My bookmarksSign up free

Commission Decision (EU, Euratom) 2019/1963 of 17 October 2019 laying down implementing rules on industrial security with regard to classified procurement contracts

Commission Decision (EU, Euratom) 2019/1963 of 17 October 2019 laying down implementing rules on industrial security with regard to classified procurement contracts

Decision (EU, Euratom) 2019/1963 · Decision · 21 articles

Data as of 2026-07-04 · Compiled from an official source version. Later amendments or repeals may not be reflected; the official text prevails. · Read the official text ↗

CHAPTER 1 — GENERAL PROVISIONS

Subject matter and scope

Article 1

1.   This Decision sets out implementing rules on industrial security with regard to classified procurement contracts to support the implementation of Decision (EU, Euratom) 2015/444, and in particular Chapter 6 of that Decision. 2.   This Decision lays down specific requirements to ensure the protection of EU classified information (EUCI) by economic operators in pre-contract stage, throughout the life cycle of classified contracts concluded by the European Commission, and in subcontracts concluded by Commission contractors. 3.   This Decision concerns information classified at the following levels: (a) RESTREINT UE/EU RESTRICTED; (b) CONFIDENTIEL UE/EU CONFIDENTIAL; (c) SECRET UE/EU SECRET.

Responsibility within the Commission

Article 2

1.   As part of the responsibilities as described in the Financial Regulation  ( 8 ) , each authorising officer of the Commission contracting authority shall ensure that the classified contract refers to the minimum standards on industrial security set out in Chapter 6 of Decision (EU, Euratom) 2015/444 and in these implementing rules, and where appropriate in the contract notice or the invitation to tender, and that these standards are met in the course of implementation. 2.   To that end, the authorising officer concerned shall, at all stages, seek the advice of the Commission security authority on issues regarding the security elements of a classified contract, programme or project, and shall inform the local security officer about the contracts concluded. The decision on the classification level of specific subjects shall rest with the contracting authority and shall be taken with due regard to the security classification guide. 3.   In respecting the requirements of these implementing rules, the Commission security authority shall cooperate closely with the national security authorities (NSAs) and the designated security authorities (DSAs) of the Member States concerned, in particular as regards facility security clearances (FSCs) and personnel security clearances (PSCs), visit procedures and transportation plans.

