What Compaas can do for you
From gap analysis through outsourced mandates to phishing simulations – one point of contact for all topics.
Typical engagements
These are the services Compaas clients request most often.
Gap analysis
Where do we stand vs. ISO 27001 or customer requirements?
Learn more →
ISO 27001 certification
Build an ISMS, run internal audits, and support through certification.
Learn more →
External Data Protection Officer
Meet GDPR obligations without a full-time hire.
Learn more →
External ISO
Steer information security strategically and report to management.
Learn more →
Whistleblower system
Reporting channel and processes under whistleblower law – including officer role.
Learn more →
Phishing simulation & awareness
Sensitise staff – measurable and standards-compliant.
Learn more →
Vulnerability scan / pentest
Identify technical risks – not just on paper.
Learn more →
Customer audit preparation
Prepare for and support OEM and supplier audits.
Learn more →Organised in three areas
Consulting · Outsourced mandates · Technical – all from one source.
01 Consulting & Implementation
Compaas supports mid-market companies from the initial assessment through to successful certification or customer audit preparation – with deep standards expertise, clear prioritisation, and a focus on measures that work in practice.
- Gap analysis
- ISO 27001 introduction
- Customer audit preparation
02 Outsourced Mandates
Compaas takes on legally or contractually required officer roles as an external partner – reliably, cost-effectively, and with the necessary specialist expertise.
- External DPO
- Information Security Officer
- Whistleblower protection officer
03 Technical Services
From the training platform to phishing simulations and penetration testing – Compaas complements organisational compliance with technical security.
- Phishing simulation
- Vulnerability scan
- Penetration test
Frequently asked questions about our services
What company size is Compaas suited for?
Compaas primarily serves mid-market companies – typically from around 20 to several hundred employees. At this scale, regulatory requirements, customer demands, and limited internal capacity often collide without a dedicated compliance team being economically viable. Compaas scales the scope of support to your situation: from targeted advice on specific topics to holistic ISMS implementation. The approach avoids unnecessary overhead – measures are chosen to remain sustainable in day-to-day operations and are not planned beyond what the organisation can realistically support.
Do I really need an external Data Protection Officer?
For many mid-market companies, yes. Under Art. 37 GDPR, appointment of a Data Protection Officer is generally mandatory if at least 20 people are permanently engaged in automated processing of personal data – or if special categories of data, extensive monitoring, or high risks require appointment. Compaas reviews in the intro call which mandates are actually relevant for your organisation – not only the DPO but also information security officer or whistleblower protection. An external officer is often the more economical solution when a full-time role is not justified but professional qualification and independence are required.
What is the difference between a scan and a penetration test?
A vulnerability scan checks systems automatically against known technical weaknesses – fast, cost-effective, and well suited as a regular routine check. It shows where patches are missing, configurations are insecure, or known CVEs exist. A penetration test goes significantly deeper: security experts actively attempt to exploit gaps and simulate attack paths – as a real attacker would. The result is more meaningful but also more resource-intensive and should be deployed selectively, for example before certification, after major changes, or where risk is elevated. Compaas often recommends a tiered approach: regular scans as a baseline, penetration tests where risk justifies the depth.