AI-powered GRC platform

NIS2 compliance.
Intelligently automated. Verifiably documented. Cost-efficiently implemented. Future-proof and scalable.

AI-powered GRC platform made in Germany. Protects your management body from personal liability, reduces cyber risk and lowers compliance costs.

100%
NIS2 coverage
DE
Hosting & data
4-8 wks.
To compliance
72%
Compliance score
7
Open tasks
NIS2
100% covered
compliancecompass.de
Compliance Compass dashboard

Security & compliance

GDPR-compliant
Data protection guaranteed
100% sovereign
Full digital control
EU hosting
Servers in Germany
NIS2-ready
100% coverage
AI-powered
Automated & scalable

Suitable for organisations in

Energy Health Finance Transport & logistics Manufacturing IT services Public administration Telecommunications Pharmaceuticals Insurance Chemicals Food Research Waste management Energy Health Finance Transport & logistics Manufacturing IT services Public administration Telecommunications Pharmaceuticals Insurance Chemicals Food Research Waste management
The problem

Good intentions are not enough.

NIS2 compliance needs structure, traceability and the right tools – not more hours in the calendar.

The challenge

Why NIS2 compliance is so hard

The EU NIS2 Directive raises the requirements sharply – and holds management bodies personally accountable. Most organisations start without the right tools.

Complex regulation
Requirements spread across the directive, national transposition acts and technical standards – to be reinterpreted with every change.
Manual processes
Risk analyses, policies and training records in spreadsheets and email threads – slow and error-prone.
Scattered evidence
Records sit in folders, drives and mailboxes – when an audit comes, the complete trail is missing.
Personal liability
Management bodies are liable for failures – without demonstrable diligence the risk stays with the individual.
Expensive tool landscape
Several specialist solutions side by side – high licence costs, duplicated maintenance, no shared view.
9–18 months to compliance – depending on project resources
The solution: Compliance Compass

Compliance that simply works

A GRC platform that covers every NIS2 requirement – with AI-powered automation, complete evidence and hosting in Germany.

100 % NIS2 coverage
Pre-configured frameworks for NIS2, ISO 27001 and the German IT-Grundschutz standard – kept continuously up to date.
AI-powered automation
Risks, policies and tasks are created and updated automatically – instead of manual busywork.
Audit-proof evidence
Versioning, cryptographic hashing and eIDAS-compliant timestamps to RFC 3161 – central and auditable at any time.
Protection for management bodies
Every decision documented and traceable – demonstrable diligence at the touch of a button.
One platform instead of many tools
Risk, supply chain, incidents, policies and awareness in one system – one interface, one role and permission model.
4–8 weeks to compliance – with guided onboarding

From stocktaking to audit-ready evidence – one continuous process.

Book a demo now →
Platform benefits

Why Compliance Compass?

Less effort. More security. Full control.

Cost efficiency

Transparent prices with no hidden costs. No months-long implementation.

  • Cloud-based – no infrastructure costs
  • Modular & scalable
  • ROI in the first year
Trust & data security

Full data sovereignty – development, hosting and support exclusively in Germany.

  • Made in Germany – developed in DE
  • Hosting in Germany & GDPR-compliant
  • Highest security standards
Scalability

From small business to international group – one platform that grows with you.

  • Optimised for SMEs, ready for enterprise
  • Multilingual & multi-tenant
  • Flexible user & permission management
Feature set

Features that go beyond the standard

Not just documentation and checklists – Compliance Compass delivers real automation and intelligence for modern GRC processes.

