77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide
ISB consulting in medium-sized businesses: roles, costs and the step from consultation to order
IT Security & NIS-2

ISB consulting in medium-sized businesses: roles, costs and the step from consultation to order

1 July 202612 min readBy Lena Vogt
CIVAC

In medium-sized businesses, ISB consulting is often purchased as a project and ends with no permanent role. This article shows how consulting, appointment and officer-as-a-service differ, what obligations the ISB has according to NIS 2 and ISO/IEC 27001:2022 and when the transition to permanent appointment is economical.

In 2026, the information security officer will no longer be a recommendation, but rather a consistent obligation for around 29,500 German companies that fall under the NIS 2 Implementation Act. Section 38 NIS2UmsuCG requires a designated body for the security of network and information systems that reports directly to management. § 9.1 ISO/IEC 27001:2022 requires a person with defined responsibility for the ISMS. Section 130 OWiG substantiates a lack of or insufficient supervision by management with fines that range up to 10 million euros or 2% of group sales for NIS 2 essential facilities. Nevertheless, medium-sized companies often initially purchase the function as ISB consulting in project form and later decide on the permanent appointment, which makes the transition between analysis and responsibility a risk zone of its own.

This article organises the terms and shows how serious ISB consulting can be recognised, which tasks actually arise in which phase, how costs differ between consulting, internal ordering and external ordering, and when the transition from consulting mandate to a permanent role makes economic and regulatory sense. CIVAC acts in this field as a compliance platform and officer-as-a-service, with the workspace that already contains the 93 controls according to ISO/IEC 27001:2022, the 490 audit templates and the NIS 2 reporting path with 24-hour early warning and 72-hour follow-up notification.

Key Takeaways

  • ISB consulting without a subsequent order is an incomplete contract type because § 38 NIS2UmsuCG and § 9.1 ISO/IEC 27001:2022 require a permanently named function.
  • The external appointment of an ISB is economical in medium-sized companies if the company has fewer than 2,500 employees, because the fixed role of an internal ISB is rarely utilised to capacity below this threshold.
  • In the CIVAC workspace, the ISB role is linked to the appointment certificate, reporting line, ISMS and NIS-2 reporting path, so that advice and orders use the same database and it is possible to switch between the models without data migration.

What ISB consulting actually includes in 2026

ISB consulting is defined very differently in the market. Some providers understand this to be a gap analysis against BSI IT-Grundschutz or ISO/IEC 27001:2022, others a temporary project to prepare for certification, and others the operational takeover of the ISB role for 12 or 24 months. The range is relevant from a regulatory perspective because Section 38 NIS2UmsuCG and Annex A.5.2 ISO/IEC 27001:2022 require a permanently designated body, not a project. A consultation that ends after a catalogue of measures has been handed over leaves the company without the reporting line holder that the supervisory authority expects.

A serious ISB consultation in medium-sized companies therefore includes at least five components. Firstly, the inventory according to ISO/IEC 27001:2022 and NIS2UmsuCG. Secondly, the creation of the Statement of Applicability with reference to the 93 controls in Annex A. Thirdly, the establishment of the reporting line to management with a signed appointment certificate. Fourth, the commissioning of ISMS routines including risk assessment, incident management and effectiveness measurement. Fifth, the transition to the permanent role, either filled internally or appointed externally. CIVAC bundles these five components in the workspace so that the consulting phase seamlessly transitions into the ordering phase and data, risk assessment and reporting lines are not lost. The handover is the most common breaking point in classic project consulting and at the same time the most expensive because it typically has to be purchased as a second project. In practice, this means that the company spends money again six to nine months after the end of the consultation to reactivate a function that has since been gutted. A clearly structured consultation closes this gap contractually and operationally by setting up the ISB function as capable of being ordered during the consulting phase and the order then only needs to be signed. The separation between the consulting and ordering phases thus becomes a formal question, not a substantive break.

Obligations of the ISB according to NIS 2 and ISO/IEC 27001:2022

The ISB is the operational head of the information security management system. His duties arise from several sources. Section 38 NIS2UmsuCG requires a designated body that is responsible for the security of the network and information systems, reports directly to management and acts independently of instructions on technical issues. ISO/IEC 27001:2022 in clause 5.3 requires the assignment of responsibility for meeting ISMS requirements. Appendix A.5.2 specifies the defined information security role. § 9.1 requires the ongoing assessment of the effectiveness of the security measures.

