Complaica
Always audit-ready.
Trusted by critical infrastructure operators, financial services providers and industrial companies.
From information security to sustainability.
One system for every standard your organisation is subject to — and for the work they have in common.
ISO 2700x, IT-Grundschutz, GDPR, CRA, EU Data Act, NIS2, KRITIS, DORA…
Information and cyber security, and data protection
TISAX, KGAS, ASPICE, ISO 21434, ISO 26262, ISO 15118
IT, OT, software development and the automotive industry
ISO 9001, ISO 14001, ISO 19011, ISO 37001, ISO 31000
Sustainability, quality and compliance
Twelve use cases, one data set.
From the ISMS to the supply chain — every use case works on the same processes, assets and evidence.
Information security management systems
Protection requirements, controls and evidence in one data set — from the scope to the management review.
Data protection management systems
Processing activities, legal bases and retention periods that generate the record of processing and the DPIA.
Business continuity management systems
BIA, recovery times and contingency plans on the same processes the ISMS protects.
Managing critical infrastructure
Asset register, §8a BSIG evidence and reporting paths for the review at the BSI.
Automotive software and systems engineering
Process groups, capability levels and work products along the development cycle.
Cybersecurity management systems
Threat analysis and cybersecurity evidence across the whole product lifecycle.
Quality management systems
Process map, objectives and audit programme in the same High Level Structure.
Environment, social, governance
Metrics, accountabilities and supporting records for sustainability reporting.
Supply chain management and compliance
Suppliers, risk analysis and remedial action, including the annual reporting duty.
Knowledge management and awareness
Policies, briefings and responsibilities where the work actually happens.
Training
Training plan, attendance and effectiveness checks — as evidence, not as a list.
Internal policies and compliance
Keep your own rules alongside the standards and assess them like any other requirement.
This is how evidence an auditor accepts comes about.
The scope your auditor wants to see
Sites, assets and processing activities sit in one structure. Every asset carries its protection requirement, every connection is traceable — the basis for modelling and for the audit report.
One control, every standard
You document the requirement once. Complaica credits it to every standard it satisfies and keeps status, evidence and review date in one place.
Gross, control, net — on a single sheet
Assessment before the control, the control itself, assessment after. The effect is visible instead of buried in a side column.
The audit report is no longer an all-nighter
Evidence hangs off the requirement, with validity and expiry. The report is generated from the data set, not assembled from a folder.
| SIEM review minutes Q1/2026 | 12.03.2026 | ✓ valid | |
| Training records, operations | XLSX | 02.02.2026 | ✓ valid |
| Firewall configuration baseline | 28.01.2026 | ⚠ expiring |
Why Complaica and not the next tool along.
From Germany, hosted in Germany.
Development, support and data centre in Germany. No third-country transfer, and a model DPA is ready to go.
More than ten years in this niche.
Complaica is the next generation of software that has held up in audits for over a decade — not a first attempt.
Migration is part of the price.
We take over your existing spreadsheets, policies and evidence. No extra charge, no consultant days.
No lock-in. Demonstrably.
Full export of all data to Excel — any time, no request needed. If you want to leave, we will not hold you.
“Three standards from one data set — preparing the surveillance audit took us twelve days instead of six weeks.”
−40%manual effort3 standardscertified in parallel1 data setinstead of four spreadsheets
Placeholder: name, photo and company only after written approval (reference consent).
Your data stays in Germany.
Pricing you know in advance.
Licensing by users and number of standards. Migration and onboarding are included.