We are accredited: Cyberus Hypervisor achieves BSI VS-NfD and NATO RESTRICTED accreditation (Zulassung)

Today we are proud to share a milestone that has been years in the making: the Cyberus Hypervisor has received its official VS-NfD Accreditation (Zulassung) from Germany's Federal Office for Information Security (BSI) alongside NATO RESTRICTED. This isn't just a certificate on a wall. It means the Cyberus Hypervisor is now formally cleared to run classified German government workloads — and it means something bigger for the state of digital sovereignty in Germany and Europe.


CTRL-OS Logo

A multi-year path

Getting here was not a single event; it was a process.

  • September 2024: We began working with the BSI on the accreditation process for the Cyberus Hypervisor.
  • November 2025: We received the preliminary approval (Einsatzerlaubnis), a temporary permit that allowed the hypervisor to be deployed in its intended environment while the full accreditation process continued.
  • Septemer 2026: That Einsatzerlaubnis has become a full Zulassung: the completed, formal accreditation.

What does VS-NfD actually mean?

VS-NfD stands for Verschlusssache – Nur für den Dienstgebrauch. It is the lowest classification tier for German government-classified information. But "lowest" does not mean informal. It is a legally binding classification, and a wide range of organizations require products to carry it before they can even be considered: federal and state agencies, KRITIS (critical infrastructure) operators, public sector IT, and defense-adjacent companies.

A few terms worth untangling, since they get used loosely:

  • Einsatzerlaubnis: a temporary authorization to use a product in its intended environment while final accreditation is still being completed.
  • Zulassung: the completed, formal accreditation. This is the real thing, not a placeholder.
  • BSI-VSA-11111: this is our specific accreditation reference number, publicly listed in the BSI's official register of accredited IT security products.

To put this in context, the BSI's public list of accredited products includes VPN clients, encryption gateways, disk encryption tools, secure messaging apps, and similar categories. But as of now, the Cyberus Hypervisor is the only entry in that list categorized specifically as a hypervisor.

Why does this matter? A question of digital sovereignty

Step back from the acronyms for a second, and there is a bigger story here.

Europe's IT infrastructure has long leaned on a small number of non-European vendors. Especially recent years have made the risks of that dependency harder to ignore. Broadcom's acquisition of VMware, for example, triggered major licensing changes and price increases that hit European cloud providers and public-sector customers hard. This prompted complaints to EU competition authorities and renewed debate about vendor lock-in. At the same time, geopolitical and trade dynamics shifted. Particularly uncertainty around U.S. tech and trade policy has added urgency to a question European governments and companies are increasingly asking: what happens if we can no longer rely on a foreign vendor's terms, pricing, or continued goodwill?

We don't think one accreditation solves that problem. But we see it as one building block in a much larger effort to build a sovereign European digital ecosystem. An ecosystem, where critical infrastructure does not depend on a single non-European vendor's roadmap or licensing decisions.

What is accredited today? And what is on the roadmap?

The current accreditation covers secure multi-tenancy, which is the core capability of a hypervisor: safely running multiple isolated workloads on the same physical hardware.

But we are not finished here…

  • Next ("Accreditation 1.1"): we are working toward accrediting additional features, including live migration, block storage encryption, and Windows VM support.
  • Longer term: Confidential Computing is on our radar. And we would genuinely like to hear from readers and customers what else should be on this list?
  • Other classification levels: meanwhile, we are exploring what it would take to pursue higher classification tiers such as VS-GEHEIM or NATO SECRET. To be clear, these are early-stage plans, not commitments.

Cyberus Linux: we are also looking at how Cyberus Linux, our NixOS-based operating system, could eventually fit into accredited environments alongside the hypervisor. This is early-stage work, but it is a direction we are actively pursuing as part of building out a broader sovereign stack.

Get in touch

If your organization needs virtualization that meets VS-NfD requirements we would love to talk. Reach out to us at businessdevelopment@cyberus-technology.de or simply use the contact form on our website.