Compaas – Compliance as a Service

Compliance as a Service

Information security & compliance for mid-market companies

ISO 27001, GDPR, whistleblower systems, customer audits: Compaas delivers consulting, outsourced mandates, and technical measures – with one dedicated point of contact instead of rotating project teams.

Independent since 2010 ISO 27001 auditor since 2019 10+ industries One dedicated point of contact

Compaas at a glance

Years of experience

Audits conducted

Industries

Areas of expertise

Compaas combines technical expertise with pragmatic compliance consulting – personal service with a dedicated point of contact and an experienced team.

Who is Compaas for?

Typically companies with 20 to 200 employees – when compliance matters, internal capacity is limited, and a dedicated point of contact is needed.

01

Mid-market

Management, IT leadership, quality management

External expertise instead of a full-time ISO/DPO role – pragmatic and cost-effective.

02

Suppliers & subcontractors

Sales, QM, supply chain leads

ISO 27001, customer audits, and security evidence for automotive, engineering, and industry.

03

Regulated organisations

Management, administration, associations

GDPR, whistleblower protection, and demonstrable processes – e.g. in social care and non-profits.

Industries where Compaas typically supports clients

Automotive Mechanical engineering Construction Retail Tax advisory / auditing Electronics Metal fabrication Food Hospitality Social enterprises and associations

Typical situations

Does any of this sound familiar? Here is how Compaas helps in practice.

“A major customer requires ISO 27001 – we do not know where to start.”

How Compaas approaches it

  • Compaas starts with a gap analysis against ISO 27001 and relevant customer requirements – you immediately see where gaps exist in processes, documentation, and technology.
  • This yields a prioritised action plan with a realistic timeline: what must be in place before the audit, and what can follow in stages?
  • Compaas supports implementation, prepares internal audits, and guides you through to certification – structured, with a dedicated point of contact.
Consulting & Implementation

“We need a Data Protection Officer but not a full-time role.”

How Compaas approaches it

  • Compaas takes on the external DPO role with the required expertise and independence – legally sound and cost-effective.
  • Regular reports to management, maintenance of records of processing and TOMs, and support with supervisory authority enquiries.
  • Your team is relieved: Compaas prepares topics, prioritises measures, and supports implementation in day-to-day operations.
Outsourced Mandates

“Whistleblower law applies to us – we still lack a reporting system.”

How Compaas approaches it

  • Compaas selects and sets up a secure reporting channel – confidential, accessible, and compliant with whistleblower protection law.
  • Processes for intake, review, handling, and escalation are documented and integrated into your organisation.
  • If required, Compaas also takes on the officer role and guides you through initial reports and reviews.
Whistleblower system

“Our IT team is overloaded – strategic security topics are neglected.”

How Compaas approaches it

  • Compaas takes on ISO tasks at management level: risk assessment, action planning, and reporting to leadership.
  • Close coordination with IT and business units – operational topics stay with IT, strategic security with Compaas.
  • Continuous support instead of one-off projects: ISMS maintenance, internal audits, and preparation for external reviews.
External ISO

“We want no surprises before the certification audit.”

How Compaas approaches it

  • Compaas runs an internal pre-audit against the assessment criteria – weaknesses become visible before the external auditor arrives.
  • Gaps in processes, documentation, and evidence are closed systematically; open items get clear owners and deadlines.
  • You enter the certification audit with confidence: prepared, documented, and knowing what auditors expect.
Internal audits & certification

How Compaas works with you

  1. 1

    Intro call

    A no-obligation introduction: where does your organisation stand? Which standards or customer requirements are relevant? Compaas gains an initial overview.

  2. 2

    Analysis

    Gap analysis or needs assessment: Compaas identifies gaps, prioritises measures, and creates a realistic implementation plan with effort estimates.

  3. 3

    Implementation

    Joint implementation: policies, processes, technical measures, and training – pragmatic and tailored to your operations.

  4. 4

    Ongoing support

    Continuous support, internal audits, certification preparation, or outsourced mandates – Compaas remains your dedicated point of contact.

Standards & regulation

Compaas clarifies which requirements are relevant for your organisation.

Common in mid-market

Typical starting points for Compaas clients

ISO 27001 Data Protection (GDPR) Whistleblower protection

Industry & product specific

When customers, products, or supply chains add further requirements

Cyber Resilience Act (CRA) EU AI Act CMMC VS-NfD / ITAR ISO 62443
Independent since 2010
ISO 27001 auditor since 2019
10+ industries
One dedicated point of contact

The Compaas team

Consultants, mandated officers, and technical expertise from one source – personal, direct, and without a call centre.

Learn more about Compaas →

Ready for an intro call?

Get in touch with Compaas – personal, no obligation, and tailored to your situation.

Contact us now