Checklist for Background Checks According to the CER Directive
For HR and security managers in organizations that may be classified as critical operators and subject to background check requirements.
Background
What is the CER Directive?
checkPurpose: To strengthen the resilience of critical operators to ensure essential services even during crises, attacks, or disruptions.
checkReplaces the previous ECI Directive (2008/114/EC).
checkComplements NIS2 (cybersecurity) but focuses on physical and organizational resilience.
checkBecomes law in Sweden through the Act on Resilience of Critical Operators (LOM).
A critical operator is an entity that:
1Provides essential services in one of the eleven designated sectors.
2Has critical infrastructure in Sweden.
3Where an incident could have significant disruptive effects.
Timeline
Important Dates
14 July 2026The Swedish government submitted the bill on the Act on Resilience of Critical Operators (LOM) to the Riksdag (prop. 2025/26:303).
1 January 2027LOM is proposed to enter into force. The supervisory authorities then identify which organizations are critical operators.
10 months after identificationOrganizations are to have implemented routines, including background checks.
Authorities
Supervisory Authorities
checkMyndigheten för civilt försvar (MCF, formerly MSB): Coordinating authority for CER in Sweden, responsible for guidance, national strategy, and reporting to the EU.
checkSupervisory authorities: Each sector will have its own supervisory authority (e.g., the Energy Agency for the energy sector).
checkSanction fees: For private operators: the higher of 2% of global annual turnover or the equivalent of EUR 10 million. For public operators: up to SEK 10 million.
Sectors
Which Sectors Are Covered?
The CER Directive applies to 11 critical sectors:
boltEnergy
directions_busTransport
account_balanceBanking
trending_upFinancial Markets
local_hospitalHealthcare
water_dropDrinking Water Supply
wavesWastewater
dnsDigital Infrastructure
publicPublic Administration
restaurantFood Production
rocket_launchSpace Activities
Operators of European significance: If the organization operates in multiple EU countries or has cross-border impact, it should assess whether it may be classified as an operator of European significance under the CER Directive. This may entail additional reporting and coordination requirements with the EU Commission.
Control Requirements
Who Should Be Checked and When?
checkPositions that, following a documented position analysis, are assessed as potentially causing more than minor disruption to the essential service – may include employees, consultants, and suppliers
checkFrequency: When warranted, but no later than within two years of the most recent check
What Is Included in a Background Check According to CER?
Verified identity: Verification of an approved and valid ID document. If the expiration date has passed, the check is considered invalid. ID verification is fundamental - without this step, other checks lack credibility.
Criminal record extract: The individual brings a special extract from the criminal record (max 6 months old) which is presented in conjunction with the ID check at a physical meeting. A note that the check has been performed should be made (no copy or other information is saved).
Complementary assessment: References, employment history, assessment of loyalty and reliability, good personal knowledge.
Re-check: When warranted, but at least every two years.
Security Risks
Risks of False Identities
warning_amberFake ID documents are frequently found in the labor market and pose a significant security risk.
warning_amberFor an ID check to be considered secure, it should always include an authenticity analysis by trained personnel - visual inspection alone is not sufficient.
warning_amberIf the ID document is fake or invalid, other background checks lack credibility.
Examples of Risks
warningSabotage
visibilityEspionage
group_offInfiltration by Criminals
account_balance_walletMoney Mules
person_offEnablers
dangerousWorkplace Crime
Employers must thoroughly document personnel security work to meet the requirements of CER. This includes:
Appoint a responsible function:Appoint a person responsible for personnel security (HR manager, security manager, or equivalent) who ensures that checks are performed according to regulations and that no individuals are missed. This person is also the point of contact with the supervisory authority regarding background checks.
Timeline for compliance:Once the organization has been identified as a critical operator by the supervisory authority, it has 10 months to implement routines for personnel security, including background checks. Ensure the checklist is linked to this deadline and that an internal project plan exists to meet the requirements on time.
Policies and procedures:There must be documented internal procedures for how background checks are conducted, how often, by whom, and how results are handled. These documents may be requested by the supervisory authority and are useful for training managers and HR staff internally.
Register of checked individuals:A list should be maintained of which positions have been identified as critical and which individuals hold them. The date of the background check per individual and the planned date for the next check should also be recorded. Only authorized personnel should have access to the list.
Handling check results:If a background check raises no "red flags," it is usually sufficient to note that the person is approved without remarks. However, if something unusual emerges - e.g., the criminal record extract shows a relevant conviction - the employer must document how it has been handled. This may include a special risk assessment, decision on possible reassignment or other measures, and that the employee has been informed and given the chance to explain. These steps should also be documented.
Prepare for supervision and sanction risk:Supervisory authorities have the right to review procedures, documentation, and compliance with personnel security requirements. Deficiencies can lead to sanction fees of up to the higher of 2% of global annual turnover or the equivalent of EUR 10 million (private operators), or SEK 10 million (public operators). Ensure the checklist includes an item on internal auditing and that responsible parties are aware of the supervision process.
Conduct an operations-based risk analysis:Before positions are identified as critical, the organization should conduct a risk assessment of its operations. The purpose is to understand which functions, systems, and roles are most vulnerable in the event of incidents. This analysis should be documented and serve as the basis for which positions require background checks.
Identify critical positions:Conduct a position analysis that clarifies which roles in the organization are so significant that an unsuitable person in that role could cause more than minor harm to the essential service. This includes positions with major impact on operations and security - e.g., operations managers, system administrators, security officers, key personnel in control rooms. This also applies to external personnel.
Set external requirements:Conduct a position analysis of external personnel with access to the essential service and require that this personnel also be checked. External actors should also be able to present documentation showing which checks have been performed, when and how, upon request.
Execution:Perform background checks on individuals in these positions before appointment (i.e., upon new hire or internal transfer to such a role), and on an ongoing basis during employment. The government's CER investigation proposes that employees already in critical roles should be checked periodically - at least every two years - to detect if a previously reliable person's circumstances change in ways that may pose a risk.
Document the checks:Have organized procedures and maintain records showing that a background check has been completed for each person in the designated positions, when it was done, and by whom. The material must be available for inspection but otherwise handled under confidentiality.
Follow-up and reminders:Implement routines for notifications or reminders to responsible parties for background checks to be carried out, sent well before 24 months have passed since the last background check for an employee. The purpose is to ensure follow-up occurs on time and no checks are missed.
Checklist
Your Checklist for CER Compliance
Checklist0 of 13 done
Recommendations
Best Practices and Recommendations
Managing individual checks that include identity validation, documentation, and follow-up requires structure and system support. Both to ensure that the checks are carried out correctly and that the handling complies with applicable laws and regulations.
Sistec’s Right to Work workflow brings together identity checks, document review and follow-up. The scope of checks must be adapted to the role and applicable requirements.
Right to Work
checkAuthenticity analysis of ID documents
checkVerified identity and nationality
checkCriminal record check in conjunction with ID verification
checkSecure documentation of completed checks
checkAutomated reminders for follow-ups
checkIntegration capability with HR systems
checkCustomer portal to invite third parties who need to verify that the supplier's personnel have been checked.