VSA / VS-NfD (German Classified Information)
VS-NfD (Verschlusssache — Nur für den Dienstgebrauch, “Classified — For Official Use Only”) is the lowest of Germany’s four classification levels (VS-NfD, VS-Vertraulich, Geheim, Streng Geheim). The legal and regulatory framework governing its handling consists of the Sicherheitsüberprüfungsgesetz (SÜG) as the legal basis, the Verschlusssachenanweisung (VSA) as the administrative directive for federal agencies (fundamentally revised in 2023), and the VS-NfD-Merkblatt (Annex 4 to the Geheimschutzhandbuch) for private-sector companies handling classified contracts. The framework is administered by the BSI for IT security aspects and the BMWK (Federal Ministry for Economic Affairs) for industrial security (Geheimschutz in der Wirtschaft). Compliance is absolutely mandatory — it is a legal obligation under the SÜG, and failure to comply results in loss of the ability to participate in classified government contracts. Key IT requirements include: using exclusively BSI-approved (zugelassen) IT security products listed in the VS-Produktkatalog (BSI-Schrift 7164) for encryption, VPN, and security-critical functions; implementing an information security concept based on BSI IT-Grundschutz (including risk analysis and Grundschutz-Check); applying the multi-layered security principle (prevention, detection, reaction); and personnel security clearances under the SÜG. Since 1 September 2025, a mandatory self-accreditation (Selbstakkreditierung) obligation entered into force: every three years, the VS-NfD-responsible person must formally confirm to their management (and on request to the BMWK or the contracting authority) that all technical and organizational measures are fully implemented. The BSI’s IT-Grundschutz module CON.11.1 specifically addresses VS-NfD requirements that go beyond standard IT-Grundschutz measures.
