ISB-as-a-Service with NIS 2 Ready setup: Order in two working days instead of six weeks
With the implementation of NIS 2, around 29,500 companies in Germany are obliged to demonstrably implement technical and organisational cybersecurity measures. An appointed information security officer is the central operational person. This article describes CIVAC's ISB-as-a-Service model with a two-business-day SLA.
With the national implementation of the NIS 2 Directive via the NIS 2 Implementation and Cybersecurity Strengthening Act, which substantially expands the BSI Act, around 29,500 companies in Germany are subject to expanded information security obligations, from the energy industry and healthcare to food production and supply chains. Section 30 BSIG requires appropriate and proportionate technical and organisational measures, Section 32 BSIG requires a 24-hour early warning reporting path with 72-hour follow-up reporting to the BSI, and Section 38 BSIG requires training for management with personal liability for the management bodies. Anyone who wants to fulfil these duties without a dedicated information security officer will end up with an overload of tasks for the IT management, which will become visible in the first supervisory audit by the BSI.
CIVAC's ISB-as-a-Service model addresses exactly this gap between duty and internal capacity. It combines the appointment of a qualified natural person in accordance with Section 7 of the BSI Act with a workspace that maintains the 24h/72h reporting paths, the 93 controls according to ISO/IEC 27001:2022, 490 ready-to-use audit templates and an audit-proof audit log. The order SLA is two working days, compared to six weeks in the classic structure of an internal ISB. This article describes the scope of services, the handover process, the interaction with internal IT operations and the economic logic in which external ISB is the clean solution and in which internal ISB is the better one.
Key Takeaways
- An external ISB-as-a-Service fulfils the NIS 2 ordering obligation according to Section 30 BSIG just like an internal ISB, provided that qualifications according to Section 7 of the BSI Act and independence are contractually proven.
- The CIVAC workspace maps the 24-hour early warning and 72-hour follow-up notification path in accordance with Section 32 BSIG from a common incident data set, which also carries the GDPR Art. 33 notification in parallel.
- With 37 ready-to-use audit templates, 93 ISO/IEC 27001:2022 controls covered and a two-business-day order SLA, the time to NIS 2-Ready is significantly shorter than with internal construction.
NIS 2 obligations in the BSI Act: What Sections 30, 32 and 38 BSIG specifically require
The NIS 2 Directive was implemented into German law through the NIS 2 Implementation and Cybersecurity Strengthening Act, which substantially expands and partially restructures the BSI Act. Three paragraphs carry the main obligation and define the operational framework for the ISB. Section 30 BSIG requires essential and important facilities to take appropriate and proportionate technical and organisational measures in order to control risks to the security of network and information systems. The standard lists ten areas of measures, including risk analysis, incident processing, backup management, supply chain security, cryptography, identity and access management, personnel security and training.
§ 32 BSIG standardises the reporting obligations. A significant security incident must be reported to the BSI within 24 hours in the form of an early warning, followed by an updated follow-up report within 72 hours and a final report within one month. The deadlines start from the time the incident is known, not from the start of the internal analysis, and the BSI documents the receipt of the report down to the minute. Section 38 BSIG adds a training requirement for management and stipulates the personal responsibility of management bodies, which shifts the liability risk from the operational IT area to the management level.
The fines are significant. For essential facilities they are up to EUR 10 million or 2 percent of global group sales, and for important facilities they are up to EUR 7 million or 1.4 percent. In addition, there is the personal liability of management in accordance with Section 38 BSIG for oversight failures, which is not covered across the board by D&O insurance. Anyone who wants to implement these obligations without a named information security officer as the central operational body will take on the coordination between IT, legal and management with additional internal effort and without a clear allocation of responsibility.
What does ISB-as-a-Service mean in the CIVAC definition
ISB-as-a-Service is more than an external consultant with an hourly rate and a daily pass for the business premises. The CIVAC model bundles four components in a representative order, which, as a closed package, meets the NIS 2 requirements and can be verified as a unit in the audit. First: the appointment of a qualified natural person as ISB, with proof of qualifications in accordance with Section 7 of the BSI Act, documented training hours of at least 40 per year and financial loss liability insurance with appropriate coverage. The order is made formally via an appointment certificate, countersigned by the named ISB and the management of the person responsible.
Secondly: a workspace with multi-client architecture, EU data residency and audit-proof audit log with hash backup. The workspace maintains the 93 controls according to ISO/IEC 27001:2022 in a structured form so that risk analyses, effectiveness tests, evidence documents and action plans are managed in one system. Third: 490 ready-to-use audit templates that are kept up to date for NIS 2 audits, BSI inquiries, supplier audits and ISO 27001 pre-audits. These templates are not static, but are updated against new supervisory guidance from the BSI and ENISA.