This results in a specific catalogue of obligations. The ISB keeps the ISMS up to date, carries out the risk assessment and risk treatment in accordance with clauses 6.1 and 6.2, coordinates incident management in accordance with appendix A.5.24 to A.5.28, organises the awareness program in accordance with A.6.3, monitors supplier risks in accordance with A.5.19 to A.5.22 and reports to the management at least once a year. In the NIS 2 context, there is also the obligation to ensure the 24-hour early warning path and the 72-hour follow-up reporting path to the responsible authority, both technically and organizationally. CIVAC maps this catalogue in the ISB role object, which contains the appointment certificate, the reporting line and the effectiveness measurement as connected elements. The auditor calls, the evidence is ready. because the catalogue of obligations does not live in a separate document, but as an operational system. In addition, there are sector obligations that differ from the general list of obligations depending on the NIS 2 classification: energy suppliers, healthcare facilities and providers of digital services each have additional requirements that the ISB must clearly reflect during ongoing operations. The interaction with the data protection officer in the case of double reporting obligations according to Art. 33 GDPR and Section 32 NIS2UmsuCG is also part of the catalogue of obligations, because a lack of coordination in a real incident leads to inconsistent reports.

Consultant, internal ISB, external ISB: Three contract types in comparison

The three contract types differ in terms of responsibility, liability and duration. The consultant provides recommendations and tools, but does not take on an ordering function. He is liable for errors in advice within the scope of his contract, but is not the ISB within the meaning of Section 38 NIS2UmsuCG. The internal ISB is an employee of the company who assumes the role in whole or in part, is represented in the reporting line to management and is personally designated to fulfil the ISMS obligations. The external ISB is a contractually bound natural or legal person outside the company who is formally appointed, signs an appointment document and assumes the ISB duties towards the management.

The choice between the three models depends on the size, the sector allocation and the availability of qualified people on the labour market. Below around 2,500 employees, the internal role is rarely at 100% capacity, leading to part-time solutions that are regulatory permissible but operationally fragile. With over 5,000 employees, the internal role is generally economically viable. In the middle range, external ordering comes into play as an economically viable alternative because it provides the full function without a full-time salary. CIVAC offers external ordering in the officer-as-a-service model with a service level of 2 working days to start work, compared to a classic market standard of 2 to 6 weeks for recruiting and onboarding. Licence the workspace for your internal representatives, or have our representatives order it. Both models use the same 490 audit templates and reporting line. A point that is often overlooked is the replacement regulation: While an internal person cannot perform the function if they are on vacation or sick, the external appointment is typically coupled with a documented replacement so that the NIS-2 reporting paths are also used in the absence of the main person. This continuity is a separate point of review in the audit discussion and in many cases shifts the evaluation of the model in favor of external orders, without the management having previously included this aspect in the profitability analysis.

What an ISB consultancy must specifically achieve in terms of scoping

The scoping phase is the most important part of an ISB consultation because it determines which obligations the company actually bears. This starts with clarifying the sector classification according to NIS 2: is the company an essential facility, an important facility or does it fall below the application threshold. The allocation decides on the risk of fines between 7 million euros and 10 million euros and on the supervision mode between event-related and routine. Advice that does not reliably document this assignment is incomplete because the subsequent measures are defined without anchors.

The second pillar is the inventory according to ISO/IEC 27001:2022. Here, the 93 controls from Annex A are checked against the actual implementation in the company, a statement of applicability is created and the gaps are prioritised. The third pillar is the risk analysis according to clause 6.1, which documents the company's technical and organisational risk profile. The fourth pillar is the action plan with those responsible, deadlines and effectiveness indicators. The fifth pillar is the handover to permanent operation, including the ISB appointment certificate, signed reporting line and a quarterly report template. CIVAC delivers these five pillars as a package in the workspace, so that the consultation phase ends with a testable set of artifacts and not with a PowerPoint recommendation. Audit-proof, documented, Section 38-proof. Others run compliance like a filing cabinet. We run it like software., which makes the difference between advice and ordering practically tangible. The five pillars can usually be set up within eight to twelve weeks, depending on the size and preparatory work in the company. If preparatory work from previous ISMS initiatives already exists, such as an older Statement of Applicability version or a risk register, this can be migrated to the workspace without losing the previous history.

Costs and profitability: A calculation for medium-sized businesses

The cost structure of the three contract types differs significantly. A pure consultation in the form of a project with an inventory, statement of applicability, risk analysis and action plan typically costs between 30,000 and 80,000 euros for 8 to 16 weeks in medium-sized companies, without an ordered function afterwards. An internal ISB role with qualified personnel has a fully charged annual salary of between 95,000 and 130,000 euros, plus recruiting costs of between 25,000 and 40,000 euros as well as a training phase of 6 to 9 months in which the function is only partially effective.

