Personnel security under NIS2 — from statutory duty to documented screening.
The NIS2 Implementation Act (NIS2UmsuCG) has been in force since 6 December 2025 — without a transition period. Around 29,500 organizations fall under the re-founded BSIG, and § 30 Abs. 2 explicitly demands concepts for personnel security, access control, and supply-chain security. Indicium turns the human-risk duty into documented, audit-ready screening: dated sources, human final review, management-ready sign-off.
The duty is in the statute. The concept is what auditors miss.
Your framework, our documentation.
Every report is built so its documentation slots directly into your ISMS and your NIS2 audit file.
| Framework | What it requires | How Indicium documents it |
|---|---|---|
| NIS2 Art. 21(2)(i) | Personnel security as a named category of risk-management measures | Role-based screening with documented risk assessment, dated sources, audit trail |
| § 30 BSIG (NIS2UmsuCG) | Concepts for personnel security, access control, and supply-chain security | Graded screening concept for hiring, role changes, and service providers |
| § 38 BSIG | Management must approve the measures and oversee their implementation | Management-ready summary for sign-off, documented oversight trail |
| §§ 28, 33 BSIG | Scope of application and registration duty | Documented scope check as step one of the screening concept |
| SÜG | State security clearance (sovereign; does not fulfill the operator duty) | Pre-screening layer: surfaces disqualifying findings before the official procedure begins |
| BDSG §26 / GDPR | Legal basis for processing candidate and employee data | Berechtigtes Interesse assessment, human final review (Art. 22 GDPR) |
The honest boundary: a state security clearance (SÜG) does not fulfill the personnel-security duty under § 30 BSIG, and Indicium does not decide your scope under § 28 BSIG. Indicium is the documented screening layer that keeps the human-risk category auditable — dated sources, human final review. Scope and legal-basis decisions remain with you and your counsel.
Three screening occasions the statute already implies.
A concept for personnel security stays abstract in the law. Operationally, the proven structure follows three occasions — and Indicium documents each one, graded by role criticality.
From routine role screening to analyst-led escalation.
Does a state security clearance (SÜG) fulfill our § 30 BSIG personnel-security duty?+
Which roles must we screen under § 30 BSIG?+
Do internal role changes and external service providers need screening too?+
Can we delegate NIS2 personnel security to HR or IT?+
What does a concept for personnel security actually require?+
Is screening candidates lawful under GDPR?+
Where is our data hosted — and which deployment options are available?+
This page provides general information about Indicium's services and the regulatory frameworks named above (NIS2 Directive (EU) 2022/2555, NIS2UmsuCG/BSIG, SÜG, BDSG/GDPR, BetrVG). It does not constitute legal or regulatory advice and does not replace an assessment by your own counsel, your data protection officer, or your supervisory authority for your specific case. Regulatory mapping reflects our understanding of the cited frameworks and does not guarantee a particular compliance outcome or supervisory acceptance.