77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide
News & Insights

What officers need to know.

Regulatory shifts, framework updates and operational guidance, curated for Data Protection, IT Security, Compliance and AI Governance leads. Written from the field, verified against primary sources.

Latest
Operating instructions for hazardous substances in accordance with Section 14 GefStoffV: Sample, mandatory content and testing in the audit
Hazardous Substances & Occupational Health23 July 202613 min read

Operating instructions for hazardous substances in accordance with Section 14 GefStoffV: Sample, mandatory content and testing in the audit

Section 14 of the Hazardous Substances Ordinance requires activity-related operating instructions for each hazardous substance, written, understandable and in the language of the employees. We show mandatory content, sample structure and an audit-proof maintenance process.

Read more
Hazardous substances officer: appointment, tasks, liability and duties 2026
Hazardous Substances & Occupational Health23 July 202613 min read

Hazardous substances officer: appointment, tasks, liability and duties 2026

Appointing a hazardous materials officer is not a sure-fire success, but rather a documented obligation with extensive liability. This guide organises the legal basis, tasks, qualifications and operational tools for audit-proof proof.

Read more
Environmental management software: What commissioners really need in 2026
Environmental Protection23 July 202613 min read

Environmental management software: What commissioners really need in 2026

If you want to combine ISO 14001:2015, EMAS, KrWG and the EU reporting requirements in one system, you need more than an Excel folder. This article shows which functions environmental management software must provide and how CIVAC integrates the environmental officer.

Read more
Energy audit according to DIN EN 16247: Who is obliged, who checks, who is liable
Environmental Protection23 July 202612 min read

Energy audit according to DIN EN 16247: Who is obliged, who checks, who is liable

The energy audit obligation according to Section 8 EDL-G and DIN EN 16247-1 applies to every non-SME in Germany every four years. Anyone who misses the deadline risks fines of up to 50,000 euros and EnEfG consequential obligations. This article explains thresholds, methodology, audit trail and the appointment option for the environmental officer.

Read more
ISO 14001 Certification Consulting in Germany: A Practical Guide for 2026
Environmental Protection23 July 202613 min read

ISO 14001 Certification Consulting in Germany: A Practical Guide for 2026

ISO 14001:2015 certification in Germany requires more than a generic environmental management system. This guide explains the steps, costs, role of the Umweltbeauftragter, and what to expect from a credible German consulting partner.

Read more
Environmental protection officer in the company: duties, appointment and reporting line 2026
Environmental Protection22 July 202613 min read

Environmental protection officer in the company: duties, appointment and reporting line 2026

Obligation, appointment, appointment document and reporting line: What lies behind the term environmental protection officer, when it is obligatory and how the role is embedded in a compliance architecture in an audit-proof manner.

Read more
Waste representative duty: From what quantity does the order become binding
Environmental Protection22 July 202612 min read

Waste representative duty: From what quantity does the order become binding

Anyone who produces or disposes of hazardous waste in certain quantities must appoint a waste representative. The article explains threshold values ​​according to AbfBeauftrV, ordering procedures, documentation and reporting obligations, including operational setup.

Read more
Sign the LkSG declaration of principles: template, content and duties of the management
Supply Chain22 July 202613 min read

Sign the LkSG declaration of principles: template, content and duties of the management

The declaration of principles according to Section 6 Paragraph 2 LkSG is the central anchor of the Supply Chain Due Diligence Act. This article shows the mandatory components, a structural proposal, common errors and the audit-proof signing process by the management, including connection to the LkSG representative.

Read more
LkSG obligation: scope, duty of care and appointment of the representative
Supply Chain22 July 202612 min read

LkSG obligation: scope, duty of care and appointment of the representative

Since 2024, the LkSG has applied to companies with 1,000 or more employees. We explain the nine due diligence obligations, the BAFA reporting requirement, fines of up to 800,000 euros and how to appoint an LkSG representative via the CIVAC Compliance platform and Officer-as-a-Service.

Read more
Occupational Safety Compliance in Germany for English-Speaking Operations
Arbeitssicherheit22 July 202612 min read

Occupational Safety Compliance in Germany for English-Speaking Operations

If your operations in Germany run in English, occupational safety compliance under ASiG, ArbSchG and DGUV V2 still applies in full. This guide explains the legal duties, the SiFa appointment, and how to keep audit evidence in one workspace.

Read more
Supply Chain Due Diligence in Germany: LkSG, CSDDD and What Foreign Companies Must Do
Supply Chain22 July 202614 min read

Supply Chain Due Diligence in Germany: LkSG, CSDDD and What Foreign Companies Must Do

Germany was the first large EU economy to impose mandatory supply chain due diligence. This guide covers the 2024 thresholds, eleven protected rights, BAFA enforcement record, and how to set up an audit-ready officer function in two working days.

Read more
CSRD reporting requirement in medium-sized businesses 2026: operational implementation step by step
Supply Chain21 July 202613 min read

CSRD reporting requirement in medium-sized businesses 2026: operational implementation step by step

From the 2026 financial year, the CSRD reporting obligation applies to large medium-sized corporations in accordance with Section 267 Paragraph 3 of the German Commercial Code (HGB). This guide shows the operational implementation in medium-sized companies: materiality analysis, data collection, supplier connection, attesting and workspace structures.

