<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=1732033&amp;fmt=gif">
Skip to content

indigo integration for iPhone and iPad up to VS-NfD

indigo | iOS Native Devices in Government Operations


indigo is Apple's solution for using standard iPhones and iPads with classified information. The BSI, Germany's Federal Office for Information Security, lists it with Apple Inc. as manufacturer among its approved IT security products, with approvals up to VS-NfD (BSI-VSA-10900) and NATO RESTRICTED (BSI-VSA-11003), valid until 31 October 2027. It is aimed at German security agencies (BOS), public administration, KRITIS operators and the defense industry. Besides the devices, the platform includes a UEM, VPN gateways, a PKI with certificate management and fixed IT policies. The approval is held by Apple, not by ISEC7: as an indigo integrator, ISEC7 delivers architecture, build-out and operations and monitors compliance with ISEC7 SPHERE.

SECURE MOBILE COMMUNICATION
 

Why indigo?

With the BSI approval for Apple's indigo, standard iPhones and iPads can handle classified information up to VS-NfD inside your own IT infrastructure. The user experience doesn't change: it works just like a private iPhone.

indigo at a glance

  • BSI approvals for Apple's indigo: up to VS-NfD (BSI-VSA-10900) and NATO RESTRICTED (BSI-VSA-11003), plus an operating permission up to VS-NfD (BSI-VSA-10901), all valid until 31 October 2027. The approvals are held by Apple Inc.; ISEC7 is the integrator.
  • Runs on standard iOS devices (iPhone, iPad), no special hardware
  • Target users: German security agencies (BOS), KRITIS operators, defense industry, public administration
  • UEM: BlackBerry UEM, Common Criteria certificate BSI-DSZ-CC-1235-2025, held by BlackBerry Ltd.
  • ISEC7 is an indigo integrator, based in Hamburg, in the market since 2003, with its own compliance monitoring (ISEC7 SPHERE, Software Made in Germany)
indigo by ISEC7: BSI-approved iOS for VS-NfD

Which UEM runs in an indigo environment?

 

The central building block of indigo is Unified Endpoint Management (UEM). For indigo environments, ISEC7 runs BlackBerry UEM, from the Sovereign Cloud if you prefer. BlackBerry UEM Server 12.21.1 holds Common Criteria certificate BSI-DSZ-CC-1235-2025, issued on 8 September 2025 (EAL4+, valid until 7 September 2030); the certificate holder is BlackBerry Ltd., ISEC7 is the operator. ISEC7 supports vendor-neutral UEM selection and migration.

Secure Network

 

The indigo platform implements the German VSA framework in technology: approved VPN gateways, Public Key Infrastructure (PKI) with certificate management, app blocklists, hardened IT policies on the device. All components work together, from the iPhone to the data center.

Secure Communication

 

On an indigo device, users run native iOS features plus a set of approved ecosystem apps for secure voice (ISEC7 MANAGED SECURE VOICE), mail, browser, file access and messaging. Users work with the apps they know.

VS-NfD ready iOS workplace for government use

indigo Info Sheet

COMMUNICATION UP TO VS-NfD
 

Your Path to indigo

ISEC7 guides public-sector and enterprise customers through a structured build-out of an indigo-compliant platform. Our consultants assess your current state, document the gaps against the VSA, design the target architecture and take over implementation, process definition and operations. Optionally, we add ISEC7 MANAGED SECURE VOICE for encrypted mobile calls and Samsung devices with the Knox Native Solution, for which Samsung holds a BSI operating permission up to VS-NfD (BSI-VSA-11044, valid until 31 August 2027).

ON THE SAFE SIDE WITH ISEC7 SPHERE
 

indigo compliance monitoring with ISEC7 SPHERE

ISEC7 SPHERE monitors an indigo infrastructure continuously against the VSA parameters: IT policies, certificates, VPN status, ecosystem and blocklisted apps, Apple DEP, iOS version. Software Made in Germany, no US cloud access.

  • Real-time indigo compliance status
  • Configurable notification paths for violations: integration partner, CISO, optional BSI
  • Checks against every mandatory VSA and SecOps requirement, including versioning
  • ISEC7 SPHERE, Software Made in Germany, hosted in German data centers
  • Also valuable for NIS2 compliance evidence in KRITIS environments
indigo compliance monitoring dashboard by ISEC7

Frequently asked questions about indigo

Can you use a standard iPhone or iPad for classified information up to VS-NfD?

