The act modernising the SÜG (German Security Clearance Act) of 11 January 2026 has been in force since 16 January 2026 (Federal Law Gazette — BGBl. 2026 I No. 6/7) and noticeably tightens the state security clearance. The most important change for practice: internet research now becomes mandatory even at the basic security clearance level (Ü1) — until now, the depth of review at the lowest level lagged clearly behind Ü2 and Ü3. For companies under official classified-information protection (Geheimschutz), this means the state review is converging methodologically with what professional private screening has long delivered.
The three levels of security clearance at a glance
In §§ 7–10 SÜG, the act provides for three types of clearance, graded by the sensitivity of the activity:
- Ü1 — basic security clearance (§ 8 SÜG): the entry level for activities with access to classified information of lower classification.
- Ü2 — extended security clearance (§ 9 SÜG): the intermediate level with greater depth of review, including, among other things, the personal environment.
- Ü3 — extended security clearance with security investigations (§ 10 SÜG): the most intensive level for particularly security-sensitive activities.
Which level applies depends on the security-sensitive activity — not on the level of hierarchy. You will also find a classification of the terms in our glossary.
What the amendment changes in concrete terms
The core of the modernisation is the adaptation of the review methodology to digital reality. Publicly accessible information on the internet — from search-engine results and media reports to publicly viewable profiles — is now mandatorily included in the clearance already at level Ü1. Until now, this depth of research was reserved for the higher levels; going forward: anyone who is security-vetted at all is also vetted online.
The legislature is thereby catching up with what has long been consensus in security practice: a person’s online reputation is a distinct, relevant subject of review. Extremist statements, problematic connections or contradictions to a person’s self-presentation often show up first online — not in registers.
What this means for ongoing and future clearances
For security officers (Sicherheitsbevollmächtigte) and compliance managers in companies under classified-information protection, three practical consequences follow:
- New applications will be assessed against the tightened standard. Candidates should be prepared for the fact that their publicly visible online presence is part of the clearance.
- Pre-selection gains weight: Anyone who nominates a person for a security-sensitive activity whose online reputation carries recognisable risks is risking delays in the procedure. A structured integrity check before the application reduces this risk — more on this in the article on classified-information protection in industry.
- Supervisory expectations rise overall: When the state makes OSINT research a mandatory standard of its own reviews, it becomes harder to justify why a company’s own screening for sensitive roles should do without this dimension.
The state catches up — but does not replace your own screening
The direction of the amendment is remarkable: with mandatory internet research, the legislature introduces exactly the depth of review that professional private screening — OSINT research, adverse-media checks, online reputation analysis — has established as standard for years. This validates the methodological approach but changes nothing about the fundamental division of labour: the state security clearance serves the protection of classified information and sovereign protected interests; questions such as CV integrity, economic conflicts of interest or ongoing changes between review cycles remain the employer’s responsibility. The precise demarcation between the two worlds is covered in the article State security clearance vs. own screening.
Recommended course of action
First, review which positions in your company are subject to a security clearance under §§ 7–10 SÜG and which procedures are currently in progress. Make nominated persons aware that their online presence is now a subject of review at all levels. Establish a structured, documented pre-check before you submit clearance applications — this avoids delays and treats all candidates by the same standard. Indicium supports this with audit-proof software reports that include dated sources and a human final review (Art. 22 GDPR) — from €79 per report. For security-sensitive industries, we are happy to show the implementation in a demo.
This article provides general information and does not constitute legal advice.