CIVAC as an all-in-one compliance platform for medium-sized businesses: architecture, roles, document depth
Medium-sized companies manage data protection, information security, occupational safety and whistleblowing in separate Excel worlds. CIVAC bundles 25 officer roles into one platform with EU data residency and delivers officer-as-a-service in two business days.
Medium-sized companies today have to manage data protection in accordance with the GDPR, information security in accordance with NIS-2 and ISO/IEC 27001:2022, occupational safety in accordance with the ArbSchG, whistleblower protection in accordance with the HinSchG, money laundering prevention in accordance with the AMLA and, depending on the industry, 15 to 25 other mandatory roles in parallel. The BSI estimates the number of companies affected by NIS 2 in Germany alone to be around 29,500; the fines for important institutions are up to 10 million euros or 2 percent of group sales. The classic solution so far has been five to ten Excel tables, three external consulting contracts and a filing cabinet for the appointment certificates. Supervisory authorities and auditors are accepting this fragmentation less and less because it creates systemic consistency gaps and, in an emergency, does not allow submission within the legal deadlines.
CIVAC is built as a compliance platform and officer-as-a-service for exactly this problem. 25 officer roles are mapped in one workspace, from data protection officer to supplier auditor, with 93 controls according to ISO/IEC 27001:2022, 490 ready-to-use audit templates and an NIS 2 reporting path with 24-hour early warning and 72-hour follow-up notification. This article shows how the platform is structured architecturally, what depth of documentation it provides, which two reference models SMEs can choose and in which time frame an initial order becomes viable. He also explains the cost model compared to classic consulting and the implementation steps from day 1 to week 8.
Key Takeaways
- CIVAC bundles 25 mandatory and recommendation roles into one platform with EU data residency, instead of fragmented Excel worlds and isolated consulting contracts.
- Two reference models: Workspace licence for internal representatives or Officer-as-a-Service with appointment certificate, reporting line and CIVAC SLA of two working days.
- 93 ISO controls, 37 audit templates and the NIS-2 reporting path with 24/72 hour logic are built in as templates and cannot be purchased as a consulting project.
The problem: Fragmented compliance in medium-sized companies
A typical medium-sized company with 150 to 800 employees now has between eight and twelve mandatory roles in parallel. Data protection officer according to Art. 37 GDPR, occupational safety specialist according to § 5 ASiG, fire protection officer according to ASR A2.2, hazardous substances officer according to GefStoffV, if necessary dangerous goods officer according to § 1 GbV, information security officer according to NIS-2 and BSI recommendations, internal reporting office according to HinSchG, money laundering officer according to § 7 GwG, quality management officer according to ISO 9001:2015, environmental protection officer according to BImSchG or KrWG. There are also industry-specific roles such as hygiene officer in food production or radiation protection officer in radiology practices.
Each role has its own ordering obligations, its own reporting lines, its own audit templates, its own retention periods and its own fine framework. In practice, they are distributed among five to ten people, often as an additional task without clear hourly quotas. The documentation is in Excel tables on various drives, the appointment certificates in file folders, the audit protocols in PDF collections without version control. During an event-related audit, management must establish consistency within 14 days that was never achieved internally.
This fragmentation creates three systemic risks: First, deadlines are overlooked because there is no central view of the reporting lines. Secondly, contradictions arise between documents, for example between the DSB directory and the ISMS asset list. Thirdly, in the fine proceedings there is no proof of proper organisation in accordance with Section 130 OWiG. Others run compliance like a filing cabinet. We run it like software.
A fourth risk is business-related: the consultant fees add up without a consistent evidence base being created. Anyone who holds three external consulting contracts with daily rates between 1,200 and 2,500 euros and licences two to four special tools at the same time will regularly spend 60,000 to 250,000 euros per year in an SME without creating a uniform view of risks, measures and residual risks. This gap takes its toll on takeovers, bank audits, insurance contracts or procurement procedures: the due diligence is delayed, the conditions worsen and, in the worst case, the contract is lost.
