Vorsprung durch Wissen und Erfahrung
Home › CADIS Consulting
CADIS · Defence & Armaments Industry · 2026

CADIS – Cybersecurity Assessment for Defence Industry Suppliers –
Pass the assessment. Secure your supply chain. Build trust.

CONSUVATION GmbH is an official DEKRA consulting partner for CADIS and guides suppliers to the defence and armaments industry through every phase of assessment preparation – from gap analysis to a successfully passed DEKRA audit. With over 25 years of consulting experience and 100% senior consultants. Across the DACH region and internationally.

25+Years of Experience
14CADIS Assessment Modules
DEKRAOfficial Consulting Partner
Free Initial Consultation → See CADIS Overview
Official DEKRA Consulting Partner
14 CADIS Modules Covered
ISO 27001 · TISAX · NIS2
100% Senior Consultants
DACH Region & International
External CADIS Officer

Quick Check

How well prepared is your company for CADIS?

Find out in 30 seconds where your company stands in its CADIS preparation – free and without registration.

CADIS Maturity Check

Based on CADIS (DEKRA) As of: June 2026 Reviewed by CONSUVATION Experts

At a Glance

What is CADIS?

CADIS (Cybersecurity Assessment for Defence Industry Suppliers) is the first European assessment procedure for cyber and information security developed specifically for suppliers to the defence and armaments industry. It was developed by DEKRA and is also audited by DEKRA – CADIS is a registered trademark of DEKRA.

The procedure comprises 14 modules, selected on a risk basis via the contracting party's Supplier Criticality Evaluation (SCE). The depth of examination follows the Level of Examination (LoE 1–3) – from a plausibility check to a full on-site audit.

With growing requirements from NIS2, the German IT Security Act (BSIG) and EU procurement practice, a structured demonstration of cyber resilience along the supply chain is increasingly becoming a market access prerequisite.

🏆 CONSUVATION – Official DEKRA Consulting Partner for CADIS

As a certification body, DEKRA itself may not offer consulting services. CONSUVATION closes this gap: with deep knowledge of the CADIS procedure, a direct line to the assessment body, and over 25 years of experience in information security, OT security, BCM, risk management and compliance.

▶️
Cybersecurity in the defence industry – a current TV report: German public broadcaster Hessischer Rundfunk (HR/ARD) reports, in its "Frag Schreiber" format, how Russian hacker groups specifically target defence companies such as Rheinmetall. The report is publicly available in the ARD Mediathek (in German) and illustrates why CADIS has become so relevant for the industry.
Watch video on ARD Mediathek →

CADIS – Structure of the Assessment Procedure

The Fundamentals of the CADIS Assessment Procedure

CADIS is not a certification procedure in the classic ISO sense, but a modular assessment procedure by DEKRA: management system, risk-based module selection and a documented process model come together.

Building Block 1

CADIS Management System

Structural and process organisation as the foundation for all CADIS modules – developed by CONSUVATION and governs the modules deployed within your organisation.

Basis for All Modules

Building Block 2

14 Assessment Modules & Module Selection

CADIS covers 14 topic areas from IT to OT security. The contracting party determines the relevant modules on a risk basis via the Supplier Criticality Evaluation (SCE).

14 Modules, Risk-Based

Building Block 3

Level of Examination (LoE 1–3)

The depth of examination per module ranges from a plausibility check (LoE 1) to a full on-site audit (LoE 3) – matched to the criticality and risk profile of the supplier.

Tiered Examination Depth

Building Block 4

IT & OT Security

CADIS assesses both classic IT with a focus on data management and operational technology (OT) – production facilities, machinery and building technology (IACS per IEC 62443).

IT + OT Covered

Building Block 5

CADIS Process Model

Documented end-to-end processes for identification, preparation, implementation and evidencing of CADIS requirements – visualised as a flowchart and directly applicable to daily operations.

Documented & Visualised
DEKRA
Assessment Body
DEKRA assesses – we prepare you: CADIS was developed by DEKRA and is also assessed by DEKRA; CADIS is a registered trademark of DEKRA. As a certification body, DEKRA itself may not offer consulting services – CONSUVATION closes this gap as an official DEKRA consulting partner with a direct line to the assessment body.

Our Tool

The CONSUVATION CADIS Process Model

Rather than a plain collection of policies, we provide a documented and visualised process model that translates the requirements of the CADIS modules into a repeatable, auditable workflow – from gap analysis to assessment-ready evidence for DEKRA.

