Complaica
Always audit-ready.
Information security, data protection, quality management, business continuity and — not least — your own internal policies.
Complaica is the cost-effective (and elegant) software for capturing every aspect of compliance as quickly and simply as possible.
For more than 10 years we have been building compliance software in Germany, for German companies and German regulatory requirements.
The three compliance aspects
Technical, organisational & regulatory data
Connected
Any time, for anyone
Single source of truth
Fast and transparent
Collaboration
Proven approaches instead of reinventing the wheel.
01 / 07 Scope management
What is in scope
A typical compliance scope covers processes, infrastructure and data — sometimes a whole organisation, sometimes a single role.
- You see the entire scope in one place. Objects in the scope can be imported or created with AI assistance.
- Every change is fully traceable — who changed what, and when. You are notified of the changes that matter.
- Dependencies and compliance goals are laid out in plain sight.
02 / 07 Requirements and obligations
Which requirements have to be met
For every compliance object you get a clear overview of the requirements it has to meet, including their current status. The other way round, for every requirement you see all the objects it has to be implemented in.
Complaica assigns the requirements automatically, and you can adjust any assignment by hand. For every requirement it supplies the exact text of the standard — no looking it up separately in a policy or a book.
You also see the controls and tasks that implement the requirements, and the people accountable for each of them.
03 / 07 Current status and trends
Where things stand today
Status information is the heart of compliance, and it is calculated and updated continuously.
- You see the status of every single object, requirement, risk and other compliance element.
- Aggregated statuses are available as well — for all applications, say, or for every documentation requirement.
- At the top level you get an overall status for the whole organisation, or for a single standard.
- Not only where it stands today, but the full history of every status change.
- And you are notified of status changes automatically — above all when a status gets worse.
04 / 07 Tasks and accountability
Who is doing what
At a glance you see:
- who is accountable for the status of specific processes, assets and organisational units,
- the risk owners and the decision-makers,
- who implements which controls and tasks,
- and every open item and measure in progress.
05 / 07 Risks, threats and vulnerabilities
What the risks are
Complaica assigns the relevant threats automatically; you can correct any of them by hand at any time.
- Threats can be assessed by likelihood, impact and category.
- The structure of the risk matrix is fully configurable.
- You can set your risk appetite.
- You can watch the overall risk picture develop over time and see gross against net risk.
- And you can define treatment strategies, countermeasures, owners, deadlines and budgets.
06 / 07 Reports and evidence
Which documents are required
All data is presented in the Complaica dashboards and/or exported to external systems for further analysis.
Every standard report you need is produced automatically, for example:
- IT-Grundschutz A.1 to A.6
- ISO 27001 Statement of Applicability
- GDPR Records of Processing Activities (RoPA) and Data Protection Impact Assessment (DPIA)
07 / 07 Search and AI
Where to find what
Not least, you do not have to remember the whole data structure — type any text at all and the system finds everything relevant straight away.
The Compl-AI-ca AI services help you define the structure, assign tasks and risks, and keep watch over changes.
The BI functions let you analyse the data quickly and efficiently.
Why Complaica and not the next tool along.
SaaS or on-premises, the same licence price.
Run Complaica as a service or inside your own infrastructure — the licence costs the same either way. The SaaS edition is hosted in Germany.
Secure by design, tested for vulnerabilities.
Security is part of the architecture rather than a layer over it, and the application is checked against known vulnerabilities.
Truly multi-norm.
Whatever can be shared between standards is entered once and reused wherever it applies — nothing is maintained twice.
Among the least expensive compliance software on the market.
And among the most capable: the functionality sits at the top of the field, the price at the bottom of it.
Migration is part of the price.
Your data from other systems comes across with you. Included, not quoted separately.
Trade in your existing licences.
If you hold licences for another ISMS, DSMS or GRC system, we deduct what they cost you from the price of your Complaica licences.
Fast, also on large data volumes.
Response times stay short as the inventory grows: speed is a design goal, not a property of small installations.
Connects to practically anything.
Integration and data exchange in both directions with the systems you already run.
MCP is supported.
Your own AI can read and update data in Complaica — as far as your information security policy allows.
No lock-in.
Full export of all data — any time, no request needed. If you want to leave, we will not hold you.
Twelve use cases, one data set.
From the ISMS to the supply chain — every use case works on the same processes, assets and evidence.
Information security management systems
Protection requirements, controls and evidence in one data set — from the scope to the management review.