The CIVAC architecture: One workspace, 25 roles, one receipt model
CIVAC maps all 25 representative roles in a common workspace. The roles range from the data protection officer (DSB) to the compliance officer (CO), the information security officer (ISB), the occupational safety officer (SiFa), the fire protection, hazardous substances, dangerous goods, environmental protection, money laundering, quality management and supply chain officers to specialised roles such as radiation protection, major incidents, emergency, pollution control, inclusion, waste and water protection officers. Each role has its own module with mandatory documents, audit templates, reporting line to management and reporting logic to the responsible supervisory authority.
The architecture follows a three-stage document model: order, activity, audit. At the order level, the appointment certificate is generated, signed and linked to the report to the supervisory authority if there is a reporting obligation. At the activity level, the annual mandatory activities are planned and documented: training, inspections, risk assessments, registers, emergency exercises. At the audit level, external tests, ISO certifications or supervisory requests are mapped with preparation, implementation and follow-up.
The 93 controls according to ISO/IEC 27001:2022 are stored as a mapping to the NIS 2 requirements, to Art. 32 GDPR and to industry-specific frameworks. Anyone who edits a control automatically updates the referencing documents. EU data residency is standard, all content is located in an ISO/IEC 27001:2022 certified data centre in the European Union. The appointment certificate, signed, filed, verifiable.
The link between the modules follows a consistent reference model: Every statement in a document is linked to the supporting document, every order to the report, every training session to the proof of participation, every incident to the cause analysis and the action plan. These links are not optional, but rather an architectural principle. Anyone who changes a document can immediately see which other documents are affected and will be guided to the update. This prevents the typical consistency gaps that arise in the Excel world between the directory, AVV, TOM and DPIA and which are seen in supervisory audits as evidence of systemic organisational deficiencies.
Two reference models: licence the workspace or appoint representatives
CIVAC offers two reference models, which are chosen depending on the size of the company, internal expertise and the desired distribution of liability. In the first model, companies licence the workspace for their internally appointed representatives. The roles are in-house, the appointment certificates are signed internally, the platform provides the templates, the reporting lines, the audit templates and the version control. This model is suitable for companies with a developed internal compliance function, for example with a legal department, a CISO, a human resources management and a QM function, which bear the operational burden but want to get rid of the fragmented documentation.
In the second model, CIVAC takes over the appointment of the external representatives as an officer-as-a-service. The order is documented with an appointment certificate, a report to the supervisory authority and a contractually agreed reporting line to management. CIVAC assumes operational responsibility for role management to the extent specified in the contract, from the creation of the directory in accordance with Art. 30 GDPR to responding to data breaches in accordance with Art. 33 GDPR to preparation for supervisory audits. The management remains responsible according to Art. 24 GDPR and Section 130 OWiG, but has a contractually binding escalation and reporting structure.
Both models can be combined: A company can manage the DPO internally, appoint the ISB externally and keep the money laundering officer as a pure workspace licence, depending on competence and workload. Licence the workspace for your internal representatives, or have our representatives order it. The CIVAC SLA of two working days until the signed order is valid in both models.
The choice between the models is not just a question of cost, but also a question of liability distribution and internal capacity. For internal orders, the management bears full responsibility in accordance with Art. 24 GDPR, Section 130 OWiG and the respective technical laws. When ordering externally, the operational burden is contractually shifted to CIVAC, but ultimate responsibility remains with the person responsible. This distribution is fixed in the officer-as-a-service contract with clear escalation rules, response deadlines and reporting obligations, so that management can provide concrete evidence of the supervisory standard required by Section 130 OWiG, even when appointed externally.
Depth of evidence and audit robustness: What the platform achieves in an audit
Audit robustness is created by three characteristics: seamless linking of statements and evidence, versioning with change history and the ability to submit within legal deadlines. The CIVAC platform meets all three points as an architectural principle, not as an add-on. Every statement in the list according to Art. 30 GDPR is linked to the underlying AVV, the TOM document and the DSIA, if applicable. Each ISMS statement is linked to the corresponding control according to ISO/IEC 27001:2022. Each order is linked to the report to the responsible supervisory authority and to the current status of activity.
