IT security for the Aerospace & Defense industry

Meet regulations and standards, close security gaps, secure contracts.

Whether you're new to the Aerospace & Defense industry or expanding your existing business there: NIS2, classified information security, ISO 27001, and CADIS each come with different requirements. We clarify what applies in your case and support you in delivering securely.

16+

years of experience in information security and data protection

800+

clients who trust our advice

25+

consultants from law and technology under one roof

We were able to complete the project in record time. ISiCO's expertise and experience were a key success factor.

The challenge

What makes security difficult in the defense industry

Whether you're new to the industry or have been supplying it for years: companies in the defense industry face an interplay of regulatory frameworks, technical requirements, and a supply chain with varying levels of security. Three issues come up especially often.

Rules that overlap

Aerospace & Defense regulations, including but not limited to NIS2, the Geheimschutzhandbuch (GHB, Germany's classified information security manual), the Verschlusssachenanweisung (VSA, the classified information directive for authorities), IEC 62443, the Cyber Resilience Act (CRA), CADIS, ISO 27001, ISO 15408 / Common Criteria (CC), and ISO 9001, often apply at the same time without fully overlapping. And the classification keeps shifting: new contracts, new products, or new rules like NIS2 continuously change what applies to you, even if you've known the industry for years.

Security in day-to-day operations

Network segmentation, encryption, access rights, and emergency plans all require ongoing maintenance. In day-to-day business, they can easily come under pressure, for example through exceptions or permissions that run longer than planned.

The supply chain as an entry point

Whether you supply others or have suppliers of your own: your customers scrutinize you, and you depend on partners whose security level you barely know. A single weak point in the chain is enough to gain access to the entire network.

A real-world example: After a publicly reported data leak at a German defense manufacturer, more than 100 supplier companies named in the documents were never actively notified of the breach. Working reporting chains across the supply chain are not a side issue; they are a basic requirement.

Your outcome

What changes for you

Win and grow contracts

Proven security maturity becomes an argument in its own right during the procurement process, whether for your first contract or your next one. You meet the requirement before the client even asks.

Clarity instead of guesswork

You know exactly which requirements actually apply to your company, instead of working your way through various information security regulations on your own.

Audit-ready when it counts

Your information security management system holds up to scrutiny from clients and certification bodies, documented and traceable. You're also prepared for regulatory reporting obligations, including those taking effect under NIS2 from 2027.

One point of contact for everything

Law and technology from a single source: from the initial assessment to ongoing support as your external information security officer.

Why ISiCO

What sets us apart

Regulatory expertise meets tech, forensics, and cryptography, all on the same team.

Team

Law and technology from a single source

Our team combines IT security law and AI regulation in drone and aviation technology with technical implementation, from forensics to cryptography. You work with one experienced, versatile team instead of a rotating cast of specialists.

Experience

We know what matters

Whether you're a manufacturer or a supplier, working with public or private clients, new to the industry or active for years: we quickly identify which requirements are connected for you and where the effort involved is often underestimated.

Frameworks

Applied daily, not just read

ISO 27001, BSI IT-Grundschutz, NIS2, and the Cyber Resilience Act (CRA) are our core business. We factor in industry-specific add-ons such as CADIS or ZDv A-960/1, among others, from the very start.

Does this affect you?

Who this is worth it for

New to the industry

Your first contract in the defense industry

You've received a request from a private client such as a defense group or systems house, or you're planning to take part in a tender from the German Armed Forces or another public authority. Or you're a manufacturer planning to enter the market with your own product and don't yet know which requirements come with it.

Growing

More contracts, more requirements

You're already active in the industry as a manufacturer or supplier, but you still lack a documented information security management system or preparation for handling classified information.

Security-critical products

Software, electronics, connected systems

Your products contain software or wireless interfaces, for example in drones or connected systems, and need a security approach that goes beyond classic office IT.

Our services

The building blocks at a glance

Bookable individually, but designed to work together. In the initial consultation, we'll work out together where it makes the most sense for you to start.

Baseline assessment

The compact starting point: we clarify which requirements apply to you and where your IT security stands today.

Learn more

ISMS setup under ISO 27001

From structural analysis to audit readiness, based on either ISO 27001 or BSI IT-Grundschutz. On request, we build in CADIS requirements as standard from the outset, instead of adding them on afterward.

Learn more

NIS2 and CRA classification and implementation

Clear classification by NACE activity and size threshold for NIS2, complemented by CRA requirements for products with digital elements, plus support with risk management, reporting processes, and registration.

Learn more

Preparation for classified information handling (VS-NfD)

A designated security officer for classified information, structural analysis, an IT environment compliant with classified-information rules, and the necessary physical processes.

Learn more

Penetration testing

Technical verification of the measures you've put in place, from individual systems to your entire IT environment, ahead of your next client audit.

Learn more

Supply chain security management

Security requirements for subcontractors, an effective supplier assessment, and working reporting chains in both directions.

Learn more

How it works

From initial assessment to ongoing security

Initial consultation

30 minutes, no obligation. We listen to where you stand and give you an initial assessment of what applies to you.

Prioritization

Together, we determine whether ISMS setup, NIS2 implementation, or classified-information preparation comes first, often several of these at once.

Implementation

We support the build-up through to audit readiness, including a penetration test ahead of your next client review.

Ongoing support

As your external information security officer, we remain your point of contact, even after the project is complete.

Your contacts

Our experts on this topic

Jonas Schütz

Jonas Schütz

Senior Legal Consultant

Justus Richard Weller

Justus Richard Weller

Managing Consultant

Frequently asked questions

What companies often ask us

No. Only government bodies such as the German Armed Forces or security authorities are exempt. Private manufacturers and suppliers are subject to NIS2 like any other company, provided they meet the size thresholds.

No. ISO 27001 covers general information security and provides a good foundation. As soon as classified information from VS-NfD level upward is involved, additional requirements apply, such as BSI-approved encryption and the need-to-know principle.

CADIS is an industry-specific certification standard that builds on ISO 27001 and NIST frameworks and adds topics such as physical security and export control. On request, we factor in CADIS requirements as standard right from the ISMS setup, so you don't have to build things twice.

That depends heavily on your company's scope and starting point, so a blanket timeframe here wouldn't be credible. The baseline assessment at the start shows what scope and timeframe is realistic for you.

That depends on your starting point and the scope you need. We'll work that out together with you in the free initial consultation.

Ready for the first step?

Find out in a free initial consultation which requirements apply to you and how to implement them.

Free initial consultation. 30 minutes, no obligation.