CHAPTER 2 — HANDLING OF CALLS FOR TENDER FOR CLASSIFIED CONTRACTS

Basic principles

Article 3

1.   Classified contracts shall be awarded only to economic operators registered in a Member State, or to economic operators registered in a third country or established by an international organisation where that third country or international organisation has concluded a security of information agreement with the European Union or entered into an administrative arrangement with the Commission  ( 9 ) . 2.   Before launching an invitation to tender for a classified contract, the contracting authority shall determine the security classification of any information that could be provided to tenderers. The contracting authority shall also determine the maximum security classification of any information generated in the performance of the contract or programme or project, or at least the anticipated volume and type of information to be produced or handled, and the need for a classified communication and information system (CIS). 3.   The contracting authority shall ensure that contract notices for classified contracts provide information about the special security obligations related to classified information. Annex I contains a sample template for the contract notice information. 4.   The contracting authority shall ensure that information classified RESTREINT UE/EU RESTRICTED, CONFIDENTIEL UE/EU CONFIDENTIAL and SECRET UE/EU SECRET is disclosed to tenderers only after they have signed a non-disclosure agreement, obliging tenderers to handle and protect EUCI in accordance with Decision (EU, Euratom) 2015/444 and its implementing rules. 5.   All contractors which are required to handle or store information classified CONFIDENTIEL UE/EU CONFIDENTIAL or SECRET UE/EU SECRET within their facilities, either during the performance of the classified contract itself or at the pre-contractual stage, shall hold an FSC at the required level. The following identifies the three scenarios that may arise during the tendering stage for a classified contract involving EUCI at CONFIDENTIEL UE/EU CONFIDENTIAL or SECRET UE/EU SECRET level: (a) no access to EUCI at CONFIDENTIEL UE/EU CONFIDENTIAL or SECRET UE/EU SECRET level during the tendering stage: Where the contract notice or the invitation to tender concerns a contract that will involve EUCI at CONFIDENTIEL UE/EU CONFIDENTIAL or SECRET UE/EU SECRET level, but does not require the tenderer to handle such information at the tender stage, a tenderer which does not hold an FSC at the required level shall not be excluded from the bidding process on the grounds that they do not hold an FSC. (b) access to EUCI at CONFIDENTIEL UE/EU CONFIDENTIAL or SECRET UE/EU SECRET level on the premises of the contracting authority during the tendering stage: Access shall be granted to tenderer personnel who hold a PSC at the required level and who have a need-to-know. Before such access is granted, the contracting authority shall verify, through the Commission security authority, with the respective NSA/DSA whether an FSC is also required under national laws and regulations at this stage. (c) handling or storage of EUCI at CONFIDENTIEL UE/EU CONFIDENTIAL or SECRET UE/EU SECRET level on the premises of the tenderer during the tendering stage: Where the contract notice or the invitation to tender requires tenderers to handle or store EUCI on their premises, the tenderer shall hold an FSC at the required level. In such circumstances the contracting authority shall obtain, through the Commission security authority, an assurance from the relevant NSA/DSA that the tenderer has been granted an appropriate FSC. Access shall be granted to tenderer personnel who hold a PSC at the required level and who have a need-to-know. 6.   In principle, an FSC shall not be required for access to RESTREINT UE/EU RESTRICTED information, either at the tender stage or for the performance of the contract. Where Member States require an FSC for contracts or subcontracts at RESTREINT UE/EU RESTRICTED level under their national laws and regulations, as listed in Annex IV, those national requirements shall not place any additional obligations on other Member States or exclude tenderers, contractors or subcontractors from Member States that have no such FSC requirements for access to RESTREINT UE/EU RESTRICTED information from related contracts/subcontracts or a competition for such. These contracts shall be performed in Member States in accordance with their national laws and regulations. 7.   Where an FSC is required for the performance of a classified contract, the contracting authority shall submit, through the Commission security authority, a request to the contractor's NSA/DSA using a facility security clearance information sheet (FSCIS). Annex III, Appendix D, contains an example of an FSCIS  ( 10 ) . The classified contract shall not be awarded until the contractor's NSA/DSA has confirmed the tenderer's FSC. Response to an FSCIS is provided, to the extent possible, within ten working days of the date of the request.

Subcontracting in classified contracts

Article 4

1.   The conditions under which a contractor awarded a Commission classified contract may subcontract shall be defined in the invitation to tender and in the contract documentation. Where the classified contract permits subcontracting of some of its parts, such subcontracting shall be subject to prior written consent from the contracting authority. Before giving its consent, the contracting authority shall consult the Commission security authority. 2.   Classified contracts shall be subcontracted only to economic operators registered in a Member State, or to economic operators registered in a third country or established by an international organisation where that third country or international organisation has concluded a security of information agreement with the EU or entered into an administrative arrangement with the Commission  ( 11 ) .

CHAPTER 3 — LETTING COMMISSION CLASSIFIED CONTRACTS

Basic principles

Article 5

1.   When letting a classified contract, the contracting authority, together with the Commission security authority, shall ensure that the contractor's obligations regarding the protection of EUCI provided to that contractor or generated in the performance of the contract are an integral part of the contract. Contract-specific security requirements shall take the form of a security aspects letter (SAL). A sample template of a SAL is set out in Annex III. 2.   Before signing a classified contract, the contracting authority shall prepare, after consulting the Commission security authority, a security classification guide (SCG) for the tasks to be performed and information generated in the performance of the contract, or at programme or project level, where applicable. The SCG shall be part of the SAL. 3.   Programme or project-specific security requirements shall take the form of a programme (or project) security instruction (PSI). The PSI may be drafted using the provisions of the SAL template as set out in Annex III. The PSI shall be developed by the Commission department managing the programme or project, in close cooperation with the Commission security authority, and submitted for advice to the Commission Security Expert Group. Where a contract is part of a programme or project with its own PSI, the SAL of the contract shall have a simplified form and shall include reference to the security provisions set out in the PSI of the programme or project. 4.   The contracting authority shall be considered the originator of classified information created and handled for the performance of the contract. 5.   The contracting authority, through the Commission security authority, shall notify the NSAs/DSAs of all contractors and subcontractors about the conclusion of classified contracts or subcontracts and any extensions or early terminations of such contracts or subcontracts. A list of country requirements is provided in Annex IV. 6.   Contracts involving information classified RESTREINT UE/EU RESTRICTED shall include a contract security clause making the provisions set out in Annex III, Appendix E binding upon the contractor. Those contracts shall include an SAL setting out, as a minimum, the requirements for handling RESTREINT UE/EU RESTRICTED information including information assurance aspects and specific requirements to be fulfilled by the contractor under delegation from the contracting authority for the accreditation of the contractor's CIS handling RESTREINT UE/EU RESTRICTED information. 7.   Where RESTREINT UE/EU RESTRICTED information is provided to tenderers or to potential contractors, the minimum requirements mentioned in paragraph 6 shall be included in tenders or in relevant non-disclosure arrangements concluded at the tender stage. 8.   Where this is required by Member States' national laws and regulations, NSAs/DSAs ensure that contractors or subcontractors under their jurisdiction comply with the applicable security provisions for the protection of RESTREINT UE/EU RESTRICTED information and conduct verification visits to contractors' facilities located in their territory. Where the NSA/DSA is not under such an obligation, the contracting authority shall ensure that the contractor implements the required security provisions set out in Annex III.