An external order via the officer-as-a-service model costs between 30,000 and 60,000 euros per year, depending on size, sector and complexity, and includes ongoing maintenance of the ISMS, incident management, reporting line to management and audit export. The function is active within 2 working days because the platform is preconfigured with 490 audit templates and 93 ISO controls. For a company with 800 employees, the annual difference between an internal full-time role and an external appointment is typically 70,000 euros per year, without compromising quality because the external ISB works with qualified representation, documented training and professional liability insurance. CIVAC delivers the external order using the same tools that an internal ISB would use, so that a later switch to internal staffing remains possible without data migration. The deadline begins as soon as it is known, and taking over the function reliably starts this deadline in the event of NIS 2-relevant incidents. The issue of insurance must also be taken into account: an external ISB has professional liability insurance in the seven-figure range, which structurally relieves the management's personal liability situation in accordance with Section 130 OWiG because there is an appointed supervisory body with insurance cover. The recruiting comparison is also clearly in favor of external appointments because qualified ISB candidates are scarce on the labour market and waiting times of six months are realistic.

Reporting line, certificate of appointment, independence

The formal anchoring of the ISB is often the weakest point of the compliance architecture in medium-sized companies. Section 38 NIS2UmsuCG requires a direct reporting line to management. Appendix A.5.2 ISO/IEC 27001:2022 requires the role to be defined and documented. Section 130 OWiG proves a lack of supervision by the management with fines regardless of the security breach itself. In practice, a signed appointment certificate is often missing, the reporting line is anchored on paper in the IT department instead of at the management level, and the independence of the ISB is jeopardized by a personal union with the IT manager.

A reputable ISB consultancy systematically closes these gaps. The appointment certificate is drawn up, signed and stored as a version in the workspace. The reporting line is documented using an organisational chart and rules of procedure, so that management does not instruct the ISB via middle management levels. Independence is ensured by separating operational IT responsibilities and ISB functions, which in smaller companies can often only be implemented through external ordering. CIVAC treats the appointment certificate, reporting line and proof of independence as connected objects in the workspace, with timestamps and versioning. The appointment certificate, signed, filed, verifiable. An auditor reviewing formal anchoring sees a complete bundle rather than a collection of loose documents, significantly reducing audit time and avoiding discussions about gaps in the anchoring. For groups with several legally independent subsidiaries, the appointment certificate is drawn up for each client so that the supervisory authority recognises a clear addressee for each company and does not have to puzzle over group boundaries. This point regularly becomes a crucial detail in coordinated supervisory procedures. In addition, there is the ongoing maintenance of the formal anchoring: Changes in management automatically trigger an obligation to review the reporting line in the workspace, so that supervision does not encounter an outdated organisational structure after a change.

From advisory mandate to permanent appointment

The typical path in medium-sized companies is a short consulting phase in which the gaps to ISO/IEC 27001:2022 and NIS2UmsuCG are closed, followed by a permanent ISB function. The transition is the critical phase because knowledge can be lost here. Classic consulting projects end with the handover of an action plan and a PowerPoint presentation, without knowledge of the specific risk situation, the prioritised measures and the expected follow-up processes being transferred to an operational role. The result is a second consulting project six months later because the function has now fallen behind.

In the CIVAC model, the transition is solved structurally differently. The consultation phase already takes place in the workspace, in which the subsequent order also operates. The statement of applicability, the risk assessment, the action plan and the reporting line are already stored during the consultation where the ISB continues to work after being ordered. If the model changes from consulting to ordering, the contractual constellation and responsibility change, but not a single date is migrated. If the model changes from external order to internal order, the internal ISB gets exactly the same workspace with the same history. Licence the workspace for your internal representatives, or have our representatives order it, and make the model decision based on your personnel strategy. This continuity is the central economic lever compared to classic consulting models because it eliminates recurring onboarding costs. The reporting history to the management is also retained without any gaps, which makes it easier to prove in the event of an audit that the supervisory obligation in accordance with Section 130 OWiG was carried out throughout. Ultimately, the risk position changes positively compared to the management's insurance because a continuously appointed ISB function provides a clearly documented risk reduction contribution.

What to look for when choosing an ISB consultant

The selection of an ISB consultant can be clearly structured according to six criteria. Firstly, the qualifications of the person employed: recognised certificates such as ISO/IEC 27001 Lead Implementer or Lead Auditor, professional experience in medium-sized companies and verifiable mandates in the relevant sector. Secondly, the willingness to take on the function as an external ISB after the consulting phase, because otherwise the handover becomes a second project. Thirdly, the consulting firm's own certification according to ISO/IEC 27001:2022, because it is difficult for a non-certified consultant to convey the requirements credibly.

