Skip to main content

ABDO (General Security Requirements for Defence Contracts)

Dutch Ministry of Defence security requirements for suppliers handling classified defence information: ABDO 2019 for existing contracts, ABRO for new ones.

ABDO stands for Algemene Beveiligingseisen voor Defensieopdrachten, the general security requirements for defence contracts issued by the Dutch Ministry of Defence. If you supply the Dutch MoD and will handle classified information, ABDO is the baseline you are held to. ABDO 2019 still governs existing contracts, including when they are renewed. For new contracts Defence moves during 2026 to ABRO, the Algemene Beveiligingseisen voor Rijksoverheidsopdrachten, which central government has applied since 1 January 2026.

The four domains

ABDO 2019 contains more than 600 requirements, which is less daunting than it sounds because only a subset applies to you. They fall into four areas, and the breadth is the point: it is not an IT standard.

DomainCovers
Governance and organisationAccountability, a designated security officer, policy, and how you handle incidents and deviations.
PersonnelScreening and vetting for anyone with access, plus awareness and the rules on leaving.
Physical securityZoning of premises, storage of classified material, access to rooms and cabinets.
CybersecuritySystems that process classified information: separation, encryption, logging and approved equipment.

The classification list decides your scope

Which requirements apply is not for you to judge. The client completes a Rubriceringsaanduidingslijst (RAL) per contract, marking the classification involved, and the applicable requirements follow from that level.

So the first question in an ABDO project is not "what must we implement" but "what classification are we handling". Ask for the RAL early. Scoping against the highest level you can imagine wastes money, and scoping too low means rework you cannot get around.

It follows the chain

ABDO obligations pass down to your subcontractors. If you engage a hosting provider, a courier or a maintenance firm that touches classified information, they come into scope and you are the one who has to demonstrate it.

Treat that as part of supplier management rather than a separate exercise. The evidence an assessor wants is the same shape as any supplier risk assessment: who is in scope, what was agreed, and what you check.

How it relates to ISO 27001

An ISO 27001 certificate does not make you ABDO compliant. The two overlap heavily on management system and personnel requirements, so existing certification is a genuine head start, but ABDO adds classified-specific physical and handling rules that ISO 27001 never addresses.

In practice you keep one control set and map it to both, rather than running two programmes. What you cannot do is present the certificate and expect the ABDO requirements to be considered met.

Frequently asked questions

What is ABDO?
ABDO (Algemene Beveiligingseisen voor Defensieopdrachten, or General Security Requirements for Defence Contracts) is the Dutch security standard that companies must meet to handle classified contracts for the Ministry of Defence, overseen by its intelligence service the MIVD. ABDO 2019 still governs existing contracts; for new contracts Defence moves to ABRO during 2026.
Who needs to comply with ABDO?
Companies in the Netherlands that carry out classified contracts for the Ministry of Defence must meet ABDO’s physical and information-security requirements.
What does ABDO cover?
ABDO 2019 structures its requirements into four security domains — organisational, personnel, physical and cyber security — covering how classified information is handled.