PROTECTED INFORMATION / READINESS ASSESSMENT

VS-NfD Readiness Check

A structured orientation for organisations preparing to handle VS-NfD information in industrial and project environments. Identify organisational, personnel, technical and operational gaps before they become delivery constraints.

24 questionsAnonymousLocal browser analysisImmediate readiness profile
WHY THIS MATTERS

Readiness has to exist before protected information enters the operating environment.

VS-NfD readiness is not a document exercise. Responsibilities, personnel, information handling, technical environments, physical controls and suppliers need to function as one controlled model.

This check provides a first orientation. It does not replace a formal, project-specific assessment, accreditation, certification or competent-authority guidance.

Please answer all questions before calculating the result.
01

Governance & Organisation

Ownership, documented responsibilities and an operating model for protected information.

Is responsibility for VS-NfD handling formally assigned within the organisation?
Are roles, responsibilities and escalation paths documented and understood?
Is there a current organisational handbook or equivalent procedure set for VS-NfD handling?
Are project-specific security requirements reviewed before work begins?
02

Personnel & Awareness

Access discipline, briefing, awareness and lifecycle control for involved personnel.

Are personnel granted access strictly on a need-to-know basis?
Are required briefings/instructions documented before access is granted?
Is access removed or reviewed promptly when personnel leave or change roles?
Is recurring awareness training provided for protected-information handling?
03

Information Handling

Identification, storage, transmission, reproduction, disposal and traceability.

Are VS-NfD documents and data clearly identifiable throughout their lifecycle?
Are approved storage locations and handling rules defined and enforced?
Are transmission methods restricted to approved and controlled channels?
Are printing, copying, retention and disposal processes defined and auditable?
04

IT & Secure Collaboration

Technical environments, access control, endpoint security and controlled collaboration.

Is the IT environment used for VS-NfD work explicitly approved for the intended handling model?
Are strong authentication and role-based access controls consistently enforced?
Are endpoints, removable media and data transfers technically controlled?
Are logging, monitoring and incident evidence capabilities sufficient for the environment?
05

Physical & Operational Security

Physical access, workspace controls, meetings and daily operating discipline.

Are workspaces used for protected information access-controlled and appropriate for the activity?
Are unattended documents, screens and removable media protected from unauthorised observation or access?
Are meetings, visitors and external participants managed under defined security rules?
Are deviations and security incidents reported through a known process?
06

Suppliers & Assurance

Third-party involvement, contractual controls and evidence that measures remain effective.

Are suppliers/subcontractors assessed before receiving access to protected information?
Are security requirements contractually passed down where necessary?
Are external collaboration tools and service providers reviewed before use?
Are controls periodically reviewed, tested or internally audited for continued effectiveness?
0
Readiness / 100
Assessment result

Readiness profile

Priority areas

Turn the assessment into an actionable route.

Discuss the result confidentially with Artefaktum. No unnecessary disclosure.

Start confidential dialogue →
This self-assessment provides an initial orientation only. It is not an accreditation, certification, formal VS-NfD approval or legal opinion and does not replace project-specific requirements, contractual obligations or competent-authority guidance.

FAQ

Before VS-NfD becomes operational.

What does VS-NfD readiness mean for a company?

It means more than possessing a policy. The organisation needs a coherent handling model covering responsibilities, personnel, information lifecycle, suitable technical environments, physical and operational controls and relevant third parties, aligned to the applicable project and customer requirements.

When should a defence supplier start preparing?

Ideally before protected information is introduced into the organisation or a project becomes dependent on it. Early preparation provides more room to resolve organisational and technical gaps without turning them into delivery constraints.

Is the online Readiness Check a certification or formal approval?

No. It is an initial orientation only. It does not constitute accreditation, certification, formal VS-NfD approval or legal advice and cannot replace project-specific requirements, contractual obligations or competent-authority guidance.

Does Artefaktum only assess readiness, or can you support implementation?

Artefaktum can support the route from initial gap analysis through organisational structures, procedures, personnel measures, secure handling concepts, technical and operational coordination, evidence preparation and implementation support, depending on the mandate.

Can an existing IT environment simply be adapted for VS-NfD?

That depends on the intended handling model and the applicable requirements. Existing architecture, identity and access controls, endpoints, collaboration, data flows, logging, segregation and operational administration need to be evaluated in context rather than assumed suitable.

How do we start without disclosing sensitive project details?

An initial conversation can focus on the requirement, current readiness, constraints and target state without unnecessary disclosure. More sensitive information can be introduced only when it is necessary and under an appropriate confidentiality framework.

Confidential dialogue

Readiness is easier to build before it becomes urgent.

If VS-NfD handling is becoming relevant to a contract, customer or programme, we can help establish what is required, what is missing and how to move toward a controlled operating model.

Confidential Consultation

Start a confidential conversation.

Share the essential context of your request.