Advantage Through Knowledge and Experience
Market Access for Defense Through Compliance CADIS® TISAX® ISO 27001 OT Security Automotive Security RED Directive RCE Directive NIS-2
Defense Industry Market Entry Consulting

Market Access for Defense Through Compliance

Becoming a supplier to the defense and armament industry means satisfying laws, standards and customer requirements at the same time — from personnel security clearance through CADIS® and AQAP to the NCAGE code. As a market entry consulting partner for the defense industry, CONSUVATION gives you the complete standards overview and compliance map, and guides you through to contract readiness.

View the Compliance Map Request the Whitepaper
39 requirements systematically mapped
Official DEKRA partner for CADIS®
ISMS pioneer since BS 7799 (2000)
Experience with BAAINBw & systems integrators
Three Requirement Layers

What suppliers must satisfy at the same time

Market access to the defense and armament industry does not depend on a single certification — it depends on the interplay of three layers.

13

Laws & Regulations

KWKG, AWG/AWV, SÜG, the Confidentiality Protection Manual, VSVgV, NIS-2, GDPR and further national and European legal bases.

15

Standards

The AQAP series, ISO 9001, EN 9100/AS9100, TISAX, CADIS®, ISO 27001, IEC 62443 and the NCAGE code as technical prerequisites.

11

Customer Requirements

BAAINBw procurement conditions, systems-integrator supplier manuals, company security clearance and personnel vetting.

Classification

Mandatory or de facto necessary?

Every analysis we deliver draws a clear line between what is legally or contractually binding and what the market simply expects.

Mandatory (Law/Contract)

Binding under law, regulation, or contract. Failure to comply results in exclusion from the tender or in legal consequences — e.g. personnel security clearance, the NCAGE code, ISO 9001.

De Facto Necessity

No direct legal basis, but a market standard or precondition for being listed as a supplier to systems integrators — e.g. AQAP 2110, EN 9100, TISAX, CADIS®.

Legal Framework

Laws & Regulations

A selection of the central legal bases for suppliers in the defense and armament sector.

War Weapons Control Act (KWKG)

Mandatory

Licensing requirement for manufacturing, transport, acquisition and transfer of war weapons.

Authority: BAFA

Security Clearance Act (SÜG)

Mandatory

Governs the security vetting of individuals with access to classified information.

Renewed every 5–10 years

Confidentiality Protection Manual (GHB)

Mandatory

Organizational, personnel, and physical confidentiality protection in industry — a precondition for classified contracts.

Evidence: company security clearance

Defense Procurement Regulation (VSVgV)

Mandatory

Special procurement law for supply, construction, and services in the defense and security sector.

Procuring bodies: BAAINBw and others

NIS2UmsuCG

Mandatory

Risk management, reporting duties, and management liability — in force since 06.12.2025 with no grace period; often directly relevant for manufacturing operations.

Authority: BSI · As of August 2026

US ITAR / EAR

De Facto

Extraterritorial US export control where US technology content is present in the supply chain.

Authority: DDTC / BIS (USA)
Technical Requirements

Standards

Management-system and industry-specific standards that determine bid eligibility and listing with systems integrators.

AQAP 2110

De Facto

NATO quality assurance for design, development and production — a frequent explicit contract requirement of BAAINBw.

Re-audit typically every 3 years

EN 9100 / AS9100

De Facto

QMS for aerospace and defense, extending ISO 9001 with configuration management and traceability requirements.

Listed in the IAQG OASIS database

CADIS®

De Facto

Industry-specific information security standard for the defense industry. CONSUVATION is an official DEKRA-authorized consulting partner.

TISAX® (VDA ISA)

De Facto

Increasingly required by defense systems integrators with a vehicle connection. CONSUVATION advises and prepares — not a DEKRA assessment partner for TISAX.

ISO/IEC 27001

Mandatory

ISMS certification, frequently contractually required for access to customer networks and program data.

Re-certification every 3 years

NCAGE Code

Mandatory

Unique supplier identification — without an NCAGE code, bidding in the NATO procurement environment is generally not possible.

Registration: BAAINBw / codification authority
Contract Practice

Customer Requirements

Public procuring authorities and systems integrators add further, sometimes company-specific requirements.

BAAINBw Procurement Requirements

Mandatory

Special contract conditions for direct suppliers to Germany's Federal Office for Bundeswehr Equipment, IT and In-Service Support.

Systems-Integrator Supplier Manuals

De Facto

Company-specific quality and security requirements from Rheinmetall, KNDS, Diehl, Hensoldt, Airbus D&S and others.

Company Security Clearance (USB)

Mandatory

Confirms a company's suitability to handle classified information — a formal precondition for classified contracts.

Personnel Reliability Check (ZÜP)

Mandatory

Individual vetting required before access to classified information or security-sensitive areas.

Conflict Minerals Declaration

De Facto

Due-diligence evidence for tin, tantalum, tungsten and gold — especially required where there is a US customer link.

NIS-2 Pass-Through from Systems Integrators

De Facto

NIS-2-obligated customers must assess supply-chain cybersecurity and contractually pass minimum requirements down to their suppliers.

Full Overview & Standards Overview

The Complete Compliance Map

All 39 requirements — laws, standards and customer requirements — have been systematically compiled with legal basis, scope, required evidence documents and renewal cycle for each item. As part of a consultation request, we walk you through which points are specifically relevant to your company.

18 × Mandatory

Legally or contractually binding requirements with exclusion consequences if unmet.

21 × De Facto Necessity

Market standards and preconditions for being listed and eligible to bid with systems integrators.