Yes, with indigo, Apple's solution for off-the-shelf iPhones and iPads, for which the BSI has issued approvals up to VS-NfD (BSI-VSA-10900) and NATO RESTRICTED (BSI-VSA-11003), valid until 31 October 2027. Besides the devices, the platform includes a UEM, VPN gateways, a PKI with certificate management and fixed IT policies. ISEC7 designs, builds and runs this platform as an indigo integrator.

What is indigo, and who holds the approval?

indigo is Apple's solution for using standard iPhones and iPads with classified information up to VS-NfD, Germany's classification for restricted official information, and NATO RESTRICTED. The BSI approvals are held by Apple Inc.: BSI-VSA-10900 as an approval up to VS-NfD, BSI-VSA-11003 as an approval for NATO RESTRICTED and BSI-VSA-10901 as an operating permission up to VS-NfD, all valid until 31 October 2027. ISEC7 holds no indigo approval of its own; it designs, builds and runs the platform as an integrator.

Which iOS versions does the approval cover?

According to Apple, the approval up to VS-NfD (BSI-VSA-10900) covers iOS and iPadOS 18, the NATO RESTRICTED approval (BSI-VSA-11003) covers iOS and iPadOS 26, and operating permission BSI-VSA-10901 covers iOS and iPadOS 18 and 26. The platform uses off-the-shelf iPhones and iPads, no special hardware. The BSI keeps the current status in its list of approved IT security products (BSI publication 7164).

Which MDM or UEM do you need for iPhones handling VS-NfD?

In an indigo environment, a UEM manages the devices according to the platform's fixed IT policies. For this, ISEC7 runs BlackBerry UEM, from the Sovereign Cloud if you prefer; BlackBerry UEM Server 12.21.1 holds Common Criteria certificate BSI-DSZ-CC-1235-2025, issued on 8 September 2025 at EAL4+ and valid until 7 September 2030, and the certificate holder is BlackBerry Ltd. In its announcement of 18 September 2025, BlackBerry describes itself as the first MDM vendor with this BSI certification for use with indigo and Samsung Knox. ISEC7 advises vendor-neutrally on choosing and migrating between UEM platforms.

Can Android phones be used for VS-NfD?

For Samsung devices, yes: on 28 July 2026 the BSI granted Samsung an operating permission up to VS-NfD for Knox Native Solution 3.13, BSI-VSA-11044, valid until 31 August 2027. ISEC7 can integrate Samsung Knox into the same platform as your indigo devices.

How do you set up an environment for iPhones handling VS-NfD?

It starts with an assessment of the current state and documentation of the changes required under the German VSA, followed by architecture, build-out, process definition and operations. ISEC7 takes on these steps as an indigo integrator for public authorities and companies, whether you are building a new platform or rebuilding an existing one. ISEC7 is based in Hamburg and has been in business since 2003.

How do I monitor whether iPhones keep meeting VS-NfD requirements?

By checking the environment continuously against the requirements: IT policies, certificates, VPN, ecosystem apps, blocklisted apps, Apple DEP status and iOS version. ISEC7 SPHERE checks the indigo infrastructure against exactly these VSA and SecOps parameters, with versioning, and shows compliance status in real time. Violations trigger notifications to the integration partner, the CISO or, optionally, the BSI. ISEC7 SPHERE is software made in Germany and runs in German data centers.

Does a VS-NfD solution for iPhones help with NIS2 and KRITIS obligations?

It does not replace them: indigo covers handling classified information up to VS-NfD on iPhone and iPad, while NIS2 and KRITIS obligations separately require measures and evidence from your organization. ISEC7 SPHERE documents the compliance status of indigo devices continuously and reports violations. You can use these reports in your own evidence for the NIS2 Directive.

Can the UEM for indigo run from a cloud in Germany?

Yes. In the Regulated Sovereign Cloud for BlackBerry UEM, ISEC7 runs the UEM in certified German data centers, operated by ISEC7 GmbH staff in Germany, with extended documentation and audits. Neither the manufacturer nor third parties have access to systems or data.

Last reviewed: 28 September 2026 · Approval details per BSI publication 7164 · BlackBerry UEM certificate as listed by the BSI

IT SECURITY IN VS-NfD ENVIRONMENTS
 

Secure indigo infrastructures for German government

 

iPhone and iPad up to VS-NfD for German security agencies, public administration and KRITIS operators. ISEC7 is your indigo integrator from Hamburg, in business since 2003.

  • indigo implementations by ISEC7
  • VS-NfD apps from the indigo ecosystem
  • indigo compliance monitoring with ISEC7 SPHERE
  • BSI approval held by Apple, valid until 31 October 2027
  • NATO RESTRICTED approval held by Apple (BSI-VSA-11003)