Fourth: the 24h/72h reporting path with defined triage and escalation. A security incident that must be reported goes through five stages: detection with a time stamp, triage by the ISB within four hours, early warning to the BSI within 24 hours, follow-up report within 72 hours and final report within one month. Licence the workspace for your internal representatives or have our representatives order it. Both models use the same tenant and templates. The ISB-as-a-Service is the second variant, with a named natural person from the CIVAC team. Others run compliance like a filing cabinet. We run it like software. The difference is not reflected in the offer, but in the first real report to the BSI.
Order SLA: Two business days instead of six weeks
The classic setup of an internal ISB takes six to twelve weeks, longer in many medium-sized companies if the job market for qualified security specialists is tight. The phases include job advertisement, selection process, contractual adjustment, formal order with appointment certificate, familiarization with the IT inventory, creation of documentation and initial calibration of the measures. When an external order is placed through a traditional law firm, the process typically takes three to six weeks because contracts first have to be negotiated, the documentation file is set up again and the law firm still allocates resources internally.
The CIVAC order SLA of two working days is possible because three structural preparations are permanently in place. First: standardised appointment certificate templates with an independence clause and reporting line, which are only supplemented by client data and scope. Secondly: a well-maintained pool of designated ISB people with different industry focuses (industry, health, finance, energy), so that the professional fit is determined on the first working day. Third: a preconfigured workspace tenant with preset templates that is filled with the client data, the initial risk analysis and the first control assessments within 24 hours.
What happens in the two working days can be clearly described. Working day one: Kickoff appointment (60 minutes), clarification of the scope, preliminary NIS 2 classification (essential, important, not affected), handover of the existing security documentation and the relevant contracts with IT service providers. Working day two: Sending the appointment certificate for countersigning, activation of the workspace tenant, initial triage readiness of the ISB and filing of the reporting paths. From the third working day, the 24-hour reporting path is activated and the ISB can be reached. The appointment certificate, signed, filed, verifiable. If you want to run faster, you can check it out, but the market realistically can't do it without compromising your qualifications.
How ISB-as-a-Service works with internal IT operations
An external ISB does not replace internal IT operations, but rather structures it against NIS 2 requirements and provides the external audit perspective. The interface to IT must be clearly defined from day one, with responsibilities, escalation paths and reporting cadence. The ISB is not authorised to give instructions to IT, but rather advises, checks and reports. The responsibility for implementing the technical measures remains with the management and the CISO or the IT manager; the ISB ensures compliance with Section 30 BSIG and documents it.
In practice, four routines have proven themselves that seamlessly integrate the ISB into IT operations. First: monthly meeting between ISB and IT management, in which ongoing measures, open risks, new vulnerabilities and the current vulnerability patch backlog are discussed. Second: quarterly risk report to the management with a consolidated assessment against the 93 ISO 27001 controls and a short heatmap. Third: event-based escalation of incidents, with a defined threshold (e.g.: any incident that affects personal data or critical infrastructure, or that results in a service interruption of more than four hours). Fourth: annual effectiveness check of the measures with a documented test report, which can also be presented with the next BSI request.
Where a data protection officer has been appointed, the ISB and DSB work closely together because many security incidents are also data protection mishaps. In the CIVAC workspace, both reporting paths run from the same incident data set: Section 32 BSIG for the NIS 2 report, Art. 33 GDPR for the data protection report. This consolidation prevents contradictory statements of facts to the BSI and the data protection supervisory authority, which would immediately be noticed in a parallel audit. The auditor calls, the evidence is ready. This only works if the interfaces are defined in advance and are not improvised in the event of an incident.
The 24h/72h reporting path in CIVAC operations
The 24-hour early warning and 72-hour follow-up notification path according to Section 32 BSIG is the operational test for every ISB and the point at which poorly prepared setups visibly fail in the first crisis. In the CIVAC workspace, the path is shown in five stages, all of which have a time stamp, a person responsible and a pre-filled message text. Level one is incident detection, typically through the SOC, a SIEM system, an endpoint detection solution or an employee report via a central hotline. The detection time is the anchor for all deadlines, which is why it is stored in the audit log down to the minute.
Stage two is triage by the ISB within four hours of detection. This is where a decision is made as to whether the incident needs to be reported. The criteria from Section 32 Paragraph 1 BSIG (significant security incident) are queried in a structured manner in the workspace, with assessments of impact, severity and affected services. If the answer is yes, the 24-hour early warning starts. Stage three is the early warning to the BSI, technically via the BSI reporting portal, with the content of the template provided by CIVAC, which contains the minimum information from Section 32 Paragraph 4 BSIG.
