<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Government on Le Site de François</title><link>https://lesitedefrancois.be/en/tags/government/</link><description>Recent content in Government on Le Site de François</description><generator>Hugo -- gohugo.io</generator><language>en</language><copyright>© 2026 François</copyright><atom:link href="https://lesitedefrancois.be/en/tags/government/index.xml" rel="self" type="application/rss+xml"/><item><title>VSA / VS-NfD (German Classified Information)</title><link>https://lesitedefrancois.be/en/compliance/vs-nfd/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://lesitedefrancois.be/en/compliance/vs-nfd/</guid><description>&lt;p&gt;&lt;strong&gt;VS-NfD&lt;/strong&gt; (Verschlusssache — Nur für den Dienstgebrauch, &amp;ldquo;Classified — For Official Use Only&amp;rdquo;) is the lowest of Germany&amp;rsquo;s four classification levels (VS-NfD, VS-Vertraulich, Geheim, Streng Geheim). The legal and regulatory framework governing its handling consists of the &lt;strong&gt;Sicherheitsüberprüfungsgesetz (SÜG)&lt;/strong&gt; as the legal basis, the &lt;strong&gt;Verschlusssachenanweisung (VSA)&lt;/strong&gt; as the administrative directive for federal agencies (fundamentally revised in 2023), and the &lt;strong&gt;VS-NfD-Merkblatt&lt;/strong&gt; (Annex 4 to the Geheimschutzhandbuch) for private-sector companies handling classified contracts. The framework is administered by the &lt;strong&gt;BSI&lt;/strong&gt; for IT security aspects and the &lt;strong&gt;BMWK&lt;/strong&gt; (Federal Ministry for Economic Affairs) for industrial security (Geheimschutz in der Wirtschaft). Compliance is &lt;strong&gt;absolutely mandatory&lt;/strong&gt; — it is a legal obligation under the SÜG, and failure to comply results in loss of the ability to participate in classified government contracts. Key IT requirements include: using &lt;strong&gt;exclusively BSI-approved (zugelassen) IT security products&lt;/strong&gt; listed in the VS-Produktkatalog (BSI-Schrift 7164) for encryption, VPN, and security-critical functions; implementing an information security concept based on &lt;strong&gt;BSI IT-Grundschutz&lt;/strong&gt; (including risk analysis and Grundschutz-Check); applying the multi-layered security principle (prevention, detection, reaction); and personnel security clearances under the SÜG. Since &lt;strong&gt;1 September 2025&lt;/strong&gt;, a &lt;strong&gt;mandatory self-accreditation&lt;/strong&gt; (Selbstakkreditierung) obligation entered into force: every three years, the VS-NfD-responsible person must formally confirm to their management (and on request to the BMWK or the contracting authority) that all technical and organizational measures are fully implemented. The BSI&amp;rsquo;s IT-Grundschutz module &lt;strong&gt;CON.11.1&lt;/strong&gt; specifically addresses VS-NfD requirements that go beyond standard IT-Grundschutz measures.&lt;/p&gt;</description></item></channel></rss>