Access to EUCI by personnel of contractors and subcontractors

Article 6

1.   The Commission department, as contracting authority, shall ensure that classified contracts include provisions indicating that personnel of a contractor or subcontractor who, for the performance of the classified contract or subcontract, require access to EUCI may be granted such access only if: (a) it has been established that they have a need-to-know; (b) for information classified CONFIDENTIEL UE/EU CONFIDENTIAL or SECRET UE/EU SECRET, they have been granted a PSC at the relevant level by the respective NSA/DSA or any other competent security authority; (c) they have been briefed on the applicable security rules for protecting EUCI, and have acknowledged their responsibilities with regard to protecting such information. 2.   If a contractor or subcontractor wishes to employ a national of a non-EU country in a position that requires access to EUCI classified CONFIDENTIEL UE/EU CONFIDENTIAL or SECRET UE/EU SECRET, it is the responsibility of the contractor or subcontractor to initiate the security clearance procedure of such a person in accordance with national laws and regulations applicable at the location where access to the EUCI is to be granted.

CHAPTER 4 — VISITS IN CONNECTION WITH CLASSIFIED CONTRACTS

Basic principles

Article 7

1.   Where the Commission, contractors or subcontractors require access to information classified CONFIDENTIEL UE/EU CONFIDENTIAL or SECRET UE/EU SECRET on each other's premises for the performance of a classified contract, visits shall be arranged in liaison with the NSAs/DSAs or any other competent security authority concerned. 2.   The visits referred to in paragraph 1 shall be subject to the following requirements: (a) the visit shall have an official purpose related to a classified contract let by the Commission; (b) any visitor shall hold a PSC at the required level and have a need-to-know in order to access EUCI provided or generated in the performance of a classified contract let by the Commission.

Requests for visits

Article 8

1.   Visits by contractors to other contractors' facilities, or to Commission premises, that involve access to information classified CONFIDENTIEL UE/EU CONFIDENTIAL or SECRET UE/EU SECRET shall be arranged in accordance with the following procedure: (a) the security officer of the facility sending the visitor shall complete all relevant parts of the request for visit (RFV) form and submit the request to the facility's NSA/DSA. A template of the RFV form is set out in Annex III, Appendix C; (b) the sending facility's NSA/DSA needs to confirm the visitor's PSC before submitting the RFV to the host facility's NSA/DSA (or the Commission security authority if the visit is to Commission premises); (c) the security officer of the sending facility shall then obtain from its NSA/DSA the reply of the host facility's NSA/DSA (or the Commission security authority) either authorising or denying the RFV; (d) an RFV is considered approved if no objections are raised until five working days before the date of the visit. 2.   Visits by Commission officials to contractor facilities that involve access to information classified CONFIDENTIEL UE/EU CONFIDENTIAL or SECRET UE/EU SECRET shall be arranged in accordance with the following procedure: (a) the visitor shall complete all relevant parts of the RFV form and submit it to the Commission security authority; (b) the Commission security authority shall confirm the PSC of the visitor before submitting the RFV to the host facility's NSA/DSA; (c) the Commission security authority shall obtain a reply from the host facility's NSA/DSA either authorising or denying the RFV; (d) an RFV is considered approved if no objections are raised until five working days before the date of the visit. 3.   An RFV may cover either a single visit or recurring visits. In the case of recurring visits, the RFV may be valid for up to one year from the start date requested. 4.   The validity of any RFV shall not exceed the validity of the PSC of the visitor. 5.   As a general rule, an RFV should be submitted to the host facility's competent security authority at least 15 working days before the date of the visit.

