✔ Data stored in EU   ✔ GDPR-compliant   ✔ Safe and secure (ISO-certified)

KRITIS compliance: why pre-employment screening is essential

We can’t tell you who to hire, we can tell you who you’re hiring
 

KRITIS refers to the system of organisations and facilities vital to the countries functioning, such as finance, energy, healthcare and water sectors. The main purpose of the KRITIS Framework Act is to ensure a high level of physical and digital security for companies. 

Pre-employment screening is the perfect way to establish safety and integrity within your organisation. In our whitepaper: Basics of Pre-employment screening , you will find everything you need to know about Pre-employment screening to create a safe work environment. 

Learn about:

  • Why is screening important?
  • Who is being screened?
  • When do you start?
disa employees walking

What does KRITIS mean?

KRITIS means kritische Infrastrukturen. The Critical Infrastructures (KRITIS) are regulated under the BSI Act. The legal framework serves to protect essential sectors, whose failure could lead to severe supply shortages, disruptions to public order and safety, or other serious consequences. 

Businesses operating in these sectors are required to comply with the statutory provisions due to the high level of responsibility involved. This also applies to employees: anyone performing a critical function involving sensitive information or systems, or applying for a corresponding position, must be trustworthy and meet the applicable compliance standards.

 

Critical Infrastructure sectors

Under the KRITIS framework, all organisations in these sectors (large or small) are recognised as Critical Infrastructures:

  1. Energy
  2. Health
  3. Information technology and telecommunications
  4. Transport and traffic
  5. Media and culture
  6. Water
  7. Finance and insurance
  8. Food
  9. Municipal waste disposal
  10. State and administration
     

 

disa employees working
disa employees working

KRITIS compliance and regulations


The BSI KRITIS Regulation specifies which facilities and organisations are impacted by this law. This is based on threshold values that determine the national importance of their services. 

Organisations are legally required to comply with:

  1. reporting,
  2. verification,
  3. and cybersecurity standards as outlined by the Federal Office for Information Security (BSI).

 

 

Is pre-employment screening crucial in combination with KRITIS?

The KRITIS law also includes the human factor. Employees with access to sensitive systems or data are a risk for companies within these critical sectors. Many businesses are involving employment screening in their compliance strategy. 

This way, you will hire someone with the right qualifications. This will not affect your time-to-hire. The average screening time is around 5 working days.   

Verifying the trustworthiness and integrity of your candidates not only strengthens internal security but also shows a proactive commitment to BSI-compliant risk management.

Pre-employment screening will give your company the comfort of being sure and is crucial, because it strengthens your compliance strategy. 
 

 

 

Relevant background checks

By screening your candidates, you show that your company is taking BSI compliance seriously. There are different background checks that you can do to protect your systems and the people who depend on your company:

Always confirm the applicant’s identity using a valid ID document. Employers must keep a copy for their records. Beyond a basic ID verification, DISA also provides a Personal ID-check, which confirms both the authenticity of the document and that the person presenting it is the rightful holder.

Verify that all listed diplomas or degrees are genuine. 

Reach out to the references listed by the candidate to confirm their previous employment. Make sure job titles, responsibilities, and dates correspond with the information provided on the CV.

Perform a careful review of publicly available online information. Ensure that all findings and actions fully comply with GDPR and privacy regulations.

This check helps organisations identify potential risks before they escalate. If an employee or partner has a questionable background, the financial and reputational impact can be severe. By conducting these checks early, you protect your organisation from unnecessary exposure and costly mistakes.