Stage four is the follow-up report within 72 hours, with an extended assessment of the effects, the systems affected, the measures taken and the expected recovery time. Stage five is the final report within one month, which also documents the lessons learned, the adjustment of the TOM and, if necessary, the information of other authorities. If the incident concerns personal data, the GDPR deadline according to Art. 33 runs parallel to 72 hours from the date of knowledge. The workspace provides coordinated texts from an incident data record for both reports. Deadline begins as soon as we become aware of it. Anyone who has practiced the path with dry feet will be able to follow it even in an emergency.
Qualifications, independence and certificate of appointment of the external ISB
Section 7 of the BSI Act requires ISB expertise and reliability as a mandatory prerequisite for the order. The expertise includes knowledge of information security, risk management and the relevant standards, in particular ISO/IEC 27001:2022, BSI-IT-Grundschutz and industry-specific standards such as B3S for healthcare facilities. Reliability is demonstrated by professional experience of at least three to five years, regular training with documented hours and the absence of relevant criminal records. For each named ISB, CIVAC documents a qualification profile with certificates, professional experience, industry focus and training hours, which is presented to the client and to the supervisory authority upon request.
Independence is the second supporting pillar of the ISB function. The ISB must neither be bound by instructions to the operational IT nor have any conflicts of interest in management decisions, especially not in budget decisions regarding security measures. With an external ISB, independence is structurally easier to maintain than with an internal employee because the ISB is not in the organisational chart of the IT department and has no career dependency on the management. Independence is secured contractually, with a reporting line directly to the management and a clause that excludes instructions on technical issues and provides protection against dismissal while protecting the ISB function.
The appointment certificate is the formal document that makes the order verifiable to third parties. It contains the name and qualifications of the ISB, scope of the appointment, start date and (open or limited) duration, reporting line, independence clause, representation regulations and the signature of the management as well as the countersignature of the ISB. The appointment certificate, signed, filed, verifiable. The BSI regularly queries the appointment certificate as part of requests for information, particularly after security incidents. When ordering via CIVAC, the appointment certificate is stored digitally in the workspace with a time stamp and in paper form with the client.
ISO/IEC 27001:2022, 93 Controls und ISMS-Integration
NIS-2 refers in Section 30 BSIG to the state of the art as a benchmark for suitable and proportionate measures. The practical reference point for this in Germany is actually the ISO/IEC 27001:2022 with its 93 controls in Annex A, which represents the international counterpart to the BSI-IT-Grundschutz and is used as a reference grid in the vast majority of audit reports. An ISB-as-a-Service must be able to operationalize these 93 controls, even if the client is not yet certified and is not seeking formal certification. The CIVAC workspace structures the controls into four subject areas: organisational measures (A.5), personnel measures (A.6), physical measures (A.7) and technological measures (A.8).
For each control, the following is documented in the workspace: current maturity level on a five-level scale, evidence documents with versioning, person responsible with email and function, test date and next effectiveness test. The data can be exported in common formats, so that later ISO 27001 certification by an accredited certification body is possible without re-entering the data. The ISB-as-a-Service does not provide the certification itself (which comes from an accredited certification body such as DEKRA or TÜV), but the complete ISMS documentation package that makes certification possible and halves the internal preparation time.
For clients who are not required to certify but must be NIS-2 compliant, the ISMS structure without formal certification is sufficient. The supervisory authority accepts the ISMS structure as proof of the state of the art in accordance with Section 30 BSIG, as long as the documentation is consistent, up-to-date and comprehensible for external auditors. Audit-proof, documented, § 30 BSIG-proof. Anyone who outsources the ISMS setup is buying structured documentation and ongoing maintenance against changing supervisory practices, not just a representative with a business card.
Economic logic: When external ISB calculates, when internal ISB
The choice between external and internal ISB is primarily a question of capacity utilization, not legal certainty. Both models fulfil Section 7 of the BSI Act and Section 30 of the BSIG identically if the order is formally correct and the qualification is proven. The rule of thumb is: up to an ISB utilization of around 60 percent of an FTE, the external ISB-as-a-Service is economically superior. In addition, the internal ISB becomes more attractive because the fixed personnel costs have a degressive effect and the internal ISB permanently builds context.
Specifically important in numbers for a medium-sized company with 200 employees and NIS 2 classification: an internal ISB costs between 110,000 and 160,000 EUR per year based on full costs, including social security contributions, training, certification maintenance, workplace costs and replacement regulations. An external ISB-as-a-Service costs EUR 28,000 to EUR 48,000 per year including workspace, templates, 24h/72h reporting path and representation. The breaking point is typically at a company with 500 to 800 employees and several locations, from which the internal position is fully utilised even without external support.
