European Defence Compliance

Security frameworks for defence companies in Europe

European defence security requirements are not defined by one certification. They combine cybersecurity, classified-information protection, quality assurance, product security, export controls and customer-specific contractual obligations. I work out which of them actually apply to your company.

Framework applicability depends on jurisdiction, contract, classification level and product scope. This content is informational and not legal advice.

01 — Applicability

A layered requirement model

There is no European equivalent to CMMC. Instead of one certification, I work out which layers apply to your organisation at once — and which do not.

01

Jurisdiction

National rules apply where your entity and operations are located.

02

Customer and contract

Defence ministries, primes, NATO and EU programmes can impose contractual controls.

03

Classification

National classified information, NATO classified information and EUCI require additional safeguards.

04

Product route

Defence-only, dual-use and commercial digital products can have different regulatory treatment.

05

Supply chain

Requirements commonly flow down to suppliers and subcontractors.

06

Cross-border delivery

Hosting, remote support, source code and technical data may trigger export-control and data-transfer requirements.

02 — Overview

Frameworks at a glance

None of these frameworks applies automatically to every company. The overview below sets out what triggers applicability in each case.

Framework Category When it matters Focus Driver
ISO/IEC 27001 Information security management Foundational baseline for most defence suppliers and frequently requested by customers. ISMS governance, risk management, access control, supplier security, incident response and continuous improvement. Core baseline
NATO AQAP Defence quality assurance NATO procurement or contracts that include AQAP requirements through a customer or prime contractor. Design and production assurance, configuration control, traceability, supplier assurance and quality records. Contract-driven
NATO classified-information requirements Industrial and classified security Contracts involving NATO classified information. Personnel and facility security, need-to-know, secure environments, secure communications and subcontractor controls. Classification-driven
EU Classified Information (EUCI) EU programme security EU institutional contracts and defence programmes, including European Defence Fund activities where security requirements apply. Handling of EU classified information, programme-specific security instructions, personnel, physical and information security. Programme-driven
NIS2 and national implementation Cybersecurity regulation Depends on national implementation, entity type, activities and applicable defence/national-security exemptions. Cyber-risk management, governance accountability, supply-chain security, incident handling and resilience. Jurisdiction-driven
EU Cyber Resilience Act (CRA) Product cybersecurity Digital hardware or software products placed on the EU market; assess defence-only exclusions separately from dual-use/commercial products. Secure-by-design products, vulnerability management, support lifecycle, technical documentation and incident/vulnerability reporting. Product-driven
GDPR Data protection Personal data in workforce, supplier, customer, telemetry, testing and operational processes. Personal-data processing, privacy-by-design, processor management, breach handling and international transfers. Cross-cutting
Export controls and sanctions Controlled technology and trade compliance Cross-border transfer of controlled goods, software, source code, cryptography, technical data, remote support and know-how. Classification, licensing, end-use/end-user checks, sanctions screening and controlled technical-data transfers. Cross-border

03 — Germany

Germany: additional requirements

Germany
  • BSI IT-Grundschutz

    A detailed German security baseline that can complement ISO 27001 through structured security concepts, protection-need assessment and risk treatment.

  • VS-NfD

    Work involving VS-NUR FÜR DEN DIENSTGEBRAUCH may require controlled handling processes, need-to-know access, secure IT environments and contractual requirements that flow to subcontractors.

  • Industrial security

    German defence work can involve personnel, physical, organisational and information-security requirements under national industrial-security arrangements.

The applicable conditions must be confirmed with the contracting authority and competent national authority before classified information is handled.

04 — Approach

How requirements are determined

  1. Identify your organisation and operating countries.
  2. Review customer, contract and programme obligations.
  3. Determine classification regime and handling requirements.
  4. Categorise products as defence-only, dual-use or commercial.
  5. Assess supply-chain, hosting and cross-border delivery exposure.
  6. Map applicable controls, evidence and remediation actions.

An effective defence compliance programme maps each requirement to a contract, system boundary, control owner and auditable evidence record.

05 — Baseline

What a practical baseline looks like

Organisation and technology

  • Governance and ISMS.
  • Asset and information classification.
  • Identity, endpoint and network security.
  • Secure software development and configuration control.
  • Vulnerability management and incident response.

Supply chain and evidence

  • Supplier and subcontractor assurance.
  • Business continuity and resilience.
  • Quality assurance and engineering traceability.
  • Classified-information handling where required.
  • Export-control and privacy governance.

Controls become more stringent when classified information, restricted programmes, critical systems or cross-border controlled technology are involved.

06 — Contact

Turn complex defence requirements into an auditable control programme.

I build you a clear view of applicable frameworks, contractual obligations, control ownership and evidence across your organisation and supply chain. Write to me in English or German.