Visit procedures

Article 9

1.   Before allowing visitor to have access to EUCI, the security office of the host facility shall comply with all the visit-related security procedures and rules laid down by its NSA/DSA. 2.   Visitors shall prove their identity upon arrival at the host facility by presenting a valid ID card or passport. That identification information shall correspond to the information supplied in the RFV. 3.   The host facility shall ensure that records are kept of all visitors, including their names, the organisation they represent, the date of expiry of the PSC, the date of the visit and the names of the persons visited. Such records shall be retained for a period of at least five years or longer if required by the national rules and regulations of the country where the host facility is located.

Visits arranged directly

Article 10

1.   In the context of specific projects, the relevant NSAs/DSAs and the Commission security authority may agree on a procedure whereby visits for a specific classified contract can be arranged directly between the visitor's security officer and the security officer of the facility to be visited. A template of the form to be used for this purpose is set out in Annex III, Appendix C. Such an exceptional procedure shall be set out in the PSI or other specific arrangements. In such cases, the procedures set out in Article 8 and Article 9(1) shall not apply. 2.   Visits involving access to information classified RESTREINT UE/EU RESTRICTED shall be arranged directly between the sending and receiving entity without the need to follow the procedures set out in Article 8 and Article 9(1).

CHAPTER 5 — TRANSMISSION AND CARRIAGE OF EUCI IN PERFORMANCE OF CLASSIFIED CONTRACTS

Basic principles

Article 11

The contracting authority shall ensure that all decisions related to EUCI transfer and carriage are in accordance with Decision (EU, Euratom) 2015/444 and its implementing rules, and with the terms of the classified contract, including the consent of the originator.

Electronic handling

Article 12

1.   Electronic handling and transmission of EUCI shall be carried out in accordance with Chapters 5 and 6 of Decision (EU, Euratom) 2015/444 and its implementing rules. The communication and information systems owned by a contractor and used to handle EUCI for the performance of the contract (‘contractor CIS’) shall be subject to accreditation by the responsible security accreditation authority (SAA). Any electronic transmission of EUCI shall be protected by cryptographic products approved in accordance with Article 36(4) of Decision (EU, Euratom) 2015/444. TEMPEST measures shall be implemented in accordance with Article 36(6) of that Decision. 2.   The security accreditation of contractor CIS handling EUCI at RESTREINT UE/EU RESTRICTED level and any interconnection thereof may be delegated to the security officer of a contractor if this is permitted by national laws and regulations. Where that task is delegated, the contractor shall be responsible for implementing the minimum security requirements described in the SAL when handling RESTREINT UE/EU RESTRICTED information on its CIS. However, the relevant NSAs/DSAs and SAAs retain responsibility for the protection of RESTREINT UE/EU RESTRICTED information handled by the contractor and the right to inspect the security measures taken by the contractors. In addition, the contractor shall provide to the contracting authority and, where required by national laws and regulations, the competent national SAA, a statement of compliance certifying that the contractor CIS and related interconnections have been accredited for handling EUCI at RESTREINT UE/EU RESTRICTED level  ( 12 ) .

Transport by commercial couriers

Article 13

The transport of EUCI by commercial couriers shall abide by the relevant provisions of Commission decisions on implementing rules for handling RESTREINT UE/EU RESTRICTED information and CONFIDENTIEL UE/EU CONFIDENTIAL information.

