Skip to content
EN
Book a demo
01
European compliance management

Complaica

Always audit-ready.

Hosted in Germany · DPA available · Migration included
srv-erp-01 Server Protection needs
Availability
No informationNormalHigh Very high
Recommended level – Very high Show origin
Maximum principle · the highest level wins
ERP system Very high
Warehouse management High
Link graph Server · application · process
+5
srv-erp-01 Server
Production
Availability High
ERP system Application
Availability Very high
+11
Warehouse management Application
Availability High
+5
02

Trusted by critical infrastructure operators, financial services providers and industrial companies.

Water utility · KRITIS · ~450 employees
Financial services provider · BaFin-regulated · DORA scope
Automotive supplier · TISAX AL 3
Municipal utility · ISO 27001 + IT-Grundschutz
03

From information security to sustainability.

One system for every standard your organisation is subject to — and for the work they have in common.

ISO 2700x, IT-Grundschutz, GDPR, CRA, EU Data Act, NIS2, KRITIS, DORA…

Information and cyber security, and data protection

TISAX, KGAS, ASPICE, ISO 21434, ISO 26262, ISO 15118

IT, OT, software development and the automotive industry

ISO 9001, ISO 14001, ISO 19011, ISO 37001, ISO 31000

Sustainability, quality and compliance

04

Twelve use cases, one data set.

From the ISMS to the supply chain — every use case works on the same processes, assets and evidence.

ISMS

Information security management systems

Protection requirements, controls and evidence in one data set — from the scope to the management review.

DSMS

Data protection management systems

Processing activities, legal bases and retention periods that generate the record of processing and the DPIA.

BCMS

Business continuity management systems

BIA, recovery times and contingency plans on the same processes the ISMS protects.

KRITIS

Managing critical infrastructure

Asset register, §8a BSIG evidence and reporting paths for the review at the BSI.

Automotive software and systems engineering

Process groups, capability levels and work products along the development cycle.

CSMS

Cybersecurity management systems

Threat analysis and cybersecurity evidence across the whole product lifecycle.

QMS

Quality management systems

Process map, objectives and audit programme in the same High Level Structure.

ESG

Environment, social, governance

Metrics, accountabilities and supporting records for sustainability reporting.

LkSG

Supply chain management and compliance

Suppliers, risk analysis and remedial action, including the annual reporting duty.

Knowledge management and awareness

Policies, briefings and responsibilities where the work actually happens.

Training

Training plan, attendance and effectiveness checks — as evidence, not as a list.

Internal policies and compliance

Keep your own rules alongside the standards and assess them like any other requirement.

05

This is how evidence an auditor accepts comes about.

01 / 04

The scope your auditor wants to see

Sites, assets and processing activities sit in one structure. Every asset carries its protection requirement, every connection is traceable — the basis for modelling and for the audit report.

ISMS scope 2026 Sites 3 · Assets 128
Site South plant KRITIS · B3S water
SCADA control system A.8.16A.5.7 Protection requirement: very high
Telecontrol link A.8.20 Protection requirement: high
Site Administration ISO 27001 · GDPR
HR administration Art. 30A.5.34 Processing activity no. 14
02 / 04

One control, every standard

You document the requirement once. Complaica credits it to every standard it satisfies and keeps status, evidence and review date in one place.

A.5.7 Threat intelligence
implemented 3 pieces of evidence reviewed 04/2026
ISO 27001NIS2 §30TISAXB3S
03 / 04

Gross, control, net — on a single sheet

Assessment before the control, the control itself, assessment after. The effect is visible instead of buried in a side column.

12345 12345
Gross Net Axes: likelihood × impact
R-014 · Control system outage · Control: redundancy + emergency drill
04 / 04

The audit report is no longer an all-nighter

Evidence hangs off the requirement, with validity and expiry. The report is generated from the data set, not assembled from a folder.

Evidence for A.8.16 Generate audit report
SIEM review minutes Q1/2026 PDF 12.03.2026 ✓ valid
Training records, operations XLSX 02.02.2026 ✓ valid
Firewall configuration baseline PDF 28.01.2026 ⚠ expiring
06

Why Complaica and not the next tool along.

From Germany, hosted in Germany.

Development, support and data centre in Germany. No third-country transfer, and a model DPA is ready to go.

More than ten years in this niche.

Complaica is the next generation of software that has held up in audits for over a decade — not a first attempt.

Migration is part of the price.

We take over your existing spreadsheets, policies and evidence. No extra charge, no consultant days.

No lock-in. Demonstrably.

Full export of all data to Excel — any time, no request needed. If you want to leave, we will not hold you.

07

“Three standards from one data set — preparing the surveillance audit took us twelve days instead of six weeks.”

Photo
Name, Information Security Officer
Municipal utility · KRITIS · ~450 employees
−40%
manual effort
3 standards
certified in parallel
1 data set
instead of four spreadsheets

Placeholder: name, photo and company only after written approval (reference consent).

08

The clocks are already running.

StandardStatusSource
DORA applicable since 17 Jan 2025 EUR-Lex
NIS2 / BSIG in force since 6 Dec 2025 · BSI registration grace period until 31 Jul 2026 BSI
CRA reporting duties from 11 Sep 2026 · fully applicable from 11 Dec 2027 EUR-Lex
09

Your data stays in Germany.

Data centre
Germany, ISO 27001-certified operator
Encryption
TLS 1.3 in transit, AES-256 at rest
Processing agreement
Model DPA available as a PDF
Certification
ISO 27001 in preparation · architecture aligned to C5
10

Pricing you know in advance.

Licensing by users and number of standards. Migration and onboarding are included.

from €490 / month
See all pricing
11

30 minutes, your standards, your scope.

No sales pitch
A demo on your use case, not on sample data
Reply within one business day
Your data is never passed to third parties

By submitting you agree to the privacy policy.

Book a demo