We come from this environment: our engineers are VS-NfD-briefed and have project experience in classified environments of the defence sector – from architecting and piloting an SD-WAN landscape for a group in the sector to taking an application delivery platform into regular operation, including knowledge transfer to the internal team. What we learned there is less about the technology than about how it is handled: documented changes, traceable access, no shortcuts.
The second question is where your data sits. We run our systems on our own infrastructure in Germany – our own server park, our own IP address space, right down to self-hosted language models. In a sector where technical documentation leaving the country can itself be an export event, that is not a marketing point. Contracts on an EVB-IT basis are routine for us; as a specialist partner we also work as a subcontractor within existing lots.
What matters for Defence Industry
- B-03Network & ConnectivityDevelopment network, production, test benches, and office belong in separate zones with controlled transitions – and wherever classified data is processed, in a separation an auditor can follow. We plan and operate segmented networks and secure site interconnects.
- B-04Cyber Security & ProtectionDesign and manufacturing documentation is the real target in this sector, and the way in is rarely the front door: it is the supplier, the machine builder's remote maintenance, the neglected VPN access. We harden the perimeter, control access with a second factor, and run monitoring that flags anomalies before they become exfiltration.
- B-09Regulation & ComplianceWe first establish what actually applies to you – NIS-2 exposure under the BSI Act, requirements contractually passed down by your customers, ISO 27001 as an evidence framework – and then close the gaps technically. On classified-information protection we state our limit plainly: we are VS-NfD-briefed, we are not a company under formal Geheimschutz supervision. Where your contract demands more, we say so up front.
- B-06Business Continuity & ResilienceA delivery delay in this sector is rarely just a commercial problem. Veeam-based immutable backups to geo-redundant targets of our own, tested recovery, and a rehearsed emergency plan keep an incident from toppling your deadlines.
- B-11Sovereign AIAI tools are already in the building in this sector too – the question is where the prompts go. We run language models on our own hardware in Germany so technical documentation never leaves the house, and we clarify beforehand which use case actually justifies it.
Classified protection, export control, NIS-2: three regimes that do not overlap
Three strands of requirements meet in the defence industry, and they are easily confused. Classified-information protection governs how Verschlusssachen are handled and depends on your contract and your supervision by the responsible ministry – VS-NfD is the lowest tier and the only one that works without a formal security clearance. Export control under German foreign trade law and the EU Dual-Use Regulation covers not only goods but technical documentation: a design data set landing on a server outside the EU can be a licensable event. And NIS-2 has applied since December 2025 independently of both, once you reach the thresholds. We separate these with you before touching any technology – and we say honestly which part needs advice from a Geheimschutz officer rather than from us.