Hand carriage

Article 14

1.   The carriage of classified information by hand shall be subject to strict security requirements. 2.   RESTREINT UE/EU RESTRICTED information may be hand carried by contractor personnel within the EU, provided the following requirements are met: (a) the envelope or packaging used is opaque and bears no indication of the classification of its contents; (b) the classified information does not leave the possession of the bearer; (c) the envelope or packaging is not opened en route . 3.   For information classified CONFIDENTIEL UE/EU CONFIDENTIAL and SECRET UE/EU SECRET, hand carriage by contractor personnel within an EU Member State is arranged in advance between the sending and receiving entities. The dispatching authority or facility informs the receiving authority or facility of the details of the consignment, including reference, classification, expected time of arrival and name of courier. Such hand carriage is permitted, provided the following requirements are met: (a) the classified information is carried in a double envelope or packaging; (b) the outer envelope or packaging is secured and bears no indication of the classification of its contents, while the inner envelope bears the level of classification; (c) EUCI does not leave the possession of the bearer; (d) the envelope or packaging is not opened en route ; (e) the envelope or packaging is carried in a lockable briefcase or similar approved container of such size and weight that it can be retained at all times in the personal possession of the bearer and not be consigned to a baggage hold; (f) the courier carries a courier certificate issued by his/her competent security authority authorising the courier to carry the classified consignment as identified. 4.   For hand carriage by contractor personnel of information classified CONFIDENTIEL UE/EU CONFIDENTIAL and SECRET UE/EU SECRET from one EU Member State to another, the following additional rules shall apply: (a) the courier shall be responsible for the safe custody of the classified material carried until it is handed over to the recipient; (b) in the event of a security breach, the sender's NSA/DSA may request that the authorities in the country where the breach occurred carry out an investigation, report their findings and take legal or other action as appropriate; (c) the courier shall have been briefed on all the security obligations to be observed during carriage and shall have signed an appropriate acknowledgement; (d) the instructions for the courier shall be attached to the courier certificate; (e) the courier shall have been provided with a description of the consignment and an itinerary; (f) the documents shall be returned to the issuing NSA/DSA upon completion of the journey(s) or be kept available by the recipient for monitoring purposes; (g) if customs, immigration authorities or border police ask to examine and inspect the consignment, they shall be permitted to open and observe sufficient parts of the consignment so as to establish that it contains no material other than that which is declared; (h) customs authorities should be urged to honour the official authority of the shipping documents and of the authorisation documents carried by the courier. If a consignment is opened by customs, this should be done out of sight of unauthorised persons and in the presence of the courier where possible. The courier shall request that the consignment be repacked and shall ask the authorities conducting the inspection to reseal the consignment and confirm in writing that it was opened by them. 5.   Hand carriage by contractor personnel of information classified RESTREINT UE/EU RESTRICTED, CONFIDENTIEL UE/EU CONFIDENTIAL and SECRET UE/EU SECRET to a third country or an international organisation will be subject to provisions of the security of information agreement or the administrative arrangement concluded between, respectively, the European Union or the Commission and that third country or international organisation.

CHAPTER 6 — BUSINESS CONTINUITY PLANNING

Contingency plans and recovery measures

Article 15

The Commission department, as contracting authority, shall ensure that classified contract requires the contractor to set out business contingency plans (BCP) for protecting EUCI handled in connection with the performance of the classified contract in emergency situations, and to put in place preventive and recovery measures in the context of business continuity planning to minimise the impact of incidents in relation to the handling and storage of EUCI. The contractor shall inform the contracting authority of its BCP.

Entry into force

Article 16

This Decision shall enter into force on the twentieth day following that of its publication in the Official Journal of the European Union .

Supplementary provisions

ANNEX ISupplementary provisions

ANNEX I STANDARD INFORMATION IN PROCUREMENT CONTRACT NOTICES (to be adapted to the contract notices used) For contracts involving information classified CONFIDENTIEL UE/EU CONFIDENTIAL or SECRET UE/EU SECRET Other particular conditions ( if applicable ) The performance of the contract is subject to particular conditions yes no ( if yes ) Description of particular conditions: The contract will involve access to, handling and/or storage of information classified CONFIDENTIEL UE/EU CONFIDENTIAL or SECRET UE/EU SECRET, which is subject to the security rules for protecting EU classified information laid down in Decision (EU, Euratom) 2015/444 and to the Decision’s implementing rules  ( 1 ) . Facility security clearance will be required as well as personnel security clearances for contractor personnel handling classified information. Special security obligations will be part of the contract (security aspects letter, annexed to the contract). Subcontracting will be subject to written prior agreement by the contracting authority and compliance with all the security rules by the subcontractor and its personnel. For contracts involving information classified RESTREINT UE/EU RESTRICTED Other particular conditions ( if applicable ) The performance of the contract is subject to particular conditions yes no ( if yes ) Description of particular conditions: The contract will involve or entail access to, handling and/or storage of information classified RESTREINT UE/EU RESTRICTED, which is subject to the security rules for protecting EU classified information laid down in Decision (EU, Euratom) 2015/444 and to the Decision’s implementing rules  ( 2 ) . Special security obligations will be part of the contract (security aspects letter, annexed to the contract). Subcontracting will be subject to written prior agreement by the contracting authority and compliance with all the security rules by the subcontractor and its personnel. ( 1 )   The contracting authority should insert the references once the implementing rules have been adopted. ( 2 )   The contracting authority should insert the references once the implementing rules have been adopted.