Versioning is not optional. Every change is stored with a time stamp, editor and before-and-after comparison. In the case of a supervisory request, a fine procedure or a due diligence examination, the historical status can be reconstructed as of any date. This is not just a convenience feature, but a concrete level of evidence: in damages proceedings according to Art. 82 GDPR or in fine proceedings according to Art. 83 GDPR, the person responsible bears the burden of proof that they were properly organised.
Ability to submit within the deadlines is the third pillar. In the event of a data breach in accordance with Art. 33 GDPR, the 72-hour reporting requirement applies; with NIS-2, the logic of 24 hours of early warning and 72 hours of follow-up reporting applies. The platform provides the reporting path with prepared templates; the mandatory fields are linked to the ISMS and the directory. The auditor calls, the evidence is ready. Audit-proof, documented, § 30-proof, § 8a-proof, ISO-proof.
Audit-proof also has an impact in the sales pipeline and in supplier audits. Banks, insurance companies, KRITIS operators and authorities are increasingly demanding evidence of the GDPR directory, ISO certification, AVV, TOM and whistleblower reporting centre in procurement procedures. Anyone who delivers this evidence within hours instead of weeks wins contracts that others lose. In the case of takeovers and due diligence checks, the document depth reduces the effort for the data room and is directly reflected in the purchase price and scope of the guarantee because the risk discounts that are regularly applied in the event of incomplete compliance are eliminated.
ISO/IEC 27001:2022 and NIS-2: How 93 controls and 24/72 logic are built in
The transition period for ISO/IEC 27001:2022 expires on October 31, 2026, from this date only certificates according to the new standard are valid. The 93 controls in the new Annex A structure are divided into four themes: organisational, personal, physical and technological measures. The CIVAC platform maps all 93 controls as editable templates, with links to the NIS 2 requirements according to BSIG, to Art. 32 GDPR and to industry-specific frameworks such as B3S for KRITIS operators. Each control has a maturity indicator from 1 to 5, a person responsible, a review date and a connection point to audit findings.
NIS-2 requires around 29,500 companies in Germany to be classified as essential and important facilities. Important facilities carry a risk of fines of up to 10 million euros or 2 percent of group sales, important facilities up to 7 million euros or 1.4 percent. The NIS 2 reporting obligation follows the 24/72 logic: an early warning to the BSI within 24 hours of knowledge, a follow-up report within 72 hours and a final report within one month.
CIVAC maps this logic as an ISB module. The early warning is created in a guided workflow, with mandatory fields for issue, concern, availability restriction and initial measures. The follow-up message builds on the early warning and complements the root cause analysis and the planned follow-up measures. Deadline begins as soon as we become aware of it. Anyone who works without a system regularly loses the 24-hour deadline in the first few hours because internal escalation and external reporting have to happen in parallel.
The ISO/IEC 27001:2022 certification is issued by accredited bodies, not by CIVAC. However, the platform prepares the certification consistently: all 93 controls are evaluated, documented and linked to evidence, the internal audits are planned and carried out, the management review is shown as a function, and the findings from previous audits are stored with action plans. If you are an SME going for ISO certification for the first time, you can use the CIVAC platform to reduce the preparation time from typically six to twelve months to three to six months.
Data residency, confidentiality and client separation
A compliance platform processes particularly sensitive data: appointment certificates with names and addresses of the representatives, audit findings with descriptions of vulnerabilities, whistleblower reports with identity information, risk analyses with threat models, directories with overviews of all processing activities. This information is the core objective of any regulatory review and is also an attractive target for attackers because it provides a complete picture of a company's vulnerabilities. Data residency and confidentiality are therefore not compliance requirements, but rather architectural decisions.
CIVAC operates the platform in an EU data residency in accordance with ISO/IEC 27001:2022 with 93 controls. All content, including backups and logs, is located in data centres within the European Union. There is no routine transfer to third countries. The client separation is implemented logically and cryptographically, with separate key hierarchies for each client. Privileged access by CIVAC staff is logged, requires four eyes and is limited to contractually defined occasions.
