With the KRITIS-Dachgesetz (Germany’s umbrella act on critical infrastructure resilience), federal law for the first time requires private operators of critical facilities to conduct systematic screenings of personnel and service providers as part of the resilience plan. Personnel security is thereby placed on an equal legal footing with technical and structural security — anchored in EU law in Art. 13 (1) lit. e and Art. 14 of the CER Directive (EU) 2022/2557, which expressly provides for background checks. Implementation succeeds in four steps: classify roles on a risk basis, define screening depth per risk class, document in an audit-proof manner, define re-screening cycles.
The Legal Position: Personnel Security as an Operator Duty
The KRITIS-Dachgesetz, in force since March 2026 — the core duties are found in particular in § 13 KRITIS-DachG — obliges operators to take resilience measures that cover not only facilities and processes but also personnel; an overview of deadlines and sectors is provided in the article KRITIS-Dachgesetz 2026. The CER Directive names the security of personnel as a measure category in Art. 13 (1) lit. e and regulates background checks for persons in sensitive functions in Art. 14. In data protection terms, the screening rests on Art. 6 (1) lit. c and lit. f GDPR and § 26 BDSG (German Federal Data Protection Act) — the operator’s statutory duty supports the processing, and proportionality sets its limits.
Steps 1 and 2: Classify Roles, Define Screening Depth
Not every position needs the same screening — that would be neither proportionate nor efficient. The starting point is a risk-based role classification: who has access to critical parts of the facility, control and command systems or security-relevant information? Who can circumvent or disable protective measures? This typically yields two to three risk classes, each assigned a screening depth. A full screening for the highest class covers several categories:
- identity verification and consistency of the career history
- education and qualification credentials
- professional positions and references
- register and insolvency information from permissible sources
- sanctions and watch lists
- adverse media (media and press sources, dated)
- economic entanglements and conflicts of interest
For lower risk classes, a reduced selection suffices. What matters is that the mapping of role to screening depth is reasoned and applied consistently — a seemingly arbitrary practice that treats comparable roles differently is open to challenge both under data protection law and vis-à-vis the supervisory authority.
Steps 3 and 4: Documentation and Re-Screening
Vis-à-vis the supervisory authority, what counts is not that screening took place, but that it can be evidenced. Every check should record trigger, scope, sources (with dates), result and the responsible person — in a format you can submit unaltered in the event of an audit. The concept itself is equally in need of documentation: the criteria of the role classification, the mapping of screening depths and the data protection justification per screening category. Only this second layer turns individual checks into a system that withstands a supervisory review. Repetition also belongs in the concept: a hiring check is a snapshot; for critical roles, event-driven checks (role changes, concrete indications) and appropriate cycles must be defined. And do not forget service providers — third-party personnel with facility access belongs in the same grid as your own employees.
Why the State Vetting Covers Only Part of the Picture
Some operators point to existing official procedures — such as the security clearance under the SÜG (German Security Clearance Act) or sector-specific reliability vettings. These procedures, however, cover only certain roles, test narrowly against sovereign protected interests, and provide the employer with no usable result beyond “reliable/not reliable”. CV integrity, economic conflicts of interest and the time between vetting cycles remain unaddressed. They therefore do not fulfil the operator’s duty of personnel security — the detailed distinction is set out in the article State Security Clearance vs. Employer Screening.
Recommended Course of Action
Set up personnel security as a dedicated work package in the resilience plan — with a clear schedule before the ten-month deadline expires: role classification in weeks one to four, screening concept and data protection alignment thereafter, then the roll-out starting with the most critical roles. The Indicium software report maps the screening across the categories named above in an audit-proof manner — with dated sources and human final review (Art. 22 GDPR), from €79 per report. Examples from energy, water and health are available under Industries; for your specific setup, a demo is recommended.
This article provides general information and does not constitute legal advice.