ANNEX IISupplementary provisions

ANNEX II STANDARD PROCUREMENT CONTRACT CLAUSES (to be adapted to the contracts used) ARTICLE XX SECURITY-RELATED OBLIGATIONS XX.1 EU classified information If the implementation of the contract involves using or generating EU classified information, such information must be treated in accordance with the security aspects letter (SAL) and its security classification guide (SCG) as set out in Annex 1, and Decision (EU, Euratom) 2015/444 and its implementing rules  ( 1 ) , until it is declassified. Any deliverables containing classified information must be submitted in accordance with special procedures agreed with the contracting authority. Action tasks involving classified information must not be subcontracted without prior explicit written approval from the contracting authority. EU classified information must not be released to any third party (including subcontractors) without prior explicit written approval from the contracting authority. ( 1 )   The contracting authority should insert the references once the implementing rules have been adopted.

[Annex IV (to the Framework Contract)]

ANNEX IIISupplementary provisions

ANNEX III [Annex IV (to the Framework Contract)] SECURITY ASPECTS LETTER (SAL) [Model]

Facility and personnel security clearance for contractors involving RESTREINT UE/EU RESTRICTED information and NSAs/DSAs requiring notification of classified contracts at RESTREINT UE/EU RESTRICTED level  ( 1 )

ANNEX IVSupplementary provisions

ANNEX IV Facility and personnel security clearance for contractors involving RESTREINT UE/EU RESTRICTED information and NSAs/DSAs requiring notification of classified contracts at RESTREINT UE/EU RESTRICTED level  ( 1 ) Member State FSC Notification of contract or subcontract involving R-UE/EU-R information to NSA/DSA PSC YES NO YES NO YES NO Belgium   X   X   X Bulgaria   X   X   X Czechia   X   X   X Denmark X   X   X   Germany   X   X   X Estonia X   X     X Ireland   X   X   X Greece X     X X   Spain   X X     X France   X   X   X Croatia   X X     X Italy   X X     X Cyprus   X X     X Latvia   X   X   X Lithuania X   X     X Luxembourg X   X   X   Hungary   X   X   X Malta   X   X   X Netherlands X (for defence-related contracts only)   X (for defence-related contracts only)     X Austria   X   X   X Poland   X   X   X Portugal   X   X   X Romania   X   X   X Slovenia X   X     X Slovakia X   X     X Finland   X   X   X Sweden X (for defence-related contracts only)   X (for defence-related contracts only)   X (for defence-related contracts only)   United Kingdom   X   X   X ( 1 )   These national requirements for FSC/PSC and notifications for contracts involving RESTREINT UE/EU RESTRICTED information must not place any additional obligations on other Member States or contractors under their jurisdiction. N.B.: Notifications of contracts involving CONFIDENTIEL UE/EU CONFIDENTIAL and SECRET UE/EU SECRET information are obligatory.

