INTRA/PS/PS001Pre-employment screening
The verification, before employment begins, of who the candidate is, that they may lawfully work, and that the account they give of their own history holds against evidence that does not come from them.
| Control | Jurisdiction | Source | What it establishes | Prerequisite or recommendation |
|---|---|---|---|---|
| PS001/EUMandatory | European Union | Commission Implementing Regulation (EU) 2024/2690European Commission · read 29 Aug 2026Directive (EU) 2022/2557 on the resilience of critical entities, articles 13 and 14European Parliament and Council · read 1 Sep 2026 | What the directive’s categories hold, in an annex setting out asset classification, the inventory, access control, privileged accounts, and removable media as requirements rather than as headings. | For the digital infrastructure and service providers it reaches, verification of an employee’s background is required as far as it can be done, where it is necessary for the role, the responsibilities, and the authorizations held. The mechanisms for hiring are named in the same place: reference checks, vetting procedures, validation of certifications, or written tests. For a critical entity the persons a check may be requested on include those under consideration for a sensitive role, or for a role authorized to reach the premises, the information, or the control systems. That check corroborates identity and examines the criminal record for offences relevant to the specific position, and it is carried out for the sole purpose of evaluating a security risk. |
| PS001/ATMandatory | Austria | Arbeitsverfassungsgesetz, sections 96 and 96aNationalrat · read 29 Aug 2026 | That a control measure touching human dignity has no legal effect without the works council’s consent, and that consent for automated processing and for assessment systems can be replaced by a conciliation board while consent under section 96 cannot. | What needs the works council’s consent is the form put to the person: a personnel questionnaire asking beyond general particulars and the professional qualifications for the work intended. Verification carried out against a third party is not reached by it. |
| PS001/ITMandatory | Italy | Determinazione ACN n. 379907 del 18 dicembre 2025Agenzia per la cybersicurezza nazionale · read 29 Aug 2026 | The baseline security measures an Italian NIS subject has to adopt, among them the recording of remote and administrative access and its central retention, the detection of privilege abuse, and the vetting of the people admitted to the systems that matter. | For a subject in the national NIS register, the people authorized to reach the systems that matter are identified on a prior assessment of experience, capability, and trustworthiness, and have to give suitable guarantee that they will keep to the rules on information security. The trustworthiness of human resources is one of the areas the determination requires a written policy to cover. |
| PS001/ESMandatory | Spain | Real Decreto 311/2022, Esquema Nacional de SeguridadGobierno de España · read 29 Aug 2026 | The security measures a Spanish public sector body has to apply, graded by category, among them the concurrence of two people on critical tasks so that no single authorized individual can abuse their rights, an access control on the activity records themselves, and the recording of evidence where an incident may end in disciplinary action. | The requirements a person has to satisfy to hold a post are defined, in particular on confidentiality, and they are taken into account in selecting who will hold it. What is verified is named: the employment history, the training, and other references, in conformity with the law and with respect for fundamental rights. |
| Recommended | Belgiumwhere written | CyberFundamentals 2025, EssentialCentre for Cybersecurity Belgium · read 29 Aug 2026 | What the Belgian centre sets out for the heaviest of its assurance levels, and the only place in this record where a national authority names the insider as something the detection tools are there to catch. | A background verification check should be carried out before a person is brought into a sensitive role, and it takes into account the applicable laws, regulations, and ethics in proportion to the business requirements. |
| Recommended | Germanywhere written | IT-Grundschutz-Kompendium, Edition 2023Bundesamt für Sicherheit in der Informationstechnik · read 29 Aug 2026 | What the German federal authority holds to be the state of the art, in numbered requirements, among them the checking of a candidate’s own account of themselves, a logging infrastructure the administrators who run it cannot alter, a regular audit of the detection systems against the state they are supposed to be in, and how evidence is secured. | A new employee should be checked for trustworthiness before being hired, and everyone taking part in the selection should check whether what the candidate says bearing on that is credible. The curriculum vitae is examined for correctness, plausibility, and completeness, and whatever looks conspicuous in it is followed up. Separately, the qualifications a post requires are to be formulated exactly, and a post filled only by someone who has them. |
| Recommended | Netherlandswhere written | Baseline Informatiebeveiliging Overheid 2, versie 1.3Nederlandse overheid · read 29 Aug 2026 | The government measures Dutch public bodies add on top of the two information security standards, among them a screening policy, a detection use case named in the text, and a log retention set against the scenario that an attacker has been inside for a long time. | Every entity has a screening policy that has been settled. On entering service, and on a change of function, a certificate of conduct may be asked for on the basis of a weighing of the risk. |
| Recommended | United Kingdomwhere written | Ongoing Personnel Security: A Good Practice GuideNPSA · read 11 Aug 2026 | Good practice for personnel security through employment rather than at the door, holding that protective monitoring should be proportionate. | Good practice treats screening at recruitment as the opening of a process rather than its completion. |
