
Certificates and compliance
Our standard: quality and compliance. What we recommend to our customers, we practise ourselves.
At 7P, technological excellence and responsible action go together, internally and in our work with customers. Many of them come from highly regulated, security-critical industries. They rely on traceable standards, transparent processes and a compliance culture that is lived every day.
- ISO 9001
- ISO/IEC 27001
- ISAE 3402
- Member of the Alliance for Cyber Security
Our certifications and standards
With certified management systems, firm control mechanisms and a binding corporate culture, we take responsibility for our customers and for society.
ISO 9001
Certified at location level. For reliable structures and high quality standards.
ISO/IEC 27001
Certified at location level. Our information security management system is based on systematic risk analysis.
ISAE 3402
External auditing firms regularly assess our internal control systems, in each case for specific customer projects and the related services.
Security and compliance in customer projects
Compliance is part of every phase of application lifecycle management (ALM), the entire lifecycle of an application. From initial process consulting through architecture and software design to secure operation and further development, our process models make sure that security and compliance are embedded in every phase. We work with frameworks such as ISO 27001, ISO 9001 and ISAE 3402 and with industry-specific requirements such as DORA, NIS2, BAIT and VAIT.
Analysis and consulting
We analyse your regulatory and functional requirements and turn them into specific technical and organisational measures.
Compliance by design
Security, data protection and compliance are built into concept and architecture from the start.
Development and operations
Whether custom software or system integration: we document in an audit-proof way, manage risks actively and report transparently, for example in accordance with ISAE 3402.
Sustainable integration
Our managed services keep operations secure and compliant for the long term, flexibly scalable and integrated into your organisation.
Related services: 360° consulting, AI for Enterprise,Managed Services and Security and Compliance.

Industry knowledge and regulatory expertise
Our teams know highly regulated sectors from many projects. We implement requirements so that they work in practice: in the BAIT-compliant operation of banking software, in DORA-compliant managed services or in secure platforms for digitalisation under the OZG (German Online Access Act) and NIS2.
Internal knowledge management and ongoing training keep our expertise on new requirements up to date: documented, systematic and applied directly in your projects.
Our industries
Telecommunications
Test automation, customer experience monitoring and change impact assessment.
Financial Services
IT governance, compliance by design and resilient operating models for regulated financial organisations.
Public sector
Scalable open source software for implementing the OZG and the register modernisation act (RegMoG).
Information security, Code of Conduct and reporting
How does 7P organise information security and data protection?
With two management systems that are part of our integrated management system. The information security management system (ISMS) is based on systematic risk analysis and an assessment of the protection needs of our company assets. The data protection management system protects personal data and ensures compliance with legal requirements. Quality and business continuity management are also part of it.
How does the management system stay up to date?
Through binding policies, clearly defined roles, awareness measures and internal and external audits. We are also a member of the Alliance for Cyber Security (Allianz für Cyber-Sicherheit), which works for greater digital resilience and a reliable IT security situation in Germany.
What does the Code of Conduct cover?
It is our binding guide for lawful and responsible conduct and applies to all employees and managers at 7P. It provides guidance on legal requirements and on respectful cooperation within the company.
What does 7P expect from business partners and suppliers?
Respect for human rights, fair working conditions and ethical behaviour. These requirements are set out in the Code of Conduct and in more detail in our Supplier Code of Conduct, which is the binding basis of our business relationships.
How can I report a possible violation?
Through our whistleblower portal, confidentially, as an employee or as an external person. Every report is reviewed and handled in a defined procedure. In doing so, we protect personal data and protect whistleblowers against reprisals or discrimination.
What role does sustainability play?
We focus where we can make a real difference: on environmental measures such as energy efficiency and on social issues, above all a conscious approach to diversity and a values-based working culture. This is based on an internal sustainability strategy with clear goals that we review regularly.
Questions about compliance at 7P?
We look forward to talking with you.