What officers need to know.
Regulatory shifts, framework updates and operational guidance, curated for Data Protection, IT Security, Compliance and AI Governance leads. Written from the field, verified against primary sources.
Operating instructions for hazardous substances in accordance with Section 14 GefStoffV: Sample, mandatory content and testing in the audit
Section 14 of the Hazardous Substances Ordinance requires activity-related operating instructions for each hazardous substance, written, understandable and in the language of the employees. We show mandatory content, sample structure and an audit-proof maintenance process.
Hazardous substances officer: appointment, tasks, liability and duties 2026
Appointing a hazardous materials officer is not a sure-fire success, but rather a documented obligation with extensive liability. This guide organises the legal basis, tasks, qualifications and operational tools for audit-proof proof.
Environmental management software: What commissioners really need in 2026
If you want to combine ISO 14001:2015, EMAS, KrWG and the EU reporting requirements in one system, you need more than an Excel folder. This article shows which functions environmental management software must provide and how CIVAC integrates the environmental officer.
Energy audit according to DIN EN 16247: Who is obliged, who checks, who is liable
The energy audit obligation according to Section 8 EDL-G and DIN EN 16247-1 applies to every non-SME in Germany every four years. Anyone who misses the deadline risks fines of up to 50,000 euros and EnEfG consequential obligations. This article explains thresholds, methodology, audit trail and the appointment option for the environmental officer.
ISO 14001 Certification Consulting in Germany: A Practical Guide for 2026
ISO 14001:2015 certification in Germany requires more than a generic environmental management system. This guide explains the steps, costs, role of the Umweltbeauftragter, and what to expect from a credible German consulting partner.
Environmental protection officer in the company: duties, appointment and reporting line 2026
Obligation, appointment, appointment document and reporting line: What lies behind the term environmental protection officer, when it is obligatory and how the role is embedded in a compliance architecture in an audit-proof manner.
Waste representative duty: From what quantity does the order become binding
Anyone who produces or disposes of hazardous waste in certain quantities must appoint a waste representative. The article explains threshold values according to AbfBeauftrV, ordering procedures, documentation and reporting obligations, including operational setup.
Sign the LkSG declaration of principles: template, content and duties of the management
The declaration of principles according to Section 6 Paragraph 2 LkSG is the central anchor of the Supply Chain Due Diligence Act. This article shows the mandatory components, a structural proposal, common errors and the audit-proof signing process by the management, including connection to the LkSG representative.
LkSG obligation: scope, duty of care and appointment of the representative
Since 2024, the LkSG has applied to companies with 1,000 or more employees. We explain the nine due diligence obligations, the BAFA reporting requirement, fines of up to 800,000 euros and how to appoint an LkSG representative via the CIVAC Compliance platform and Officer-as-a-Service.
Occupational Safety Compliance in Germany for English-Speaking Operations
If your operations in Germany run in English, occupational safety compliance under ASiG, ArbSchG and DGUV V2 still applies in full. This guide explains the legal duties, the SiFa appointment, and how to keep audit evidence in one workspace.
Supply Chain Due Diligence in Germany: LkSG, CSDDD and What Foreign Companies Must Do
Germany was the first large EU economy to impose mandatory supply chain due diligence. This guide covers the 2024 thresholds, eleven protected rights, BAFA enforcement record, and how to set up an audit-ready officer function in two working days.
CSRD reporting requirement in medium-sized businesses 2026: operational implementation step by step
From the 2026 financial year, the CSRD reporting obligation applies to large medium-sized corporations in accordance with Section 267 Paragraph 3 of the German Commercial Code (HGB). This guide shows the operational implementation in medium-sized companies: materiality analysis, data collection, supplier connection, attesting and workspace structures.
IT security costs in 2026: What an effective ISMS really costs in medium-sized businesses
IT security rarely costs less than 50,000 euros per year in medium-sized businesses. The article breaks down the costs into setup, operation and audit, compares the internal model with officer-as-a-service and provides a template for budget plausibility to management and the supervisory board.
IT security concept: Structure, content and obligations according to NIS-2, ISO 27001 and BSI-Grundschutz
An IT security concept documents technical and organisational measures according to recognised standards. This guide shows the structure, mandatory content and interfaces to NIS-2, ISO 27001:2022 and BSI-Grundschutz and makes the duty of the information security officer operationally tangible.
BSI security incident notification: The 24-hour workflow under NIS-2
NIS-2 (§ 32 BSIG) requires an early warning to the BSI within 24 hours of becoming aware of a significant security incident, a follow-up report after 72 hours and a final report after one month. This post describes the complete workflow without any gaps.
How to Comply with the NIS-2 Directive in Germany: A 90-Day Operational Plan
Around 29,500 German entities fall in scope of NIS-2. The directive's value emerges from disciplined operational execution: scoping, risk management, named information security officer, 24/72 reporting, management training. This guide is a 90-day plan for entities still building the foundation.
ADR catalogue of fines 2021: What still applies today and what was reframed in 2025
Anyone who thinks of 2021 as the reference year for ADR fines will overlook the adjustments from GGVSEB 2023 and the GbV amendment 2024. This article classifies the status of 2021, shows the sanction framework in force today and provides the dangerous goods officer with a practical checklist.
ADR refresher course: exam questions, online format and requirements
What you need to know about the ADR refresher course: Exam questions, online formats, validity of the ADR certificate, training requirement according to ADR 1.3 and how to submit evidence in an audit-proof manner using the CIVAC platform.
ADR 1.3 Instruction: Duties, intervals, evidence
The 1.3 instruction according to ADR is mandatory for everyone involved in the dangerous goods process. This article shows what content it includes, at what intervals it needs to be refreshed and how the proof exists before the BAG inspection.
Hazard number 90, UN 3082: What the label means for transport and compliance
The combination 90 and 3082 stands for environmentally hazardous liquid substances of class 9. Anyone who transports, stores or ships them has clear ADR obligations. This guide organises labelling, packaging, ordering requirements and fine risks sorted by §§ and ADR chapters.
ADR dangerous goods: How companies organise road transport in a legally compliant manner
ADR has been regulating the road transport of dangerous goods in Europe since 1957. What shippers, packers and carriers will have to prove in 2026 and how the GGB will keep the documentation audit-proof.
Dangerous goods 30/1202: Transport and document diesel and heating oil in accordance with ADR
The hazard table number 30/1202 shows a flammable liquid substance of UN number 1202: diesel fuel or heating oil. The article explains the ADR obligations from sender to recipient, the role of the dangerous goods officer and the auditable documentation.
ISO 27001 Risk Assessment Template: What a Certifiable Workflow Looks Like in 2026
An ISO 27001 risk assessment is a workflow, not a spreadsheet. This guide explains the 2022 revision, the methodology your auditor expects, the structure of a defensible risk register, and how CIVAC packages the templates inside one Workspace.
ISMS consultants in comparison: External structure of an ISO/IEC 27001:2022 system
An ISMS consultant leads the information security management system to certification maturity. The choice between classic advice, platform-based in-house services and officer-as-a-service decides on time, costs and audit verifiability.