The German NIS2 implementation act (NIS2UmsuCG) has been in force since 6 December 2025 — without a transition period. Around 29,500 companies fall under the recast BSIG (German act on the Federal Office for Information Security) as “particularly important” or “important entities”, and § 30(2) BSIG expressly requires them to have concepts for personnel security, access control and supply-chain security. § 38 BSIG makes senior management personally responsible for implementation. Anyone who has so far treated “personnel security” as a password policy has not fulfilled the duty — what is required is a concept that vets people, not just accounts.
Who is covered — and which deadline has already passed
The scope follows from § 28 BSIG: covered are particularly important and important entities from a broad range of sectors — considerably more companies than under the old KRITIS regime. Many mid-sized businesses are affected without knowing it. The registration obligation under § 33 BSIG had to be fulfilled by 6 March 2026; anyone who has not yet assessed whether they are in scope should do so now and document it. For operators of critical facilities, the KRITIS-Dachgesetz (German act on the resilience of critical infrastructure) applies in parallel with its own deadlines — see KRITIS-Dachgesetz 2026: duties and deadlines.
What § 30 BSIG specifically requires
§ 30(2) BSIG transposes Art. 21(2)(i) of the NIS2 Directive (EU) 2022/2555 into German law and names the measure categories that every entity must cover — expressly including:
- Personnel security: concepts addressing the risk arising from the human factor — from hiring through role changes to departure.
- Access control: who receives which permissions, who decides on them, how are they revoked?
- Supply-chain security: the inclusion of service providers and suppliers in your own security concept.
The sequencing is striking: the legislator places the human dimension alongside the technical one. An entity that can point to firewalls and patch management but cannot explain how it assures the integrity of the persons holding privileged access has simply left a mandatory category unaddressed.
From abstract duty to screening concept
“Concepts for personnel security” remains abstract in the statute — operationally, a structure along three triggers has proven itself:
- Hiring: risk-based screening before work begins, tiered by the criticality of the role (administrators, control-centre staff and key functions more intensively than roles without privileged access).
- Role change: anyone moving internally into a critical function was never vetted for that function — the move is a screening trigger in its own right.
- Service providers: externals with system access go through no HR onboarding and would otherwise slip through every net; the supply-chain duty of § 30 BSIG expressly brings them into the concept.
Implementation practice in the KRITIS domain provides a methodological template — the implementation guide for background checks can be transferred to NIS2 entities. Important for roles subject to state vetting: the state security clearance does not fulfil the operator duty — on the distinction, see State security clearance vs. employer screening.
The liability dimension: § 38 BSIG
§ 38 BSIG obliges senior management to approve the risk-management measures under § 30 BSIG and to oversee their implementation — a personal duty of the leadership level that cannot be fully delegated. For managing directors and board members, this means: the question “how do we ensure personnel security?” must be answered at leadership level, and the answer must be documented. A gap in a statutorily named measure category is hard to explain when things go wrong — especially when the incident came from inside and a check never took place.
Recommended course of action
Proceed in three steps: first, clarify and document your status under §§ 28, 33 BSIG — scope and registration. Second, mirror your existing security concepts against the measure categories of § 30(2) BSIG — with an honest answer to the question of whether “personnel security” at your organisation is more than a policy on the intranet. Third, set up a tiered screening concept for hiring, role changes and service providers and submit it to senior management for approval. Indicium supports this with audit-proof software reports with dated sources and human final review (Art. 22 GDPR) — from €79 per report; sector-specific examples are available under Industries.
This article provides general information and does not constitute legal advice.