Services / ABDO & ABRO Compliance
ABDO / ABRO
Readiness
Prepared for Defence related assignments with security requirements, without unnecessary complexity.
ABDO and ABRO chapters side by side, plus the four IPB classification levels.
Four concrete reasons to be ABDO and ABRO ready before the contract arrives.
Three options that scale from a focused quick scan to a complete plan with implementation.
Our five-step process, starting with a free introductory meeting.
Who provides what across Unified International, your organisation and your IT partner..
Quick answers about ABDO, ABRO, IPB, timelines and how this relates to NIS2 and ISO 27001.
Request a free intake call or download the flyer. Direct line to Rick van Dijk.
Services
ABDO and ABRO are mandatory Dutch security frameworks for organisations doing business with the Ministry of Defence and central government.
They apply to assignments involving an Interest to be Protected (IPB), in Dutch Te Beveiligen Belang (TBB): information, systems, materiel, goods or objects that require protection due to national security or governmental interests.
The frameworks affect more than the prime contractor. They flow down to every party that touches an IPB, from prime contractors and integrators to Tier 1, Tier 2 and Tier 3 subcontractors. This page is just as relevant if you are supplying Defence indirectly, through another contractor, as it is for organisations dealing with Defence directly.
ABDO currently applies to existing Defence contracts and remains in force. ABRO is the newer framework that has been broadened across central government and police, and will gradually replace ABDO. New assignments are increasingly awarded under ABRO. Many organisations will run both frameworks side by side for several years, on different projects, since ABDO and ABRO are assigned per project, not per company.
Without verifiable readiness, an assignment can stall or fail to start. We make sure your organisation is prepared, pragmatically, with structure, and aligned to how your business actually runs.
Framework Overview
Both frameworks structure security requirements across a small number of chapters, applied according to the classification level of the Interest to be Protected. Here is what they look like.
| Ch. | ABDO 2019 (4 chapters) | ABRO 2026 (5 chapters) | Condensed keywords |
|---|---|---|---|
| 01 | Bestuur en Organisatie | Bestuur en Organisatie | Policy, risk, security plan, roles, ownership, suppliers, incidents |
| 02 | Personeel | Personeel | Screening, VGB, VOG, confidentiality, trusted roles, training, travel |
| 03 | Fysiek | Fysiek | Compartments, access control, physical measures, storage, transport, destruction |
| 04 | Cyber | Cyber | ICT assets, access, networks, encryption, logging, patching, monitoring |
| 05 | n/a | Cloud | Public cloud, CSP controls, assurance, data location |
An Interest to be Protected (IPB), in Dutch Te Beveiligen Belang (TBB), is classified at one of four levels. The level determines how strict the security measures must be.
The highest classification. If this information leaks, it can cause exceptional and lasting damage to the Dutch state, its allies, or national security.
A leak would cause serious damage to the Dutch state, its security, or international relations.
A leak would cause damage to state interests or international relations, but at a lower level than Secret.
Not a state secret, but still sensitive. A leak would damage the work or interests of a specific government department.
Why Now
Readiness is not only about responding to a specific assignment. Preparing early creates strategic, operational and commercial advantages that compound over time.
Without verifiable security arrangements, an assignment can stall or fail to start. Early readiness eliminates that risk before it becomes a critical path issue.
When a Defence or government opportunity appears, you respond from a position of strength, without scrambling to assemble security documentation under tender pressure.
Demonstrable readiness signals seriousness to primes, integrators and contracting authorities. It opens doors to conversations and partnerships that simply do not happen without it, and shortens the path to becoming a trusted supplier.
The ABDO and ABRO disciplines (governance, screening, physical security, supplier control) sharpen the way your organisation runs, well beyond Defence work. Investments made here directly support NIS2 and ISO 27001 obligations, so one effort yields multiple returns.
Our Services
Not every organisation needs the same level of support. We scale our involvement to your situation, whether you need confidence that you are on track, or full delivery of a working security framework.
A focused readiness assessment. We map where you stand against ABDO or ABRO and identify the most material gaps.
A security plan covering a defined subset, for example Governance and Personnel only. Useful when scope is bounded, when the assignment is limited, or when you want a phased build.
A complete security plan covering all chapters, plus rollout when the time is right. Includes coordination of implementation, supplier guidance and support for BIV, MIVD and NBIV interactions.
Scope and IT partner involvement
We coordinate across all ABDO and ABRO chapters and ensure coherence, consistency and a single evidence base. For the Cyber chapter under ABDO, and the Cyber and Cloud chapters under ABRO, we provide your IT partner with guidance on the applicable requirements, expected evidence and practical interpretation based on our experience. The IT partner implements the required technical and organisational IT measures and supports drafting the technical content where needed.
