Jurisdiction
National rules apply where your entity and operations are located.
European Defence Compliance
European defence security requirements are not defined by one certification. They combine cybersecurity, classified-information protection, quality assurance, product security, export controls and customer-specific contractual obligations. I work out which of them actually apply to your company.
Framework applicability depends on jurisdiction, contract, classification level and product scope. This content is informational and not legal advice.
01 — Applicability
There is no European equivalent to CMMC. Instead of one certification, I work out which layers apply to your organisation at once — and which do not.
National rules apply where your entity and operations are located.
Defence ministries, primes, NATO and EU programmes can impose contractual controls.
National classified information, NATO classified information and EUCI require additional safeguards.
Defence-only, dual-use and commercial digital products can have different regulatory treatment.
Requirements commonly flow down to suppliers and subcontractors.
Hosting, remote support, source code and technical data may trigger export-control and data-transfer requirements.
02 — Overview
None of these frameworks applies automatically to every company. The overview below sets out what triggers applicability in each case.
| Framework | Category | When it matters | Focus | Driver |
|---|---|---|---|---|
| ISO/IEC 27001 | Information security management | Foundational baseline for most defence suppliers and frequently requested by customers. | ISMS governance, risk management, access control, supplier security, incident response and continuous improvement. | Core baseline |
| NATO AQAP | Defence quality assurance | NATO procurement or contracts that include AQAP requirements through a customer or prime contractor. | Design and production assurance, configuration control, traceability, supplier assurance and quality records. | Contract-driven |
| NATO classified-information requirements | Industrial and classified security | Contracts involving NATO classified information. | Personnel and facility security, need-to-know, secure environments, secure communications and subcontractor controls. | Classification-driven |
| EU Classified Information (EUCI) | EU programme security | EU institutional contracts and defence programmes, including European Defence Fund activities where security requirements apply. | Handling of EU classified information, programme-specific security instructions, personnel, physical and information security. | Programme-driven |
| NIS2 and national implementation | Cybersecurity regulation | Depends on national implementation, entity type, activities and applicable defence/national-security exemptions. | Cyber-risk management, governance accountability, supply-chain security, incident handling and resilience. | Jurisdiction-driven |
| EU Cyber Resilience Act (CRA) | Product cybersecurity | Digital hardware or software products placed on the EU market; assess defence-only exclusions separately from dual-use/commercial products. | Secure-by-design products, vulnerability management, support lifecycle, technical documentation and incident/vulnerability reporting. | Product-driven |
| GDPR | Data protection | Personal data in workforce, supplier, customer, telemetry, testing and operational processes. | Personal-data processing, privacy-by-design, processor management, breach handling and international transfers. | Cross-cutting |
| Export controls and sanctions | Controlled technology and trade compliance | Cross-border transfer of controlled goods, software, source code, cryptography, technical data, remote support and know-how. | Classification, licensing, end-use/end-user checks, sanctions screening and controlled technical-data transfers. | Cross-border |
03 — Germany
A detailed German security baseline that can complement ISO 27001 through structured security concepts, protection-need assessment and risk treatment.
Work involving VS-NUR FÜR DEN DIENSTGEBRAUCH may require controlled handling processes, need-to-know access, secure IT environments and contractual requirements that flow to subcontractors.
German defence work can involve personnel, physical, organisational and information-security requirements under national industrial-security arrangements.
The applicable conditions must be confirmed with the contracting authority and competent national authority before classified information is handled.
04 — Approach
An effective defence compliance programme maps each requirement to a contract, system boundary, control owner and auditable evidence record.
05 — Baseline
Controls become more stringent when classified information, restricted programmes, critical systems or cross-border controlled technology are involved.
06 — Contact
I build you a clear view of applicable frameworks, contractual obligations, control ownership and evidence across your organisation and supply chain. Write to me in English or German.