Vorsprung durch Wissen und Erfahrung
Home › CADIS® Consulting
CADIS® · Defence & Armaments Industry · 2026

CADIS® – Cybersecurity Assessment for Defence Industry Suppliers –
Pass the assessment. Secure your supply chain. Build trust.

CONSUVATION GmbH is an official DEKRA consulting partner for CADIS® and guides suppliers to the defence and armaments industry through every phase of assessment preparation – from gap analysis to a successfully passed DEKRA audit. With over 25 years of consulting experience and 100% senior consultants. Across the DACH region and internationally.

25+Years of Experience
15CADIS® Assessment Modules
DEKRAOfficial Consulting Partner
Free Initial Consultation → See CADIS® Overview
Official DEKRA Consulting Partner
15 CADIS® Modules Covered
ISO 27001 · TISAX · NIS2
100% Senior Consultants
DACH Region & International
External CADIS® Officer

Quick Check

How well prepared is your company for CADIS®?

Find out in 30 seconds where your company stands in its CADIS® preparation – free and without registration.

CADIS® Maturity Check

Based on CADIS® (DEKRA) As of: August 2026 Reviewed by CONSUVATION Experts

At a Glance

What is CADIS®?

CADIS® (Cybersecurity Assessment for Defence Industry Suppliers) is the first European assessment procedure for cyber and information security developed specifically for suppliers to the defence and armaments industry. It was developed by DEKRA and is also audited by DEKRA – CADIS® is a registered trademark of DEKRA.

The procedure comprises 15 modules, selected on a risk basis via the contracting party's Supplier Criticality Evaluation (SCE). The depth of examination follows the Level of Examination (LoE 1–3) – from a plausibility check to a full on-site audit.

With growing requirements from NIS2, the German IT Security Act (BSIG) and EU procurement practice, a structured demonstration of cyber resilience along the supply chain is increasingly becoming a market access prerequisite.

The authoritative official information on modules, process and assessment scope is published by DEKRA as the conducting body: DEKRA – CADIS® (official procedure page) →

🏆 CONSUVATION – Official DEKRA Consulting Partner for CADIS®

As a certification body, DEKRA itself may not offer consulting services. CONSUVATION closes this gap: with deep knowledge of the CADIS® procedure, a direct line to the assessment body, and over 25 years of experience in information security, OT security, BCM, risk management and compliance.

▶️
Cybersecurity in the defence industry – a current TV report: German public broadcaster Hessischer Rundfunk (HR/ARD) reports, in its "Frag Schreiber" format, how Russian hacker groups specifically target defence companies such as Rheinmetall. The report is publicly available in the ARD Mediathek (in German) and illustrates why CADIS® has become so relevant for the industry.
Watch video on ARD Mediathek →

CADIS® – Structure of the Assessment Procedure

The Fundamentals of the CADIS® Assessment Procedure

CADIS® is not a certification procedure in the classic ISO sense, but a modular assessment procedure by DEKRA: management system, risk-based module selection and a documented process model come together.

Building Block 1

CADIS® Management System

Structural and process organisation as the foundation for all CADIS® modules – developed by CONSUVATION and governs the modules deployed within your organisation.

Basis for All Modules

Building Block 2

15 Assessment Modules & Module Selection

CADIS® covers 15 topic areas from IT to OT security – now including the new Geheimschutz (protection of classified information) module. The contracting party determines the relevant modules on a risk basis via the Supplier Criticality Evaluation (SCE).

15 Modules, Risk-Based

Building Block 3

Level of Examination (LoE 1–3)

The depth of examination per module ranges from a plausibility check (LoE 1) to a full on-site audit (LoE 3) – matched to the criticality and risk profile of the supplier.

Tiered Examination Depth

Building Block 4

IT & OT Security

CADIS® assesses both classic IT with a focus on data management and operational technology (OT) – production facilities, machinery and building technology (IACS per IEC 62443).

IT + OT Covered

Building Block 5

CADIS® Process Model

Documented end-to-end processes for identification, preparation, implementation and evidencing of CADIS® requirements – visualised as a flowchart and directly applicable to daily operations.