5 Worksheets

Overview, Laws & Regulations, Standards, Customer Requirements, consolidated matrix.

Request a Consultation
Our Support

How CONSUVATION guides you to contract readiness

From gap assessment to certification — structured along the three requirement layers.

One provider for management systems and IT solutions

CONSUVATION delivers not only consulting but also the matching central software application, covering your entire portfolio — data protection, information security, CADIS® and compliance management — in one unified, centrally maintained application, complemented by specialized Excel/tool-based registers, correlation matrices, and compliance calendars for day-to-day operation. This gives you complete service offerings for the necessary management systems and IT solutions from a single source — for AQAP-aligned quality requirements, CADIS®, IEC 62443, ISO 27001, NIS-2, and security-clearance preparation — instead of fragmented point solutions from multiple providers.

CADIS® Consulting

As an official DEKRA-authorized partner, we guide you from gap analysis through to certification readiness.

DEKRA Partner

Confidentiality Protection & SÜG

Building the security plan and support through company security clearance and personnel vetting.

Classified Contracts

AQAP & EN 9100

Introduction and integration into existing ISO 9001 systems, preparation for Government Quality Assurance.

Quality Management

TISAX® Preparation

Consulting and preparation for the VDA ISA assessment — advisory only, not a DEKRA assessment partner for TISAX.

Automotive Interface

ISO 27001 / NIS-2

Building an ISMS, risk management under §30 of the new BSI Act, and implementing contractually passed-down security requirements.

Information Security

Export Control Compliance

Processes for export licensing, goods-list classification, and internal compliance programs (ICP).

KWKG / AWG
Full Consulting Portfolio

Extended Service Offerings: Defense & Armament

Our "Defense and Armament Industry" consulting practice in detail — from strategy to security awareness.

Strategy and Business

Strategic and business consulting for market entry and positioning in the defense and armament sector.

Supply Chain, Supplier Qualification and Audits

Assessment, qualification, and auditing of suppliers along the defense-technology supply chain.

Technology

Technology consulting for security-relevant systems and production environments in the defense industry.

Cybersecurity for Defence Companies

Building an ISMS based on ISO 27001 or CADIS® — or, where an ISMS already exists, integrating requirements via our own correlation matrices with end-to-end support through to certification.

CADIS Assessment

Preparation for CADIS® — the first European assessment scheme designed specifically for suppliers to the defense and armament industry, evaluating cyber and information security across the supply chain.

NIS-2 for Defence Companies

Implementing NIS-2 requirements tailored specifically to applicability and supply-chain obligations in the defense industry.

Privacy & Security by Design for Defence Platforms

Embedding data protection and security requirements from the earliest stages of concept and development for defense platforms and products.

Quality, Certification and Audit Consulting

Support in building, certifying, and preparing audits for quality management systems in the defense industry.

Defence Security Awareness Programme

Training and awareness programs for employees on security-relevant topics in the defense industry.

Governance / Compliance

Building governance and compliance structures tailored to the specific regulatory requirements of the defense and armament industry.

Service Packages

Three paths to contract readiness

Choose the depth of support that matches your maturity level and program phase.

Compact Check

Clarify applicability
  • Sector and program analysis
  • Comparison against the compliance map
  • Prioritized gap list
  • Short report with recommendations
Request

Ongoing Support

Sustain compliance long-term
  • Monitoring of re-audits and deadlines
  • Maintenance of the compliance map
  • Support during customer audits
  • Point of contact for new programs
Request
Frequently Asked Questions

FAQ Defense & Armament

Is CADIS® mandatory for all defense suppliers?

No, CADIS® is not a legal requirement, but it has established itself as a de facto market standard for information security in the defense industry and is increasingly required for listing with systems integrators. CONSUVATION is an official DEKRA-authorized consulting partner for CADIS®.

What is the difference between AQAP 2110 and ISO 9001?

ISO 9001 is the international base standard for quality management and a prerequisite for AQAP. AQAP 2110 extends ISO 9001 with NATO-specific requirements for development, design and configuration management, and is assessed by the national quality assurance authority (in Germany, BAAINBw) through a Government Quality Assurance process.

Do we need an NCAGE code for Bundeswehr contracts?

Yes. The NCAGE code is the unique supplier identification within the NATO procurement system and is generally a precondition for bidding on NATO or Bundeswehr programs — regardless of company size or product portfolio.

When is a security clearance under SÜG required?

Whenever staff need access, in the course of a contract, to classified information at or above the CONFIDENTIAL level. The individual security clearance is typically preceded by a declaration of commitment under §1 SÜG and, at company level, by the company security clearance.

Does NIS-2 also apply to smaller suppliers who are not directly in scope?

Indirectly, yes: customers obligated under NIS-2 (systems integrators, critical-infrastructure operators) must assess the cybersecurity of their supply chain and contractually pass minimum requirements down to their suppliers — even if those suppliers do not themselves meet the sector or size thresholds of the NIS2UmsuCG.

How does TISAX® relate to the defense industry?

TISAX® originated in the automotive supply chain but is increasingly required by defense systems integrators with a vehicle connection (e.g. armored vehicles, mobility systems). CONSUVATION advises and prepares clients for TISAX®.

Get clarity on your requirements

Request the complete compliance map or schedule a no-obligation initial consultation with our defense and armament experts.

Get in Touch
Tilsiter Str. 6 · D-71065 Sindelfingen, Germany · +49 (0) 7031.4181-860 · contact@consuvation.com
Legal Notice · Privacy Policy · Contact