ANNEX VSupplementary provisions

ANNEX V LIST OF NATIONAL SECURITY AUTHORITY/DESIGNATED SECURITY AUTHORITY DEPARTMENTS RESPONSIBLE FOR HANDLING PROCEDURES ASSOCIATED WITH INDUSTRIAL SECURITY BELGIUM National Security Authority FPS Foreign Affairs Rue des Petits Carmes 15 1000 Brussels Tel. +32 25014542 (Secretariat) Fax +32 25014596 Email: nvo-ans@diplobel.fed.be BULGARIA 1. State Commission on Information Security — National Security Authority 4 Kozloduy Street 1202 Sofia Tel. +359 29835775 Fax +359 29873750 Email: dksi@government.bg 2. Defence Information Service at the Ministry of Defence (security service) 3 Dyakon Ignatiy Street 1092 Sofia Tel. +359 29227002 Fax +359 29885211 Email: office@iksbg.org 3. State Intelligence Agency (security service) 12 Hajdushka Polyana Street 1612 Sofia Tel. +359 29813221 Fax +359 29862706 Email: office@dar.bg 4. State Agency for Technical Operations (security service) 29 Shesti Septemvri Street 1000 Sofia Tel. +359 29824971 Fax +359 29461339 Email: dato@dato.bg (The competent authorities listed above conduct the vetting procedures for issuing FSCs to legal entities applying to conclude a classified contract, and PSCs to individuals implementing a classified contract for the needs of these authorities.) 5. State Agency National Security (security service) 45 Cherni Vrah Blvd. 1407 Sofia Tel. +359 28147109 Fax +359 29632188, +359 28147441 Email: dans@dans.bg (The above security service conducts the vetting procedures for issuing FSCs and PSCs to all other legal entities and individuals in the country applying to conclude a classified contract or implementing a classified contract.) CZECHIA National Security Authority Industrial Security Department PO BOX 49 150 06 Praha 56 Tel. +420 257283129 Email: sbr@nbu.cz DENMARK 1. Politiets Efterretningstjeneste (Danish Security Intelligence Service) Klausdalsbrovej 1 2860 Søborg Tel. +45 33148888 Fax +45 33430190 2. Forsvarets Efterretningstjeneste (Danish Defence Intelligence Service) Kastellet 30 2100 Copenhagen Ø Tel. +45 33325566 Fax +45 33931320 GERMANY 1. For matters concerning industrial security policy, FSCs, transportation plans (except for crypto/CCI): Federal Ministry of Economic Affairs and Energy Industrial Security Division — ZB3 Villemombler Str. 76 53123 Bonn Tel. +49 228996154028 Fax +49 228996152676 Email: dsagermany-zb3@bmwi.bund.de (office email address) 2. For standard visit requests from/to German companies: Federal Ministry of Economic Affairs and Energy Industrial Security Division – ZB2 Villemombler Str. 76 53123 Bonn Tel. +49 228996152401 Fax +49 228996152603 Email: zb2-international@bmwi.bund.de (office email address) 3. Transportation plans for crypto material: Federal Office for Information Security (BSI) National Distribution Agency/NDA-EU DEU Mainzer Str. 84 53179 Bonn Tel. +49 2289995826052 Fax +49 228991095826052 Email: NDAEU@bsi.bund.de ESTONIA National Security Authority Department Estonian Foreign Intelligence Service Rahumäe tee 4B 11316 Tallinn Tel. +372 6939211 Fax +372 6935001 Email: nsa@fis.gov.ee IRELAND National Security Authority Ireland Department of Foreign Affairs and Trade 76-78 Harcourt Street Dublin 2 D02 DX45 Tel. +353 14082724 Email: nsa@dfa.ie GREECE Hellenic National Defence General Staff E' Division (Security INTEL, CI BRANCH) E3 Directorate Industrial Security Office 227-231 Mesogeion Avenue 15561 Holargos, Athens Tel. +30 2106572022, +30 2106572178 Fax +30 2106527612 Email: daa.industrial@hndgs.mil.gr SPAIN Autoridad Nacional de Seguridad Oficina Nacional de Seguridad Calle Argentona 30 28023 Madrid Tel. +34 913725000 Fax +34 913725808 Email: nsa-sp@areatec.com For matters concerning personnel security clearances: asip@areatec.com For Transportation plans and international visits: sp-ivtco@areatec.com FRANCE National Security Authority (NSA) (for policy and for implementation in fields other than the defence industry) Secrétariat général de la défense et de la sécurité nationale Sous-direction Protection du secret (SGDSN/PSD) 51 boulevard de la Tour-Maubourg 75700 Paris 07 SP Tel. +33 171758193 Fax +33 171758200 Email: ANSFrance@sgdsn.gouv.fr Designated Security Authority (for implementation in the defence industry) Direction Générale de l'Armement Service de la Sécurité de Défense et des systèmes