STEP 1 Scope & SCE Define modules STEP 2 Gap Analysis Assess current state STEP 3 CADIS Implementation Implement measures STEP 4 Evidence Compilation Compile documentation STEP 5 DEKRA Audit Assessment & approval Two-year surveillance cycle (continuous improvement)

Our Approach

From First Contact to a Successfully Passed CADIS Audit

Structured, predictable and without surprises – our proven approach follows the 8-stage CADIS assessment process and leads to documentation that genuinely holds up to DEKRA.

01

Initial Consultation & Scoping

Free initial consultation, clarify the likely assessment scope and Level of Examination (LoE), create a project plan.

02

Gap Analysis

Assess existing information security (ISMS, OT), compare it against the relevant CADIS modules, identify gaps and action areas.

03

Build or Extend the Management System

Build a new CADIS management system or extend an existing ISMS (e.g. per ISO 27001/TISAX) to cover the CADIS requirements.

04

Implement Processes, Policies & CADIS

Apply the CADIS process model and policy templates, conduct risk assessments, implement technical and organisational measures (TOM) for IT and OT.

05

Training & Evidence Compilation

Train employees via the e-learning portal, jointly define and compile the evidence required for the DEKRA assessment.

06

DEKRA Audit & Surveillance

Support the DEKRA kick-off and main assessment, manage non-conformities, prepare the surveillance audit in year two.

CADIS & Other Standards

How CADIS Relates to Other Standards

CADIS takes into account all relevant norms and standards in the field of cybersecurity and can be integrated into existing management systems. CONSUVATION connects CADIS with your established standards.

CADIS → ISO 27001

If you already have an ISMS per ISO 27001, the CADIS requirements can be pragmatically integrated into it rather than building a parallel system. ISO 27001 provides the ISMS foundation for several CADIS modules.

ISMSIntegrationFoundation

CADIS → TISAX

Companies with a TISAX assessment already have robust evidence regarding information security and, in part, OT availability. This evidence can be directly reused for several CADIS modules.

TISAX ISAAutomotiveReuse

CADIS → NIS2

NIS2 affects the defence and armaments industry – in principle, all companies in the sector are considered critical under NIS2, regardless of revenue or employee thresholds. CADIS provides the structured evidence that practically covers NIS2 requirements.

NIS2Critical SectorEvidence

CADIS → IEC 62443 (OT Security)

CADIS addresses OT risk in manufacturing through a dedicated module. IEC 62443 provides the technical reference standard for industrial automation and control systems (IACS) – CONSUVATION brings both perspectives together.

OT SecurityIACSIEC 62443

CADIS → ISO 22301 (BCM)

Several CADIS modules require evidence of contingency and continuity capability for defence suppliers. An established BCMS per ISO 22301 provides the structured foundation and directly usable evidence for this.

BCMContinuityEvidence

CADIS → BSIG

Germany's IT Security Act (BSIG) forms a further regulatory framework for cybersecurity. CADIS modules pick up its requirements and translate them into an industry-specific assessment format for the defence supply chain.

BSIGRegulationSupply Chain

Core Elements

What a Successful CADIS Preparation Looks Like

CADIS requires more than a self-declaration – it is about lived processes, robust technical measures, and documentation that holds up to DEKRA.

Context

Scope & Supplier Criticality Evaluation

Clarify your role in the supply chain and the relevant CADIS modules, interpret the contracting party's Supplier Criticality Evaluation (SCE) result, anticipate the Level of Examination.

Leadership

Top Management Commitment

Senior management takes responsibility for cyber resilience in the supply chain, provides resources, and designates a responsible function or external officer.

Risk

IT & OT Risk Assessment

Systematically identify, analyse and prioritise risks for IT and OT – including supply chain and third-party risks.

Implementation

Technical & Organisational Measures

Review existing TOM, develop and implement a target model, adapt security incident and reporting processes to CADIS requirements.

Operations

Training & Awareness

Train employees via e-learning on the relevant CADIS modules, demonstrate effectiveness through testing, document attendance certificates.

Evidence

Evidence Compilation & Surveillance

Systematically compile the evidence required for the DEKRA assessment, track module status via dashboards, prepare the surveillance audit in year two.

Implementation Checklist

CADIS – What Belongs in a Successful Assessment Preparation?