Fourth, the tools: a consultant who works with Excel and Word creates a level of documentation that quickly becomes outdated during ongoing operations. A consultant working with an integrated platform leaves a workspace that keeps running. Fifth, the contract conditions: a fixed price for the consulting phase with an optional follow-up contract for the order is more transparent than a daily rate model with an unclear final cost. Sixth, professional liability insurance: an external ISB should provide proof of an insured sum in the seven-figure range, because the fines according to NIS 2 for essential institutions reach up to 10 million euros. CIVAC meets all six criteria and delivers advice with the same team that will later handle the external appointment if the client chooses this path. Others run compliance like a filing cabinet. We run it like software., and this logic applies from the first day of consulting. An additional criterion is the industry knowledge of the ISB used, because the sector obligations vary considerably between energy supply, industry and digital services and a consultant from outside the sector only recognises gaps late. Finally, the contract structure should contain a clear exit clause for both sides so that a change of model or provider does not lead to a de facto lock-in situation.

Turn reading into an assignment: Here's how to get started

A robust scoping discussion for an ISB consultation lasts 60 minutes and requires three documents: the current ISMS documentation, if available, the NIS 2 sector assignment with justification and the last audit or pen test result. On this basis, it can be clarified whether the company falls under the NIS2UmsuCG, what gaps exist in the Statement of Applicability, which type of contract is economically suitable and in what order the consulting phase and the ordering phase intertwine. The discussion takes place with a qualified ISB, not with a sales department, so that the technical questions can be clarified immediately.

The commissioning follows the service level of 2 working days from the signed order to the operational workspace with activated Statement of Applicability, ISMS risk assessment and reporting line. Within the first 30 days, the prioritised gaps will be closed, the appointment certificate will be signed and the quarterly report to management will be established. Licence the workspace for your internal representatives, or have our representatives appoint them, and decide on the contract type after the scoping phase has been completed, when the costs and effort are transparent. Turn reading into an assignment. You can reach the team at info@civac.de or via the contact form on civac.de. The initial response is made within one working day, the offer within two working days, including a fixed price for the consulting phase and an optional fixed price for the first twelve months of the external order. If requested, a qualified ISB will accompany the first quarterly meeting with management to establish the reporting line and set the standards for the following quarterly reports. This means that from the first quarter the function will be anchored not only legally but also communicatively in the management.

FAQ

Do we need an ISB if we haven't had one yet?

If the company falls under the NIS2UmsuCG, the answer is clearly yes, because Section 38 NIS2UmsuCG requires a notified body. Even without NIS 2 applicability, an ISB is advisable as soon as ISO/IEC 27001:2022 certification is sought or customers contractually require an ISMS. The sector allocation should be clarified in a 60-minute scoping discussion because the risk of fines ranges between 7 million and 10 million euros.

What is the difference between ISB advice and ISB ordering?

Consulting provides analysis, concepts and tools, but does not provide a reporting line to management. An order names a person as an ISB within the meaning of Section 38 NIS2UmsuCG, with a signed appointment certificate, documented reporting line and personal professional responsibility. In medium-sized businesses, serious advice ends with the suggestion of a specific ordering model, internal or external, and not with an open list of measures.

When is an external ISB worthwhile over an internal appointment?

The external appointment is economical if the company has fewer than 2,500 employees, the function requires more than 0.4 full-time equivalents and less than 1.0 full-time equivalents, or the personal union with the IT manager endangers the independence of the ISB. With over 5,000 employees, internal staffing is generally economically viable and operationally preferable.

What qualifications does an external ISB have to demonstrate?

Recognized certificates are ISO/IEC 27001 Lead Implementer and Lead Auditor, supplemented by BSI-IT-Grundschutz practitioner. In addition, there is professional experience in a medium-sized company, documented further training at least annually, professional liability insurance in the seven-figure range and a well-established representation mechanism so that vacation or sick leave does not jeopardize the NIS-2 reporting path. Sector certificates such as BSI C5 or industry-specific proof of experience are also useful because they additionally legitimize the ISB function vis-à-vis auditors and supervisory authorities.

Can we bring the ISB role back into the company later?

Yes. In the CIVAC model, switching between external and internal staffing is possible without data migration because both models use the same workspace. The internal ISB adopts the Statement of Applicability, the risk assessment, the reporting line and the audit templates unchanged. The external order ends contractually, compliance continuity is maintained, and the handover is supported by a documented briefing over two to four weeks.

How long does it take to commission an ISB function?

At the CIVAC service level, the executable workspace with activated ISMS framework is available two working days after the order is placed. The appointment certificate, the reporting line and the first quarterly routines are productive within 30 days. Classic recruiting for an internal ISB role, on the other hand, takes between 3 and 9 months, including training. This difference is often the decisive factor in the audit calendar.

No obligation

Sounds like a lot of work?

Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.

Turn this into a mandate.

Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.

Related articles