Framework National Cyber & Cloud Schemes
ABDO
The Algemene Beveiligingseisen voor Defensieopdrachten (ABDO, General Security Requirements for Defence Contracts) are the security requirements the Dutch Ministry of Defence imposes on companies that handle classified or otherwise sensitive defense information under a contract. The current edition, ABDO 2017, took effect June 1, 2017 and replaced ABDO 2006.
It is organized into requirement areas for governance and organization, personnel security, physical security of locations and rooms, and cyber security, the last of which is the largest chapter and was new in 2017.
The Bureau Industrieveiligheid (Industrial Security Bureau) of the military intelligence service MIVD authorizes contractors, inspects them, and can withdraw authorization; contract termination and, for serious breaches, prosecution are the sanctions.
A successor framework known as ABRO (Algemene Beveiligingseisen Rijksoverheidsopdrachten) is being introduced for wider central government contracts, so companies should check which set applies to a given tender.
In writing, an ABDO contractor needs an appointed security officer and deputy, a security plan approved by the Bureau, personnel security procedures tied to Dutch security clearances (VGB), classified information handling and registration procedures, physical security descriptions of the approved rooms and containers, an information security policy and controls for the systems that process the information, incident reporting procedures to the Bureau, and records of training and internal checks.
help
Who has to comply
Companies awarded Dutch defense contracts that involve classified information (Departementaal Vertrouwelijk and above) or that the ministry designates as sensitive, including subcontractors. Authorization is a condition of the contract, so the trigger is the contract award, not company size.
What the assessor asks to see
Appointment of the security officer; security plan; organization chart and ownership information (including foreign ownership); personnel clearance records; classified document register and handling procedures; physical security drawings and approvals for rooms and storage; information security policy, system descriptions, and control evidence for the cyber chapter; incident reports; training records; internal control and audit records.
Assessors
Who assesses ABDO
Government inspection by the Bureau Industrieveiligheid (MIVD). There are no private certifiers; consultants prepare, the Bureau authorizes.
No firm has claimed a ABDO assessor listing yet. Claim yours →
Consultants
Who helps with ABDO
A small Dutch consultancy market (security officers for hire, ISO 27001 firms with defense practices) helps companies write the security plan, map ISO 27001 controls to the ABDO cyber chapter, and prepare for the Bureau's inspection. Engagements typically run three to nine months before authorization.
Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.
No firm has claimed a ABDO consultant listing yet. Claim yours →
Software
Tools for ABDO
Tools that name this framework in their own material.
No firm has claimed a ABDO tool listing yet. Claim yours →
Need a hand implementing it?
Find a Consultant for ABDO
Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.
Not sure where to start?
Get Help with ABDO
Tell us what you are trying to put in place. We will point you to the right tool, a consultant who can implement it, or both.