77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide
ISB training: routes, providers, costs and realistic schedules
IT Security & NIS-2

ISB training: routes, providers, costs and realistic schedules

8 September 202613 min readBy Lena Vogt
CIVAC

Anyone who takes on the ISB role needs solid qualifications. This article compares the most important training paths, providers, costs and examination formats and shows how you can secure the operational takeover of the role.

With the NIS 2 Implementation Act (planned to come into force in 2026 in Germany) and ISO/IEC 27001:2022 as a living practice, the demand for qualified information security officers is increasing. There is no state-regulated training like that for occupational safety specialists. Courses according to BSI standard 200-2 and ISO/IEC 17024 accredited personal certifications are recognised.

This article compares the three market-dominant training paths, lists providers, costs and duration and shows which path is suitable for which type of company. You will also learn how CIVAC, as a compliance platform and officer-as-a-service, ensures the operational takeover of the ISB role after training, be it internally or via external order.

Key Takeaways

  • There are three dominant training paths: BSI-Grundschutz practitioner, ISO/IEC 27001 Lead Implementer and TÜV-certified ISB according to ISO 17024.
  • Costs range between 1,800 and 4,500 euros net, duration between four and twelve days of attendance.
  • Training alone does not qualify for the role; professional experience, professional suitability in accordance with Section 38 of the BSIG draft and continuous training are required.

Why there is no uniform ISB training

In contrast to the occupational safety specialist (regulated in DGUV regulation 2 and appendix 2) or the company doctor (licensed doctor and specialist in occupational medicine), ISB training is not legally standardised. Neither the BSIG nor the NIS 2 Implementation Act define a binding curriculum.

Instead, Section 38 of the current draft NIS 2 Implementation Act requires “appropriate qualifications” for those responsible for information security in essential and important facilities. This formulation gives the employer leeway, but actually translates into certified courses.

The BSI standard 200-2 (IT-Grundschutz methodology) provides the methodological basis. ISO/IEC 27001:2022 and ISO/IEC 27002:2022 complement the international reference framework. Both worlds overlap, but are not identical.

Accreditation bodies such as the German Accreditation Body (DAkkS) certify personal certifiers according to ISO/IEC 17024. These include TÜV associations, DEKRA, DGQ and private providers. Only accredited certificates are reliable.

Anyone who orders the external information security officer via CIVAC takes on a role that is already qualified and continuously trained. The proof of qualifications is stored in the workspace.

The appointment certificate, signed, filed, verifiable.

Path 1: BSI IT-Grundschutz practitioner and consultant

The BSI-IT-Grundschutz practitioner is the official training. Contents are the BSI standards 200-1 (ISMS), 200-2 (IT-Grundschutz methodology), 200-3 (risk analysis) and 200-4 (Business Continuity Management).

Typically lasts four to five days of attendance plus self-study and examination. Providers are BSI itself (academy), CONTECHNET, datenschutz cert, as well as a number of accredited training partners. Costs between 1,800 and 2,400 euros net.

This is followed by the IT-Grundschutz consultant, who also delves into profiling, structural analysis and identification of protection needs. Another three to five days, costs between 2,000 and 2,800 euros net. This level qualifies for the support of IT-Grundschutz audits.

The target group is ISBs in authorities, municipal companies, KRITIS operators and sectors related to the BSI. Private companies also choose this path when customers in the public sector require BSI auditability.

Advantage: high recognition by German authorities, methodological rigor, lively community via BSI forums. Disadvantage: heavily German-language, less reference to the international ISO world, higher complexity of the methodology compared to the leaner ISO 27001 approach.

Audit-proof, documented, BSI Standard 200-2-proof.

Path 2: ISO/IEC 27001 Lead Implementer and Lead Auditor

The ISO/IEC 27001 Lead Implementer is the international standard route. Contents are the ISO/IEC 27001:2022 standard with the 93 Annex A controls, plan-do-check-act cycle, risk management according to ISO 31000 and implementation practice.

Duration usually five days of attendance, completed with a two-hour examination. Accredited providers are PECB, BSI Group, TÜV Süd, DEKRA and DNV. Costs between 2,400 and 3,500 euros net including the audit fee.

The lead auditor follows, which also includes audit planning, execution and reporting. Another five days, costs similar. Lead Auditor qualifies for external audits and is mandatory for ISO certification body auditors.

Target group are ISBs in internationally active companies, IT service providers, SaaS providers and suppliers of OEMs with ISO requirements (TISAX, NIS 2 conformity). The English-language materials are often mandatory in corporations.

