Standards & regulation
From ISO 27001 to the EU AI Act – Compaas assesses, prioritises, and implements.
Mid-market companies face pressure from laws, industry standards, and customer requirements at the same time – often without clear prioritisation and with limited internal capacity. Compaas knows the relevant frameworks from practice: explained clearly, prioritised by risk, and implemented so measures remain sustainable in operations and audit-ready in documentation.
ISO 27001
The international standard for information security management systems (ISMS). Compaas supports gap analyses, risk assessments, action planning, internal audits, and preparation for certification audits.
- ISMS design and maintenance
- Risk analysis per ISO 27005
- Audit preparation as a certified auditor
Data Protection (GDPR)
The General Data Protection Regulation requires demonstrable technical and organisational measures. Compaas assists with records of processing, data protection impact assessments, contract management, and integration into your business processes.
- TOM concepts
- DPIA support
- Data processing agreements & contracts
Whistleblowing / Whistleblower Protection
Whistleblower protection legislation requires many companies to establish reporting channels. Compaas advises on system selection, process design, and the appointment of a whistleblower protection officer.
- Reporting system design
- Process and escalation rules
- Outsourced mandate
Cyber Resilience Act (CRA)
The CRA introduces new requirements for manufacturers and providers of digital products with network connectivity. Compaas analyses affected product lines and supports implementation of conformity requirements.
- Scope analysis
- Documentation obligations
- Process integration in development
Defence: Classified Information / VS-NfD / ITAR
Companies in defence supply chains face special security requirements. Compaas supports VS-NfD concepts, ITAR compliance, and preparation for official inspections.
- VS-NfD security concepts
- ITAR export control
- Audit support
EU AI Act
The EU AI Act classifies AI systems by risk category and defines corresponding obligations. Compaas helps inventory AI applications and derive necessary governance measures.
- AI inventory & risk classification
- Governance frameworks
- Documentation obligations
CMMC
Cybersecurity Maturity Model Certification is relevant for US defence contractors and their suppliers. Compaas supports determining the required maturity level and step-by-step implementation.
- Maturity level assessment
- Gap analysis against CMMC practices
- Implementation roadmap
ISO 62443
This standard addresses industrial automation and control systems (IACS). Compaas supports manufacturers and operators in securing OT/ICS environments per ISO 62443.
- Zone and conduit concepts
- Security level definition
- OT/IT process integration