CADIS® – structured preparation for defence industry examinations
CADIS® – Cybersecurity Assessment for Defence Industry Suppliers
Related topics
CADIS® (Cybersecurity Assessment for Defence Industry Suppliers) is the first European assessment procedure to evaluate cyber and information security for defence industry suppliers in a uniform, transparent, and measurable way.
For many companies, such proof is becoming a prerequisite for market access and cooperation.
bitformer supports you in a practical way throughout the entire preparation process – from the initial inventory to the successful assessment.
Structurally prepared, auditable and proven, sustainably secured.
Important for context: CADIS® is an audit procedure of DEKRA Certification GmbH and is carried out exclusively by DEKRA. bitformer is an independent preparation partner – we bring your company to audit readiness; the audit and certification itself is carried out neutrally by DEKRA.
What is CADIS®
In the defence and arms industry, robust, secure, and resilient supply chains are a critical success factor today. At the same time, demands are continuously increasing: technological dependencies, networked production and IT environments, growing cyber threats, and a multitude of different standards and regulatory requirements make the transparent and reliable assessment of suppliers more difficult. To identify risks at an early stage and ensure security of supply in the long term, a holistic approach to measuring and strengthening resilience along the entire supply chain is required.
CADIS® creates uniform and clear specifications for measures and processes, as well as a fixed evaluation framework for the cybersecurity of companies in the defence supply chain. The procedure was developed by DEKRA and is exclusively certified by them. Instead of inconsistent individual certifications for various clients, a transparent, comparable standard is created – a reliable signal for clients, a clearly defined goal for suppliers.
The procedure is based on recognised standards and frameworks – including ISO/IEC 27001, IEC 62443, NIS2, and the EU Cyber Resilience Act – and bundles their requirements into a modular, risk-based audit model.
Official procedural information: The essential details regarding modules, procedures and the scope of examination are published by DEKRA as the executing body:
Why CADIS® – and why now
Pressure for robust security assurances is growing from two sides:
Regulatory. NIS2, the BSI Act, and the EU Cyber Resilience Act are continuously raising the bar for cybersecurity and information security. Security is no longer a voluntary add-on but an increasing legal obligation.
Practical. Customers and partners expect reliable security credentials along the entire supply chain. Those who cannot provide them will be disqualified as suppliers – regardless of the quality of the actual product.
CADIS® translates this diffuse pressure into a defined, testable framework. This transforms an open requirement into a clear objective that can be worked towards in a planned manner.
The added value of structured preparation: Those who approach the audit in a planned manner secure market access and trust, make the effort calculable, and avoid costly rework during the audit. A seemingly complex requirement becomes a manageable path.
Cybersecurity in the defence industry – current TV report
The Hessian Broadcasting Corporation (HR/ARD) highlights in its format „Ask the writer“, how Russian hacker groups are specifically spying on arms manufacturers – including Rheinmetall.
The contribution can be accessed in the ARD media library and impressively demonstrates why high-performance cybersecurity solutions such as CADIS® for the defence industry are more important today than ever before.
Our Process Model – Six Steps
Our six-step preparation model; the actual DEKRA test then follows its own multi-stage process. A proven, plannable procedure – transparent and without surprises. From the initial assessment to the successful test:
- Analyse – Inventory and Scope: An overview of systems, processes, and responsibilities.
- Review Maturity and GAP: honest assessment of the current security level, comparison with the relevant CADIS® test modules.
- Action planning – prioritised roadmap, sorted by risk, effort, and timeframe.
- Implementation – Technical and organisational measures in IT and OT: concrete rather than conceptual.
- Assessment Preparation - auditable evidence, trial run, preparation of interviews and on-site inspection.
- DEKRA Audit – Support during the DEKRA inspection and with follow-ups until release.
Our services
We will accompany you every step of the way – from determining the location to successful Release.
The services are divided into three phases:
Analysis & Location
- Inventory – Overview of systems, processes, and responsibilities.
- GAP Analysis – Comparison with the relevant CADIS® test modules.
- Maturity analysis – honest assessment of your current security level.
Planning & Implementation
- Action planning – prioritised by risk, effort, and time horizon.
- Technical measures – Implementation in IT and OT, concrete rather than conceptual.
- Organisational measures – Roles, policies, and processes that work in everyday practice.
Exam preparation & support
- Documentation – auditable evidence that can reliably be substantiated.
- Exam preparation – Pre-screening, interviews and on-site inspection in view.
- Accompany until release – Support for action plans and follow-ups.
Why bitformer
Our certifications aren't just on paper, they're in practice. As a consulting and implementation partner, we combine strategic management consulting with technical IT security – and support companies long-term, rather than just preparing an audit.
Experience that counts.
Our consultants have years of international experience and have successfully advised industrial companies on the implementation of standards such as ISO/IEC 27001 and TISAX® supports – at German locations as well as in international branches, for example in North and South America and Asia. This allows us to efficiently and practically prepare even complex, cross-border organisational structures for safety certifications.
What this means to you
- Extensive experience with information security management systems – bitformer is itself certified to ISO/IEC 27001.
- Combination of management consulting and technical IT security.
- Experienced security experts with project-based rather than purely theoretical knowledge.
- Personal contact persons throughout the entire project.
- Long-term support instead of pure audit preparation.
- Pragmatic, individual solutions that suit the company – no standard concepts.
Your next step
Let's design the path to a successful CADIS® examination together. The starting point is a sober assessment of your current situation: where does your company stand today, and what is the most pragmatic first step?
Arrange your no-obligation initial consultation for CADIS® consulting now.
RALPH DÖRFLER
Head of IT Security
Legal notice: CADIS® is an audit procedure of DEKRA Certification GmbH and is carried out exclusively by DEKRA. TISAX® is a registered trademark of ENX Association. bitformer GmbH is an independent consulting and preparation partner and supports companies on the path to Exams; the examination itself is carried out neutrally by DEKRA.