Documented & Visualised

Full Overview

The 15 CADIS® Modules at a Glance

01Physical Security at the Site
02Organisation of Information Security
03IT Security
04OT Security
05Use of Cloud-Based and External Services
06Continuity Management
07Incident and Crisis Management
08Identity and Access Management
09Security in Software Development
10Information Security in Project Management / HR / Procurement
11Data Protection
12Compliance Management System
13Use of Artificial Intelligence
14Transport and Handling
15Geheimschutz (Protection of Classified Information) NEW

Source: official DEKRA CADIS® product sheet; Module 15 (Geheimschutz) was added after the product sheet's publication.

DEKRA
Assessment Body
DEKRA assesses – we prepare you: CADIS® was developed by DEKRA and is also assessed by DEKRA; CADIS® is a registered trademark of DEKRA. As a certification body, DEKRA itself may not offer consulting services – CONSUVATION closes this gap as an official DEKRA consulting partner with a direct line to the assessment body.

Our Tool

The CONSUVATION Process Model and Application for Implementing CADIS®

Rather than a plain collection of policies, we provide a documented and visualised process model that translates the requirements of the CADIS® modules into a repeatable, auditable workflow – from gap analysis to assessment-ready evidence for DEKRA.

STEP 1 Scope & SCE Define modules STEP 2 Gap Analysis Assess current state STEP 3 CADIS® Implementation Implement measures STEP 4 Evidence Compilation Compile documentation STEP 5 DEKRA Audit Assessment & approval Two-year surveillance cycle (continuous improvement)

Our Approach

From First Contact to a Successfully Passed CADIS® Audit

Structured, predictable and without surprises – our proven approach follows the 8-stage CADIS® assessment process and leads to documentation that genuinely holds up to DEKRA.

01

Initial Consultation & Scoping

Free initial consultation, clarify the likely assessment scope and Level of Examination (LoE), create a project plan.

02

Gap Analysis

Assess existing information security (ISMS, OT), compare it against the relevant CADIS® modules, identify gaps and action areas.

03

Build or Extend the Management System

Build a new CADIS® management system or extend an existing ISMS (e.g. per ISO 27001/TISAX) to cover the CADIS® requirements.

04

Implement Processes, Policies & CADIS®

Apply the CADIS® process model and policy templates, conduct risk assessments, implement technical and organisational measures (TOM) for IT and OT.

05

Training & Evidence Compilation

Train employees via the e-learning portal, jointly define and compile the evidence required for the DEKRA assessment.

06

DEKRA Audit & Surveillance

Support the DEKRA kick-off and main assessment, manage non-conformities, prepare the surveillance audit in year two.

CADIS® & Other Standards

How CADIS® Relates to Other Standards

CADIS® takes into account all relevant norms and standards in the field of cybersecurity and can be integrated into existing management systems. CONSUVATION connects CADIS® with your established standards.

CADIS® → ISO 27001

If you already have an ISMS per ISO 27001, the CADIS® requirements can be pragmatically integrated into it rather than building a parallel system. ISO 27001 provides the ISMS foundation for several CADIS® modules.

ISMSIntegrationFoundation

CADIS® → TISAX

Companies with a TISAX assessment already have robust evidence regarding information security and, in part, OT availability. This evidence can be directly reused for several CADIS® modules.

TISAX ISAAutomotiveReuse

CADIS® → NIS2

NIS2 affects the defence and armaments industry – in principle, all companies in the sector are considered critical under NIS2, regardless of revenue or employee thresholds. CADIS® provides the structured evidence that practically covers NIS2 requirements.

NIS2Critical SectorEvidence

CADIS® → IEC 62443 (OT Security)

CADIS® addresses OT risk in manufacturing through a dedicated module. IEC 62443 provides the technical reference standard for industrial automation and control systems (IACS) – CONSUVATION brings both perspectives together.

OT SecurityIACSIEC 62443

CADIS® → ISO 22301 (BCM)

Several CADIS® modules require evidence of contingency and continuity capability for defence suppliers. An established BCMS per ISO 22301 provides the structured foundation and directly usable evidence for this.

BCMContinuityEvidence

CADIS® → BSIG

Germany's IT Security Act (BSIG) forms a further regulatory framework for cybersecurity. CADIS® modules pick up its requirements and translate them into an industry-specific assessment format for the defence supply chain.

BSIGRegulationSupply Chain

Core Elements

What a Successful CADIS® Preparation Looks Like

CADIS® requires more than a self-declaration – it is about lived processes, robust technical measures, and documentation that holds up to DEKRA.

Context

Scope & Supplier Criticality Evaluation

Clarify your role in the supply chain and the relevant CADIS® modules, interpret the contracting party's Supplier Criticality Evaluation (SCE) result, anticipate the Level of Examination.