For clients that fall under NIS-2 or industry-specific regulations such as BAIT, VAIT, DORA, CIVAC provides order processing in accordance with Art. 28 GDPR with standard contractual clauses, TOM documentation in accordance with Art. 32 GDPR and an ISMS interface. The configuration of the protection requirement classes is client-specific and follows BSI standards 200-2 and 200-3, so that the CIVAC platform fits seamlessly into existing ISMS structures. The appointment certificate, signed, filed, verifiable.
The whistleblower reporting point according to the HinSchG requires special confidentiality guarantees because identifying information must be protected. CIVAC represents the reporting office as its own, client-separate area with additional encryption of the content, with a dedicated reporting line to the receptionist designated by the company and with an auditable separation of access rights. Access by CIVAC personnel is limited to contractually defined maintenance events and is fully logged so that the requirements for protecting the identity of the person providing the information in accordance with Section 8 of the HinSchG are met.
Implementation: From the first request to the productive platform
The initial implementation follows a standardised path with the CIVAC SLA of two working days for the appointment of external representatives and four to eight weeks for the full expansion of the platform. Day 1 after conclusion of the contract: Workspace set up, client activated, user roles assigned, first appointment certificate generated from the template and ready to be signed. Day 2: Appointment certificate signed, report sent to the supervisory authority if necessary, reporting line to management set up as a function.
Week 1 to 2: Master data for processing activities taken from the inventory or collected with the departments in two to three workshops per area. AVV register imported, TOM document updated to the status of the 93 ISO controls, first risk analysis prepared according to ISO/IEC 27005. Week 3 to 4: Audit templates selected from the 490 templates for the specific roles, first annual program planned, training plan drawn up for employees.
Week 5 to 8: First internal audit carried out, findings documented, action plan decided. Configured interfaces to HR systems, ticket systems and SIEM solutions. Management receives the first CO report according to a standard structure with risks, measures and residual risks. Compared to classic implementation, which typically takes two to six months, the platform is in productive operation in less than two months. Turn reading into a mandate.
During ongoing operations, the platform takes over the reminder logic for mandatory appointments: annual training, inspections, risk assessments, ISMS reviews, ISO re-certifications, AMLA due diligence obligations, NIS 2 tests. Each reminder is linked to the appropriate assignee and escalation level in the reporting line. The management sees the next 30, 60 and 90 days and the outstanding measures from the last audit in a dashboard. This view replaces the usual quarterly meeting with five Excel spreadsheets with a consolidated risk view that can be captured in 15 minutes.
Cost model, ROI and comparison to classic consulting
Classic compliance consulting in medium-sized businesses combines two to five external consultants with daily rates of 1,200 to 2,500 euros, expenses between 20 and 80 days per year depending on the scope of the role, and a software landscape of two to four special tools with annual licence costs between 8,000 and 40,000 euros. The typical total burden of a medium-sized company with eight to twelve mandatory roles is between 60,000 and 250,000 euros per year, without a consistent document depth.
CIVAC bundles these tasks in a platform with a licence model that scales according to roles and reference model. In the workspace model, companies pay an annual licence that includes all 25 roles with templates, versioning, audit templates and interfaces. In the officer-as-a-service model, a fixed monthly fee is charged for each role ordered, which covers operational management, reporting obligations and preparation for supervisory examinations. Mixed models are permitted.
The ROI arises in three dimensions. First: direct cost savings through bundling in one platform instead of three to five special tools and multiple consulting contracts. Secondly: avoided risks of fines and damages according to Art. 83 GDPR up to 10 million euros, according to NIS-2 also up to 10 million euros, according to § 130 OWiG personal liability of the management. Third: Accelerate the sales pipeline and due diligence because supplier audits and procurement procedures can be responded to without delay. The auditor calls, the evidence is ready.
A conservative calculation for a medium-sized company with eight mandatory roles and 300 employees regularly results in cost parity in the first year and a cost reduction of between 30 and 50 percent from the second year onwards, calculated without the avoidance effects of fines and without the positive effects in the sales pipeline. If these effects are assessed with conservative probabilities of occurrence, the economic advantage is significantly higher than the pure cost calculation. However, more important than the ROI is the avoided residual risk, which is regularly underestimated in SMEs with fragmented compliance because it is not on the balance sheet.
