DEKRA establishes CADIS®, a Europe-wide security assessment

New Standard for Cyber- and Information Security in the Defense Industry

Aug 20, 2026Cyber Security
  • Standardized assessment framework establishes trust, transparency, and security
  • Resilient supply chains protect sensitive information
  • First pilot audit at renowned system manufacturer delivers positive results

DEKRA has developed the first standard for cybersecurity and information security tailored specifically to the European defense industry. The Cyber Assessment for Defence Industry Suppliers (CADIS®) sets out a transparent approach for assessing suppliers with a view to strengthening trust, resilience, and compliance in the defense industry. An initial pilot audit at a supplier, conducted in collaboration with a renowned German manufacturer of military equipment, finished with positive results.

The demands placed on cybersecurity and information security in the defense industry are constantly increasing, with cybersecurity and resilience now considered essential conditions of collaborations. All industry players have a special responsibility to protect sensitive information, critical technology, and complex supply chains.
Experts at DEKRA Certification have developed the Cyber Assessment for Defence Industry Suppliers (CADIS®) as a standardized basis for assessing cybersecurity and information security at manufacturers and suppliers. CADIS® is the first assessment method developed specifically for suppliers to the European defense industry and enables an objective, transparent, and risk-based evaluation of the entire supply chain.
The standard takes into account all requirements of the security-critical sector and brings together technical, organizational, and physical security aspects. A key feature of CADIS® is its modular design. A total of 14 assessment modules are available, which can be flexibly combined depending on the role played by the company, the sensitivity of the products or services, and the individual risk profile.
The assessment delivers numerous benefits to companies:
  • Potential weaknesses in the supply chain are identified and reduced at an early stage.
  • Security standards that have been verifiably assessed sharpen the company’s competitive edge and foster trust among clients.
  • Improved opportunities to be included in security-critical procurement processes.
  • Clear requirements enable companies to plan with certainty.
  • The company positions itself as a responsible partner with a strong security culture.
DEKRA has also provided the “Supplier Criticality Evaluation” tool for supplier assessments by system manufacturers. The assessment scheme enables the individual assessment scope to be determined in a standardized and transparent way and ensures each supplier is classified based on risk.
The CADIS® assessment process includes several steps. Following the kick-off meeting and a remote preliminary review based on the submitted documents, the main assessment is carried out. Its scope is based on the applicable “Level of Examination” (LoE) – which ranges from a plausibility review, to in-depth remote interviews, all the way to comprehensive on-site audits including interviews, spot checks, and site inspections.
The results and non-conformities are recorded in a binding action plan. CADIS® also provides for a risk-based surveillance assessment the following year as part of the two-year assessment cycle. Once the assessment cycle is complete, the process begins again and is adapted to the current circumstances and updated supplier risk profile.