ABDO stands for Algemene Beveiligingseisen voor Defensieopdrachten, the general security requirements for defence contracts issued by the Dutch Ministry of Defence. If you supply the Dutch MoD and will handle classified information, ABDO is the baseline you are held to. The version in force is ABDO 2019.
The four domains
ABDO 2019 contains more than 600 requirements, which is less daunting than it sounds because only a subset applies to you. They fall into four areas, and the breadth is the point: it is not an IT standard.
| Domain | Covers |
|---|---|
| Governance and organisation | Accountability, a designated security officer, policy, and how you handle incidents and deviations. |
| Personnel | Screening and vetting for anyone with access, plus awareness and the rules on leaving. |
| Physical security | Zoning of premises, storage of classified material, access to rooms and cabinets. |
| Cybersecurity | Systems that process classified information: separation, encryption, logging and approved equipment. |
The classification list decides your scope
Which requirements apply is not for you to judge. The client completes a Rubriceringsaanduidingslijst (RAL) per contract, marking the classification involved, and the applicable requirements follow from that level.
So the first question in an ABDO project is not "what must we implement" but "what classification are we handling". Ask for the RAL early. Scoping against the highest level you can imagine wastes money, and scoping too low means rework you cannot get around.
It follows the chain
ABDO obligations pass down to your subcontractors. If you engage a hosting provider, a courier or a maintenance firm that touches classified information, they come into scope and you are the one who has to demonstrate it.
Treat that as part of supplier management rather than a separate exercise. The evidence an assessor wants is the same shape as any supplier risk assessment: who is in scope, what was agreed, and what you check.
How it relates to ISO 27001
An ISO 27001 certificate does not make you ABDO compliant. The two overlap heavily on management system and personnel requirements, so existing certification is a genuine head start, but ABDO adds classified-specific physical and handling rules that ISO 27001 never addresses.
In practice you keep one control set and map it to both, rather than running two programmes. What you cannot do is present the certificate and expect the ABDO requirements to be considered met.