Companies executing classified federal contracts (VS-Aufträge) — for instance in defence, space or secure IT — are placed under industrial security supervision by the German Federal Ministry for Economic Affairs and Climate Action (BMWK). The legal basis is the non-public sector of the SÜG (the German Security Clearance Act, §§ 24 ff. SÜG); the operational rules come from the BMWK’s Industrial Security Manual (GHB) and the Classified Information Directive (VSA). The company must appoint a Security Officer (Sicherheitsbevollmächtigter, SiBe) who is responsible for personnel and physical security of classified information — and who requests employee security clearances through the BMWK. The pre-selection of candidates, however, rests solely with the company.
When a Company Is Placed Under Industrial Security Supervision
Companies enter industrial security supervision when they are to participate in classified federal contracts and need access to classified information at a supervision-relevant classification level. The impetus usually comes from the public contracting authority; the BMWK examines the requirements and admits the company to supervision. Without this status, the rule is: no access to correspondingly classified information, no participation in relevant tenders. For many mid-sized companies in the defence and space supply chain, industrial security supervision is therefore effectively a market-entry requirement.
The Duties of the Security Officer
The SiBe is the central interface between the company and the BMWK. Appointed by management, the SiBe must hold a security clearance personally and, under the rules of the GHB, is essentially responsible for:
- Personnel security: determining which employees are designated for classified work, preparing and submitting security clearance requests through the BMWK, and formally obligating and briefing cleared persons.
- Physical security: implementing the requirements for storing, managing and transmitting classified information under the GHB and VSA — from the registry to the IT environment.
- Ongoing duties: reporting security-relevant findings and changes, training and awareness, acting as point of contact for inspections and visits, and maintaining the overview of cleared persons.
In practice, the SiBe role is often an additional function alongside a line job — with personal responsibility towards the authority and management. That makes clear internal processes all the more important, so that requests, reports and records do not depend on a single person.
The Clearance Request: Procedure via the BMWK
The security clearance itself is and remains a sovereign act: the SiBe requests it through the BMWK, and the state conducts the vetting. The company only receives the outcome — clearance granted or refused — not the underlying findings. With the modernisation of the SÜG, the depth of state vetting has recently changed noticeably; what that means for ongoing and future procedures is covered in SÜG modernisation 2026. What remains unchanged: the procedure needs lead time, and projects involving classified information must be staffed and planned correspondingly early.
The Gap in Practice: Pre-Selection Before the Request
This is the point many companies underestimate. The state vets whom the company proposes — the selection and integrity assessment of the candidate beforehand is the company’s own responsibility. Anyone who sends a candidate into the procedure without a verified CV, without a look at their financial environment and without checking their publicly available reputation risks a refusal — and every refused request costs months during which the project position remains unfilled. A structured integrity check before the clearance request is therefore not distrust of the authority but project risk management. This applies not only to new hires: internal replacements, deputy arrangements and succession planning for the SiBe role itself should go through the same documented pre-selection step — anyone who starts the candidate search only when the need is acute loses time twice over. How state vetting and a company’s own screening are cleanly delineated is shown in state security clearance vs. employer screening.
Recommended Action
Anchor pre-selection as a fixed process step: before the SiBe files a clearance request, every candidate goes through a documented integrity check — CV verification, register and sanctions-list screening, adverse media research, business affiliations. Indicium provides audit-proof software reports for this, with dated sources and final human review (Art. 22 GDPR) — from €79 per report. We are happy to show you in a demo how this can interact with your industrial security organisation; sector insights are available under industries.
This article provides general information and does not constitute legal advice.