IndiciumIndicium
Log in
← Back to blog
Background checks for HR, Legal and Compliance

Turn public-source risk signals into audit-ready decisions.

Indicium helps regulated teams screen candidates, counterparties and sensitive hires — with dated sources, human review and reports your Legal team can defend.

The Indicium report maps the personnel-security duties under the KRITIS-DachG and BSIG in audit-proof form — with dated sources and human final review.

Employee Screening for Critical Infrastructure: A Decision Guide

KRITIS operators in energy, water and health: which role needs which screening depth — state-run, internal or software report. A decision guide.

Operators of critical facilities in energy, water and health must now implement personnel security as a distinct set of duties: the KRITIS-Dachgesetz (German act on the resilience of critical infrastructure) requires resilience measures under § 13 KRITIS-DachG, which — pursuant to Art. 13(1)(e) and Art. 14 of the CER Directive (EU) 2022/2557 — expressly include the security of personnel, including background checks; in parallel, § 30(2) BSIG (revised German act on the Federal Office for Information Security) demands personnel-security concepts on the cyber side. The answer to the question “which check for which role?” is: tiered — state-run vetting where a statute prescribes it, complemented by an internal, documented screening programme for all roles that undergo no state vetting or whose risks such vetting does not cover.

After the registration deadline of 17 July 2026, the follow-up deadlines of the KRITIS-Dachgesetz apply to operators subject to registration: risk analysis and, subsequently, the resilience plan — personnel security is a mandatory component of it, not a footnote. Anyone who missed registration should complete it without delay; details in the article KRITIS-Dachgesetz: duties, deadlines and sectors. In parallel, the revised BSIG regularly applies to the same organisations: § 30(2) BSIG requires, among other things, concepts for personnel security and access control, and § 38 BSIG places personal responsibility on senior management — examined in depth in the article NIS2 and § 30 BSIG. Under data protection law, screening operates within the bounds of § 26 BDSG (German Federal Data Protection Act) and Art. 6 GDPR: necessary, proportionate, documented.

Which roles need which screening depth

The yardstick is the damage potential of the role, not its place in the hierarchy. A cross-sector orientation:

  • Control rooms and grid operations (energy, water): persons who can operate facilities or trigger switching actions — highest screening depth, repetition in fixed cycles, event-driven checks in case of red flags.
  • IT and OT administration, medical-technology admins (all sectors): privileged access to control and supply systems — enhanced screening including CV verification and adverse media, re-screening on role changes.
  • External firms and service providers (maintenance, cleaning in security zones, external IT): often far-reaching access without HR onboarding — baseline check across the board, enhanced screening for coordinators and permanently deployed staff.
  • Administrative roles without facility or system access: a baseline check at hiring regularly suffices; no continuous monitoring without cause.

Where state-run vetting applies — and where it does not

State-run reliability checks exist only where a specific statute mandates them — for instance under § 7 LuftSiG (German Aviation Security Act) in aviation security or under § 12b AtG in conjunction with the AtZüV in the nuclear sector. For the control room of a municipal utility, the grid operations of a water supplier or the medical-technology administrator of a hospital, there is no comparable state vetting: here, only the operator’s own programme applies. And even where state vetting exists, it covers neither CV integrity nor economic entanglements nor the period between vetting cycles — the article State security clearance vs. employer screening sets out the distinction in detail.

The tiered programme: software report for the broad base, hybrid for key roles

For implementation, a two-tier model has proven itself: a standardised software report for the broad base of roles subject to screening — defined check categories, repeatable, documented in an audit-proof manner — and an enhanced hybrid procedure with analytical case-by-case assessment for key roles. This creates a programme that can be presented to the supervisory authority as a systematic implementation of § 13 KRITIS-DachG and § 30(2) BSIG. Indicium delivers audit-proof software reports for this purpose, with dated sources and human final review (Art. 22 GDPR) — from €79 per report. You will find the complete implementation guide to the operator duty in the article Background checks as an operator duty.

Start with a role classification along damage potential, assign each class a screening depth and a repetition cycle, and expressly include external firms. Document the concept as part of your resilience plan and your BSIG measures — senior management should formally adopt it. We would be glad to show you what such a programme looks like in your sector — energy, water and health — in a personal conversation: book a demo.

This article provides general information and does not constitute legal advice.

Ready to move from reading to doing?

See how a reviewable risk report is built — from name to verdict in minutes, not weeks.

Book a demo See a sample report