Operational notes Regulation

RESTREINT UE: the facility clearance is not required, the accredited system is

7 min read

A row of grey armoured doors lined up along a white-walled corridor, photographed in black and white
Each door in this corridor is accredited to its own level: in EU defence programmes, security is assessed door by door, not company by company.

A company entering a European defence or security programme looks first at its own facility clearance: it is the natural reflex. But the European Commission’s Decision (EU, Euratom) 2015/444 of 13 March 2015, “on the security rules for protecting EU classified information”, says something different for the level most contractors meet first. At RESTREINT UE/EU RESTRICTED, that clearance is not required. What is required is that the information system the company uses to handle the information be accredited — a shift that changes where due diligence starts for anyone answering a tender.

The gate for a company, when it actually applies

Chapter 6 of the decision — industrial security — defines the Facility Security Clearance (FSC) in Article 44(1): “an administrative determination by a NSA, DSA or any other competent security authority that, from the security viewpoint, a facility can afford an adequate level of protection to EUCI to a specified security classification level.” It applies to CONFIDENTIEL UE/EU CONFIDENTIAL and SECRET UE/EU SECRET, not across the board. Article 44(4) sets the point that matters for a business: the contracting authority “shall not award a classified contract or a grant agreement to a preferred bidder or participant before having received confirmation from the NSA, DSA or any other competent security authority of the Member State in which the contractor or subcontractor concerned is registered that, where required, an appropriate FSC has been issued.” Article 44(6) closes the loop from the other side: withdrawal of an FSC “shall constitute sufficient grounds for the contracting or granting authority, to terminate a classified contract or exclude a candidate, tenderer or applicant from the competition.”

Article 43 adds the condition for people, not just for the company: contractor staff may access EUCI only if they have “been security authorised to the relevant level or [are] otherwise duly authorised by their need-to-know”, have “been briefed on the applicable security rules for protecting EUCI, and have acknowledged their responsibilities with regard to protecting such information”, and have “been security cleared at the relevant level for information classified CONFIDENTIEL UE/EU CONFIDENTIAL or SECRET UE/EU SECRET”. Article 42 then puts in writing what makes all of this enforceable inside a contract: the PSI (Programme or Project Security Instruction) and, above all, the SAL (Security Aspects Letter), defined as a set of conditions that “forms an integral part of any classified contract”, containing “the provisions requiring the contractor or beneficiary to comply with the minimum standards laid down in this Decision” — with the explicit warning that non-compliance “may constitute sufficient grounds for the contract or the grant agreement to be terminated.” Also mandatory is the SCG (Security Classification Guide), governed by a plain arithmetic rule: “the overall level of classification of the contract may not be lower than the highest classification of any of its elements.”

RESTREINT UE: the obligation moves from the company to the system

This entire apparatus — FSC, personnel clearance, SAL, SCG — assumes information classified CONFIDENTIEL UE or SECRET UE. One level down, Article 50 changes register from paragraph 1: protection of RESTREINT UE/EU RESTRICTED rests on “the principles of proportionality and cost-effectiveness.” Paragraph 2 is the sentence that carries this piece: “No FSC or PSC shall be required in the context of classified contracts or classified grant agreements involving the handling of information classified at the level of RESTREINT UE/EU RESTRICTED.” For the share of European defence and security programmes that most companies actually meet, the facility clearance simply is not a requirement.

But paragraph 3 leaves no free pass: where that handling takes place “in a CIS operated by a contractor”, the contracting authority ensures the contract “specifies the necessary technical and administrative requirements regarding accreditation or approval of the CIS commensurate with the assessed risk”, and “the scope of accreditation or approval of such CIS shall be agreed between the Commission Security Authority and the relevant NSA or DSA.” The obligation does not disappear: it moves. From the company to the information system the company works on — and the decision hands the concrete scope of that accreditation to the competent national authority, the NSA or DSA, to be agreed case by case.

What accrediting a CIS actually involves

Article 37 spells out what a company signs up to once that shift applies. “All CIS handling EUCI shall undergo an accreditation process”, with a formal validation of the security plan that must confirm, among other things, that “the System Owner has knowingly accepted the residual risk”: not a formality, a named responsibility. The accreditation authority then issues “an accreditation statement which determines the maximum classification level of the EUCI that may be handled in the CIS as well as the corresponding terms and conditions for operation” — a ceiling and a perimeter, both written down.

Paragraph 5 places the documentary burden squarely on one side: “the responsibility for the preparation of the accreditation files and documentation shall rest entirely upon the CIS System Owner.” And paragraph 6 turns accreditation into a relationship that continues over time, not a one-off stamp: the authority may, “at any moment in the life cycle of the CIS”, require a fresh accreditation process, “audit or inspect the CIS”, and, where operating conditions are no longer met, go as far as “withdrawing permission to operate the CIS until conditions for operation are again satisfied.”

The right question before answering a tender

It is worth reversing the order in which most companies prepare for a European defence or security programme. The question is not “do we have the clearance?” — at RESTREINT UE, it is almost never required: it is a European regime, distinct from national security classifications, worth not conflating even when both apply to the same project. The question is: can the system we will use to handle that information be accredited, and who prepares the file that proves it? Accreditation fixes a maximum classification level and specific operating terms and conditions: a system whose architecture, supplier or configuration keeps changing is a system that must go back through the process every time — with the concrete risk, set out in Article 37 itself, of having its permission to operate withdrawn until it is compliant again.

This is not limited to the Commission’s own EUCI: as with cloud qualification for critical public-sector data, the decision consistently defers to national NSAs and DSAs for the concrete scope of accreditation — a referral every company must follow through before signing, rather than assuming its own internal procedures are enough on their own.

How we solve this

An accreditation file built by hand, updated whenever someone remembers to, is exactly the risk Article 37 has in mind when it talks about withdrawing permission to operate. The way to avoid running it is to turn the SAL’s and the SCG’s requirements into a check that runs against the client’s documents and systems, so that the accreditation file becomes a product of the system, not a hand-written attachment: who handled which piece of information, at what classification, when, with what outcome — the trail an audit or inspection can demand at any moment in the CIS’s life cycle.

The same structure, extended beyond the single contractual obligation, holds an organisation’s archives, management systems, sensors and scattered documents together in a single operational model, on which AI agents execute decisions with an operator in command — for large enterprises, defence, public administration and healthcare. Here the on-premise argument carries more weight than usual: a system that needs a defined perimeter and a declared maximum classification level is easier to accredit on self-contained machines that require no deep integration into the client’s network, following the method behind our platform. The alternative remains a dedicated cloud, with a data centre resident in Italy — never a single option, always with shared administration.

Do you need to respond to a tender involving EU classified information, and don’t know whether your system can be accredited? Half an hour with one of our experts for a first read of what the contract will actually require.

Sources