IndiciumIndicium
Log in
NIS2 Personnel Security & Compliance

Personnel security under NIS2 — from statutory duty to documented screening.

The NIS2 Implementation Act (NIS2UmsuCG) has been in force since 6 December 2025 — without a transition period. Around 29,500 organizations fall under the re-founded BSIG, and § 30 Abs. 2 explicitly demands concepts for personnel security, access control, and supply-chain security. Indicium turns the human-risk duty into documented, audit-ready screening: dated sources, human final review, management-ready sign-off.

NIS2 Art. 21(2)(i)NIS2UmsuCG§ 30 BSIG§ 38 BSIG§§ 28, 33 BSIGSÜG pre-screening
from €79 per report·120+ companies trust Indicium·3,000+ reports in the last two years·six-month satisfaction guarantee
See a sample report
01 Where NIS2 compliance actually gets stuck

The duty is in the statute. The concept is what auditors miss.

a
A legally named duty category
§ 30 Abs. 2 BSIG transposes Art. 21 Abs. 2 lit. i of Directive (EU) 2022/2555 into German law and names personnel security explicitly, alongside access control and supply-chain security. An organization that can show firewalls and patch management but cannot explain how it secures the integrity of people with privileged access has left a named category uncovered.
b
Management liability
§ 38 BSIG obliges the management to approve the § 30 risk-management measures and to oversee their implementation — a personal duty of the leadership level that cannot be fully delegated. If an incident comes from inside and no screening ever took place, that gap is hard to explain — to the auditor and in the boardroom.
c
More entities, fewer excuses
The new BSIG catches around 29,500 organizations as particularly important or important entities — far more than the old KRITIS regime. Many mid-market companies are in scope without knowing it. The registration duty under § 33 BSIG was due by 6 March 2026: check your status, document it, and build the personnel-security concept on top.
02 Regulatory mapping

Your framework, our documentation.

Every report is built so its documentation slots directly into your ISMS and your NIS2 audit file.

FrameworkWhat it requiresHow Indicium documents it
NIS2 Art. 21(2)(i)Personnel security as a named category of risk-management measuresRole-based screening with documented risk assessment, dated sources, audit trail
§ 30 BSIG (NIS2UmsuCG)Concepts for personnel security, access control, and supply-chain securityGraded screening concept for hiring, role changes, and service providers
§ 38 BSIGManagement must approve the measures and oversee their implementationManagement-ready summary for sign-off, documented oversight trail
§§ 28, 33 BSIGScope of application and registration dutyDocumented scope check as step one of the screening concept
SÜGState security clearance (sovereign; does not fulfill the operator duty)Pre-screening layer: surfaces disqualifying findings before the official procedure begins
BDSG §26 / GDPRLegal basis for processing candidate and employee dataBerechtigtes Interesse assessment, human final review (Art. 22 GDPR)

The honest boundary: a state security clearance (SÜG) does not fulfill the personnel-security duty under § 30 BSIG, and Indicium does not decide your scope under § 28 BSIG. Indicium is the documented screening layer that keeps the human-risk category auditable — dated sources, human final review. Scope and legal-basis decisions remain with you and your counsel.

03 From abstract duty to screening concept

Three screening occasions the statute already implies.

A concept for personnel security stays abstract in the law. Operationally, the proven structure follows three occasions — and Indicium documents each one, graded by role criticality.

a
Hiring
Risk-based check before onboarding, graded by role criticality: administrators, control-room personnel, and key functions are screened more intensively than roles without privileged access. The grading itself is documented — that is what makes the concept defensible.
b
Role changes
Whoever moves internally into a critical function was never screened for that function. The move is its own screening occasion — with the same documented depth as an external hire at the same level.
c
Service providers & externals
Externals with system access bypass HR onboarding and otherwise fall through every grid. The supply-chain category of § 30 Abs. 2 BSIG explicitly pulls them into your concept — Indicium screens contractors with the same documented rigor.
04 Matching depth to the role

From routine role screening to analyst-led escalation.

a
Software-Report
Seven check categories in parallel, from €79 — routine role screening, resolved in under 30 minutes for 80% of cases.
b
Hybrid
Software depth plus documented human review — for privileged roles: administrators, control-room personnel, and other key functions under § 30 BSIG.
c
Boutique
Fully analyst-led investigation for high-stakes cases, multi-jurisdiction backgrounds, or pre-screening ahead of a state security clearance (SÜG).
FAQ What your management and your auditor will ask
Does a state security clearance (SÜG) fulfill our § 30 BSIG personnel-security duty?+
No. The official security clearance under the SÜG is a sovereign procedure conducted by government authorities — and it does not fulfill the operator duty under § 30 BSIG. Indicium serves as a fast, documented screening layer: risk-based checks with dated sources and human final review, surfacing disqualifying findings before they become incidents.
Which roles must we screen under § 30 BSIG?+
The statute stays abstract; the defensible answer is risk-based and graded by role criticality. Roles with privileged access — administrators, control-room personnel, key functions — warrant deeper checks than roles without privileged access. What matters for the audit file is documented grading: which roles, which depth, which sources, decided by whom.
Do internal role changes and external service providers need screening too?+
Yes, in practice. An internal move into a critical function is its own screening occasion — the person was never checked for that function. Externals and service providers with system access bypass HR onboarding entirely, and § 30 Abs. 2 BSIG explicitly includes supply-chain security, which pulls them into your personnel-security concept.
Can we delegate NIS2 personnel security to HR or IT?+
Not fully. § 38 BSIG obliges the management to approve the risk-management measures under § 30 BSIG and to oversee their implementation — a personal duty of the leadership level that cannot be completely delegated. The question of how your organization ensures personnel security must be answered and documented at management level; Indicium supplies the documented screening layer that answer rests on.
What does a concept for personnel security actually require?+
More than a password policy or an intranet guideline. The law demands a concept that addresses the human factor across the employment lifecycle — hiring, role changes, and exit — alongside access control and supply-chain security. The proven structure is a graded screening concept for these occasions, approved by the management and documented for audits.
Is screening candidates lawful under GDPR?+
Pre-employment screening in Germany typically relies on berechtigtes Interesse (legitimate interest, Art. 6(1)(f) GDPR) within the bounds of BDSG §26. Indicium reports include documented human final review (Art. 22 GDPR). Screening of existing employees can require works council involvement; we recommend clarifying the setup with your works council and your data protection officer before implementation.
Where is our data hosted — and which deployment options are available?+
Query and report data is currently hosted and processed in the EU on AWS infrastructure (Frankfurt/Ireland), with Google Cloud EMEA used for AI processing. Deployment on T Cloud Public is available on customer request and is planned as our standard setup from 1 January 2027.

This page provides general information about Indicium's services and the regulatory frameworks named above (NIS2 Directive (EU) 2022/2555, NIS2UmsuCG/BSIG, SÜG, BDSG/GDPR, BetrVG). It does not constitute legal or regulatory advice and does not replace an assessment by your own counsel, your data protection officer, or your supervisory authority for your specific case. Regulatory mapping reflects our understanding of the cited frameworks and does not guarantee a particular compliance outcome or supervisory acceptance.

Personnel security your management can sign off.

Software for the repeatable, people for the decisive, made in Europe.

Book a demo See a sample report