Industry Defense industry & classified environments

Where Cloud Scanning Is Not a Preference — It Is Prohibited

Handling rules for classified and restricted material rule out security tooling that processes data outside the protected network. That disqualifies SaaS application security entirely. Whitespots is self-hosted by design and deploys inside the zone it protects.

No internet connection required

No live vulnerability feeds, update calls or licence checks. Updates arrive as Docker images, like any other approved software.

Deploys inside the protected zone

A segmented or restricted zone, next to the systems it scans — the platform installs where your architecture allows it, not where a vendor requires it.

Administered by cleared staff

Where the regime requires internal administration of security tooling, an on-premise platform your own people run is the only shape that fits.

Evidence for the accreditation

A dated per-finding record per system, exportable for the authority or prime contractor that has to sign it off.

Key challenges

What Defense Suppliers Run Into

Most application security tooling assumes a network with a route to the vendor. In this segment that assumption is the disqualifier.

The entire SaaS market is out of scope

Once handling rules prohibit analysis outside the protected network, the shortlist is not "which cloud scanner" — it is which platform can run inside.

Two networks, one engineering team

An unclassified development environment and a restricted one, with the same people and often the same components moving between them.

Tools that expect the internet

Many security tools need a live connection for vulnerability feeds, updates or licence checks. In a disconnected network, each of those becomes another exception to accredit.

Requirements from the prime contractor

Requirements arrive through the contract chain. A supplier several tiers down still has to evidence secure development to a standard set elsewhere.

Clause map

What the Handling Rules Actually Require

The regimes most often cited by defense suppliers, and where each one touches application security tooling.

BMWE · VS-NfD handling Germany

Requirements for protective software

At the lowest classification tier, malware-detection and analysis software must not perform its scanning outside the protected network — cloud-based analysis is excluded — and the tooling is administered internally.

How Whitespots helps

Self-hosted is the only deployment model that satisfies this, which is why the shortlist in this segment is short. The platform runs inside the network and administers itself from within it.

BSI Germany

IT-Grundschutz · building blocks

Documented protection requirements per system, with modules for software development, patch and change management, and vulnerability handling.

How Whitespots helps

Per-system scoping plus a persistent finding history — the evidence layer the building blocks assume already exists.

DoD · CMMC United States

NIST SP 800-171 · 3.11 and 3.14

Periodic vulnerability scanning of systems and applications, remediation in accordance with risk assessment, and monitoring of security alerts and advisories for controlled unclassified information.

How Whitespots helps

A defined scan cadence, remediation timelines tracked per severity, and an advisory-driven record of what was affected and when.

MOD United Kingdom

DEFCON 658 · cyber risk in the supply chain

Suppliers assess cyber risk against the contract's risk profile and flow equivalent requirements down to sub-contractors, with evidence of compliance.

How Whitespots helps

Business criticality is set per product, so each system is scanned according to its own risk profile — including the code your sub-contractors deliver. The platform adds nobody to the chain: it runs isolated inside your infrastructure.

Cyber Resilience Act European Union

reporting obligations · defence exclusion

From 11 September 2026, manufacturers of products with digital elements report actively exploited vulnerabilities and severe incidents; remaining obligations and penalties apply from 11 December 2027. Products developed exclusively for national security or defence purposes are excluded from scope.

How Whitespots helps

Relevant to the dual-use half of a defense supplier's portfolio. Every change is scanned, and each finding records when it first appeared and when it was fixed, so a report can go out inside the window.

ISO/IEC 27001:2022 International

Annex A, as listed in BSI's mapping table

Management of technical vulnerabilities, secure development lifecycle, secure coding, and security testing in development and acceptance.

How Whitespots helps

Each control maps to an artefact the platform already produces, which is what turns a control statement into audit evidence.

References reflect published text as of August 2026 and describe obligations rather than a certification we grant. Handling regimes differ by nation and by classification tier, and the row above addresses the lowest German tier specifically — it does not describe higher tiers or other nations. Confirm every requirement with your security officer and the contracting authority.

Platform

What Whitespots Gives a Defense Supplier

The deployment model first, because in this segment it is the qualifying criterion rather than a feature.

Protected network 01

Qualifies for the protected network, with nothing to exempt

  • Runs air-gapped Segmented, restricted or fully disconnected zones.

  • Only your cleared staff operate it Administered internally.

  • Zero outbound data No code, findings, logs or usage data leave your servers.

See deployment options →
Two environments 02

Unclassified and restricted networks: one standard, no bridge

  • Same rules on both sides Separate deployments with identical configuration.

  • Updates without a live connection Delivered as Docker images.

  • History for the life of the system Retained per environment.

Explore the platform →
Supply-chain flow-down 03

Pass the prime's requirements down, and prove it

  • Sub-contractor code checked at the gate Quality gates run before handover.

  • Scanning matched to criticality Business criticality set per product.

  • Reports the prime can use For the prime contractor or the authority.

How it works →
Developer workflow 04

Cleared developers spend their time fixing, not operating tools

  • Developers see the issue on the exact line Findings in the IDE, with remediation guidance.

  • Caught in the pull request Checks run as code is written, not in a pre-delivery scramble.

  • No pipeline rewrite Onboarding through a VCS webhook.

See the IDE integration →
Outcomes

Where It Lands

What a defense supplier's security function is usually asked to produce.

  • Scenario

    The handling regime rules out cloud analysis

    With Whitespots platform

    A platform that runs entirely inside the protected network.

  • Scenario

    A prime contractor flows down secure-development requirements

    With Whitespots platform

    Assets split per contract, with reports from the platform you already run.

  • Scenario

    A disconnected environment needs a platform update

    With Whitespots platform

    New Docker images brought in like any other approved software, with no outbound connection.

  • Scenario

    An accreditation asks how findings are managed

    With Whitespots platform

    A dated per-finding record with owners and decisions, exported.

FAQ

What Defense Teams Ask First

Why does self-hosting matter more here than in other industries?

Because it stops being a preference. Handling rules for restricted material constrain where protective software may process data, and at the German VS-NfD tier that excludes cloud-based scanning outright. Elsewhere self-hosting wins on risk; here it is the entry requirement.

Can it run fully air-gapped?

Yes. The platform is self-hosted with no cloud dependency, sends nothing outward and needs no vulnerability feed from outside. Updates are Docker images, so they reach a closed network the same way as any other approved software. Licence activation is the only step that normally needs a connection, and for disconnected deployments we agree an offline way to do it.

We run an unclassified and a restricted environment. Do we need two deployments?

Usually yes — one per environment, with the same configuration and rules on both. That keeps the standard identical without creating a connection between the two networks.

Does the Cyber Resilience Act apply to us?

Products developed exclusively for national security or defence purposes are outside its scope, but most suppliers also sell dual-use or commercial products that are not. For those, reporting obligations start on 11 September 2026 and the remaining obligations and penalties on 11 December 2027. Confirm the split across your portfolio with your regulatory function.

Who administers the platform?

Your own staff. There is no vendor access path by default, which is what makes the internal-administration requirement satisfiable rather than something to seek an exception for.

A Platform That Can Actually Be Installed Where You Work

Talk to us about a deployment inside a restricted or disconnected network, or start with a free external scan of your unclassified public surface.