We protect what your mission depends on.
VS-NfD & BSI IT-Grundschutz for defence suppliers – from your first classified (VS-NfD) contract to a certified ISMS. For the defence industry, armed forces, government agencies and critical infrastructure.
The threat landscape has changed
Hybrid attacks no longer target only troops and equipment – they target networks, supply chains and trust. Anyone serious about defence readiness must treat information security as part of operational capability.
Hybrid threats
Cyber attacks, espionage, sabotage – and, increasingly, unmanned aerial systems over sensitive sites. The line between peace and conflict is blurring, and the attack surface keeps growing.
Growing regulation
NIS-2, KRITIS regulation and classified-information requirements place binding obligations on operators and suppliers. Those who cannot provide evidence today will lose contracts and approvals tomorrow.
Vulnerable supply chains
The security of a system does not end at the factory gate. Suppliers and service providers are becoming the preferred point of entry – and thus a mandatory task for every security management system.
Does this sound familiar?
Four situations that suppliers and organisations in the defence environment bring to us every day.
Your first classified (VS-NfD) contract on the table?
We prepare your company for the official classified-information oversight and build VS-capable IT before the contracting authority asks.
Processing test or design data of third-party defence equipment?
Protection needs arise from customer data – we make them demonstrable.
New to the defence business?
From civilian manufacturer to qualified supplier – ISMS and IT-Grundschutz from day one.
Export control, customs, supplier questionnaires?
NIS-2 and supply-chain evidence without your own security department.
Our services for the defence sector
From classified IT to audit support – we support you with clear concepts and evidence that stands up to scrutiny.
VS-NfD & Classified Info
Preparation for the official classified-information oversight by the BMWK, implementation support, security domain and IT-Grundschutz – we build VS-capable structures before the contracting authority asks.
VS-NfD Cloud Build-up
Design and build-up of VS-capable IT and cloud environments – from architecture to approval readiness.
ISMS & ISO 27001
Initial build-up, gap analysis and certification preparation – pragmatic, audit-proof and compatible with military requirements.
NIS-2 & KRITIS
Applicability analysis, baseline protection and compliance evidence – including reporting processes for operators and suppliers.
BCM
Business continuity and crisis management per BSI Standard 200-4 – so an incident does not become a standstill.
Supply Chain
Supplier questionnaires, awareness and evidence – structured audits against recognised audit catalogs.
Audit Support
Customer, certification and authority audits – as a baseline assessment or a dress rehearsal before the real thing.
Sovereign AI
AI expert assistance on your own hardware in your own network – no external cloud, even for sensitive and classified topics.
Detect, assess and counter drones
Unmanned aerial systems over barracks, ports and critical facilities have long been a reality. We treat the drone threat as part of the security concept – from analysing your site to a coordinated drone detection and countermeasure concept.
- Threat analysis for sites, events and critical facilities
- Drone detection and countermeasure concepts – technology-neutral and within the legal framework
- Integration into security, reporting and emergency management (BSI 200-4)
Making supply chains auditable
Defence projects are a team effort involving many suppliers – and every unaudited partner is a risk. With structured supplier audits we create evidence that stands up to scrutiny: against recognised audit catalogs, with weighted scores and clear corrective actions. Our own supplier audit tool bundles around 50 audit catalogs with more than 11,600 audit questions for exactly this purpose.
- Audits against ISO 27001, BSI IT-Grundschutz, NIST SP 800-161 and further catalogs
- Weighted scores, findings and corrective actions with deadlines
- PDF audit reports and dashboards – traceable for clients and assessors
Digital sovereignty is not a buzzword
We run our own AI lab on local hardware in our own network – without any external cloud. We bring the same mindset to your projects: architectures you control, data that stays with you, and evidence that stands up to scrutiny.
- Self-hosted tools instead of dependence on third-party clouds
- Concepts compatible with BSI requirements and classified-information protection
- Clear documentation for assessments, audits and approvals
German Expertise. European Security.
Why DLAU
We are not an anonymous corporation but a specialised consulting team – with short lines, plain language and demonstrable quality.
-
Certified quality
Certified to ISO/IEC 27001 and ISO 9001 (DAkkS accredited, valid until 03/2029) – we meet the standards we advise on.
-
Experience in classified environments
Our consultants bring experience from projects involving classified information (VS) and hold the required security clearances.
-
Our own tools
We develop our compliance and audit tools ourselves and run them self-hosted – from supplier audits to the ISMS.
-
Independent & sovereign
Consulting from Germany, vendor-neutral and free of hidden product interests – your security is the mandate.
In-house tools that save years
Our consulting is backed by software tools we develop and host ourselves – the same figures as on our card:
Grundschutz++
998 requirements · 20 practices
ISMS/Siko-Factory
proven: 2,445 requirements
Lieferantenaudit-Tool
≈ 50 catalogues · > 11,600 questions
NIS-2-Tool
75 questions in 11 categories
Let's talk security.
A first conversation costs nothing – and often brings more clarity than a hundred pages of concept. Confidential, and on site if you prefer.