Navigation

Get in touch
Logo
News

Sensitive environments / VS-NfD, NATO & sensitive environments

Classified information security leaves no room for improvisation.

For sensitive project documents and mobile devices, we offer two specific Utimaco solutions: u.trust LAN Crypt 13.0.x for file encryption up to VS-NfD, and DiskEncrypt 9.10 for disk encryption up to VS-NfD as well as EU and NATO RESTRICTED. As an exclusive EMEA distributor, OTOKO® handles adaptation, installation, commissioning, maintenance and Level 1-3 support. Personnel requirements, including any required Ü3, are clarified separately for the specific deployment.

Services in detail
brown and black truck on green grass field during daytime — illustrative image
VS-NfD, NATO & sensitive environments

Analysis, integration and documented handover

Utimaco / OTOKO®

Encryption from the product to ongoing operation.

Exclusive EMEA distributor for DiskEncrypt and u.trust LAN Crypt. Your partner for custom adaptations, installation, commissioning, maintenance and Level 1-3 support.

File and folder encryption

u.trust LAN Crypt

Protect confidential files in a targeted way and control access through a planned role and key model. OTOKO® supplies u.trust LAN Crypt and integrates the solution into your file storage, workflows and administration.

For small businesses, midsize companies and enterprises: standard deployment and separate editions for classified information. We align licensing, user scope and support with your organization.

Approved edition: version 13.0.x · VS-NfD
Vendor
Utimaco IS GmbH
BSI approval
BSI-VSA-10966 · up to VS-NfD
Approved on
11/15/2025
Valid until
11/15/2028
Entry as of
11/15/2025

This entry names VS-NfD. No EU or NATO approval is shown here for this version.

u.trust LAN Crypt in detail

Disk encryption

DiskEncrypt

Protect stored data on company devices against unauthorized reading. OTOKO® supplies DiskEncrypt and handles the integration of authentication, key management, device rollout and recovery.

For small businesses, midsize companies and enterprises: standard deployment and separate editions for classified information. We align licensing, user scope and support with your organization.

Approved edition: version 9.10 · VS-NfD
Vendor
Utimaco IS GmbH
BSI approval
BSI-VSA-10717 · up to VS-NfD
Approved on
02/15/2025
Valid until
02/29/2028
Entry as of
02/15/2025
EU
RESTREINT UE/EU RESTRICTED · 03/10/2025
NATO
NATO RESTRICTED · 02/15/2025
DiskEncrypt in detail

These details apply to the versions named and their respective deployment and operating conditions. Customer-specific modifications and changes are reviewed for their effect on the scope of approval before implementation. BSI list of approved products.

Your brief for OTOKO®

VS-NfD, NATO & sensitive environments: what we take on for you.

The work packages are derived from your current situation. Your team knows the agreed scope, the required involvement and the results that should be available at handover.

Clarifying classification and use case

What information is processed, where and by whom? The answer determines the required level of protection. Together with the responsible points of contact, we turn this into a solid list of requirements.

Your result

Aligned requirements and documented responsibilities.

Selecting permitted products and versions

File and disk encryption are assessed according to their respective purpose. Approval status, version and conditions of use are reviewed for the project before a specific technical choice is included in the plan as suitable.

Your result

A well-founded selection decision for the intended setup.

Preparing operation, maintenance and recovery

Administration, key management and recovery must match the requirements. Updates and changes are also planned as controlled procedures and coordinated with the responsible bodies.

Your result

Operations and handover documentation for the agreed scope.

Coordinating access and personnel requirements

Required clearances, permissions and project access are clarified before the specific individuals are deployed. Collaboration uses the communication and documentation channels permitted for the project.

Your result

Clarified prerequisites for actual involvement in the project.

Planning & implementation

VS-NfD, NATO & sensitive environments in everyday project work.

