• Blog
  • VS-NfD and confidentiality protection in the construction industry: Why IT compliance will be the entry ticket for large projects.

VS-NfD and confidentiality protection in the construction industry: Why IT compliance will be the entry ticket for large projects.

Classified information in construction projects: What VS-NfD means for planners, construction companies, and their supply chain – and why proof of compliance decides access to major public projects.

abstraktes Schloss mit digitalen Strömen zur Darstellung von IT Sicherheit
Jonathan Bauer

Jonathan Bauer

CEO FC-X

The article explains why verifiable handling of classified information is increasingly determining access to public large-scale projects for planning and construction companies – and what this proof actually requires organizationally and technically.

The article explains why verifiable handling of classified information is increasingly determining access to public large-scale projects for planning and construction companies – and what this proof actually requires organizationally and technically.

At a glance

  • VS-NfD is the lowest level of confidentiality - but in the construction environment, it is by far the most common.

  • The requirements affect not only IT, but also roles, processes, and the entire supply chain.

  • Those who cannot demonstrate the secure handling of classified information will be excluded in the future before professional suitability is even assessed.

A market changes its access rules

Defense, internal security, energy supply, administration, critical infrastructure: In hardly any segment is the construction volume currently growing as clearly as where the public sector itself is the builder. The legislator is accompanying this development. The draft of a Bundeswehr Infrastructure Acceleration Act, adopted by the Federal Cabinet in July 2026 and currently in the parliamentary process, classifies military infrastructure projects as of overriding public interest and significantly shortens approval and participation procedures.

This is an opportunity for planning and construction companies. However, it is subject to a condition that was long a footnote in tender documents: the verifiable handling of classified information.

VS-NfD is the lowest level - and the most relevant

German security clearance law recognizes four classification levels: TOP SECRET, SECRET, CONFIDENTIAL, and RESTRICTED FOR OFFICIAL USE ONLY (VS-NfD). VS-NfD is the lowest level - and at the same time the one that practically always occurs in construction projects. It affects precisely the documents that arise in every project anyway:

  • Site and floor plans of security-relevant properties

  • Schematics of technical building equipment as well as energy and network structures

  • Security, access, and locking concepts

  • Fire protection, escape, and evacuation planning

  • As-built and revision documentation

Unlike higher classifications, VS-NfD generally does not trigger a security check for individuals. Instead, briefing and written commitment from all involved, a consistently practiced need-to-know principle, a designated responsible person with a reporting line to management, and the physical protection of the documents themselves: labeling, locked storage, transfer only with approval from the issuing office, and verifiable destruction are required.

Specific rules apply to electronic processing. Classified information does not belong in a regular email inbox or a standard cloud. Where VS-NfD is processed or transmitted digitally, approved procedures and authorized products are required; the relevant lists are maintained by the BSI.

The conflict lies in the methodology, not in the technology

This is where the real challenge arises. The construction and planning industry has consistently optimized its collaboration for openness over the years: common models, a central CDE, many participants, mobile devices on the construction site, short paths via messenger and distributor. Security requires the opposite - segmentation, traceability, documented access.

  • Typical weaknesses are therefore rarely of a technical nature:

  • Classified plans are unclassified in the general project area

  • Specialist planners and subcontractors are not contractually bound

  • There is a lack of clean separation between classified documents and the rest of the project inventory

  • Plan excerpts are photographed and forwarded on-site

  • No one can prove who received which document and when

A BIM model then is not just a BIM model.

This becomes particularly clear with digital planning information.

For example, a building model can contain information about room structures, technical facilities, security areas, routing, access systems, or critical infrastructure. The same applies to CAD plans, technical calculations, specifications, or documentation.

Once such information is classified accordingly, a classic office workplace is no longer automatically sufficient.

Specific requirements exist for secure IT workplaces, communication channels, and the security products used for handling VS-NfD.

This affects not just the encryption of individual files.

Relevant are, among others:

  • Workplace systems and operating systems

  • Identity and authorization management

  • Network architectures

  • Data storage and data exchange

  • Applied specialized applications

  • Mobile workplaces

  • Logging and administration

  • Interfaces to other companies and project partners

A security requirement quickly becomes an architectural question.

A stipulation becomes a tender criterion

Public clients are increasingly shifting these requirements forward: into participation competitions, eligibility proofs, and performance descriptions. This changes the point at which a company must deliver. Those who only start building structures after the contract is awarded have usually already lost the order.

Two points are regularly underestimated. First, the requirement moves down the entire supply chain - to the specialist planner, the expert, the surveyor. Second, a certificate does not replace security clearance: An information security management system according to ISO 27001 is a good foundation but does not cover either the approval or procedural requirements of security clearance.

What companies should do now

The implementation can succeed incrementally - provided it starts before the next tender.

Verifizierter Nutzer

Clarify exposure

Systematically check projects, clients, and contract clauses for security clearance requirements.

Implementation Check Icon

Classify information

Determine which documents are classified and consistently separate them from the rest of the project inventory.

Icon Person

Assign responsibility

Establish a responsible person with a clear mandate and reporting line to management.

Verifizierter Nutzer

Create a protected working environment

Use approved procedures, authorized products, and documented access rights instead of standard tools.

process

Involve the supply chain

Contractually bind, instruct, and verifiably control subcontractors and specialist planners.

Konzept

Enable the organization

Train participants, establish site rules, and practice handling plans and devices.

Frequently asked questions

Conclusion

Confidentiality protection is no longer a sideshow for the IT department in the construction industry but a prerequisite for market access. The good news is that the requirements are manageable and largely organizational in nature. Timing is crucial. Companies that are currently establishing classification, responsibilities, and protected work environments can demonstrate in procurement procedures what others are only promising - thereby gaining an advantage that is professionally difficult to catch up on.

How we support

The FC-Gruppe combines planning and project management expertise with IT security and digitalization. We assess the impact on your projects, develop classification and role concepts, design protected work and storage environments, and support the integration of your supply chain - from the tender phase to project operation. Contact us if you want to know where your company stands today.

Written by Jonathan Bauer

More On This Topic

Realise projects with us?

Speak directly with our experts.

FC-Gruppe GmbH

Administration
Contact Data

Am Storrenacker 8 76139 Karlsruhe