People in a meeting room behind glass walls, blurred against the light

Certificates and compliance

Our standard: quality and compliance. What we recommend to our customers, we practise ourselves.

At 7P, technological excellence and responsible action go together, internally and in our work with customers. Many of them come from highly regulated, security-critical industries. They rely on traceable standards, transparent processes and a compliance culture that is lived every day.

  • ISO 9001
  • ISO/IEC 27001
  • ISAE 3402
  • Member of the Alliance for Cyber Security

Our certifications and standards

With certified management systems, firm control mechanisms and a binding corporate culture, we take responsibility for our customers and for society.

  • ISO 9001

    Certified at location level. For reliable structures and high quality standards.

  • ISO/IEC 27001

    Certified at location level. Our information security management system is based on systematic risk analysis.

  • ISAE 3402

    External auditing firms regularly assess our internal control systems, in each case for specific customer projects and the related services.

Security and compliance in customer projects

Compliance is part of every phase of application lifecycle management (ALM), the entire lifecycle of an application. From initial process consulting through architecture and software design to secure operation and further development, our process models make sure that security and compliance are embedded in every phase. We work with frameworks such as ISO 27001, ISO 9001 and ISAE 3402 and with industry-specific requirements such as DORA, NIS2, BAIT and VAIT.

  1. Analysis and consulting

    We analyse your regulatory and functional requirements and turn them into specific technical and organisational measures.

  2. Compliance by design

    Security, data protection and compliance are built into concept and architecture from the start.

  3. Development and operations

    Whether custom software or system integration: we document in an audit-proof way, manage risks actively and report transparently, for example in accordance with ISAE 3402.

  4. Sustainable integration

    Our managed services keep operations secure and compliant for the long term, flexibly scalable and integrated into your organisation.

Related services: 360° consulting, AI for Enterprise,Managed Services and Security and Compliance.

Hand operating a digital interface with financial charts

Industry knowledge and regulatory expertise

Our teams know highly regulated sectors from many projects. We implement requirements so that they work in practice: in the BAIT-compliant operation of banking software, in DORA-compliant managed services or in secure platforms for digitalisation under the OZG (German Online Access Act) and NIS2.

Internal knowledge management and ongoing training keep our expertise on new requirements up to date: documented, systematic and applied directly in your projects.

Our industries

Information security, Code of Conduct and reporting

How does 7P organise information security and data protection?

With two management systems that are part of our integrated management system. The information security management system (ISMS) is based on systematic risk analysis and an assessment of the protection needs of our company assets. The data protection management system protects personal data and ensures compliance with legal requirements. Quality and business continuity management are also part of it.

How does the management system stay up to date?

Through binding policies, clearly defined roles, awareness measures and internal and external audits. We are also a member of the Alliance for Cyber Security (Allianz für Cyber-Sicherheit), which works for greater digital resilience and a reliable IT security situation in Germany.

What does the Code of Conduct cover?

It is our binding guide for lawful and responsible conduct and applies to all employees and managers at 7P. It provides guidance on legal requirements and on respectful cooperation within the company.

What does 7P expect from business partners and suppliers?

Respect for human rights, fair working conditions and ethical behaviour. These requirements are set out in the Code of Conduct and in more detail in our Supplier Code of Conduct, which is the binding basis of our business relationships.

How can I report a possible violation?

Through our whistleblower portal, confidentially, as an employee or as an external person. Every report is reviewed and handled in a defined procedure. In doing so, we protect personal data and protect whistleblowers against reprisals or discrimination.

What role does sustainability play?

We focus where we can make a real difference: on environmental measures such as energy efficiency and on social issues, above all a conscious approach to diversity and a values-based working culture. This is based on an internal sustainability strategy with clear goals that we review regularly.

More on sustainability at 7P

Noch zu ergänzen: Link zum HinweisgeberportalNoch zu ergänzen: Code of Conduct und Verhaltenskodex für Lieferanten als PDF

Questions about compliance at 7P?

We look forward to talking with you.