Compaas – Compliance as a Service
Menu

Compliance as a Service

Compaas supports mid-market companies with information security, cybersecurity, and IT compliance – pragmatic, cost-effective, and with a dedicated point of contact.

Focus on your core business – compliance as a service

Laws, standards, and customer requirements are becoming more demanding – qualified specialists in information security and compliance are hard to find and retain.

Compaas takes on these topics as an external partner: structured, transparent, and without you first having to build a dedicated specialist department. You retain oversight; we deliver the specialist implementation – from analysis through implementation to audit support.

Whether your first ISO 27001 certification, ongoing GDPR maintenance, preparation for a customer audit, or compliance with new regulation such as CRA and the EU AI Act: Compaas shows clearly where action is needed, prioritises measures by risk and effort, and implements solutions that work in practice and are documented in an audit-ready manner.

The result: your organisation reliably meets requirements, your teams are not burdened with unnecessary bureaucracy – and you can focus on your core business.

Gap analysesEfficient implementationAudits & certification

"Compaas aims to relieve organisations so they can focus on their core business – with measures that actually work in day-to-day operations."

— Compaas
Compaas Compliance as a Service

What Compaas offers you

  • Personal intro call – no obligation
  • One dedicated point of contact at Compaas
  • Response typically within 24 hours
  • Practical approach, not standard slide decks

Behind Compaas

Founded by Christian Lorenz – technical and compliance expertise from a single source.

Christian Lorenz – Founder of Compaas

Christian Lorenz

Founder & primary contact

Compaas builds on many years of experience in software development and compliance consulting. Christian Lorenz started in the late 1990s with his first own web applications – that is where programming began. Since then, demanding, complex web applications have always been the focus. He has been self-employed since 2010, initially in software development and soon thereafter in the compliance topics that Compaas covers today.

Learn more about Compaas →

Standards & regulation

From ISO 27001 to the EU AI Act – Compaas assesses, prioritises, and implements.

Mid-market companies face pressure from laws, industry standards, and customer requirements at the same time – often without clear prioritisation and with limited internal capacity. Compaas knows the relevant frameworks from practice: explained clearly, prioritised by risk, and implemented so measures remain sustainable in operations and audit-ready in documentation.

ISO 27001

The international standard for information security management systems (ISMS). Compaas supports gap analyses, risk assessments, action planning, internal audits, and preparation for certification audits.

  • ISMS design and maintenance
  • Risk analysis per ISO 27005
  • Audit preparation as a certified auditor

Data Protection (GDPR)

The General Data Protection Regulation requires demonstrable technical and organisational measures. Compaas assists with records of processing, data protection impact assessments, contract management, and integration into your business processes.

  • TOM concepts
  • DPIA support
  • Data processing agreements & contracts

Whistleblowing / Whistleblower Protection

Whistleblower protection legislation requires many companies to establish reporting channels. Compaas advises on system selection, process design, and the appointment of a whistleblower protection officer.

  • Reporting system design
  • Process and escalation rules
  • Outsourced mandate

Cyber Resilience Act (CRA)

The CRA introduces new requirements for manufacturers and providers of digital products with network connectivity. Compaas analyses affected product lines and supports implementation of conformity requirements.

  • Scope analysis
  • Documentation obligations
  • Process integration in development

Defence: Classified Information / VS-NfD / ITAR

Companies in defence supply chains face special security requirements. Compaas supports VS-NfD concepts, ITAR compliance, and preparation for official inspections.

  • VS-NfD security concepts
  • ITAR export control
  • Audit support

EU AI Act

The EU AI Act classifies AI systems by risk category and defines corresponding obligations. Compaas helps inventory AI applications and derive necessary governance measures.

  • AI inventory & risk classification
  • Governance frameworks
  • Documentation obligations

CMMC

Cybersecurity Maturity Model Certification is relevant for US defence contractors and their suppliers. Compaas supports determining the required maturity level and step-by-step implementation.

  • Maturity level assessment
  • Gap analysis against CMMC practices
  • Implementation roadmap

ISO 62443

This standard addresses industrial automation and control systems (IACS). Compaas supports manufacturers and operators in securing OT/ICS environments per ISO 62443.

  • Zone and conduit concepts
  • Security level definition
  • OT/IT process integration

View all consulting topics in detail →

Ready for an intro call?

Get in touch with Compaas – personal, no obligation, and tailored to your situation.

Contact us now