Personnel security that works with your Betriebsrat — not against it.
Critical infrastructure operators face a dual challenge: NIS2 and the KRITIS-Dachgesetz demand personnel security for critical roles, but German labor law demands works council involvement. Indicium bridges both — with screening that satisfies BSI expectations and process documentation that satisfies your Betriebsrat.
The regulator wants screening. The Betriebsrat wants co-determination.
Your framework, our documentation.
Every report is built so its documentation slots directly into your ISMS and your BSI audit file.
| Framework | What it requires | How Indicium documents it |
|---|---|---|
| NIS2 Art. 21 | Personnel security measures for critical roles | Role-based screening with documented risk assessment, dated sources, audit trail |
| KRITIS-Dachgesetz | Implementation of NIS2 in German law for KRITIS operators | Regulatory mapping in report annex, BSI-audit-ready documentation |
| SÜG | Official security clearance procedure (sovereign) | Pre-screening layer: surfaces disqualifying findings before the official procedure begins |
| BSI / IT-SiG §8a | KRITIS security standards and oversight | Report compatible with ISMS documentation, BSI-audit-ready format |
| BDSG §26 | Legal basis for employee data processing | Berechtigtes Interesse assessment, pre-employment vs. employee screening differentiation |
| §87 BetrVG | Works council co-determination for technical monitoring | Process documentation and template Betriebsvereinbarung for works council negotiation |
The honest boundary: Indicium does not replace the sovereign SÜG procedure. It is the pre-screening layer that prevents obvious failures from reaching the official process — saving months and fees. The final security clearance decision remains with the government authority.
A tool your Betriebsrat can say yes to.
The biggest blocker for KRITIS personnel screening is not the technology — it is the works council. Indicium comes with the documentation that makes the negotiation productive instead of adversarial.
From routine role screening to analyst-led escalation.
Does Indicium replace the official SÜG security clearance?+
How does Indicium work with our works council (Betriebsrat)?+
Is social media screening legal for our employees?+
Where is our data hosted — and is sovereign deployment available?+
This page provides general information about Indicium's services and the regulatory frameworks named above (NIS2, KRITIS-Dachgesetz, SÜG, BSI/IT-SiG, BDSG, BetrVG). It does not constitute legal or regulatory advice and does not replace an assessment by your own counsel, your works council, or your BSI contact for your specific case. Regulatory mapping reflects our understanding of the cited frameworks and does not guarantee a particular compliance outcome or supervisory acceptance.