d'Information (DGA/SSDI) 60 boulevard du général Martial Valin CS 21623 75509 Paris Cedex 15 Tel. +33 988670421 Email: for forms and outgoing RFVs: dga-ssdi.ai.fct@intradef.gouv.fr for incoming RFVs: dga-ssdi.visit.fct@intradef.gouv.fr CROATIA Office of the National Security Council Croatian NSA Jurjevska 34 10000 Zagreb Tel. +385 14681222 Fax +385 14686049 Email: NSACroatia@uvns.hr ITALY Presidenza del Consiglio dei Ministri D.I.S. - U.C.Se. Via di Santa Susanna 15 00187 Roma Tel. +39 0661174266 Fax +39 064885273 CYPRUS ΥΠΟΥΡΓΕΙΟ ΑΜΥΝΑΣ Εθνική Αρχή Ασφάλειας (ΕΑΑ) Λεωφόρος Στροβόλου, 172-174 Στρόβολος, 2048, Λευκωσία Τηλέφωνα: +357 22807569, +357 22807764 Τηλεομοιότυπο: +357 22302351 Email: cynsa@mod.gov.cy Ministry of Defence National Security Authority (NSA) 172-174, Strovolos Avenue 2048 Strovolos, Nicosia Tel. +357 22807569, +357 22807764 Fax +357 22302351 Email: cynsa@mod.gov.cy LATVIA National Security Authority Constitution Protection Bureau of the Republic of Latvia P.O. Box 286 Riga LV-1001 Tel. +371 67025418, +371 67025463 Fax +371 67025454 Email: ndi@sab.gov.lt, ndi@zd.gov.lv LITHUANIA Lietuvos Respublikos paslapčių apsaugos koordinavimo komisija (The Commission for Secrets Protection Coordination of the Republic of Lithuania) National Security Authority Gedimino 40/1 LT-01110 Vilnius Tel. +370 70666703, +370 70666701 Fax +370 70666700 Email: nsa@vsd.lt LUXEMBOURG Autorité Nationale de Sécurité 207, route d'Esch L-1471 Luxembourg Tel. +352 24782210 Email: ans@me.etat.lu HUNGARY National Security Authority of Hungary H-1399 Budapest P.O. Box 710/50 H-1024 Budapest, Szilágyi Erzsébet fasor 11/B Tel. +36 13911862 Fax +36 13911889 Email: nbf@nbf.hu MALTA Director of Standardisation Designated Security Authority for Industrial Security Standards & Metrology Institute Malta Competition and Consumer Affairs Authority Mizzi House National Road Blata I-Bajda HMR9010 Tel.: +356 23952000 Fax +356 21242406 Email: certification@mccaa.org.mt NETHERLANDS 1. Ministry of the Interior and Kingdom Relations PO Box 20010 2500 EA The Hague Tel. +31 703204400 Fax +31 703200733 Email: nsa-nl-industry@minbzk.nl 2. Ministry of Defence Industrial Security Department PO Box 20701 2500 ES The Hague Tel. +31 704419407 Fax +31 703459189 Email: indussec@mindef.nl AUSTRIA 1. Federal Chancellery of Austria Department I/12, Office for Information Security Ballhausplatz 2 1014 Vienna Tel. +43 153115202594 Email: isk@bka.gv.at 2. DSA in the military sphere: BMLVS/Abwehramt Postfach 2000 1030 Vienna Email: abwa@bmlvs.gv.at POLAND Internal Security Agency Department for the Protection of Classified Information Rakowiecka 2A 00-993 Warsaw Tel. +48 225857944 Fax +48 225857443 Email: nsa@abw.gov.pl PORTUGAL Gabinete Nacional de Segurança Serviço de Segurança Industrial Rua da Junqueira n o 69 1300-342 Lisbon Tel. +351 213031710 Fax +351 213031711 Email: sind@gns.gov.pt, franco@gns.gov.pt ROMANIA Oficiul Registrului Național al Informațiilor Secrete de Stat — ORNISS Romanian NSA — ORNISS — National Registry Office for Classified Information 4th Mures Street 012275 Bucharest Tel. +40 212075115 Fax +40 212245830 Email: relatii.publice@orniss.ro, nsa.romania@nsa.ro SLOVENIA Urad Vlade RS za varovanje tajnih podatkov Gregorčičeva 27 1000 Ljubljana Tel. +386 14781390 Fax +386 14781399 Email: gp.uvtp@gov.si SLOVAKIA Národný bezpečnostný úrad (National Security Authority) Security Clearance Department Budatínska 30 851 06 Bratislava Tel. +421 268691111 Fax +421 268691700 Email: podatelna@nbu.gov.sk FINLAND National Security Authority Ministry for Foreign Affairs P.O. Box 453 FI-00023 Government Email: NSA@formin.fi SWEDEN 1. National Security Authority Utrikesdepartementet (Ministry for Foreign Affairs) UD SÄK/NSA SE-103 39 Stockholm Tel. +46 84051000 Fax +46 87231176 Email: ud-nsa@gov.se 2. DSA Försvarets Materielverk (Swedish Defence Materiel Administration) FMV Säkerhetsskydd SE-115 88 Stockholm Tel. +46 87824000 Fax +46 87826900 Email: security@fmv.se UNITED KINGDOM UK National Security Authority Room 335, 3rd Floor 70 Whitehall London SW1A 2AS Tel. +44 2072765497, +44 2072765645 Email: UK-NSA@cabinet-office.x.gsi.gov.uk

Source: EUR-Lex (Publications Office of the EU), © European Union, reuse permitted under Commission Decision 2011/833/EU.

What to look at next