ABDO (General Security Requirements for Defence Contracts)

Dutch Ministry of Defence security requirements that apply to any supplier handling classified defence information, in force as ABDO 2019.

ABDO stands for Algemene Beveiligingseisen voor Defensieopdrachten, the general security requirements for defence contracts issued by the Dutch Ministry of Defence. If you supply the Dutch MoD and will handle classified information, ABDO is the baseline you are held to. The version in force is ABDO 2019.

The four domains

ABDO 2019 contains more than 600 requirements, which is less daunting than it sounds because only a subset applies to you. They fall into four areas, and the breadth is the point: it is not an IT standard.

DomainCovers
Governance and organisationAccountability, a designated security officer, policy, and how you handle incidents and deviations.
PersonnelScreening and vetting for anyone with access, plus awareness and the rules on leaving.
Physical securityZoning of premises, storage of classified material, access to rooms and cabinets.
CybersecuritySystems that process classified information: separation, encryption, logging and approved equipment.

The classification list decides your scope

Which requirements apply is not for you to judge. The client completes a Rubriceringsaanduidingslijst (RAL) per contract, marking the classification involved, and the applicable requirements follow from that level.

So the first question in an ABDO project is not "what must we implement" but "what classification are we handling". Ask for the RAL early. Scoping against the highest level you can imagine wastes money, and scoping too low means rework you cannot get around.

It follows the chain

ABDO obligations pass down to your subcontractors. If you engage a hosting provider, a courier or a maintenance firm that touches classified information, they come into scope and you are the one who has to demonstrate it.

Treat that as part of supplier management rather than a separate exercise. The evidence an assessor wants is the same shape as any supplier risk assessment: who is in scope, what was agreed, and what you check.

How it relates to ISO 27001

An ISO 27001 certificate does not make you ABDO compliant. The two overlap heavily on management system and personnel requirements, so existing certification is a genuine head start, but ABDO adds classified-specific physical and handling rules that ISO 27001 never addresses.

In practice you keep one control set and map it to both, rather than running two programmes. What you cannot do is present the certificate and expect the ABDO requirements to be considered met.

Frequently asked questions

What is ABDO?
ABDO (Algemene Beveiligingseisen voor Defensieopdrachten, or General Security Requirements for Defence Contracts) is the Dutch security standard — current version ABDO 2019 — that companies must meet to handle classified contracts for the Ministry of Defence, overseen by its intelligence service the MIVD.
Who needs to comply with ABDO?
Companies in the Netherlands that carry out classified contracts for the Ministry of Defence must meet ABDO’s physical and information-security requirements.
What does ABDO cover?
ABDO 2019 structures its requirements into four security domains — organisational, personnel, physical and cyber security — covering how classified information is handled.