Compaas – Compliance as a Service

About Compaas

Compliance as a Service for mid-market companies – pragmatic, personal, and with an experienced team.

Known until 2025 as Lorenz Security

Compaas is a consultancy for information security, cybersecurity, and IT compliance. The offering is aimed specifically at mid-market companies that must meet growing regulatory and security requirements – without having to build extensive internal structures.

  • On the market since 2010
  • ISO 27001 auditor on the team
  • Consulting, mandates & technical from one source
  • Stable team instead of rotating project leads
About Compaas

Our team

Behind Compaas is an experienced team of consultants, mandated officers, and technical specialists – with one dedicated point of contact for your organisation.

Compaas builds on many years of experience in software development and compliance consulting. Since 2010, the company has supported mid-market clients on information security and IT compliance – today with a team of consultants, mandated officers, and technical specialists.

Compaas has supported a large number of clients across a wide range of industries – with a focus on the mid-market companies the offering is designed for.

The team brings together consulting, audit, and technical perspectives – including certified ISO 27001 auditors. Pragmatic and without unnecessary bureaucracy.

Christian Lorenz – Founder of Compaas

Christian Lorenz

Founder & senior consulting

Focus on compliance consulting, ISO 27001, and software development. Certified ISO 27001 auditor since 2019.

Industry experience

AutomotiveMechanical engineeringConstructionRetailTax advisory / auditingElectronicsMetal fabricationFoodHospitalitySocial enterprises and associations

"Compaas aims to relieve organisations so they can focus on their core business – with measures that actually work in day-to-day operations."

— Compaas

The challenge

Standards, laws, and customer requirements are becoming more complex. At the same time, qualified specialists in information security and compliance are hard to find and retain. Building internal capability costs time, money, and distracts from core business.

The Compaas solution

With Compliance as a Service, Compaas assumes specialist responsibility as an external partner: from gap analysis through pragmatic implementation to audit and certification support. Maximum effectiveness and efficiency – cost-effective and without unnecessary bureaucracy.

Our approach

1

Pragmatic, not theoretical

measures that work

2

Efficient, not overloaded

lean processes, clear priorities

3

Standards-compliant, not fear-based

serious and transparent

4

Personal and partnership-oriented

Compaas understands mid-market companies

Who we serve

For companies that want to implement or further develop ISO 27001, GDPR, whistleblower protection, CRA, defence requirements, the EU AI Act, CMMC, ISO 62443, or comparable standards – with a partner who thinks along and delivers.

What Compaas offers you

  • Personal intro call – no obligation
  • One dedicated point of contact at Compaas
  • Response typically within 24 hours
  • Practical approach, not standard slide decks
ISO 27001 Data Protection (GDPR) Whistleblower Protection Cyber Resilience Act (CRA) VS-NfD / ITAR EU AI Act CMMC ISO 62443

Ready for the next step?

Get to know Compaas – personal, non-binding, and tailored to your situation.