• An old iron key is stuck in the keyhole of a wooden door
Insight

The path to federal security clearance

The path to federal classified information security through security clearance decisions, security officers and personnel security vetting.

| Reading time 7 min. | Author: Martin Neupert

Contracts involving classified government information may only be carried out by companies that are formally registered with the federal security authorities, have a designated security officer, and whose staff have all undergone security vetting. The Federal Ministry for Economic Affairs is responsible for this through its Security Forum. The application for security clearance is not submitted by the company itself, but by the contracting authority. Several months may elapse between the submission of the application and the receipt of the security clearance decision. Security vetting ranges from Ü1 for ‘VS-VERTRAULICH’ (Confidential) via Ü2 for ‘GEHEIM’ (Secret) to Ü3 for ‘STRENG GEHEIM’ (Top Secret). Since 16 January 2026, an amendment to the Security Clearance Act (SÜG) has extended the security authorities’ internet searches to include social media. A key issue for newcomers is foreign shareholdings, which must be disclosed and which may prevent the granting of security clearance or trigger additional conditions.

What does confidentiality mean for a company?

Classified information protection is divided into two areas. Official classified information protection concerns the handling of classified information within public authorities. Non-official classified information protection, also known as classified information protection in the private sector, applies to companies that handle classified material on behalf of the Federal Government, foreign public authorities or international organisations. Only the second area, which is overseen by the Federal Ministry for Economic Affairs, is relevant to private contractors.

Within this framework, a distinction must be made between two types of security measures. Personnel security ensures, through security vetting, that only trustworthy individuals are granted access to classified information. Physical security encompasses the technical and organisational security measures – in other words, how classified information is protected from unauthorised access in premises, IT systems and processes.

A third element is preventive protection against sabotage by personnel. It aims to keep potential internal perpetrators away from facilities vital to life or national defence. The legal basis for this is the Security Vetting Act (SÜG). The specific procedural rules for organisations are set out in the Ministry’s Security Manual (GHB).

How does a company come to be covered by security clearance?

A company cannot be admitted to the security clearance scheme on its own initiative. The process is always triggered by a specific need. The application for security clearance is submitted either by a public authority, such as the Federal Office for Equipment, Information Technology and Use of the German Armed Forces (BAAINBw), or by a company that is already under security clearance and wishes to award a classified subcontract. It is only this application that sets the process in motion at the Federal Ministry for Economic Affairs.

During the process, the Ministry assesses whether the company meets the necessary personnel and material requirements. This includes appointing a security officer, clarifying ownership and shareholding structures, and verifying that the planned premises and IT systems meet the requirements.

If the assessment is successful, the Ministry issues a security clearance certificate. This confirms that the company is authorised to handle classified information up to a certain security level and specifies the individuals authorised to do so.

No classified material may be handed over without a valid security clearance certificate. In practice, this means that the time required for this process must be factored into tender and project planning, as several months may elapse between the application and the issuance of the certificate.

What is the difference between security clearances Ü1, Ü2 and Ü3?

The scope of the security clearance depends on the classification level and the specific role. The basic security clearance Ü1 is intended for access to information classified as ‘VS-VERTRAULICH’. It focuses on the identity of the individual concerned and any information relevant to security.

Access to ‘GEHEIM’ or to a larger number of documents classified as ‘VS-VERTRAULICH’ requires the extended security clearance Ü2. This takes additional sources of information into account and, as a rule, also covers the person’s adult spouse or partner. The Ü3, i.e. the extended security clearance involving security investigations, applies to roles involving access to ‘STRENG GEHEIM’. This involves more extensive investigations, such as interviewing referees.

At all levels, the principle of ‘need-to-know’ applies. Not every person in the company is vetted as a precautionary measure, but only if access is required for a specific task. Stays abroad and circumstances that are difficult to clarify can significantly prolong the duration of the process. For this reason, staff planning and project timelines should be coordinated at an early stage.

What does VS-NfD mean, and how does it differ from higher classification levels?