Data protection management systems
Processing activities, legal bases and retention periods that generate the record of processing and the DPIA.
Business continuity management systems
BIA, recovery times and contingency plans on the same processes the ISMS protects.
Managing critical infrastructure
Asset register, §8a BSIG evidence and reporting paths for the review at the BSI.
Automotive software and systems engineering
Process groups, capability levels and work products along the development cycle.
Cybersecurity management systems
Threat analysis and cybersecurity evidence across the whole product lifecycle.
Quality management systems
Process map, objectives and audit programme in the same High Level Structure.
Environment, social, governance
Metrics, accountabilities and supporting records for sustainability reporting.
Supply chain management and compliance
Suppliers, risk analysis and remedial action, including the annual reporting duty.
Knowledge management and awareness
Policies, briefings and responsibilities where the work actually happens.
Training
Training plan, attendance and effectiveness checks — as evidence, not as a list.
Internal policies and compliance
Keep your own rules alongside the standards and assess them like any other requirement.
What applies, and when.
Extract from our European compliance calendar for information and cybersecurity, data protection, AI and resilience.
NIS2 / BSIG
Three-month registration deadline for organisations already subject to the new BSIG when it entered into force.
Energy · Transport · Health · Manufacturing · IT · Digital services · Public sector
KRITIS-DachG
The German KRITIS-Dachgesetz enters into force.
Critical infrastructure
CRA
Rules for notification of conformity-assessment bodies start applying.
Software · Hardware · IoT · Industrial products
CER Directive
Member States must identify their critical entities.
Energy · Transport · Health · Water · Food · Public administration
EU AI Act
The main AI Act regime becomes applicable; transparency requirements apply.
All industries using or providing AI
CRA
Vulnerability and severe-incident reporting duties start.
Software · Hardware · IoT · Embedded products
EU Data Act
Connected products newly placed on the market must make product and service data accessible.
Automotive · IoT · Machinery · Energy · Smart products
EU AI Act
Transitional deadline for certain transparency and marking obligations concerning existing AI systems.
AI providers
Machinery Regulation
The new Machinery Regulation becomes applicable, including cybersecurity-related requirements.
Machinery · Industrial automation · Robotics
EU AI Act — GPAI
GPAI models placed on the market before 2 Aug 2025 must comply with the applicable obligations.
AI · Foundation-model providers
EU Data Act
Unfair contractual-terms provisions extend to certain legacy contracts.
IoT · Data economy · B2B
CRA
Further standardisation-related transitional milestone.
Software · Hardware · IoT · Industrial products
EU AI Act
High-risk AI rules for Annex III systems become applicable.
HR · Education · Biometrics · Essential services · Law enforcement
CRA
The CRA becomes fully applicable.
Commercial software · Hardware · Products with digital elements
Frequently asked questions
What is Complaica?
Complaica is Ciqualia’s business line for compliance-centred solutions and consulting — and at the same time the name of our core software.
How long have you worked in compliance?
More than ten years, above all in IT security, data protection and cybersecurity, and in industry-specific topics — particularly in automotive (ASPICE, KGAS, TISAX, ISO 21434).
Which services do you offer?
Consulting and training in IT security and data protection, and the implementation, adaptation and integration of our compliance software.
Which existing systems does Complaica integrate with?
Microsoft Azure, Office 365, Teams, SharePoint and Atlassian Jira, among many others.
Do we need compliance experts of our own to work with you?
Not necessarily. In IT security, data protection, software development, cloud technologies and AI we advise end to end and take on the training as well.
What advantages does Complaica offer?
Several frameworks in one system, cloud or on-premise, multilingual, freely configurable data structures and processes, strong performance even with large data volumes, visualisation and teamwork.
Which industries do you work in?
We work in the automotive industry, in e-mobility and smart home production, in energy, media, education, health, marketing, compliance, the public sector and transportation, among others, as well as in other data-intensive fields.
How do you ensure security and compliance?
We take data protection, security standards, organisational requirements and regulatory obligations into account from the start – from the architecture through to operations.
How can I discuss a project or an idea with you?
Through the contact form on this website or directly by message. We answer quickly and are glad to talk about your requirements and the solutions that are possible.
Working with us is easy and pleasant!
Ask us – we answer quickly.
Thank you.
We will get back to you within one business day.
Not sent.
That did not work. Please check the fields or email us directly.