Leadership

Top Management Commitment

Senior management takes responsibility for cyber resilience in the supply chain, provides resources, and designates a responsible function or external officer.

Risk

IT & OT Risk Assessment

Systematically identify, analyse and prioritise risks for IT and OT – including supply chain and third-party risks.

Implementation

Technical & Organisational Measures

Review existing TOM, develop and implement a target model, adapt security incident and reporting processes to CADIS® requirements.

Operations

Training & Awareness

Train employees via e-learning on the relevant CADIS® modules, demonstrate effectiveness through testing, document attendance certificates.

Evidence

Evidence Compilation & Surveillance

Systematically compile the evidence required for the DEKRA assessment, track module status via dashboards, prepare the surveillance audit in year two.

Implementation Checklist

CADIS® – What Belongs in a Successful Assessment Preparation?

📋 Organisational Measures

  • 🏛️Clarify the assessment scope and relevant CADIS® modules based on the SCE
  • 📜Build a CADIS® management system or extend an existing ISMS
  • 👤Designate responsibility (internal or external CADIS® officer)
  • 🔍Conduct a gap analysis of the current state
  • 📋Realistically assess the Level of Examination (LoE) per module
  • 🎓Introduce a training and awareness programme for relevant modules
  • 🔄Regularly track internal non-conformity status
  • 📊Establish status and progress meetings with management

🔧 Operational & Methodological Measures

  • 🔐Systematically conduct risk assessments for IT and OT
  • 🛡️Implement technical and organisational measures (TOM) per module
  • 🔒Adapt the security incident and reporting process to CADIS® requirements
  • 💾Prepare documentation and evidence for assessment readiness
  • 📡Set up OT-specific tools and protective measures
  • 🚨Define escalation and non-conformity management
  • ☁️Check integration into existing management systems (ISO 27001, TISAX)
  • 🔗Schedule DEKRA kick-off, main assessment and surveillance audit

Services

CADIS® Consulting, All From a Single Source

From gap analysis to a successfully passed DEKRA audit – all from a single source, with senior consultants and an official DEKRA consulting partnership.

01

CADIS® Gap Analysis

Systematic as-is/to-be comparison against the relevant CADIS® modules: what exists, what is missing, what must be prioritised – clearly documented with an action plan.

CADIS®Gap Analysis

02

CADIS® Management System Setup

Full setup of a CADIS® management system or pragmatic extension of your existing ISMS (e.g. ISO 27001, TISAX) to cover the CADIS® requirements.

Management SystemISMS Extension

03

CADIS® Process Model & Policies

Deployment of our CADIS® process model with ready-made policy templates and organisational tools for all 15 modules – individually tailored to your company.

Process ModelPolicies

04

Technical & Organisational Measures (TOM)

Review of existing TOM for IT and OT, development of a target model, and support in selecting suitable technical security solutions.

IT SecurityOT Security

05

Training & E-Learning Portal

E-learning platform with suitable training content for the CADIS® modules in German and English, effectiveness verification via test and automatic attendance certificate.

E-LearningAwareness

06

CADIS® Dashboards

Dashboards individually tailored to your system environment for managing CADIS® operations: module status, action tracking and management reporting.

DashboardOperations Management

07

External CADIS® Officer

A fixed point of contact acting as project coordinator, documentation owner and interface to DEKRA – available remotely, with optional on-site visits.

External OfficerDEKRA Interface

08

DEKRA Audit & Surveillance Support

Support for kick-off, main assessment and interviews with DEKRA, non-conformity management through to sign-off, preparation of the surveillance audit in year two.