Three special cases shift the logic. First, highly regulated industries (finance, energy, healthcare, critical infrastructure) often need industry-specific depth and experience with the respective regulator, which an external ISB with appropriate focus brings. Second: Corporations with several subsidiaries subject to NIS 2 benefit from a central external ISB with a multi-client workspace that generates economies of scale and delivers consolidated reports. Thirdly: fast-growing companies can use the external ISB as a bridge until the internal position can be filled without having to bear the risk of a fine in the meantime. CIVAC supports all three models because the workspace remains identical and only the named person changes. Data migration is no longer necessary because the tenant is the same. The appointment certificate, signed, filed, verifiable.
Turning an obligation into an order: next steps with CIVAC
The NIS 2 requirement is not negotiable, the implementation is. Anyone who is classified as an essential or important facility needs a reliable order from the ISB, a reporting path with a time stamp and an ISMS documentation package that passes the first check. Anyone who has to set this up in the next 24 months anyway can use the external ISB-as-a-Service as a bridge and fill the internal position later without having to bear the risk of a fine from the BSI during the transition period.
The concrete next step is a 30-minute clarification of the scope between management, IT management and CIVAC. Three pieces of information are sufficient: the NIS 2 classification (essential, important, unclear), the number of employees per location and the rough IT stack (cloud share, in-house operation, third-party providers, critical applications). On this basis, CIVAC creates a binding offer with a draft appointment certificate, workspace preparation and SLA definition within two working days. CIVAC is a compliance platform and officer-as-a-service. Licence the workspace for your internal representatives or have our representatives order it. Both models lead to the NIS 2 ready state with the same technical basis: 93 controls according to ISO/IEC 27001:2022, 490 audit templates, 24h/72h reporting path, EU data residency.
If you take the step today, in two working days you will have an ordered ISB, an activated reporting path and an ISMS documentation package that has been started and will be in the audit from the third working day withstands. Turn reading into an assignment. A message to info@civac.de or the contact form on civac.de starts the process. The test run of the reporting path that every new client carries out in the first 30 days is part of the package and cannot be calculated separately. Anyone who has passed the test run knows their ISB, knows the workspace and is not surprised when the first real incident starts.
FAQ
What qualifications does an external ISB have to demonstrate in accordance with Section 7 of the BSI Act?
Expertise and reliability. Expertise includes knowledge of information security, risk management and relevant standards such as ISO/IEC 27001:2022 and BSI-IT-Grundschutz. Reliability includes work experience of at least three to five years, documented annual barking hours and the absence of relevant criminal records. CIVAC maintains a qualification profile for each designated ISB, which is presented to the supervisory authority upon request.
How does the 24-hour early warning path according to Section 32 BSIG differ from the 72-hour path according to Art. 33 GDPR?
Section 32 BSIG requires an initial early warning to the BSI within 24 hours of becoming aware of a significant security incident, followed by a 72-hour follow-up report. Art. 33 GDPR requires a 72-hour report to the data protection supervisory authority in the event of a data breach involving personal data. If an incident satisfies both offenses, both deadlines run parallel and must be served from a consistent incident data record.
Can an external ISB be appointed for several group companies at the same time?
Yes, an appointment for several group companies is possible if accessibility from each location is guaranteed and there are no conflicts of interest between the mandates. Each company needs its own appointment certificate. The CIVAC workspace supports multi-tenants with separate authorizations and consolidated group reports, so that a central ISB can be used at scale.
What happens if the named ISB is unavailable (illness, vacation, change of mandate)?
CIVAC provides a contractual representation arrangement with a named replacement person who is ready for action within 24 hours. The representative knows the client from the shared workspace storage and takes over all reports and triage decisions in the event of an incident. If there is a permanent change in the named person, a new appointment certificate will be issued and the supervisory authority will be informed. The workspace and all evidence remain unchanged.
What fines are there for breaches of duty under NIS-2 in Germany?
Section 65 BSIG provides for fines of up to EUR 10 million or 2 percent of global group sales for essential facilities, whichever is higher. For important institutions, the limit is EUR 7 million or 1.4 percent. Section 38 BSIG also establishes personal liability for management for breaches of supervisory duties, which is not covered across the board by D&O insurance.
How quickly can an NIS 2 ready status be realistically achieved via CIVAC?
The formal appointment of the ISB and the start of the reporting path are completed in two working days. The complete ISMS structure with documented 93 controls according to ISO/IEC 27001:2022, risk analysis, TOM documentation and training plans takes six to twelve weeks, depending on the size of the client. The supervisory authority accepts the documented structure as evidence of compliance efforts as long as a realistic schedule is presented.
Sounds like a lot of work?
Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.
Turn this into a mandate.
Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.