How We Work
Whatever the scope, the path is structured. You always know where we are, what comes next, and what ownership remains with your organisation.
Roles and Boundaries
Our role is to provide the structure and practical methodology to implement ABDO and ABRO and draft the content on Governance, Personnel and Physical security. Your organisation retains operational ownership, provides input on procedures and company-specific information for the security plan, and appoints a Security Officer who is ultimately responsible for ABDO and ABRO compliance. Your IT partner handles Cyber and Cloud implementation, under our coordination on coherence and evidence.
No IT partner yet?
We have a network of trusted IT partners experienced with Cyber and Cloud implementation under ABDO and ABRO. We are happy to introduce you to a partner that fits your situation.
Frequently Asked Questions
Quick answers to the most common questions about ABDO, ABRO and the path to readiness. Need more detail on a specific situation? Get in touch and we will respond within one working day.
ABDO (Algemene Beveiligingseisen voor Defensieopdrachten) is the Dutch security framework for assignments awarded by the Ministry of Defence. It defines mandatory security requirements across governance, personnel, physical security and cyber for organisations handling classified or sensitive Defence-related information, systems or materiel.
The current version is ABDO 2019. It remains in force for existing contracts, and is being phased out in favour of ABRO 2026 for new assignments.
ABRO (Algemene Beveiligingseisen voor Rijksopdrachten) is the Dutch security framework for assignments awarded by central government and police. It applies the same methodology as ABDO but has been broadened beyond Defence to cover the whole of central government. ABRO 2026 adds a fifth chapter on Cloud security alongside the existing four.
ABRO will gradually replace ABDO over the coming years. New assignments are increasingly awarded under ABRO, while existing ABDO contracts remain governed by ABDO until they end or transition.
The frameworks share a common methodology. The differences are scope, structure and timing.
Scope: ABDO applies to Ministry of Defence assignments. ABRO has been broadened across the whole of central government, including police, and will replace ABDO.
Structure: ABDO 2019 has four chapters (Governance, Personnel, Physical, Cyber). ABRO 2026 has five chapters, splitting Cloud out from Cyber.
Timing: ABDO remains in force for existing Defence contracts, but new assignments are increasingly awarded under ABRO. An organisation can be subject to both frameworks at the same time, for different projects, since ABDO and ABRO are assigned per project, not per company.
Any organisation entering into a contract with the Dutch Ministry of Defence, central government or police that involves an Interest to be Protected (IPB), in Dutch Te Beveiligen Belang (TBB), must comply with the applicable framework. This covers prime contractors, integrators, subcontractors and suppliers across the Defence and government supply chain.
The requirement is contractual. It flows down from the contracting authority through the prime to subcontractors, so smaller suppliers often encounter ABDO or ABRO when a larger contractor brings them into scope.
An IPB (Interest to be Protected), in Dutch Te Beveiligen Belang (TBB), is any information, system, materiel, good or object that needs protection because of national security or governmental interests. An assignment becomes subject to ABDO or ABRO when it touches an IPB.
IPBs are classified at one of four levels (IPB 1 Top Secret, IPB 2 Secret, IPB 3 Confidential, IPB 4 Departmental Confidential). The classification level determines how strict the required security measures are.
Indicative timelines based on our practice:
Quick scan and gap analysis: 1 to 2 weeks. Complete security plan: 2 to 4 months from kick-off to a plan ready for inspection, depending on scope and organisation size. Implementation on top of the plan, including supplier guidance and the awareness training format your team will then deliver, typically adds 1 to 2 months.
Concrete planning is set during the plan of approach, after the quick scan has established the real scope.
The overlap with NIS2 and ISO 27001 sits primarily in the Cyber and Cloud chapters (Chapter 4 in ABDO, Chapters 4 and 5 in ABRO). Those are the chapters delivered by your IT partner, not by us.
If your organisation already operates under NIS2 or ISO 27001, your IT partner benefits from significant reuse on the Cyber and Cloud chapters, since many controls map directly. The Governance, Personnel and Physical chapters (Chapters 1, 2 and 3), where Unified International focuses, have only partial overlap with those frameworks. Our involvement therefore remains broadly the same scope whether or not NIS2 or ISO 27001 is in place. The main benefit is faster delivery on the IT partner side.
It depends on the assignments. Some organisations are best served by a single security plan with framework-specific addenda; others need two separate plans because the projects are clearly distinct.
We decide case by case during the plan of approach, looking at how many projects fall under each framework, how they overlap operationally, and what is most efficient to maintain over time.
Get started
Begin with a quick scan, or move directly into a full readiness trajectory. We adapt to the maturity, capacity and existing processes of your organisation.
Contact
Rick van Dijk
Phone
Office
Pr. Margrietplantsoen 33, Den Haag