Certifications

This is how we implement compliance, data protection and security in order to be your trusted partner.

Certifications for company processes and systems

Materna SE's service products enjoy an excellent reputation among our customers worldwide due to their high quality, which is also confirmed by our quality management system in accordance with ISO9001. This gives us a far-reaching responsibility towards our customers, our employees and society. The associated tasks are recognised as an integral part of corporate policy in all areas at Materna SE, from procurement to sales. ISO 9001 certification demonstrates our commitment to maintaining strict quality standards in all products and services.

With the introduction of the environmental, occupational health and safety management system in accordance with DIN EN ISO 14001 and DIN ISO 45001, further conditions have been created to strengthen the trust of customers, employees and suppliers as well as the social environment in Materna for the future. With ISO 14001 certification, we are signalling that environmentally friendly practices are firmly anchored in our corporate culture. With ISO 45001, we are committed to the highest standards in the area of occupational safety.

The ISO/IEC 27001 certificate stands for effective information security management - we take comprehensive measures to ensure the confidentiality, integrity and availability of information.

Information security

ISMS

Information security, implemented in the form of an information security management system (ISMS), is the central component for protecting the company's information assets. This explicitly includes relationships with stakeholders outside the company, such as customers, suppliers, and other business partners. In times of ever-increasing threats from cyberspace, the issue is also constantly present at management level. Our information security guideline expresses this through the signature of the Executive Board. Continuous further development of the ISMS also results from EU regulations (GDPR, CRA, NIS2, DORA, etc.). Information security is therefore an important part of compliance.

All employees receive regular training and awareness-raising on information security issues.

ISO/IEC 27001:2022

We are certified according to the internationally recognized ISO 27001 standard.

Statement of Applicability (SoA)

The Statement of Applicability (SoA) is an internal document that we only make available to third parties if they can demonstrate a legitimate interest. With regard to the measures listed in Annex A of ISO 27001, there are no exclusions in our company.

NIS 2

Our certification according to ISO/IEC 27001:2022 also covers the requirements of NIS 2 (Directive (EU) 2022/2555), Directive on measures for a high common level of cybersecurity across the Union.

DORA

The same applies to the requirements of DORA (REGULATION (EU) 2022/2554), the Digital Operational Resilience Act, in the event that we are a critical or non-critical service provider to a DORA-regulated financial institution.

C5

In addition, we have a Type 2 C5 attestation (Cloud Computing Compliance Criteria Catalogue) for the BMC Helix German regulated Cloud (GrC) service, valid until January 31, 2025, which we make available to interested parties with a legitimate interest upon request. Please contact your sales representative at Materna for more information.

TISAX

The ENX Association supports the joint acceptance of information security assessments in the automotive industry with TISAX (Trusted Information Security Assessment Exchange) on behalf of the VDA. TISAX assessments are carried out by TISAX audit service providers who prove their qualifications at regular intervals. TISAX and TISAX audit results are not intended for the general public. For Materna Information & Communications SE, the confidentiality, availability, and integrity of information are of great importance. We have taken extensive measures to protect sensitive information. That is why we follow the information security questionnaire of the German Association of the Automotive Industry (VDA ISA). The audit was carried out by an audit service provider, in this case the TISAX audit service provider TÜV Nord. The result is available exclusively via the ENX portal: TISAX Assessment Results · ENX Portal.

PCI DSS

We are also certified according to PCI DSS (Payment Card Industry Data Security Standard). PCI DSS is a security standard for the credit card industry. Compliance with this standard is required of all companies that handle credit card payments and data.

Process quality

The continuous improvement of all processes in our group of companies is an integral part of our corporate philosophy.

Quality Officer: Jürgen Kalmbach (act.)
Phone: +49 711 28471 125
Email: [email protected]

Environmental protection

As a family-owned group of companies, the basic principle of sustainability is deeply rooted and one of our most important corporate values. Thinking in terms of generations rather than quarters characterises family businesses like ours. Materna recognises this social responsibility and actively and gladly accepts it.

It is therefore only natural that Materna has also introduced an environmental management system and is also certified according to the internationally recognised ISO14001 standard and is oriented towards the globally recognised requirements for an environmental management system.

The aim of the environmental management system is to systematically record internal and external environmental influences and to continuously reduce the resulting environmental impact.

The measures required for this are effective in the areas of energy, paper and water consumption as well as the consistent reduction of our CO2 emissions.

All employees are regularly sensitised to environmental protection issues.

Environmental Officer: Pauline Theek
Phone: +49 173 6703450
Email: [email protected]

Occupational health and safety

Economic activity and organisation is an essential guiding principle for all employees and can also be associated with health risks for everyone involved.

Occupational health and safety is an important prerequisite for healthy, motivated and creative employees and the competitiveness of our company. We are therefore committed to promoting, supporting and further developing systematic and consistent prevention in occupational health and safety and the humane design of workplaces.

It was therefore only logical for us to be certified in accordance with the internationally recognised ISO45001 standard.

Occupational Health and Safety Officer: Tanja Dirven
Phone: +49 231 5599 5012
Email: [email protected]

Occupational health and safety officer for occupational medicine: Sora Kim
Phone: +49 231 5599 8332
Email: [email protected]