01 — AUTOMATION

Intelligence instead of busywork

AI-powered automation & risk analysisAI
Intelligent workflows for risk management, policy creation and incident response – with AI-based risk identification and assessment.
Dynamic policy generationAI
AI creates and updates policies automatically from your organisational context and regulatory requirements – in several languages.
Proactive task management
Tasks generated automatically from assets, risks and policies – with deadline tracking, escalation and central evidence collection.
02 — GOVERNANCE

Evidence that holds up in an audit

Tamper-proof documentation
Versioning, cryptographic hashing and legally sound timestamps for full audit compliance.
Guided implementation paths
Step by step through NIS2 and ISO 27001 – with progress tracking, evidence management and links to the relevant controls.
Incident responseAI
Automated planning for business continuity and disaster recovery – with structured notification workflows inside the NIS2 deadlines.
03 — OPERATIONS

An overview of your organisation

Asset managementAI
A central inventory of all digital and physical assets – with AI-powered vulnerability analysis and maintenance suggestions.
Supplier risk managementAI
Automated onboarding and continuous assessment of the security posture across your entire supply chain.
Awareness & training
Integrated training campaigns with progress tracking, automatic reminders and audit-ready records.
NIS2 scope check

Does NIS2 apply to your organisation?

Find out in 3 simple steps whether your organisation falls within the scope of the NIS2 Directive.

Progress
0/3

1. In which sector does your organisation operate?

Select the main sector that applies to your organisation:

2. How large is your organisation?

Size determines whether and how NIS2 applies to you.

Directive (EU) 2022/2555

NIS2 compliance: the clock is running

Organisations have to act. Compliance Compass covers every NIS2 requirement in full.

EUR 10 million or 2 % of worldwide annual turnover
minimum fine ceiling
Member States may set more
NIS2 core obligations
How Compliance Compass solves it
NIS2 requirement
1
Risk management measures
Systematic identification, assessment and control of IT security risks.
Our solution
Central risk inventory with AI scanning
NIS2 requirement
2
Incident response plans
Structured preparation for security incidents with clear responsibilities and escalation paths.
Our solution
AI-powered crisis management
NIS2 requirement
3
Supply chain security
Assessing and monitoring the cybersecurity of direct and indirect suppliers.
Our solution
Supplier risk management system
NIS2 requirement
4
Security training
Regular awareness training for all staff, including the management body.
Our solution
Integrated awareness campaigns
NIS2 requirement
5
Encryption & access control
Cryptography, multi-factor authentication and role-based access rights.
Our solution
Tamper-proof documentation
NIS2 requirement
6
Management accountability
Personal liability of the management body for cybersecurity measures.
Our solution
Audit & task management with deadlines
1
16 Jan 2023
NIS2 Directive entered into force in the EU
2
17 Oct 2024
Deadline for Member States to transpose the directive
3
18 Oct 2024
Directive applies – national laws take effect country by country
!
Now
Time to act – start your compliance programme
A detailed look

Platform features in detail

See how Compliance Compass supports every aspect of your GRC strategy.

Intelligent risk management

A central asset and risk inventory with AI-powered vulnerability scanning that goes far beyond static models.

Asset inventory
Automatic capture and categorisation of all digital and physical assets.
AI-based risk analysis
Continuous scanning and intelligent assessment of vulnerabilities.
Risk heatmaps & dashboards
Critical risks visualised for fast decision-making.
Risk management dashboard

Dynamic policy management

AI creates and updates policies automatically from templates, organisational context and regulatory requirements.

AI-powered policy generation
Context-specific policies created automatically in seconds.
Multilingual support
Policies in every language you need, at one click.
Version control & approval workflows
A traceable change history with a structured approval process.
Policy management

Automated training management

Integrated training campaigns with progress tracking, automatic reminders and audit-ready records.

Campaign-based training
Audience-specific courses with automatic assignment.
Progress tracking & reporting
A real-time view of training status and compliance rate.
Audit-ready certificates
Automatic documentation of every completed course.
Training management

Supplier risk management

Automated onboarding and continuous assessment of the security posture across your entire supply chain.

Automated onboarding
A structured process for capturing supplier data and security standards.
Continuous risk assessment
Regular review and assessment of supplier compliance.
Supply chain visibility
Full transparency across your entire supply chain.
Supplier management

Incident response & BC/DR

Automated planning for business continuity and disaster recovery plus structured incident response with built-in workflows.

