Compaas – Compliance as a Service

What Compaas can do for you

From gap analysis through outsourced mandates to phishing simulations – one point of contact for all topics.

Organised in three areas

Consulting · Outsourced mandates · Technical – all from one source.

Frequently asked questions about our services

Illustration for frequently asked questions
What company size is Compaas suited for?

Compaas primarily serves mid-market companies – typically from around 20 to several hundred employees. At this scale, regulatory requirements, customer demands, and limited internal capacity often collide without a dedicated compliance team being economically viable. Compaas scales the scope of support to your situation: from targeted advice on specific topics to holistic ISMS implementation. The approach avoids unnecessary overhead – measures are chosen to remain sustainable in day-to-day operations and are not planned beyond what the organisation can realistically support.

Do I really need an external Data Protection Officer?

For many mid-market companies, yes. Under Art. 37 GDPR, appointment of a Data Protection Officer is generally mandatory if at least 20 people are permanently engaged in automated processing of personal data – or if special categories of data, extensive monitoring, or high risks require appointment. Compaas reviews in the intro call which mandates are actually relevant for your organisation – not only the DPO but also information security officer or whistleblower protection. An external officer is often the more economical solution when a full-time role is not justified but professional qualification and independence are required.

What is the difference between a scan and a penetration test?

A vulnerability scan checks systems automatically against known technical weaknesses – fast, cost-effective, and well suited as a regular routine check. It shows where patches are missing, configurations are insecure, or known CVEs exist. A penetration test goes significantly deeper: security experts actively attempt to exploit gaps and simulate attack paths – as a real attacker would. The result is more meaningful but also more resource-intensive and should be deployed selectively, for example before certification, after major changes, or where risk is elevated. Compaas often recommends a tiered approach: regular scans as a baseline, penetration tests where risk justifies the depth.