IndiciumIndicium
Log in
← Back to blog
Background checks for HR, Legal and Compliance

Turn public-source risk signals into audit-ready decisions.

Indicium helps regulated teams screen candidates, counterparties and sensitive hires — with dated sources, human review and reports your Legal team can defend.

Working through this checklist? The Indicium report documents your personnel-security answers with dated sources and human final review.

NIS2 readiness: 10 questions that reveal your real status

A NIS2 readiness checklist of 10 questions: registration, § 30 BSIG measures, incident reporting and management duties, each with a good and a bad answer.

A NIS2 readiness check in Germany reduces to four statutory questions: does § 28 BSIG capture you, did you register with the BSI in time (§ 33), could you report a significant incident within 24 hours (§ 32), and can senior management evidence its oversight (§ 38)? The ten questions below turn these duties into a self-assessment for one afternoon; each carries a good answer to document and a bad answer that names the consequence. The recast BSIG applies since 6 December 2025, without a transition period.

The ten questions

1. Do you know whether § 28 BSIG captures you?

A good answer is a written scope assessment with a date on it. The law distinguishes particularly important entities under § 28(1) from important entities under § 28(2), and the sector annexes span 18 sectors, from energy and health through waste management to research. Entities self-assess; no authority writes to tell you that you are covered. The bad answer, “we assumed we were too small”, is the most expensive assumption in the regime. For sectors that additionally carry KRITIS status, see What is KRITIS? Sectors, thresholds and duties.

2. Are you registered with the BSI, and is the data current?

The registration portal has been live since 6 January 2026, and the statutory three-month deadline under § 33 BSIG expired on 6 March 2026. The duty outlives the deadline: late registration remains mandatory and separately sanctionable with fines of up to 500,000 euros. A good answer shows the portal confirmation, a named owner for the data, and a habit of filing changes within two weeks. A bad answer is an unfiled registration nobody owns. Under § 33(3) BSIG the BSI may substitute the registration itself, and you lose control over what the authority holds about you.

3. Can you show a current risk analysis and an IT-security concept?

§ 30(2) BSIG opens its catalogue with risk analysis and appropriate IT-security concepts, and § 30(1) requires documented compliance with the measures. The BSI compares this to the accountability principle in Art. 5(2) GDPR: undocumented measures count as absent ones. A good answer is a risk analysis with a review date, mapped to the measure areas, signed off at leadership level. A bad answer is the analysis from the cloud migration three years ago. For particularly important entities, § 61 BSIG adds proactive supervision: the BSI can review measures before any incident happens.

4. Does every measure area in § 30(2) have a named owner?

The catalogue prescribes ten minimum areas: risk analysis, incident handling, business continuity, supply-chain security, security in acquisition and development, effectiveness evaluation, training and awareness, cryptography, personnel security with access control, and multi-factor authentication with secured communications. A good answer maps each area to an owner and a piece of evidence. A bad answer is a single document titled “ISMS” that quietly skips some areas.

5. Does personnel security exist as a concept, not a policy?

§ 30(2) No. 9 BSIG requires concepts for the security of personnel, access control and the management of IT systems. The Commission Implementing Regulation (EU) 2024/2690 concretises this in Annex point 10: recruitment conditions, screening of personnel, termination handling and a documented disciplinary process, with recital 22 naming criminal-record queries and reviews of past professional performance as reliability checks. A good answer describes risk-based screening before access is granted, tiered by role, with re-screening on role changes and external staff included through the supply-chain concept. A bad answer is a password policy and an NDA. When an incident comes from inside, the first question is what the entity knew about the person holding the access. The operational structure is laid out in NIS2 personnel security: the duties under § 30 BSIG.

6. Would your staff recognise a phishing email aimed at them?

Basic training and awareness measures are mandatory under § 30(2) BSIG, and § 38(3) extends regular training to senior management itself. A good answer has participation records showing who was trained and when, and a management that has sat through its own session. A bad answer is a policy nobody has opened since onboarding. The reporting chain in question 7 depends on an employee who notices something and knows whom to tell.

7. Could you file the early warning within 24 hours?

Under § 32(1) BSIG, a significant incident triggers an early warning within 24 hours of becoming aware, a notification within 72 hours, and a final report within one month, with a progress report standing in if the incident continues. The clock starts at Kenntniserlangung, knowledge by an employee within working hours, not when leadership hears about it. Reports go to the joint reporting office of BSI and BBK. A justified incomplete 72-hour report is permissible; lateness is the sanctionable defect, and § 32 violations sit in the top fine tier with caps of 10 million and 7 million euros. A good answer is a rehearsed chain with a named contact and pre-drafted forms. A bad answer is improvisation on the day. The full deadline structure is in NIS2 incident reporting: deadlines under § 32 BSIG.

8. Do you know which suppliers could put your service at risk?

Supply-chain security is its own mandatory measure area under § 30(2) BSIG, and the personnel-security duty expressly reaches service-provider staff: externals with system access pass through no HR onboarding and would slip through every net. A good answer documents which providers are security-relevant, pairs contractual requirements with your own review of their posture, and routes external personnel into the screening concept. A bad answer is a folder of provider certificates. The duty sits with you, and a breach arriving through a provider is still your incident to report under question 7.

9. Has senior management approved and documented the measures?

§ 38 BSIG makes the approval of risk-management measures and the oversight of their implementation a personal duty of senior management that cannot be fully delegated, with liability under general company law for culpable damage. A good answer shows dated approval decisions, regular reporting upward, and training attendance under § 38(3). A bad answer is delegation without documentation. An approval that exists only as a conversation is hard to reconstruct when a regulator asks for it.

10. Could you hand the BSI your evidence this week?

This question tests everything above. § 30(1) makes documentation part of the duty itself, and effectiveness evaluation is one of the ten measure areas, so evidence must be current rather than archival. For particularly important entities, § 61 supervision means the request can arrive without an incident. A good answer is a folder where each of the nine questions above has its dated record: scope assessment, registration confirmation, risk analysis, measure mapping, screening records, training logs, reporting drills, provider reviews, approvals. A bad answer is a plan to assemble documents after the request arrives.

Where personnel verification fits in

Damaging incidents usually involve someone who was authorised to be there, which is why the statutes treat people as a risk vector. Operationally, that means verification before access is granted, documented per trigger: hiring, role changes, and externals entering through a provider contract. A reviewable check covers identity and employment history, sanctions and watch lists, adverse media with dated sources, and economic entanglements, with a human making the final judgement. Indicium delivers this as structured, reviewable verification of key personnel, proportionate to the access a role carries.

Frequently asked questions

Is there an official NIS2 checklist from the BSI?

Yes. The BSI publishes the NIS-2-Checkliste as a free PDF, dated 13 March 2026, as self-assessment orientation rather than a binding form. An online Betroffenheitsprüfung helps with the scope question.

Is ISO 27001 certification enough for NIS2 compliance?

No. The BSI states that a company certification alone is insufficient. Certification can support several § 30 measure areas, but registration, the § 32 reporting process and the § 38 management duties sit outside its scope.

What evidence must senior management keep ready for NIS2?

Documentation of measure compliance under § 30(1), dated approval decisions under § 38, training records including management’s own, and a rehearsed § 32 reporting chain. Undocumented approval is treated as absent approval.

This article provides general information and does not constitute legal advice.

Ready to move from reading to doing?

See how a reviewable risk report is built – from name to verdict in minutes, not weeks.

Book a demo See a sample report