DEKRA AuditSurveillance Audit

Frequently Asked Questions

CADIS® – Frequently Asked Questions

What is CADIS®?
CADIS® (Cybersecurity Assessment for Defence Industry Suppliers) is the first European assessment procedure for cyber and information security developed specifically for suppliers to the defence and armaments industry. It was developed by DEKRA and is also audited by DEKRA; CADIS® is a registered trademark of DEKRA.
Who is CADIS® relevant for?
CADIS® applies to all companies that are or want to become suppliers or service providers in the defence or armaments industry. Since NIS2 generally treats all companies in the sector as critical, CADIS® can become relevant even regardless of revenue or employee thresholds.
How many modules does CADIS® have, and who determines them?
CADIS® comprises 15 modules. Which of these are assessed for your company is determined by the system manufacturer or contracting party via the Supplier Criticality Evaluation (SCE) – on a risk basis, not across the board. The depth of examination is further governed by the Level of Examination (LoE 1–3).
Can CONSUVATION conduct the CADIS® assessment itself?
No. DEKRA is the certification body and, as such, may not offer consulting services. CONSUVATION is an official DEKRA consulting partner and prepares companies in a structured way for the DEKRA assessment – with a direct line to the assessment body.
What happens if no ISMS is in place yet?
In that case, we draw on our management system model for CADIS® and implement the requirements from a "greenfield" position, in line with the state of the art based on international standards. If an ISMS is already in place (e.g. per ISO 27001 or TISAX), we pragmatically extend it to cover the CADIS® requirements.
How are CADIS® and OT security related?
Many companies in the defence and armaments industry have a production area with corresponding OT risk. CADIS® addresses this risk through a dedicated module aligned with standards such as IEC 62443.

Our CADIS® Solutions

Complete Solution for Defence Suppliers of Any Size

Project plan, process models, our CADIS® application, training portal, dashboard and external CADIS® officer – all from a single source. Scalable for small, mid-sized and large companies.

The 5 Building Blocks of Our Complete CADIS® Solution

🏛️

CADIS® Management System

Foundation & Governance

🔄

Process Models & Policies

Up to All 15 Modules

🎓

Training Portal

DE & EN, AI & OT Modules

📊

CADIS® Dashboard

Module Status & Tracking

👤

External CADIS® Officer

Remote + Optional On-Site

Our Tool

Our CADIS® Application: Your Central Platform for Implementation

Instead of scattered Word and Excel files, we provide you with a dedicated application for CADIS® implementation. It brings together all policies, work instructions, documents and risk analyses in one place – including a dedicated employee portal with the policies, processes, work resources and training relevant to each role.

Policies

All CADIS®-relevant policies stored centrally, version-controlled and mapped to the respective modules.

Work Instructions

Concrete work instructions for practical implementation in day-to-day operations – not just theory.

Document Management

Central management of all evidence documents – version-controlled, traceable and audit-ready at any time.

Risk Analysis

Structured risk analysis per module as the basis for prioritised action planning.

Employee Portal

Role-based access for all employees to the policies, processes, work resources and training relevant to them.

Small Companies

CADIS® BASIC

Entry-level solution for small suppliers. Includes all essential building blocks for the first up to 6 CADIS® modules – pragmatic, fast and cost-efficient.

  • Standardised project plan
  • Up to 6 CADIS® modules covered
  • Ready-made policy templates & OT tools
  • Training portal for up to 15 users
  • Fixed point of contact, support for DEKRA kick-off
Request package →
Large Enterprises

CADIS® ENTERPRISE

Maximum solution for complex organisations – with multi-site planning, all 15 modules, a dedicated CADIS® officer and individually drafted policies.

  • All PROFESSIONAL services
  • Multi-site planning & all 15 CADIS® modules
  • Individually drafted policies, on-site gap workshop
  • Dedicated external CADIS® officer
  • Multi-site dashboard overview
  • On-site contingent included, status meetings on request
Request package →

Detailed Package Comparison

Service Basic
Small Companies
Professional
Mid-Sized SMEs
Enterprise
Large Enterprises
Project Plan
Standardised project plan
Individual resource plan
RACI matrix
Multi-site planning
Process Models & Policies
CADIS® modules coveredup to 6up to 10all 15
Ready-made policy templates✔ adapted✔ individual
OT-specific tools
ISO 27001 integrationon request
Gap analysis workshop✔ remote✔ remote / on-site
Training Portal
Number of usersup to 15up to 75on request
AI & OT modules
Data protection moduleon request
Dashboard
Module status & action tracking
Management reporting
Multi-site overview
External CADIS® Officer
Fixed point of contact✔ dedicated
Status meetingsQuarterlyQuarterlyon request
On-site visitsoptionalContingent included
DEKRA kick-off support
DEKRA main assessment support
Surveillance audit support

The Building Block in Detail

The External CADIS® Officer

Cybersecurity in the defence environment is a cross-functional role – it touches IT, OT, HR, procurement and corporate leadership at the same time. Many companies have neither the internal capacity nor the specific CADIS® expertise for this role. Our external officer takes on this function as a fixed point of contact, coordinator and accountable owner – available remotely, with optional on-site visits from the Professional package onward.

