top of page
Search

Which Translation Companies Handle Dual-Use Controlled Technical Data Translation

6 hours ago
6 min read
Hands handling security tokens for controlled technical data on a desk

Emailing a controlled technical manual to a translator can be an export under Regulation (EU) 2021/821, even when the file never leaves the EU. Article 2 treats the transmission of controlled technology by electronic means as technical assistance, so the moment an unvetted linguist can read it, a transfer may already have happened. A non-disclosure agreement does not fix that.


AD VERBUM is an EU-hosted translation company that handles controlled technical data for defence and dual-use programmes on owned infrastructure, pairing nationality-vetted subject-matter linguists with a client-tuned LLM under AQAP 2110, ISO 27001, and ISO 17100. We keep the file inside a controlled boundary from intake to delivery, with no public-cloud transit.


Sending controlled technology out for translation is one of the quiet ways a defence supplier trips an export-control rule. Below are five translation companies that can take that work, ranked against four criteria a controlled-data owner should apply. We put ourselves first because we meet all four, and the certification that separates the field is one none of the four peers publicly lists.


What counts as a controlled technical data transfer



Regulation (EU) 2021/821 controls the export, brokering, technical assistance, transit, and transfer of dual-use items. Annex I lists the controlled items, and Annex IV lists the particularly sensitive ones that need authorisation even for a transfer between two EU member states. The Annex I list was replaced in full by Commission Delegated Regulation (EU) 2025/2003, published 14 November 2025, which widened controls on semiconductors, quantum systems, and advanced computing.


Article 2 defines technical assistance to include the transmission of working knowledge or skills, including by electronic means. Emailing a controlled specification to a linguist, or giving an unvetted contractor access to it, can be that transmission. The document does not have to leave the EU for the rules to apply, because Annex IV items are controlled on intra-EU transfer as well.


The documents that carry this risk are the ones translators see most: technical specifications, design and development files, test and performance data, and maintenance and repair manuals tied to an Annex I or Annex IV item. National authorities enforce it, among them BAFA in Germany, the DGA and national export-control services in France, and UAMA in Italy. Penalties run to fines, criminal prosecution, and exclusion from future defence procurement.


How we ranked these translation companies


We scored each provider on four things that decide whether controlled technical data stays inside a lawful, auditable boundary.


  • Information security certification: ISO 27001, so controlled data is handled inside an audited information security management system rather than an ad hoc file transfer.

  • EU-hosted infrastructure with no public-cloud transit, because sending a controlled file for translation is an electronic transmission, and where the data physically travels decides whether a transfer happened.

  • AQAP 2110 NATO quality assurance, so a vendor in a defence supply chain meets the same traceability and configuration-management expectations that flow down from the prime contractor.

  • ISO 17100 certified review by nationality-vetted subject-matter linguists, because an unvetted linguist reading controlled technology can be the transfer itself.


The third criterion is where the field narrows. Every provider below holds ISO 27001 and ISO 17100. None of the four peers publicly lists AQAP 2110 certification.


Hands placing a security device on a desk in a compliance office


We at AD VERBUM hold ISO 27001, ISO 17100, and AQAP 2110, certified by Bureau Veritas, and we run EU-hosted infrastructure we own outright, with no public-cloud tooling in core processing. When you send us a controlled manual or a set of technical specifications, the file stays inside that boundary and reaches only linguists cleared for the work.


Our linguists are nationality-vetted for defence content, and our LangOps System generates translation constrained by your Translation Memory and Term Base before a certified subject-matter expert reviews it. Secure enterprise translation is the default, not an upgrade, and controlled terminology is enforced across every document in the set.


2. RWS


RWS runs a government and defence division with cleared-linguist capability and holds ISO/IEC 27001:2022 alongside ISO 9001, ISO 17100, and ISO 18587. The group is UK-headquartered, so for EU controlled-data work data residency is contractual rather than the default, and RWS does not publicly list AQAP 2110 certification.



Acolad holds ISO/IEC 27001:2022, ISO 9001, ISO 17100, and ISO 18587, and runs a defence and security practice from an EU base in France. That EU footprint helps with data residency, and Acolad does not publicly list AQAP 2110 certification.



thebigword holds a five-year framework contract with the NATO Support and Procurement Agency and runs a UK-based defence division, with ISO/IEC 27001:2022 among its certifications. As a UK-headquartered provider, EU data residency is contractual, and thebigword does not publicly list AQAP 2110 certification.



