment. Protection is therefore always determined by classification and access to information, not solely by the ‘Defence’ label.
The Federal Ministry for Economic Affairs and Energy (BMWE) supervises and monitors companies that receive such ‘classified contracts’. The key legal bases are, in particular, the Security Clearance Act (SÜG) and the Security Manual for Industry (GHB). Responsibility for implementing the necessary protective measures lies with the respective company.
Classified information is categorised as ‘VS – FOR OFFICIAL USE ONLY’ (VS-NfD), ‘VS – CONFIDENTIAL’, ‘SECRET’ or ‘TOP SECRET’, depending on the level of protection required. The specific requirements that arise from this depend on whether information is (to be) processed within the contractor’s own organisation, exclusively at the client’s premises, or via the contractor’s own IT systems. The classification and the resulting requirements must be disclosed by the client and incorporated into the contractual relationship.
In the case of VS-NfD, this is done by incorporating the VS-NfD information sheet into the contract (see below). For higher levels of classification, incorporation takes place via the specific classified information contract and, where applicable, through security advisory support provided by the BMWE. However, security obligations may also come into effect earlier, provided that access to classified information is already possible during a tender process or negotiations.
For many companies entering the defence sector, ‘VS-NfD’ in particular is likely to be their first practical encounter with security. The key requirements are set out in the ‘VS-NfD’ information sheet in Annex 4 to the GHB. Among other things, it governs responsibilities, access, labelling, storage, disclosure, destruction, IT processing and working from home. Its provisions are generally incorporated into the contract between the VS-NfD client and the contractor. The specific requirements of the contract must be clarified between both parties.
For VS-VERTRAULICH or higher classifications, formal security management, personnel security vetting and further organisational, physical and technical measures are usually required. Depending on the processing model, the following may be required in particular:
- a security officer (SiBe), including a deputy,
- security-vetted and authorised personnel,
- authorisation and ‘need-to-know’ processes,
- security briefings and reporting procedures,
- a classified information management system,
- controlled premises and suitable storage facilities,
- approved IT systems and transmission channels,
- controlled involvement of subcontractors.
The SiBe coordinates implementation and must report directly to senior management. Senior management remains responsible for ensuring effective organisation and adequate resources.
When building up their security capabilities, organisations often do not start from scratch. Existing structures for data protection, information security, emergency management, authorisation management, access control and supplier vetting provide important starting points. However, some of these pursue different protection objectives: whilst data protection and the protection of trade secrets safeguard personal or company-specific confidential information, information security and cyber security focus on the confidentiality, integrity and availability of information and systems.
By contrast, state secrecy protection applies to information and items that have been classified as classified information by an official body or at its instigation, and imposes specific requirements in this regard. Existing security and compliance processes can therefore often serve as a starting point, but they do not replace either the required (state) security vetting or the specific organisational, physical and technical requirements of state secrecy.
At the same time, the other regulatory frameworks – including those with a defence-related context – may remain applicable in parallel. Particularly in the case of dual-use and COTS products, in addition to the General Data Protection Regulation (GDPR), for example, the BSI Act (BSIG), the Cyber Resilience Act (CRA), the AI Regulation (AI-VO) or the Data Act (DA) – may impose additional requirements. Tensions arise in particular when statutory reporting, documentation or disclosure obligations could allow inferences to be drawn about military systems, vulnerabilities or capabilities. Capital markets communication and investor relations must also ensure that neither classified information nor other protected information is disclosed. Companies therefore require coordinated clearance and escalation processes between Security and Protection, Legal, IT Security, Data Protection, Compliance and Corporate Communications.
Establishing a system of security protection typically extends into various areas of the organisation, such as HR, IT, facilities management, procurement, legal and compliance. Security vetting, premises planning and technical approvals can require considerable lead time. Challenges may arise in particular from long processing times, queries regarding documentation, international connections or responsibilities that have not yet been fully clarified.
Focus on security: Companies should clarify these 5 questions when assessing a business opportunity
- Are classified information and security classifications involved? And if so, which ones?
- Which individuals, locations and systems are required?
- Which requirements must be in place during the tendering process, and which only when the contract is being executed?
- Which subcontractors or group companies will be involved?
- What interim solutions are available if checks or approvals are still pending?
Acquisitions, carve-outs, relocations and new cloud or shared-service models may also necessitate a reassessment. The Security Officer should therefore be involved at an early stage in major transactions and transformation projects.
Security requirements are changing the business model
Classified information security affects a smaller group of companies whose specific contracts require access to classified information – for these companies, it transforms large parts of their business model.
Our experts help companies to determine the relevant security requirements, assess existing structures and develop a realistic roadmap for establishing and maintaining the necessary security capabilities.
Interested in our services?
More KPMG Insights
Your contacts
Barbara Scheben
Partner, Audit, Regulatory Advisory, Head of Forensic, Head of Data Protection
KPMG AG Wirtschaftsprüfungsgesellschaft
- Item 2
- Item 1