📋 Organisational Measures

  • 🏛️Clarify the assessment scope and relevant CADIS modules based on the SCE
  • 📜Build a CADIS management system or extend an existing ISMS
  • 👤Designate responsibility (internal or external CADIS officer)
  • 🔍Conduct a gap analysis of the current state
  • 📋Realistically assess the Level of Examination (LoE) per module
  • 🎓Introduce a training and awareness programme for relevant modules
  • 🔄Regularly track internal non-conformity status
  • 📊Establish status and progress meetings with management

🔧 Operational & Methodological Measures

  • 🔐Systematically conduct risk assessments for IT and OT
  • 🛡️Implement technical and organisational measures (TOM) per module
  • 🔒Adapt the security incident and reporting process to CADIS requirements
  • 💾Prepare documentation and evidence for assessment readiness
  • 📡Set up OT-specific tools and protective measures
  • 🚨Define escalation and non-conformity management
  • ☁️Check integration into existing management systems (ISO 27001, TISAX)
  • 🔗Schedule DEKRA kick-off, main assessment and surveillance audit

Services

CADIS Consulting, All From a Single Source

From gap analysis to a successfully passed DEKRA audit – all from a single source, with senior consultants and an official DEKRA consulting partnership.

01

CADIS Gap Analysis

Systematic as-is/to-be comparison against the relevant CADIS modules: what exists, what is missing, what must be prioritised – clearly documented with an action plan.

CADISGap Analysis

02

CADIS Management System Setup

Full setup of a CADIS management system or pragmatic extension of your existing ISMS (e.g. ISO 27001, TISAX) to cover the CADIS requirements.

Management SystemISMS Extension

03

CADIS Process Model & Policies

Deployment of our CADIS process model with ready-made policy templates and organisational tools for all 14 modules – individually tailored to your company.

Process ModelPolicies

04

Technical & Organisational Measures (TOM)

Review of existing TOM for IT and OT, development of a target model, and support in selecting suitable technical security solutions.

IT SecurityOT Security

05

Training & E-Learning Portal

E-learning platform with suitable training content for the CADIS modules in German and English, effectiveness verification via test and automatic attendance certificate.

E-LearningAwareness

06

CADIS Dashboards

Dashboards individually tailored to your system environment for managing CADIS operations: module status, action tracking and management reporting.

DashboardOperations Management

07

External CADIS Officer

A fixed point of contact acting as project coordinator, documentation owner and interface to DEKRA – available remotely, with optional on-site visits.

External OfficerDEKRA Interface

08

DEKRA Audit & Surveillance Support

Support for kick-off, main assessment and interviews with DEKRA, non-conformity management through to sign-off, preparation of the surveillance audit in year two.

DEKRA AuditSurveillance Audit

Frequently Asked Questions

CADIS – Frequently Asked Questions

What is CADIS?
CADIS (Cybersecurity Assessment for Defence Industry Suppliers) is the first European assessment procedure for cyber and information security developed specifically for suppliers to the defence and armaments industry. It was developed by DEKRA and is also audited by DEKRA; CADIS is a registered trademark of DEKRA.
Who is CADIS relevant for?
CADIS applies to all companies that are or want to become suppliers or service providers in the defence or armaments industry. Since NIS2 generally treats all companies in the sector as critical, CADIS can become relevant even regardless of revenue or employee thresholds.
How many modules does CADIS have, and who determines them?
CADIS comprises 14 modules. Which of these are assessed for your company is determined by the system manufacturer or contracting party via the Supplier Criticality Evaluation (SCE) – on a risk basis, not across the board. The depth of examination is further governed by the Level of Examination (LoE 1–3).
Can CONSUVATION conduct the CADIS assessment itself?
No. DEKRA is the certification body and, as such, may not offer consulting services. CONSUVATION is an official DEKRA consulting partner and prepares companies in a structured way for the DEKRA assessment – with a direct line to the assessment body.
What happens if no ISMS is in place yet?
In that case, we draw on our management system model for CADIS and implement the requirements from a "greenfield" position, in line with the state of the art based on international standards. If an ISMS is already in place (e.g. per ISO 27001 or TISAX), we pragmatically extend it to cover the CADIS requirements.
How are CADIS and OT security related?
Many companies in the defence and armaments industry have a production area with corresponding OT risk. CADIS addresses this risk through a dedicated module aligned with standards such as IEC 62443.

Our CADIS Solutions

Complete Solution for Defence Suppliers of Any Size

Project plan, process models, training portal, dashboard and external CADIS officer – all from a single source. Scalable for small, mid-sized and large companies.

The 5 Building Blocks of Our Complete CADIS Solution

🏛️

CADIS Management System

Foundation & Governance

🔄

Process Models & Policies

Up to All 14 Modules

🎓

Training Portal

DE & EN, AI & OT Modules

📊

CADIS Dashboard

Module Status & Tracking

👤

External CADIS Officer

Remote + Optional On-Site

Small Companies

CADIS BASIC

Entry-level solution for small suppliers. Includes all essential building blocks for the first up to 6 CADIS modules – pragmatic, fast and cost-efficient.