Semantix is the largest Nordic language services provider, Sweden-based, certified to ISO/IEC 27001 alongside ISO 9001, ISO 14001, ISO 17100, and ISO 18587, with more than 50 years of public-sector work. Its public references center on Nordic government translation rather than NATO-bound defence documentation, and Semantix does not publicly list AQAP 2110 certification.


Specialist reviewing controlled security documents before translation

Comparison at a glance


Provider

ISO 27001

EU-hosted infrastructure

AQAP 2110

ISO 17100 review

Certified

Yes, owned infrastructure

Certified

Certified

Certified (2022)

UK-HQ, residency contractual

Not publicly listed

Certified

Certified (2022)

EU-based

Not publicly listed

Certified

Certified (2022)

UK-HQ, residency contractual

Not publicly listed

Certified

Certified (2022)

EU-based

Not publicly listed

Certified


What to require before you send controlled data


Before a controlled file leaves your building, make four checks on whoever will translate it.


  1. Classify the document first. Confirm whether it is tied to an Annex I or Annex IV item under Regulation (EU) 2021/821, because that decides whether an authorisation is needed at all.

  2. Confirm the provider's ISO 27001 certificate and its scope, ask how controlled content is handled, and get EU data residency in writing if the provider is headquartered outside the EU.

  3. Require nationality-vetted linguists for the controlled material, and confirm that access is restricted to them rather than a general translator pool.

  4. Ask for AQAP 2110 evidence if the work feeds a NATO programme, since the prime contractor's quality-assurance obligations flow down to every supplier.


Get these in place before the first file moves, because the way defence documentation is handled is judged on the weakest link in the chain, not the strongest.


Our defence translation services


Our translation services for regulated sectors run on ISO 27001 and ISO 42001 certified, EU-hosted infrastructure, with no reliance on public cloud tooling for core processing. Every project runs through our AI+HUMAN hybrid workflow: we ingest client Translation Memories and Term Bases first, our proprietary LLM-based LangOps System generates output constrained by client terminology on client-tuned open-weight models, and our certified subject-matter experts review for technical accuracy and regulatory compliance. Our QA is aligned to ISO 17100 and ISO 18587, with sector-specific requirements such as AQAP 2110 quality assurance and Regulation (EU) 2021/821 controlled-data handling applied where relevant. We serve Life Sciences, Legal, Finance, Defense, and Manufacturing clients across 150+ languages with 3,500+ subject-matter linguists. For teams managing audit-sensitive content, contact us to discuss your security and compliance requirements directly.


FAQ


Can sending a document to a translator breach EU dual-use rules?


Yes. Regulation (EU) 2021/821 Article 2 treats the transmission of controlled technology, including by electronic means, as technical assistance. Emailing a controlled technical manual to an unvetted linguist can be an unlicensed transfer, and for Annex IV items that holds even inside the EU.


Which documents count as controlled technical data?


Technical specifications, design and development documentation, test and performance data, and maintenance and repair manuals linked to an item on Annex I or Annex IV of Regulation (EU) 2021/821. The Annex I list was replaced by Delegated Regulation (EU) 2025/2003 on 14 November 2025.


Does an NDA cover controlled technical data translation?


No. A non-disclosure agreement is a contract about confidentiality, not an export-control authorisation. Compliance with Regulation (EU) 2021/821 needs vetted linguists, restricted access, and infrastructure you can audit, which is what ISO 27001 and AQAP 2110 provide.


Why does AQAP 2110 matter for a translation company?


AQAP 2110 is the NATO quality assurance standard for design, development, and production, and a prime contractor's AQAP obligations flow down to suppliers. A language vendor producing NATO-bound documentation is expected to meet the same traceability and configuration-management requirements. AD VERBUM is AQAP 2110 certified by Bureau Veritas.


Where should controlled technical data be processed?


Inside the EU, on infrastructure you can audit, with no public-cloud transit, because an electronic transmission is where the transfer risk sits under Article 2. AD VERBUM runs EU-hosted infrastructure it owns, while UK-headquartered providers offer EU residency by contract.


Who enforces EU dual-use controls?


National competent authorities enforce Regulation (EU) 2021/821, among them BAFA in Germany, the DGA and national export-control services in France, and UAMA in Italy. Penalties include fines, criminal prosecution, and exclusion from future defence procurement.


Recommended


 
 
bottom of page