At a glance: NIS2 makes personnel security a binding control requirement; Germany strengthens this through national regulations, requiring CISOs to systematically document and monitor their human risk management processes.
The NIS2 Directive contains explicit provisions on personnel security, which Germany intensifies through national regulations and compliance requirements. CISOs must review and adapt their human risk management processes.
The EU NIS2 Directive obliges companies, public sector organisations and critical infrastructure operators to anchor personnel security as an independent control. Unlike the previous NIS1 regulation, this not only requires technical and organisational measures, but also mandatorily incorporates the human component in security concepts.
Germany has partially strengthened NIS2 requirements through national implementation. The requirements include background checks for personnel with access to critical systems, security awareness and training, as well as clear procedures for personnel changes and the termination of access rights. Particular attention is paid to suppliers, service providers and temporary workers, whose security status must also be assessed.
For CISOs, this means concretely: personnel security is no longer a secondary issue, but part of the mandatory governance structure. This includes documenting security roles, regular employee training, monitoring access rights, and established offboarding processes. Companies must be able to demonstrate that these measures are implemented and regularly reviewed.
Source: news.google.com · Published 17 July 2026
Lumi AI News — AI-assisted curation according to Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.