From understanding the platform to the specific order
CIVAC does not replace corporate responsibility, but it replaces filing cabinet logic with software logic. Anyone who runs the fragmented world of Excel and consultants today knows the risk: a single supervisory audit, a single data breach, a single supplier inquiry can tie up resources for days because internal consistency does not exist. Anyone who switches to a platform is not just building a reporting tool, but an operational system that can bear the compliance burden for the next five to ten years, including NIS 2 extensions, AI Act obligations and upcoming ESG reporting requirements according to CSRD.
The decision between the two reference models depends primarily on internal competence and the desired distribution of liability. If you have an experienced CISO, a well-rehearsed legal department and an experienced QM function, you licence the workspace and manage the roles internally. If you are looking to appoint external representatives because internal resources are lacking or liability should be transferred to a contractually bound partner, you appoint the representatives as officers-as-a-service. Licence the workspace for your internal representatives, or have our representatives order it.
If you want to check the inventory for your company or order a specific role, turn reading into an order. Write to info@civac.de or use the contact form on civac.de. We will respond within one business day with a concrete proposal specifying the role, scope, reporting line and SLA. The FAQ page answers the most frequently asked questions about roles, appointment certificates and data residency in advance. If you are initially just looking for a location assessment, you can arrange a 45-minute appointment in which CIVAC reflects the current compliance status against the 25 roles, identifies the open duties and makes a suggestion for the order in which the order should be placed.
FAQ
What roles does CIVAC cover?
CIVAC represents 25 representative roles: DSB, CO, ISB, SiFa, BSB, GSB, GGB, UsB, GwB, QMB, LkSG, AGG, company doctor, HB, ESG, IMB, ImB, AB, GB, NB, SB, StB, InkB, BL, LA. Each role has its own module with appointment certificate, reporting line, audit templates and associated regulatory reporting logic. The roles can be booked both as a workspace licence for internal orders and as an officer-as-a-service.
How does the Workspace licence differ from Officer-as-a-Service?
With Workspace, you licence the platform for your internally appointed representatives and retain operational responsibility in-house. With Officer-as-a-Service, CIVAC appoints the officers externally, with an appointment document, notification to the supervisory authority and a contractually agreed reporting line to the management. Both models share the same platform, the same document depth and the same CIVAC SLA of two business days to signed order.
Where is the data located and how is client separation secured?
All data is stored in an EU data residence according to ISO/IEC 27001:2022 with 93 controls, including backups and logs. Client separation is implemented logically and cryptographically, with separate key hierarchies for each client. Privileged access by CIVAC staff is logged, requires four eyes and is limited to contractually defined occasions. Order processing in accordance with Art. 28 GDPR is standard; a TIA is not required for third country cases.
How quickly can the platform be used productively?
Day 1 to 2: Workspace set up, first appointment certificate signed, reporting line activated. Week 1 to 4: Master data collected, AVV imported, TOM updated, audit templates selected. Week 5 to 8: first internal audit carried out, first management reports created, interfaces to HR and ticket systems configured. Classic advice requires two to six months for the same status without creating a consolidated depth of documentation.
Does CIVAC replace an external auditor or law firm?
No, CIVAC is a compliance platform and officer-as-a-service, not an accounting firm or law firm. External certifications according to ISO 27001, external annual audits or legal advice in fine proceedings will continue to be provided by accredited bodies. CIVAC provides the evidence base on which these external services are based and takes over the operational management of the representative roles to the extent specified in the contract.
Can CIVAC take on individual roles or just the entire package?
Individual rolls can be ordered, the entire package is not mandatory. Many companies start with a DSB or ISB and later add a whistleblower reporting office, money laundering officer or ESG officer. The CIVAC platform is modular, each role can be licensed separately and ordered separately as Officer-as-a-Service, with its own appointment certificate and reporting line. Mixed models are permitted and common, with a central dashboard for management.
Sounds like a lot of work?
Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.
Turn this into a mandate.
Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.