Operators of critical facilities in energy, water and health must now implement personnel security as a distinct set of duties: the KRITIS-Dachgesetz (German act on the resilience of critical infrastructure) requires resilience measures under § 13 KRITIS-DachG, which — pursuant to Art. 13(1)(e) and Art. 14 of the CER Directive (EU) 2022/2557 — expressly include the security of personnel, including background checks; in parallel, § 30(2) BSIG (revised German act on the Federal Office for Information Security) demands personnel-security concepts on the cyber side. The answer to the question “which check for which role?” is: tiered — state-run vetting where a statute prescribes it, complemented by an internal, documented screening programme for all roles that undergo no state vetting or whose risks such vetting does not cover.
The legal position: two regimes run in parallel
After the registration deadline of 17 July 2026, the follow-up deadlines of the KRITIS-Dachgesetz apply to operators subject to registration: risk analysis and, subsequently, the resilience plan — personnel security is a mandatory component of it, not a footnote. Anyone who missed registration should complete it without delay; details in the article KRITIS-Dachgesetz: duties, deadlines and sectors. In parallel, the revised BSIG regularly applies to the same organisations: § 30(2) BSIG requires, among other things, concepts for personnel security and access control, and § 38 BSIG places personal responsibility on senior management — examined in depth in the article NIS2 and § 30 BSIG. Under data protection law, screening operates within the bounds of § 26 BDSG (German Federal Data Protection Act) and Art. 6 GDPR: necessary, proportionate, documented.
Which roles need which screening depth
The yardstick is the damage potential of the role, not its place in the hierarchy. A cross-sector orientation:
- Control rooms and grid operations (energy, water): persons who can operate facilities or trigger switching actions — highest screening depth, repetition in fixed cycles, event-driven checks in case of red flags.
- IT and OT administration, medical-technology admins (all sectors): privileged access to control and supply systems — enhanced screening including CV verification and adverse media, re-screening on role changes.
- External firms and service providers (maintenance, cleaning in security zones, external IT): often far-reaching access without HR onboarding — baseline check across the board, enhanced screening for coordinators and permanently deployed staff.
- Administrative roles without facility or system access: a baseline check at hiring regularly suffices; no continuous monitoring without cause.
Where state-run vetting applies — and where it does not
State-run reliability checks exist only where a specific statute mandates them — for instance under § 7 LuftSiG (German Aviation Security Act) in aviation security or under § 12b AtG in conjunction with the AtZüV in the nuclear sector. For the control room of a municipal utility, the grid operations of a water supplier or the medical-technology administrator of a hospital, there is no comparable state vetting: here, only the operator’s own programme applies. And even where state vetting exists, it covers neither CV integrity nor economic entanglements nor the period between vetting cycles — the article State security clearance vs. employer screening sets out the distinction in detail.
The tiered programme: software report for the broad base, hybrid for key roles
For implementation, a two-tier model has proven itself: a standardised software report for the broad base of roles subject to screening — defined check categories, repeatable, documented in an audit-proof manner — and an enhanced hybrid procedure with analytical case-by-case assessment for key roles. This creates a programme that can be presented to the supervisory authority as a systematic implementation of § 13 KRITIS-DachG and § 30(2) BSIG. Indicium delivers audit-proof software reports for this purpose, with dated sources and human final review (Art. 22 GDPR) — from €79 per report. You will find the complete implementation guide to the operator duty in the article Background checks as an operator duty.
Recommended course of action
Start with a role classification along damage potential, assign each class a screening depth and a repetition cycle, and expressly include external firms. Document the concept as part of your resilience plan and your BSIG measures — senior management should formally adopt it. We would be glad to show you what such a programme looks like in your sector — energy, water and health — in a personal conversation: book a demo.
This article provides general information and does not constitute legal advice.