VS-NfD (Verschlusssache — Nur für den Dienstgebrauch, “Classified — For Official Use Only”) is the lowest of Germany’s four classification levels (VS-NfD, VS-Vertraulich, Geheim, Streng Geheim). The legal and regulatory framework governing its handling consists of the Sicherheitsüberprüfungsgesetz (SÜG) as the legal basis, the Verschlusssachenanweisung (VSA) as the administrative directive for federal agencies (fundamentally revised in 2023), and the VS-NfD-Merkblatt (Annex 4 to the Geheimschutzhandbuch) for private-sector companies handling classified contracts. The framework is administered by the BSI for IT security aspects and the BMWK (Federal Ministry for Economic Affairs) for industrial security (Geheimschutz in der Wirtschaft). Compliance is absolutely mandatory — it is a legal obligation under the SÜG, and failure to comply results in loss of the ability to participate in classified government contracts. Key IT requirements include: using exclusively BSI-approved (zugelassen) IT security products listed in the VS-Produktkatalog (BSI-Schrift 7164) for encryption, VPN, and security-critical functions; implementing an information security concept based on BSI IT-Grundschutz (including risk analysis and Grundschutz-Check); applying the multi-layered security principle (prevention, detection, reaction); and personnel security clearances under the SÜG. Since 1 September 2025, a mandatory self-accreditation (Selbstakkreditierung) obligation entered into force: every three years, the VS-NfD-responsible person must formally confirm to their management (and on request to the BMWK or the contracting authority) that all technical and organizational measures are fully implemented. The BSI’s IT-Grundschutz module CON.11.1 specifically addresses VS-NfD requirements that go beyond standard IT-Grundschutz measures.
Red Hat is not an IT security product requiring BSI Zulassung (approval) — RHEL is an operating system, not a cryptographic appliance or VPN gateway — but it serves as the foundational platform upon which VS-NfD-compliant IT systems are built. The BSI’s CON.11.1 building block requires that VS-NfD IT systems implement IT-Grundschutz as a prerequisite, and RHEL provides the technical capabilities to fulfill those baseline requirements: SELinux mandatory access control for compartmentalization, system-wide cryptographic policies aligned with BSI TR-02102 recommendations, comprehensive audit logging via auditd, and OpenSCAP profiles (including the BSI-specific profile xccdf_org.ssgproject.content_profile_bsi) that assess system configuration against BSI hardening requirements. For network-level protection where BSI-approved products are mandatory (e.g., VPN encryption for cross-site VS-NfD networks), RHEL and OpenShift integrate with BSI-approved appliances (such as genuscreen firewalls or SINA VPN gateways from secunet) as the underlying platform hosting workloads behind those approved boundaries. Red Hat’s role is enabling the “Informationssicherheitskonzept” that the VS-NfD-Merkblatt demands: the Compliance Operator continuously validates that systems maintain their hardened state, Ansible Automation Platform enforces the documented security configurations reproducibly across the environment (critical evidence for self-accreditation), and Red Hat’s long-term support lifecycle ensures that the specific validated product version remains supported throughout the duration of classified contracts. For defense contractors and public-sector IT service providers subject to the new self-accreditation obligation, Red Hat’s compliance automation reduces the every-three-year confirmation from a major audit exercise to a continuous, documented compliance posture.