Naming VS-NfD and NATO RESTRICTED precisely

These terms describe requirements for handling information with the corresponding classification. For technical planning, however, it must be established more precisely which information is processed and where. Mobile work, shared storage and data media place different requirements on an encryption solution. We therefore describe the use case together with you before selecting a product. Responsible security officers are involved early so that the technical assumptions match the client’s requirements.

“NATO level” is too vague for a specific offer. The scope of services described here applies to NATO RESTRICTED and to use cases suited to it. This does not imply a general commitment for higher classifications. A national approval is likewise not transferred to a different framework without review. Which approvals are required and what documentation they need is recorded in the project. This precision makes the offer, the implementation and the later acceptance easier to verify.

Reviewing product approval and system operation separately

An approved product comes with a defined scope of validity. Product version, platform and the associated conditions of use are part of the selection. Simply naming a vendor or an encryption method is therefore not enough to state suitability. OTOKO® helps review the specific solution against the planned setup and prepare the required operating procedures. Reviewing the approval documentation remains mandatory before deployment into production.

The environment also includes devices, users, administration and communication channels. Key management, recovery and maintenance must match the intended level of protection. A later update or a changed mode of operation can therefore require a new assessment. The handover documents the agreed state and any open items. It does not replace the project-specific approval by the responsible bodies but provides the technical and organizational basis needed for it within the contracted scope.

Treating Ü3 as a personnel requirement

The extended security clearance with security investigations under section 10 of the Security Clearance Check Act (SÜG) applies to individuals and certain security-sensitive activities. It is not a technical security level for a hard drive, software or a cloud. If an engagement requires such prerequisites, they are clarified for the specific personnel deployed and the intended access. The project scope must also match the permitted activities and information channels. A personnel clearance replaces neither product approval nor system approval.

For the initial exchange, an unclassified description of the task and the support needed is sufficient. Classified documents do not belong in a general contact form, public scanning services or communication channels that have not been agreed. Once the collaboration becomes concrete, we agree on points of contact and permitted channels. This also allows smaller companies to prepare a project in an orderly way: the requirements are derived from the project, not from the size of the organization or a blanket “military environment” label.

Illustrative project scenario

Example: a supplier prepares a sensitive project

A midsize company is to process documents for a client. Classification, data paths and personnel requirements are clarified first. Only then come the selection and pilot of suitable encryption and the coordination of operation and permitted collaboration.

Before you start

Questions about VS-NfD, NATO & sensitive environments.

Is Ü3 a higher encryption level than VS-NfD?

No. Ü3 is a security clearance for individuals. VS-NfD concerns the classification of information. Product approval, system operation and personnel requirements are assessed separately.

Does NATO RESTRICTED imply approval for NATO SECRET?

No. A statement for NATO RESTRICTED must not be understood as a blanket approval for higher NATO classifications.

Is the entire worldwide team available for classified projects?

A deployment is planned exclusively with the specific prerequisites, permissions and approvals required. The size of the worldwide team says nothing about the clearance of individual people for a particular project.

Which documents should we send first?

An unclassified description is enough for the initial inquiry. Permitted channels for further documents are then agreed with the responsible points of contact.

Related services

Go to the cybersecurity overview

VS-NfD, NATO & sensitive environments with OTOKO®

Describe your project. We will clarify the right starting point.

For the first exchange, an unclassified task description is sufficient. We then align permitted channels for project documents and the required access with your responsible officers.

Discuss VS-NfD, NATO & sensitive environments

Our Partners

  • Microsoft
  • Microsoft Azure
  • Amazon AWS
  • Google Cloud
  • Thales Group
  • Arrow ECS
  • Vodafone
  • IBM
  • Veeam
  • Atlassian
  • JetBrains
  • NinjaOne
  • OPSWAT
  • Utimaco
  • Eviden

Accessibility

Adjust the display to suit your needs.

A simple version is not available for this page yet.

Settings currently apply to this visit. Allow saving in Cookie settings to remember them.