Start a free trial
Menu

The EU classified information contingency plan your grant agreement requires

A classified EDF grant agreement obliges beneficiaries to hold business contingency plans for protecting EU classified information, and to confirm to the granting authority that they exist. It is one of the least written-about obligations in the framework.

Among the obligations attached to a classified European Defence Fund grant, one is almost entirely absent from the published advice, sits in a document most applicants never open, and is straightforwardly checkable by the granting authority.

Beneficiaries must hold business contingency plans for protecting EU classified information, and must confirm to the granting authority that those plans are in place.

Where the obligation actually lives

It is not in the Model Grant Agreement. If you search that document for "contingency" or "business continuity" you will find nothing, which is one reason the requirement is so rarely written about.

It is in Commission Decision (EU, Euratom) 2021/259, the implementing rules on industrial security for classified grants. Article 16, headed "Contingency plans and recovery measures", requires the granting authority to ensure that the classified grant agreement requires beneficiaries:

"to set out business contingency plans ('BCP') for protecting EUCI handled in the context of the classified grant in emergency situations, and to put in place preventive and recovery measures … to minimise the impact of incidents in relation to the handling and storage of EUCI. The beneficiaries shall confirm to the granting authority that their BCPs are in place."

The clause that binds you directly sits in the security aspects letter annexed to your grant agreement, at Annex III, Appendix A, which obliges the beneficiary or subcontractor to protect any EUCI handled in the performance of the agreement and to inform the granting authority of its BCP.

Two details follow from the wording that are worth being precise about.

It covers EUCI generally. Not only material classified RESTREINT UE/EU RESTRICTED, and not only the highest levels. Any EU classified information handled in the context of the grant is in scope.

It has two halves. Preventive measures and recovery measures. A plan that describes only what you would do after an incident satisfies half of the requirement.

What it is not

There is a second, similarly named obligation in the same framework, and conflating them is the most likely way to satisfy neither.

The Appendix E requirement in the same annex is the narrower one. It applies to EU classified information held at RESTREINT UE/EU RESTRICTED in the beneficiary's own communication and information systems, and requires back-up procedures covering frequency, on-site or off-site storage, and control of access to the back-up copies. That is an IT continuity document.

The Article 16 BCP is about protecting classified information in an emergency. Fire, flood, forced evacuation, a site becoming unavailable, an incident that puts custody of classified material in question. It asks what happens to the classified material, who is responsible, how it is secured or destroyed, and how it is recovered.

An organisation with a solid IT disaster-recovery plan and nothing else has not met Article 16. The two documents answer different questions and the granting authority is entitled to ask about the one you have not written.

What a plan has to be able to show

The Decision does not prescribe a template, which is a mercy and a trap. The mercy is that a plan proportionate to your actual holdings is acceptable. The trap is that "we have a plan" is not the obligation. The obligation is that the plan is in place, that you have confirmed it to the granting authority, and by implication that it is current.

So the questions to be able to answer are the ordinary ones, asked about a document that is easy to write once and then forget:

  • Which version is current, who approved it, and when?
  • Does it cover both preventive and recovery measures?
  • Does it cover all the EUCI actually handled under the grant, including anything that has come into scope since it was written?
  • Who is named in it, and are those people still here?
  • When was the confirmation to the granting authority sent, and did anything material change afterwards?

That last one is the awkward one. A confirmation is a statement made on a date. If the plan changed substantially afterwards, or the classified holdings did, the confirmation describes something that no longer exists.

Which is to say it is a document control problem

Nothing in the paragraphs above is exotic. It is a controlled document with an owner, an approval, a review cadence and a distribution list, whose currency you have to be able to demonstrate at a point in time possibly years after the fact.

That is exactly the discipline behind the standards a defence supplier is already expected to hold, and exactly what document control exists to do. If your quality system already keeps procedures under version control with an approval history and a review schedule, the Article 16 plan belongs in it rather than beside it in someone's folder. If it does not, the EDF obligation is a good reason to fix a gap that was going to be found by an auditor eventually.

The related question of who is cleared to handle the material in the first place is a separate obligation, covered in clearances and the Security Aspects Letter.

Checking this yourself

  • Commission Decision (EU, Euratom) 2021/259, Article 16, and Annex III Appendix A
  • The same annex's Appendix E for the narrower back-up requirement that applies to classified information in your own systems, so you can see the difference
  • Your Security Aspects Letter, which is where these obligations reach your specific action

The wider set of requirements is in what an EDF grant actually obliges you to prove.

A contingency plan is worth what you can show about it: which version, approved by whom, and what it said on the day of the incident. See how ComplyTrain handles document control.

This describes what the published rules say as at 8 September 2026, and is not legal advice.