What officers need to know.
Regulatory shifts, framework updates and operational guidance, curated for Data Protection, IT Security, Compliance and AI Governance leads. Written from the field, verified against primary sources.
Difference between ISB and CISO explained: role, duties, reporting line
ISB and CISO are often used interchangeably, but they are different. The ISB is the formal German representative role according to BSIG and KRITIS, the CISO is the operational management function. This guide shows the dividing line, the interfaces and the document-proof setup path.
KRITIS obligation: Which operators will be subject to the stricter regulation in 2026
In 2026, the KRITIS obligations will be bundled from BSIG, KRITIS-DachG and NIS-2. Those affected have two years for implementation. The thresholds, sectors and fines in an operational overview.
NIS 2 implementation: What do companies really need to do in the first 90 days
The NIS 2 Implementation Act has been in effect since March 2026. This guide shows the operational sequence for the first 90 days, from the impact check to the ISB order to the functional reporting path to the BSI.
KRITIS Ordinance 2026: What obligations operators really have to meet
With the KRITIS umbrella law and the adapted BSI-KritisV, the threshold values, obligations to provide evidence and the amount of fines will change for operators of critical infrastructures in 2026. This article explains which obligations remain specific, which ones are new, and how an information security officer operationally establishes audit capability.
ADR certificate exam questions 2021: What drivers and dangerous goods officers need to know
Anyone looking for the ADR exam status 2021 usually asks about the basic course, classes and 1.3 instruction. This article classifies the content, shows the changes up to ADR 2025 and explains how the dangerous goods officer organises the training in the company in a way that is exam-proof.
Instruction according to ADR 1.3: Contents, deadlines, evidence legally secure
Anyone who packs, loads or ships dangerous goods requires training in accordance with Chapter 1.3 ADR. This guide shows the mandatory scope, content, deadlines and which evidence is valid before BAG inspection and audit.
Kemler number 30 and UN 1863: Understanding dangerous goods labelling of aviation turbine fuel
The orange warning sign with the number sequences 30 and 1863 indicates aviation turbine fuel. This guide explains the Kemler number, UN number, ADR class 3 and the duties of the dangerous goods officer in shipping, transport and unloading companies.
Dangerous goods labelling for trucks: ADR obligations, plates, UN numbers
Anyone who moves dangerous goods on the road must mark the towing vehicle, trailer and shipping items in accordance with ADR 2025. This guide shows which signs, labels and codes apply and when and how CIVAC bundles the evidence.
Dangerous goods 33/1203: Kemler number, UN number and obligations when transporting gasoline
The number combination 33/1203 on the orange warning sign identifies gasoline as a Class 3 flammable liquid. This guide provides an audit-compliant classification of ADR obligations, labelling and the role of the dangerous goods officer.
ISO 27001 Implementation Consulting in Berlin: A Buyer's Guide for 2026
Choosing an ISO 27001 implementation consultant in Berlin: scope, deliverables, timelines, costs, and the difference between a consultant who runs the project and one who hands you a templated PDF.
Information security management system: construction without a file graveyard
An information security management system is not a collection of documents, but a recurring operational process with an owner, deadline and audit trail. The article shows how you can bring 93 controls into everyday life without sinking into the pile of files or going over your budget.
Pen test requirement according to ISO/IEC 27001:2022 Annex A: What is really required
ISO/IEC 27001:2022 does not mention the penetration test literally, but requires it indirectly via Annex A 8.8, 8.29 and 5.36. We show what evidence an auditor expects and how the obligation can be implemented operationally.
TISAX certification for automotive suppliers: obligations, stages, preparation
OEMs require TISAX as a prerequisite for orders. This guide explains labels, assessment levels, VDA-ISA-6 controls and operational preparation for automotive suppliers in Germany and the DACH region.
DORA obligation: What financial companies have to prove since January 17, 2025
Since January 17, 2025, Regulation (EU) 2022/2554 (DORA) requires financial companies to have documented ICT risk management, incident reports and third-party registers. We show which obligations apply specifically, how they connect to ISO 27001 and where the most common gaps lie.
Convert ISO 27001:2022 now: migration path until October 2026
The deadline for switching to ISO/IEC 27001:2022 is October 31, 2026. If you plan now, you will avoid re-audit stress, duplicate documentation and certificate gaps. This guide shows operational migration in five steps.
ESG Ambiente: How the environmental pillar in German companies becomes audit-proof
ESG without ambience remains marketing. Anyone who does not provide evidence of greenhouse gases, water and waste risks accusations of greenwashing and questions from investors. This article shows how to operationally anchor the E-pillar.
Vanguard All Cap ESG: What companies can learn from the screening
The Vanguard ESG Global All Cap UCITS ETF excludes around 30% of investable companies. CIVAC shows which criteria apply and how you can prepare your own CSRD and ESRS documentation accordingly.
Vanguard ESG All-World: What sustainability officers need to know about investment policy
Vanguard ESG All-World products are increasingly being used in treasury reserves and pension models. What ESG/sustainability officers need to document regarding screening methodology, CSRD disclosure and governance obligations.
DWS ESG Women for Women: What the fund means for your ESG strategy
The DWS ESG Women for Women bundles gender lens investing in a mutual fund. We explain which diversity metrics your ESG officer must provide evidence of under CSRD and ESRS S1 and how CIVAC ensures the verification.
ESG investment criteria: How to firmly anchor environment, social and governance
ESG investment criteria have been the subject of review since the SFDR was tightened in 2023 and the CSRD was first applied in 2025. This guide shows how you can anchor environmental, social and governance factors in a verifiable investment process and not lose them in the pitch deck.
DWS Invest ESG Women for Women: Structure, strategy, ESG classification
DWS Invest ESG Women for Women is an Article 8 fund with a gender lens strategy. Read about how the investment policy is structured, which SFDR obligations apply and which reporting channels institutional investors will have to document in 2026.
MSCI World Sustainability: Methodology, ESG requirements and importance for German companies
The MSCI World ESG Leaders and the MSCI World SRI Index bring together sustainable companies from 23 industrialized countries. Anyone who wants to be included must manage ESG data quality, CSRD reporting and LkSG obligations in a robust reporting line.
ESG portal: What a reliable platform for sustainability data has to achieve
An ESG portal combines data collection, plausibility checks, audit trails and reporting. This article shows functions, selection criteria and the interconnection with the ESG officer, CSRD and LkSG.
AI-Powered Compliance Software in Germany: Capability Map for 2026 Procurement
AI-powered compliance software promises faster audits, leaner officer teams, and continuous control monitoring. Under the EU AI Act (Regulation (EU) 2024/1689) and NIS-2, the German market now also expects evidence of safe AI use inside the tool itself. This guide gives you the capability map and the procurement checklist.