Read more
IT security costs in 2026: What an effective ISMS really costs in medium-sized businesses
IT Security & NIS-221 July 202612 min read

IT security costs in 2026: What an effective ISMS really costs in medium-sized businesses

IT security rarely costs less than 50,000 euros per year in medium-sized businesses. The article breaks down the costs into setup, operation and audit, compares the internal model with officer-as-a-service and provides a template for budget plausibility to management and the supervisory board.

Read more
IT security concept: Structure, content and obligations according to NIS-2, ISO 27001 and BSI-Grundschutz
IT Security & NIS-221 July 202614 min read

IT security concept: Structure, content and obligations according to NIS-2, ISO 27001 and BSI-Grundschutz

An IT security concept documents technical and organisational measures according to recognised standards. This guide shows the structure, mandatory content and interfaces to NIS-2, ISO 27001:2022 and BSI-Grundschutz and makes the duty of the information security officer operationally tangible.

Read more
BSI security incident notification: The 24-hour workflow under NIS-2
IT Security & NIS-221 July 202613 min read

BSI security incident notification: The 24-hour workflow under NIS-2

NIS-2 (§ 32 BSIG) requires an early warning to the BSI within 24 hours of becoming aware of a significant security incident, a follow-up report after 72 hours and a final report after one month. This post describes the complete workflow without any gaps.

Read more
How to Comply with the NIS-2 Directive in Germany: A 90-Day Operational Plan
IT Security & NIS-221 July 202614 min read

How to Comply with the NIS-2 Directive in Germany: A 90-Day Operational Plan

Around 29,500 German entities fall in scope of NIS-2. The directive's value emerges from disciplined operational execution: scoping, risk management, named information security officer, 24/72 reporting, management training. This guide is a 90-day plan for entities still building the foundation.

Read more
ADR catalogue of fines 2021: What still applies today and what was reframed in 2025
Dangerous Goods & Logistics20 July 202612 min read

ADR catalogue of fines 2021: What still applies today and what was reframed in 2025

Anyone who thinks of 2021 as the reference year for ADR fines will overlook the adjustments from GGVSEB 2023 and the GbV amendment 2024. This article classifies the status of 2021, shows the sanction framework in force today and provides the dangerous goods officer with a practical checklist.

Read more
ADR refresher course: exam questions, online format and requirements
Dangerous Goods & Logistics20 July 202612 min read

ADR refresher course: exam questions, online format and requirements

What you need to know about the ADR refresher course: Exam questions, online formats, validity of the ADR certificate, training requirement according to ADR 1.3 and how to submit evidence in an audit-proof manner using the CIVAC platform.

Read more
ADR 1.3 Instruction: Duties, intervals, evidence
Dangerous Goods & Logistics20 July 202612 min read

ADR 1.3 Instruction: Duties, intervals, evidence

The 1.3 instruction according to ADR is mandatory for everyone involved in the dangerous goods process. This article shows what content it includes, at what intervals it needs to be refreshed and how the proof exists before the BAG inspection.

Read more
Hazard number 90, UN 3082: What the label means for transport and compliance
Dangerous Goods & Logistics20 July 202612 min read

Hazard number 90, UN 3082: What the label means for transport and compliance

The combination 90 and 3082 stands for environmentally hazardous liquid substances of class 9. Anyone who transports, stores or ships them has clear ADR obligations. This guide organises labelling, packaging, ordering requirements and fine risks sorted by §§ and ADR chapters.

Read more
ADR dangerous goods: How companies organise road transport in a legally compliant manner
Dangerous Goods & Logistics20 July 202613 min read

ADR dangerous goods: How companies organise road transport in a legally compliant manner

ADR has been regulating the road transport of dangerous goods in Europe since 1957. What shippers, packers and carriers will have to prove in 2026 and how the GGB will keep the documentation audit-proof.

Read more
Dangerous goods 30/1202: Transport and document diesel and heating oil in accordance with ADR
Dangerous Goods & Logistics19 July 202613 min read

Dangerous goods 30/1202: Transport and document diesel and heating oil in accordance with ADR

The hazard table number 30/1202 shows a flammable liquid substance of UN number 1202: diesel fuel or heating oil. The article explains the ADR obligations from sender to recipient, the role of the dangerous goods officer and the auditable documentation.

Read more
ISO 27001 Risk Assessment Template: What a Certifiable Workflow Looks Like in 2026
IT Security & NIS-219 July 202612 min read

ISO 27001 Risk Assessment Template: What a Certifiable Workflow Looks Like in 2026

An ISO 27001 risk assessment is a workflow, not a spreadsheet. This guide explains the 2022 revision, the methodology your auditor expects, the structure of a defensible risk register, and how CIVAC packages the templates inside one Workspace.

Read more
ISMS consultants in comparison: External structure of an ISO/IEC 27001:2022 system
IT Security & NIS-219 July 202613 min read

ISMS consultants in comparison: External structure of an ISO/IEC 27001:2022 system

An ISMS consultant leads the information security management system to certification maturity. The choice between classic advice, platform-based in-house services and officer-as-a-service decides on time, costs and audit verifiability.

Read more