What officers need to know.
Regulatory shifts, framework updates and operational guidance, curated for Data Protection, IT Security, Compliance and AI Governance leads. Written from the field, verified against primary sources.
Dangerous goods classes 1 to 9 according to ADR: Overview, labelling and obligation to order
The nine dangerous goods classes according to ADR structure all dangerous substances for roads, rails and inland waterways. This article explains the classes, the labelling, the ordering requirement for GGB and the CIVAC model.
UN 3082 and hazard number 90: What shippers and agents need to know
UN 3082 with danger number 90 is encountered more often in everyday life than expected: lubricants, crop protection, cleaning chemicals. This article explains the ADR classification, the obligations of those involved and the typical errors in transport documents, labelling and packaging.
Dangerous goods stickers: classes, obligations and audit evidence in shipping
Dangerous goods stickers are not decoration, but mandatory labelling according to ADR and GGVSEB. This article explains the nine classes of dangerous goods, the correct attachment, the obligations of those involved and how CIVAC bundles the documentation, the dangerous goods officer and the audit evidence.
Dangerous goods classes according to ADR: Overview, obligations and documentation
Dangerous goods classes structure the ADR and decide on labelling, packaging, transport and reporting obligations. This article explains the nine classes, the associated UN numbers and the operational responsibilities of those involved.
ISO 27001 certification: duration, preparation, effort
An ISO/IEC 27001:2022 certification takes 9 to 18 months from the start of the project to the certificate in medium-sized companies. This guide breaks down the phases, names the effort and shows where audits typically fail.
BSI C5 attestation for cloud providers: What it does, when it is mandatory
The BSI's C5 certificate is the standard for the security of cloud services in the German market. This article explains the structure, type 1 and type 2 testing, relationship to ISO 27001 and operational preparation as a provider and as a customer.
TISAX Certification Process for Automotive Suppliers: A Practical Roadmap
TISAX is the dominant information security label across the European automotive sector. This guide walks suppliers through the assessment levels, the VDA ISA catalogue, the ENX exchange platform and the typical timeline from gap analysis to label issuance.
Virtual CISO Germany: NIS-2, ISO 27001 and the case for a fractional model
German mid-sized companies face NIS-2, ISO 27001:2022 transition and EU AI Act obligations without a full-time CISO on payroll. A virtual CISO model provides accountable security leadership with documented mandates, board reporting and audit-ready evidence in the workspace.
Information security officer: role, duties and appointment in medium-sized companies
The information security officer (ISB) has operational responsibility for the ISMS according to ISO/IEC 27001:2022. The article explains tasks, the appointment certificate, the distinction between CISO and CIO as well as the obligations under NIS-2, KRITIS umbrella law and DORA.
TISAX consulting: what automotive suppliers really need to pass the assessment
TISAX assessments rarely fail due to technology, often due to unclear scope, incomplete documentation and officer roles that are not filled. The article shows how a reliable TISAX consultation is structured and where CIVAC relieves the burden with Workspace and Officer-as-a-Service.
Building an ISMS: Step-by-step instructions according to ISO 27001:2022
Anyone who builds an ISMS according to ISO/IEC 27001:2022 navigates 93 controls, four statements and seven process levels. This guide breaks down the journey into ten phases with responsibilities, artifacts, and realistic timelines.
Understanding Nordea ESG Stars: What the rating means for companies with ESG obligations
Nordea ESG Stars is an internal fund label from Nordea Asset Management. Companies that are in a Stars fund answer ESG questions differently than they would without investor pressure. The article classifies the label legally and shows the obligations in day-to-day business.
Flossbach von Storch and ESG: What investors need to know about integration
Flossbach von Storch manages around 70 billion euros and integrates ESG criteria into the investment process. The article places the practice within the regulatory framework: SFDR Article 8 funds, CSRD reporting requirements from fiscal year 2025, taxonomy quotas and the role of the sustainability officer.
MSCI World Momentum ESG: What the index means for corporate compliance
The MSCI World Momentum ESG combines two logics: price momentum and ESG rating. Whoever appears in the supply chain of an index candidate is also evaluated. This article explains the methodology, the obligations for German companies and the evidence that CSRD and supervision expect.
MSCI World ESG vs. SRI: Differences, methodology and importance for corporate ESG reporting
The MSCI ESG Leaders and SRI Select indices follow different methodologies. This article explains the filter logic, sector weighting, carbon footprint and the consequences for ESG officers and companies subject to CSRD.
Vanguard FTSE All Cap ESG: What companies learn from index logic
The Vanguard ESG Global All Cap UCITS ETF follows the FTSE Global All Cap Choice Index, which excludes certain sectors and thresholds. Companies that do not want to appear in such indices must prepare their ESG disclosure in a verifiable manner according to CSRD and ESRS.
Amundi Funds Global Ecology ESG: What companies derive from the fund for their own ESG obligations
The Amundi Funds Global Ecology ESG is an Article 9 fund under SFDR. What does this mean for investors and especially for companies that themselves have to report under CSRD and EU taxonomy? A practical guide to ESG governance.
ESG in the EU: CSRD, taxonomy and supply chain as an operational duty
ESG has been mandatory reporting practice in the EU since 2024. CSRD, EU taxonomy, CSDDD and ESRS interlock. This post shows how an ESG officer manages data points, dual materiality and audit evidence in one platform.
ESG 2026: From a catchphrase to an appointment certificate in German medium-sized businesses
ESG is no longer a marketing issue. CSRD, EU taxonomy, LkSG and CSDDD require reliable data, roles and reports. The article explains the obligations, the thresholds and the operational structure of an ESG function.
CIVAC Alternative: 14 evaluation criteria for compliance platforms in medium-sized companies
Anyone looking for a CIVAC alternative usually compares apples with oranges. Classic consulting firms, ISMS tools and platform solutions deliver different value propositions. This article provides 14 evaluation criteria, price bands and a decision tree for comparison.
Automate compliance training: e-learning, evidence and reporting lines in medium-sized companies
Training obligations are increasing: GDPR, NIS 2, HinSchG, ISO/IEC 27001:2022, hazardous substances, fire protection. Anyone who continues to keep records in Excel will fail the audit. This article shows how automated e-learning and a workspace carry the reporting line to management.
CIVAC Compliance: Platform, Officer-as-a-Service and the operational structure behind it
CIVAC is a German compliance platform and officer-as-a-service. The article explains how the platform brings together the mandatory representatives from DSB to fire protection in one place, which documents are kept and how CIVAC differs from classic consulting firms.
ISO 27001 Risk Assessment Template: What a Certifiable Workflow Looks Like in 2026
An ISO 27001 risk assessment is a workflow, not a spreadsheet. This guide explains the 2022 revision, the methodology your auditor expects, the structure of a defensible risk register, and how CIVAC packages the templates inside one Workspace.
One Compliance Platform for All German Officer Roles: A Practical Buyer Guide
German law requires dedicated officers for data protection, money laundering, fire safety, hazardous goods, hygiene, whistleblowing, supply chain and many more. Twenty-five mandates, one platform. This guide explains how that consolidation works.