Advantage: worldwide recognition, clearly structured standards, high market demand. Disadvantage: less method depth than BSI basic protection, more abstract controls require translation into their own context.

CIVAC uses this method internally and provides a mapping template between ISO controls and BSI blocks in the workspace.

Way 3: TÜV-certified ISB according to ISO 17024

The TÜV and DEKRA certified ISB courses are the most compact variant. They combine the basics of ISMS, ISO 27001, BSI-Grundschutz, data protection interface and legal framework in one curriculum.

Typically lasts six to eight days of attendance, often in a blended learning format with online modules. Completed with an examination before an ISO/IEC 17024 accredited personal certification body. Costs between 2,800 and 4,500 euros net.

Providers are TÜV Süd Akademie, TÜV Rheinland, TÜV Nord, DEKRA Akademie, DGQ. The accreditation of the certification body ensures that the certificate is awarded objectively and independently, not by the course provider itself.

The target group is ISBs in medium-sized companies, in family businesses and in industries with a mixed requirement profile (TISAX, NIS-2, ISO 27001, industry-specific audits). The approach is considered pragmatic and recognised across the market.

Advantage: compact, close to the market, dual orientation (BSI plus ISO), strong accreditation. Disadvantage: less specialised than the pure BSI or ISO paths, varying depth depending on the provider.

Those who fill the ISB role internally often combine this path with project-related ISO or BSI in-depth knowledge.

Cost comparison and realistic schedules

The total cost of an ISB training is between 2,000 and 9,000 euros net, depending on the path and additional modules. In addition, there are lost work costs of four to twelve days of presence, i.e. around 2,000 to 8,000 euros depending on the salary level.

Example calculations from practice: Medium-sized mechanical engineering company with ISO ambition and TISAX obligation: TÜV-ISB plus ISO 27001 Lead Implementer results in 5,500 to 7,000 euros net, ten to thirteen days of presence over six Months.

Municipal utility with BSI obligation: BSI practitioner plus consultant plus ISO lead implementer results in 6,500 to 8,500 euros net, thirteen to fifteen days of presence over nine months. International SaaS provider: two ISO lead certifications, 5,000 to 7,000 euros net.

Realistic timetable from start of course to operational takeover: three to six months. Two to four weeks of this include theory, two to four weeks for the exam and waiting time for the certificate, two to five months for parallel training in your own ISMS.

Continuing training requirement: ISO 17024 certificates require recertification every three to five years with proof of continuous further training, typically 40 hours per cycle. BSI certificates require similar refreshers.

CIVAC SLA: Anyone who uses the external ISB order via CIVAC has a qualified ISB in their mandate within two working days, instead of a two to six week search process.

What the training does NOT teach

No course replaces professional experience. The standard content can be taught in four to twelve days, the operational practice cannot. Typical gaps after training relate to stakeholder management, escalation, legal interfaces and tool selection.

Stakeholder management: How does the ISB negotiate protective measures with sales whose Salesforce configuration represents a risk deviation? How does he collect budget from the CFO if the risk is invisible? These soft skills are marginalized in curricula.

Escalation: What steps follow if management rejects a recommended measure? § 130 OWiG risks, documentation obligation according to ISO 27001 clause 9.3 (Management Review), labour law limits of a whistleblower report. Practice, not theory, helps here.

Legal interfaces: GDPR, NIS-2-UmsuCG, BSIG, Telecommunications Act, Trade Secrets Act, Criminal Code §§ 202a to 203, Secret Protection Ordinance. These topics are touched on in ISB courses, not penetrated.

Tool selection: SIEM, GRC, Asset Management, Vulnerability Scanner, Patch Management. Each tool category has ten to fifty providers. The selection is a separate project with market research, RFI, RFP, PoC.

CIVAC delivers the added value after the training: 490 audit templates, preconfigured reporting line, escalation paths and supplier evaluation.

Qualify internally or order externally? The decision

The decision between internal qualification and external appointment follows three criteria: size and industry, budget over full cost considerations, strategic importance of the role.

Size and industry: With around 250 employees and in regulated industries (finance, energy, health), an internal ISB role is worthwhile. For smaller structures or mixed groups of duties, external ordering is more efficient.

Full cost consideration: An internal ISB role typically costs 120,000 to 180,000 euros per year with six to eight weeks of initial qualification, personnel costs, training, tools and replacement arrangements. External orders start at 18,000 euros per year.