Project Coordination

Steering the preparation process, coordinating with departments, tracking progress.

Documentation Ownership

Keeping all evidence, policies and processes complete and up to date.

Internal Gap Monitoring

Continuous review of implementation status, prioritising open actions.

Interface to DEKRA

Point of contact during the assessment, coordinating kick-off, interviews and the audit.

Non-Conformity Management

Creating an action plan and supporting implementation through to sign-off.

Surveillance Cycle

Preparing and supporting the surveillance audit in the second year.

All packages include an individual project plan and are tailored to your company. Remote support included – on-site visits available on request. Schedule a Consultation Now →

Our Expertise

Official DEKRA Consulting Partner for CADIS® – Experience That Counts

CONSUVATION deploys exclusively senior consultants. With over 25 years of consulting experience in information security, IT security, OT, compliance, data protection and risk management, we are among the most experienced CADIS® consulting firms in the DACH region.

Our consultants bring experience from numerous ISO 27001, TISAX and OT security projects. We combine this practice-proven knowledge with the specific requirements of the 15 CADIS® modules to develop an assessment preparation that genuinely holds up to DEKRA.

As active members of ISO working groups (including ISO 27001), we bring insider knowledge that flows directly into your CADIS® implementation.

Our Module Expertise: All 15 CADIS® Areas

CONSUVATION offers solution models for all 15 CADIS® assessment areas, which we individually adapt to your company. Our modules are aligned with the relevant standards (ISO 27001, IEC 62443, NIS2) and ensure an audit-compliant implementation – without duplicate work, with maximum standards coverage.

25+
Years of Experience
15
CADIS® Modules Covered
DEKRA
Official Partner
100%
Senior Consultants

Official DEKRA Consulting Partner

Experienced consultants for CADIS® – from gap analysis to a successfully passed DEKRA audit

CISA · CISM · CRISC · CGEIT

The most renowned ISACA certifications – from IT audit to IT governance to risk management

ISO 27001 · TISAX · IEC 62443

An integrated security framework for IT and OT – in a single project, without duplicate work

Cross-Functional Experience Spanning Over 25 Years

Experience from information security, OT security, data protection, BCM and risk management projects

Free Download

CADIS® Whitepaper: Cybersecurity Assessment Defence Industry Suppliers

The first European assessment procedure in the defence and armaments industry for demonstrating implemented cybersecurity and information security.

  • Overview of the 15 CADIS® modules and the Supplier Criticality Evaluation (SCE)
  • Step-by-step process from gap analysis to the DEKRA audit
  • Checklist for self-assessing your maturity level
  • Real-world examples from the defence industry supply chain
Request Whitepaper

Once we receive your request with your contact details, we'll send you the download link by email.

Author: Peter Rentschler, CONSUVATION GmbH · May 2026

CADIS Whitepaper cover page: Cybersecurity Assessment Defence Industry Suppliers | CADIS – CONSUVATION GmbH
📄
The bigger picture: market access to the defense industry. Besides CADIS®, AQAP, IEC 62443, NIS-2 and security clearance requirements also decide your participation in defense contracts. Our whitepaper "Market Access Through Standards Compliance" maps out all five requirement layers – including a concrete 5-phase roadmap.
View "Market Access" Whitepaper →
🧭
Want to keep track of the entire standards and regulatory landscape for the defense industry? Our main page "Defense & Armament" brings together all relevant standards and consulting services for the sector.
Visit Main Page →
PR

Author & Subject-Matter Responsibility

Peter Rentschler

Managing Director, CONSUVATION GmbH

Over 25 years of consulting experience in information security, OT security, data protection and compliance. Active member of ISO working groups (including ISO 27001) and subject-matter lead for CONSUVATION's CADIS® consulting practice as an official DEKRA consulting partner.

Get Started Now

Ready for Your CADIS® Assessment?

Let's work out together where your company stands today – and what it needs to meet the CADIS® requirements in a structured, pragmatic way. In a free, no-obligation 30-minute initial call, we'll clarify the assessment scope, the likely LoE, and the right package for you.

Download CADIS® Checklist (PDF) Request a Consultation
CONSUVATION GmbH · Tilsiter Str. 6 · D-71065 Sindelfingen, Germany · +49 (0) 7031.4181-860 · contact@consuvation.com · Legal Notice
Read now →