EU Cyber Rules Put German Executives on the Hook for Employee Background Checks
Published on 07/26/2026 at 21:12 | Redaktion boerse-global.de
Company directors in Germany’s critical infrastructure sector now face personal liability if they fail to run automated background checks on their staff, under two European Union directives that took effect in recent months.
The rules, known as NIS2 and DORA, go far beyond the usual onboarding paperwork. They require organisations to conduct recurring security screenings — not just when someone joins, but at regular intervals throughout their employment. Depending on the risk profile of the role, those re-screenings may need to happen every year or even every quarter.
Germany’s NIS2 implementation law, published in September 2025 as Bundestag document 21/1501, spells out the obligations in detail. The revised Federal Office for Information Security Act — specifically sections 30 and 38 of the new BSIG — places the duty to monitor personnel security policies squarely on senior management. While the law does not explicitly list background checks as a standalone measure, legal experts say they are implied by the supply-chain security requirements in Article 21 of the NIS2 directive and by the broader demands of an information security management system.
When it comes to documenting workplace hazards and safety procedures, many UK companies find themselves in a similar compliance bind — knowing the rules exist but struggling to produce the right evidence. A free toolkit with 41 ready-to-use checklists and risk assessment templates can help you close that gap quickly. Download the free Risk Assessment Toolkit
Municipal Utilities Face the Tightest Scrutiny
The rules hit hardest at municipal utilities and local energy suppliers. Any such company that employs at least 50 people or generates annual revenue of €10 million or more falls under the KRITIS regulations embedded in the NIS2 implementation law. To pass a NIS2 audit, these operators must produce a complete audit trail and documented evidence that staff have completed required training.
The documentation burden grows heavier for firms using modern software development tools, including AI-powered coding assistants. Auditors now expect detailed records showing user IDs, timestamps, file hashes and model IDs. Companies must also ensure that source code stays within the European Union — for example, by routing it through specialised cloud instances in Frankfurt’s eu-central-1 region. Technical compliance further demands integration with a Security Information and Event Management system and retention of audit logs for at least 12 months.
Fines, Personal Liability and a Four-Hour Clock
Penalties for non-compliance are steep. Fines can reach €10 million or 2 percent of global annual turnover, whichever is higher. But the financial hit to the company is only part of the story. Both NIS2 and DORA introduce personal liability for executives, meaning directors can be held individually responsible for failures.
Reporting deadlines add another layer of pressure. Severe security incidents must be reported within 24 hours. Under the DORA regulation, that window shrinks to just four hours for incidents classified as significant.
To help companies keep up, service providers such as Validato now offer automated frameworks that handle financial checks, criminal record cross-references and media analysis. These systems store the documentation on European servers in a way that stands up to audit scrutiny.
The same principle of documented compliance applies to managing hazardous substances in the workplace. A dedicated COSHH toolkit provides 43 fully customisable templates and checklists to help you meet your legal duties for risk assessment and control. Get the free COSHH Toolkit
Training Directors on Their New Duties
Specialist training courses are emerging to educate senior leaders on their obligations under section 38 of the new BSIG. One online seminar scheduled for early September 2026 will cover reporting duties, documentation requirements and the specific liability risks facing management. Such training is itself part of the legally required security measures, helping companies demonstrate the due diligence expected in managing personnel-related risks.
Disclaimer regarding our articles: No investment advice, no buy or sell recommendation. Information on prices, companies, and markets is provided without guarantee; changes are possible at any time. Stock market transactions can lead to substantial losses. Our articles are created and reviewed in whole or in part automatically with the support of AI.