VS-NfD stands for ‘Classified, For Official Use Only’ and is the lowest of the four security classifications, followed by VS-CONFIDENTIAL, SECRET and TOP SECRET. For newcomers, the difference is of practical significance, as access to VS-NfD does not require a formal security clearance under the Security Clearance Act (SÜG). As a rule, handling VS-NfD merely requires the person concerned to give a formal undertaking to maintain confidentiality and to comply with the relevant protective measures. A security clearance (Ü1) is only required for information classified as VS-VERTRAULICH or higher.

This threshold is relevant for many contracts in the defence sector. A significant proportion of procurement takes place at the VS-NfD level. For this level, companies must meet organisational and technical requirements, but do not yet have to undergo a full security clearance procedure. Those who master this level have laid the foundations for the next step.

However, as soon as a contract reaches the VS-VERTRAULICH level or higher, the full security framework – comprising the security clearance decision, the security officer and personnel vetting – comes into effect. It is advisable to align your own organisation with the classification level actually required in the target market segment, rather than rushing to aim for the highest level.

What has changed as a result of the 2026 amendment to the Security Clearance Act?

The Security Clearance Act was reformed by the Act on the Modernisation of the Security Clearance Act with effect from 16 January 2026. The reasons for this are, on the one hand, the need for adjustments identified during the evaluation of the first amendment and, on the other hand, the heightened security situation, which, in the legislature’s assessment, entails a significantly higher risk of espionage and sabotage.

The focus is on the expansion of internet searches. As part of the vetting process, the security authorities are now permitted to conduct more extensive online searches, explicitly including social media – and this applies across all types of vetting.

For standard security vetting, searches on social media are included; for enhanced vetting, however, internet searches are mandatory. In addition, there is greater digitisation of the process to speed it up, as well as adjustments to preventive personnel protection against sabotage.

For companies, the reform primarily means that the basis for assessment is broadening. Security-related anomalies in publicly accessible online profiles can be given greater weight in the assessment. This must be taken into account when training the staff involved.

What are the duties of the security officer?

Every company subject to security clearance requirements must appoint a security officer. This person acts as the central point of contact with the Federal Ministry for Economic Affairs and is responsible for ensuring that the guidelines set out in the security manual are effectively implemented within the company. Their duties include initiating and overseeing security vetting of staff, controlling access to classified information in accordance with the ‘need-to-know’ principle, monitoring physical security measures and reporting security-related incidents.

The Security Officer is not merely a formality. They must possess the necessary reliability and expertise and must themselves have undergone a security vetting. The quality of this role effectively determines whether a company can meet the ongoing requirements of security protection. Support does not end with the security clearance decision, but continues throughout the entire duration of the collaboration. Companies often underestimate the fact that this requires the ongoing commitment of staff, processes and documentation. In security-sensitive areas, additional requirements apply to the personnel deployed for the purpose of preventative sabotage protection.

What particular obstacles do new entrants face?

For new market entrants, dealing with foreign shareholdings is often the most problematic aspect of the review. The Ministry investigates whether a company could be subject to foreign influence through non-German owners, shareholders or other links.

Non-German shareholdings must be disclosed. They may prevent a company from being granted security clearance or trigger additional conditions. For companies with foreign investors, parent companies or financiers, this is an issue that can call into question their entire eligibility for security clearance. It must therefore be clarified at an early stage – in case of doubt, as early as when the shareholder structure is being established.

Other typical sources of error lie in the process itself. Anyone who fails to allow sufficient time for security vetting will come under pressure at the start of the project, as staff who have not yet been cleared cannot be deployed. Anyone who underestimates the physical requirements for premises and IT will have to retrofit them under time pressure. Anyone who treats confidentiality as a one-off project rather than an ongoing task risks facing complaints during day-to-day operations. All these issues can be avoided if confidentiality is treated as part of corporate and tender planning from the outset, rather than only once a contract is already on the horizon.

How are security and public procurement law linked?

