Becoming a supplier to the defense and armament industry means satisfying laws, standards and customer requirements at the same time — from personnel security clearance through CADIS® and AQAP to the NCAGE code. As a market entry consulting partner for the defense industry, CONSUVATION gives you the complete standards overview and compliance map, and guides you through to contract readiness.
Market access to the defense and armament industry does not depend on a single certification — it depends on the interplay of three layers.
KWKG, AWG/AWV, SÜG, the Confidentiality Protection Manual, VSVgV, NIS-2, GDPR and further national and European legal bases.
The AQAP series, ISO 9001, EN 9100/AS9100, TISAX, CADIS®, ISO 27001, IEC 62443 and the NCAGE code as technical prerequisites.
BAAINBw procurement conditions, systems-integrator supplier manuals, company security clearance and personnel vetting.
Every analysis we deliver draws a clear line between what is legally or contractually binding and what the market simply expects.
Binding under law, regulation, or contract. Failure to comply results in exclusion from the tender or in legal consequences — e.g. personnel security clearance, the NCAGE code, ISO 9001.
No direct legal basis, but a market standard or precondition for being listed as a supplier to systems integrators — e.g. AQAP 2110, EN 9100, TISAX, CADIS®.
A selection of the central legal bases for suppliers in the defense and armament sector.
Licensing requirement for manufacturing, transport, acquisition and transfer of war weapons.
Governs the security vetting of individuals with access to classified information.
Organizational, personnel, and physical confidentiality protection in industry — a precondition for classified contracts.
Special procurement law for supply, construction, and services in the defense and security sector.
Risk management, reporting duties, and management liability — in force since 06.12.2025 with no grace period; often directly relevant for manufacturing operations.
Extraterritorial US export control where US technology content is present in the supply chain.
Management-system and industry-specific standards that determine bid eligibility and listing with systems integrators.
NATO quality assurance for design, development and production — a frequent explicit contract requirement of BAAINBw.
QMS for aerospace and defense, extending ISO 9001 with configuration management and traceability requirements.
Industry-specific information security standard for the defense industry. CONSUVATION is an official DEKRA-authorized consulting partner.
Increasingly required by defense systems integrators with a vehicle connection. CONSUVATION advises and prepares — not a DEKRA assessment partner for TISAX.
ISMS certification, frequently contractually required for access to customer networks and program data.
Unique supplier identification — without an NCAGE code, bidding in the NATO procurement environment is generally not possible.
Public procuring authorities and systems integrators add further, sometimes company-specific requirements.
Special contract conditions for direct suppliers to Germany's Federal Office for Bundeswehr Equipment, IT and In-Service Support.
Company-specific quality and security requirements from Rheinmetall, KNDS, Diehl, Hensoldt, Airbus D&S and others.
Confirms a company's suitability to handle classified information — a formal precondition for classified contracts.
Individual vetting required before access to classified information or security-sensitive areas.
Due-diligence evidence for tin, tantalum, tungsten and gold — especially required where there is a US customer link.
NIS-2-obligated customers must assess supply-chain cybersecurity and contractually pass minimum requirements down to their suppliers.
All 39 requirements — laws, standards and customer requirements — have been systematically compiled with legal basis, scope, required evidence documents and renewal cycle for each item. As part of a consultation request, we walk you through which points are specifically relevant to your company.
Legally or contractually binding requirements with exclusion consequences if unmet.
Market standards and preconditions for being listed and eligible to bid with systems integrators.
Overview, Laws & Regulations, Standards, Customer Requirements, consolidated matrix.
From gap assessment to certification — structured along the three requirement layers.
CONSUVATION delivers not only consulting but also the matching central software application, covering your entire portfolio — data protection, information security, CADIS® and compliance management — in one unified, centrally maintained application, complemented by specialized Excel/tool-based registers, correlation matrices, and compliance calendars for day-to-day operation. This gives you complete service offerings for the necessary management systems and IT solutions from a single source — for AQAP-aligned quality requirements, CADIS®, IEC 62443, ISO 27001, NIS-2, and security-clearance preparation — instead of fragmented point solutions from multiple providers.
As an official DEKRA-authorized partner, we guide you from gap analysis through to certification readiness.
DEKRA PartnerBuilding the security plan and support through company security clearance and personnel vetting.
Classified ContractsIntroduction and integration into existing ISO 9001 systems, preparation for Government Quality Assurance.
Quality ManagementConsulting and preparation for the VDA ISA assessment — advisory only, not a DEKRA assessment partner for TISAX.
Automotive InterfaceBuilding an ISMS, risk management under §30 of the new BSI Act, and implementing contractually passed-down security requirements.
Information SecurityProcesses for export licensing, goods-list classification, and internal compliance programs (ICP).
KWKG / AWGOur "Defense and Armament Industry" consulting practice in detail — from strategy to security awareness.
Strategic and business consulting for market entry and positioning in the defense and armament sector.
Assessment, qualification, and auditing of suppliers along the defense-technology supply chain.
Technology consulting for security-relevant systems and production environments in the defense industry.
Building an ISMS based on ISO 27001 or CADIS® — or, where an ISMS already exists, integrating requirements via our own correlation matrices with end-to-end support through to certification.
Preparation for CADIS® — the first European assessment scheme designed specifically for suppliers to the defense and armament industry, evaluating cyber and information security across the supply chain.
Implementing NIS-2 requirements tailored specifically to applicability and supply-chain obligations in the defense industry.
Embedding data protection and security requirements from the earliest stages of concept and development for defense platforms and products.
Support in building, certifying, and preparing audits for quality management systems in the defense industry.
Training and awareness programs for employees on security-relevant topics in the defense industry.
Building governance and compliance structures tailored to the specific regulatory requirements of the defense and armament industry.
Choose the depth of support that matches your maturity level and program phase.
No, CADIS® is not a legal requirement, but it has established itself as a de facto market standard for information security in the defense industry and is increasingly required for listing with systems integrators. CONSUVATION is an official DEKRA-authorized consulting partner for CADIS®.
ISO 9001 is the international base standard for quality management and a prerequisite for AQAP. AQAP 2110 extends ISO 9001 with NATO-specific requirements for development, design and configuration management, and is assessed by the national quality assurance authority (in Germany, BAAINBw) through a Government Quality Assurance process.
Yes. The NCAGE code is the unique supplier identification within the NATO procurement system and is generally a precondition for bidding on NATO or Bundeswehr programs — regardless of company size or product portfolio.
Whenever staff need access, in the course of a contract, to classified information at or above the CONFIDENTIAL level. The individual security clearance is typically preceded by a declaration of commitment under §1 SÜG and, at company level, by the company security clearance.
Indirectly, yes: customers obligated under NIS-2 (systems integrators, critical-infrastructure operators) must assess the cybersecurity of their supply chain and contractually pass minimum requirements down to their suppliers — even if those suppliers do not themselves meet the sector or size thresholds of the NIS2UmsuCG.
TISAX® originated in the automotive supply chain but is increasingly required by defense systems integrators with a vehicle connection (e.g. armored vehicles, mobility systems). CONSUVATION advises and prepares clients for TISAX®.
Request the complete compliance map or schedule a no-obligation initial consultation with our defense and armament experts.
Get in Touch