  • Standardised project plan
  • Up to 6 CADIS modules covered
  • Ready-made policy templates & OT tools
  • Training portal for up to 15 users
  • Fixed point of contact, support for DEKRA kick-off
Request package →
Large Enterprises

CADIS ENTERPRISE

Maximum solution for complex organisations – with multi-site planning, all 14 modules, a dedicated CADIS officer and individually drafted policies.

  • All PROFESSIONAL services
  • Multi-site planning & all 14 CADIS modules
  • Individually drafted policies, on-site gap workshop
  • Dedicated external CADIS officer
  • Multi-site dashboard overview
  • On-site contingent included, status meetings on request
Request package →

Detailed Package Comparison

Service Basic
Small Companies
Professional
Mid-Sized SMEs
Enterprise
Large Enterprises
Project Plan
Standardised project plan
Individual resource plan
RACI matrix
Multi-site planning
Process Models & Policies
CADIS modules coveredup to 6up to 10all 14
Ready-made policy templates✔ adapted✔ individual
OT-specific tools
ISO 27001 integrationon request
Gap analysis workshop✔ remote✔ remote / on-site
Training Portal
Number of usersup to 15up to 75on request
AI & OT modules
Data protection moduleon request
Dashboard
Module status & action tracking
Management reporting
Multi-site overview
External CADIS Officer
Fixed point of contact✔ dedicated
Status meetingsQuarterlyQuarterlyon request
On-site visitsoptionalContingent included
DEKRA kick-off support
DEKRA main assessment support
Surveillance audit support

The Building Block in Detail

The External CADIS Officer

Cybersecurity in the defence environment is a cross-functional role – it touches IT, OT, HR, procurement and corporate leadership at the same time. Many companies have neither the internal capacity nor the specific CADIS expertise for this role. Our external officer takes on this function as a fixed point of contact, coordinator and accountable owner – available remotely, with optional on-site visits from the Professional package onward.

Project Coordination

Steering the preparation process, coordinating with departments, tracking progress.

Documentation Ownership

Keeping all evidence, policies and processes complete and up to date.

Internal Gap Monitoring

Continuous review of implementation status, prioritising open actions.

Interface to DEKRA

Point of contact during the assessment, coordinating kick-off, interviews and the audit.

Non-Conformity Management

Creating an action plan and supporting implementation through to sign-off.

Surveillance Cycle

Preparing and supporting the surveillance audit in the second year.

All packages include an individual project plan and are tailored to your company. Remote support included – on-site visits available on request. Schedule a Consultation Now →

Our Expertise

Official DEKRA Consulting Partner for CADIS – Experience That Counts

CONSUVATION deploys exclusively senior consultants. With over 25 years of consulting experience in information security, IT security, OT, compliance, data protection and risk management, we are among the most experienced CADIS consulting firms in the DACH region.

Our consultants bring experience from numerous ISO 27001, TISAX and OT security projects. We combine this practice-proven knowledge with the specific requirements of the 14 CADIS modules to develop an assessment preparation that genuinely holds up to DEKRA.

As active members of ISO working groups (including ISO 27001), we bring insider knowledge that flows directly into your CADIS implementation.

Our Module Expertise: All 14 CADIS Areas

CONSUVATION offers solution models for all 14 CADIS assessment areas, which we individually adapt to your company. Our modules are aligned with the relevant standards (ISO 27001, IEC 62443, NIS2) and ensure an audit-compliant implementation – without duplicate work, with maximum standards coverage.

25+
Years of Experience
14
CADIS Modules Covered
DEKRA
Official Partner
100%
Senior Consultants

Official DEKRA Consulting Partner

Experienced consultants for CADIS – from gap analysis to a successfully passed DEKRA audit

CISA · CISM · CRISC · CGEIT

The most renowned ISACA certifications – from IT audit to IT governance to risk management

ISO 27001 · TISAX · IEC 62443

An integrated security framework for IT and OT – in a single project, without duplicate work

Cross-Functional Experience Spanning Over 25 Years

Experience from information security, OT security, data protection, BCM and risk management projects

Get Started Now

Ready for Your CADIS Assessment?

Let's work out together where your company stands today – and what it needs to meet the CADIS requirements in a structured, pragmatic way. In a free, no-obligation 30-minute initial call, we'll clarify the assessment scope, the likely LoE, and the right package for you.

Download CADIS Checklist (PDF) Request a Consultation
CONSUVATION GmbH · Tilsiter Str. 6 · D-71065 Sindelfingen, Germany · +49 (0) 7031.4181-860 · contact@consuvation.com