Incident response playbooks
Predefined workflows for different types of incident.
Automated escalation
Intelligent routing to the right stakeholders based on severity.
BC/DR plans & tests
Structured contingency plans with regular test cycles.
Incident response

Audit & task management

Central task management with deadline tracking, escalation and a complete evidence trail for audits.

Automated audit planning
Regular and ad-hoc audits based on your risk profile.
Task management with escalation
Automatic reminders and escalation when a deadline is missed.
Audit trail & evidence collection
Complete documentation of every activity as compliance evidence.
Audit management
Plans

Three plans. One platform.

Modular for one specific use case, Complete for the whole platform, Enterprise for unlimited scale – a clearly defined scope, no hidden extras.

Plan 01
Modular

For one specific use case – supplier risk only, or awareness only, for example. The platform core is always included.

  • Functional modules, freely combined
  • Platform core included – cockpit, audit log, task management
  • Knowledge base, user management & MFA
  • Self-onboarding with guided setup
  • AI chatbot with escalation to the team – response < 48 h
Request advice
Plan 03
Enterprise

For groups and multi-site organisations with high user and asset counts and their own governance requirements.

  • Unlimited users, assets & suppliers
  • Unlimited frameworks & integrations
  • SSO / SAML
  • Priority support by chat & phone – response < 4 h
  • Uptime SLA & dedicated customer success
  • Custom dashboards & corporate branding
  • Individual implementation & workshops
Get in touch

We are happy to discuss all details of prices and terms in person – book a demo now.

Team

Built by practitioners, developed with industrial customers.

Three founders with complementary experience in market, organisation and technology – backed by two business angels bringing capital, entrepreneurial experience and a strong network.

Damian Himmel – co-founder of Compliance Compass, market & growth
Damian Himmel
Market & growth

An experienced business builder focused on sales, partnerships, market development and sustainable company growth.

Philipp Minten – co-founder of Compliance Compass, organisation & compliance
Philipp Minten
Organisation & compliance

An organisational expert with deep experience in operations, HR and culture building as well as digitalisation, compliance and corporate governance.

Daniel Henter – co-founder of Compliance Compass, product & strategy
Daniel Henter
Product & strategy

A technology and innovation leader with broad experience in corporate strategy, cybersecurity, platform architecture and software development.

Dr Stefan Ebener – business angel at Compliance Compass
Dr Stefan Ebener
Business angel

A renowned AI expert, sought-after keynote speaker and industry ambassador with a strong network and high market presence.

Christoph Koch – business angel at Compliance Compass
Christoph Koch
Business angel

An experienced managing director and finance expert with broad expertise in company growth, scaling and leading mid-sized businesses.

Frequently asked questions

Questions? Here are the answers.

Everything you need to know about Compliance Compass.

No. Compliance Compass is a cloud solution that needs no installation and no infrastructure. The onboarding team handles the entire configuration. All you need is a browser and your login details.
Yes, fully. Compliance Compass hosts all data exclusively in Germany (EU). Included: a data processing agreement, encrypted transmission and storage, and regular external security audits.
Pricing is modular: you license individual functional modules or the complete package with all five modules, the controls engine and two frameworks. Setup, updates, support and EU hosting are always included – no hidden extras. Traditional GRC consulting works with six-figure project budgets; with us it is a predictable licence.
Support in English and German: every plan includes an AI chatbot with escalation to our team and a response during business hours – under 48 hours on Modular, under 24 hours on Complete. Enterprise receives priority support by chat and phone with a response under 4 hours plus a dedicated customer success manager.
Yes, absolutely. Start a free 30-day trial with the full feature set – no credit card required. You also receive a personal demo (30 min.) with a live walkthrough of the platform.

More questions? The team is happy to help.

Book a demo now & get your questions answered
Free demo

Ready for NIS2 compliance?

Book a free demo and see how Compliance Compass transforms your GRC processes.

Free 30-day trial – no credit card
Setup & onboarding included
GDPR-compliant – hosting in Germany
Book a free demo
100% GDPR-compliant Your data is used solely to contact you and is not passed on to third parties.