Strategic significance: If information security is a USP for customers (e.g. SaaS providers), the role belongs within the company. If it is purely a compliance obligation, externalization with a clear reporting line is worthwhile.

Hybrid model: Internal CISO as strategic contact, external ISB for operational implementation and audit support. This model relieves the internal role and secures specialist knowledge without shifting responsibility.

Licence the workspace for your internal representatives or have our representatives appoint one. Both models use the same system with EU data residency, ISO/IEC 27001:2022 ISMS and revision-proof audit folder.

Further training, recertification, everyday working life

An ISB training is a starting point, not an end state. The threat situation is changing, standards are being amended, tools are developing. If you don't continue learning for five years, you will lose your operational ability.

ISO 17024 certificates require formal recertification. The typical three-year cycle includes 40 hours of continuing education, documented ISB activity, and a written renewal exam. Anyone who does not provide proof will lose the certificate.

High-quality training formats include the annual it-sa in Nuremberg, the BSI-IT-Grundschutz Days, the ISACA Cyber Security Summit, webinars from the Federal Office for Information Security and manufacturer-independent GRC conferences.

Recommended in-depth courses include: ISO/IEC 27017 (Cloud Security), ISO/IEC 27018 (data protection in public cloud), ISO/IEC 27701 (Privacy ISMS), CISM (Certified Information Security Manager), CISSP (Certified Information Systems Security Professional).

In everyday working life, the role means four to six hours of daily control tasks: ISMS maintenance, meetings with IT and specialist departments, incident processing, supplier evaluation, audit preparation, reporting to management.

The Inspector calls, proof is ready. Anyone who manages the role via CIVAC has meeting minutes, action status and maturity metrics available at any time in the workspace.

From reading to ordering: This is how CIVAC supports you

CIVAC is a compliance platform and officer-as-a-service with two delivery models for the ISB role. Model one: You qualify internally and licence the workspace for your ISB. Model two: You order an external CIVAC ISB for the mandate.

Licence the workspace for your internal representatives or have our representatives order it. In both cases, you receive 490 audit templates, the preconfigured ISMS according to ISO/IEC 27001:2022, the NIS-2 24/72 reporting path, EU data residency and audit-proof reporting line.

For internal ISBs after training: The workspace accelerates the development of the ISMS, replaces Excel sprawl with structured workflows and delivers audit readiness in weeks instead of months. The 93 Annex A controls are preconfigured.

For external ISB orders: A qualified CIVAC ISB takes over the mandate, appointment certificate, reporting line and operational control. SLA: two working days from the conclusion of the contract to the acceptance of the mandate, instead of two to six weeks of the search process.

Typical entry-level situations: initial appointment after NIS 2 impact check, bridging vacancies after personnel changes, multi-location rollout, ISO 27001 initial certification, crisis mode after a security incident. Read more in the CIVAC FAQ.

Turn reading into a mandate. Write to info@civac.de or use the contact form on civac.de.

FAQ

How long does a full ISB training take?

Depending on the path, pure presence or online days are between four and twelve. Including preparation and follow-up, examination and waiting time for the certificate, you plan three to six months from the start of the course until you can take on the role.

Which training path is right for my company?

Authorities and KRITIS prefer the BSI path. International companies and SaaS providers choose ISO 27001 Lead Implementer. Medium-sized companies with mixed duties benefit from the TÜV-certified ISB. A combination is possible and often makes sense in practice.

Is a one-time training enough?

No. ISO 17024 certificates require recertification every three to five years with documented continuing education. Even without a formal obligation, continuous training is necessary because norms, threats and tools change quickly.

Can we fill the ISB role part-time?

For smaller structures, yes, but for essential NIS-2 facilities this will be difficult. The effort required for ISMS maintenance, incident processing and reporting is four to six hours a day. A staff union with IT management also involves conflicts of interest and is audit-critical.

How much does an external ISB cost year-on-year?

External ISB mandates start at around 18,000 euros per year for smaller structures and range up to 80,000 euros for complex mandates with multi-location responsibility. An internal full-time role typically costs 120,000 to 180,000 euros annually including full costs.

Does CIVAC take over the ISB role immediately after training the internal candidate?

Yes. CIVAC either provides an external ISB or supports your internally trained candidate with workspace, audit templates and senior sparring partners. Both models use the same audit-proof system with EU data residency and ISO/IEC 27001:2022 ISMS.

No obligation

Sounds like a lot of work?

Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.

Turn this into a mandate.

Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.

Related articles