In the defence sector, security and public procurement law are closely intertwined. Security-related and defence-specific contracts are awarded in accordance with specific public procurement rules. These allow the contracting authority to set requirements regarding information security and supply chain security. Demonstrating the ability to maintain confidentiality, in the form of a valid security clearance certificate for the required level of classification, is often a prerequisite for eligibility. Without this, a tenderer is excluded, regardless of the quality of their technical proposal.

In practice, this means that preparations for security clearance and the procurement strategy must be considered together. We offer both from a single source: the corporate and regulatory structuring of the company for admission to the security clearance process, as well as its positioning under public procurement law within the specific procurement procedure. We cover in detail how the public procurement law aspects of defence-specific contracts work in our articles on public procurement law in the defence and security sector.

About the author

Martin Neupert
Martin Neupert
Partners · Property and Procurement
Get in touch

Martin Neupert advises companies on public procurement law, foreign trade law, confidentiality and export controls, as well as on access to security-related contracts.

The steel cables of a suspension bridge disappear into the thick fog

Your Path into Federal Classified Information Security

We support your organisation from the application stage, through the security clearance decision, to ongoing security management, all integrated with your procurement strategy.

Get in touch

Frequently asked questions about security classification

Security clearance is the formal process by which a company is admitted to the state security clearance scheme. This enables it to carry out contracts involving classified information. The Federal Ministry for Economic Affairs is responsible for this. The process involves assessing the eligibility criteria, issuing a security clearance decision, appointing a security officer, and the ongoing monitoring of security measures throughout the duration of the collaboration.

The application is not submitted by the company itself, but by the contracting authority – that is, a public authority or a company already subject to security clearance with a classified subcontract. The Federal Ministry for Economic Affairs then assesses the personnel and material requirements, in particular the ownership structure, the security vetting of the individuals involved, and the suitability of the premises and IT systems. Upon successful completion of the procedure, the Ministry issues a security clearance decision.

The three types of security clearance are determined by the classification level. Access to ‘VS-VERTRAULICH’ requires the standard security clearance Ü1; access to ‘GEHEIM’ requires the extended security clearance Ü2; and access to ‘STRENG GEHEIM’ requires the extended security clearance with security investigations Ü3. In the case of Ü2 and Ü3, the spouse or partner is also included; in the case of Ü3, further investigations are carried out.

A check is carried out to determine whether the individual meets the security reliability criteria, i.e. whether there are any indications of vulnerability to blackmail, extremist tendencies or a particular threat posed by foreign intelligence services. This is based on the information that the individual concerned is required to provide in the security declaration, as well as on findings by the domestic intelligence agencies. Since the amendment in 2026, this has also included an extended internet search, covering social media platforms.

The duration depends on the type of vetting and the individual case, and usually takes several months. Stays abroad or matters requiring extensive clarification can significantly prolong the process. Organisations should factor this time requirement into their project planning, as staff who have not yet been cleared are not permitted to handle classified information.

VS-NfD stands for ‘Classified – For Official Use Only’ and denotes the lowest level of classification. Access to VS-NfD does not require a formal security clearance under the Security Clearance Act (SÜG); instead, it generally requires only a formal undertaking to maintain confidentiality and compliance with the relevant security measures. A security clearance is only required for information classified at the ‘VS-VERTRAULICH’ level or higher.

Foreign shareholdings represent the most critical point of scrutiny for new entrants. Non-German owners, shareholders or investors must be disclosed. They may prevent the company from being granted confidentiality status or trigger additional conditions, as confidentiality is intended to rule out any potential external influence. This point should therefore be examined at an early stage and, if necessary, taken into account when structuring the shareholder structure.

Contact

Get in touch

Send us a message. We will get back to you within one working day.

Maxfeld.legal

Rechtsanwaltsgesellschaft mbH
Leipziger Platz 21
90491 Nuremberg

Brochure

Request brochure

Enter your contact details. We will send you the brochure by email right away.