Certifications

This is how we implement compliance, data protection and security in order to be your trusted partner.

Certifications for business processes and systems

Materna SE’s service offerings enjoy an excellent reputation amongst our customers worldwide thanks to their high quality, which is also confirmed by our quality management system in accordance with ISO 9001. This gives rise to a far-reaching responsibility on our part, both towards our customers and towards our employees and society. The associated responsibilities are treated as an integral part of corporate policy across all areas of Materna SE, from procurement to sales. Our ISO 9001 certification demonstrates our commitment to adhering to strict quality standards in all our products and services.

With the introduction of the environmental, occupational health and safety management system in accordance with DIN EN ISO 14001 and DIN ISO 45001, further conditions have been established to strengthen confidence in Materna’s future amongst customers, employees and suppliers, as well as within the wider community. With ISO 14001 certification, Materna meets recognised requirements for an environmental management system. We adhere to recognised standards in the field of occupational health and safety through ISO 45001.

The ISO/IEC 27001 certificate stands for effective information security management – we take comprehensive measures to ensure the confidentiality, integrity and availability of information.

Information Security

ISMS

Information security, implemented in the form of an Information Security Management System (ISMS), forms the central component in protecting the company’s information assets. This explicitly includes relationships with external stakeholders such as customers, suppliers and other business partners. In an era of ever-increasing cyber threats, this issue is a constant concern at management level. Our information security policy reflects this through the signature of the Executive Board. The continuous development of the ISMS is also driven by EU regulations (GDPR, CRA, NIS2, DORA, etc.). Information security is therefore an important part of compliance.

All staff members receive regular training and awareness-raising on information security issues.

ISO/IEC 27001:2022

We are certified to the internationally recognised ISO 27001 standard.

Statement of Applicability (SoA)

The Statement of Applicability (SoA) is an internal document which we make available to third parties only upon proof of a legitimate interest. With regard to the measures set out in Annex A of ISO 27001, there are no exclusions within our organisation.

NIS 2

Through our certification to ISO/IEC 27001:2022, we also meet the requirements of NIS 2 (Directive (EU) 2022/2555), the Directive on measures for a high common level of cybersecurity across the Union.

DORA

The same applies to the requirements of DORA (REGULATION (EU) 2022/2554), the Digital Operational Resilience Act, in the event that we are a critical or non-critical service provider to a DORA-regulated financial institution.

C5

In addition, we hold a Type 2 C5 certificate (Cloud Computing Compliance Criteria Catalogue) for the BMC Helix German Regulated Cloud (GrC) service, which we make available upon request to interested parties with a legitimate interest. Please contact your sales representative at Materna for further details.

TISAX

The ENX Association, on behalf of the VDA, supports the mutual recognition of information security assessments in the automotive industry through TISAX (Trusted Information Security Assessment Exchange). TISAX assessments are carried out by TISAX assessment service providers, who demonstrate their qualifications at regular intervals. TISAX and TISAX assessment results are not intended for the general public. At Materna Information & Communications SE, we place great value on the confidentiality, availability and integrity of information. We have implemented comprehensive measures to protect sensitive information. We therefore adhere to the information security questionnaire of the German Association of the Automotive Industry (VDA ISA). The audit was carried out by an audit service provider, in this case the TISAX audit service provider TÜV Nord. The results are available exclusively via the ENX Portal: TISAX Assessment Results · ENX Portal.

PCI DSS

We are also certified to PCI DSS (Payment Card Industry Data Security Standard). PCI DSS is a security standard set by the credit card industry. Compliance with this standard is required of all companies that handle credit card payments and data.”

Process quality

The continuous improvement of all processes within our group of companies is an integral part of our corporate philosophy.

Quality Manager: Jürgen Kalmbach (acting)
Telephone: +49 711 28471 125
Email: [email protected]

Environmental protection

As a family-owned group of companies, Materna takes long-term considerations into account in its business development. Sustainability-related issues are addressed within the framework of defined processes and measures.

It therefore stands to reason that Materna has introduced an environmental management system, is certified to the internationally recognised ISO 14001 standard, and adheres to the globally recognised requirements for an environmental management system.

The aim of the environmental management system is to systematically identify internal and external environmental impacts and to continuously reduce the resulting environmental impact.

The measures required to achieve this relate to energy use, paper and water consumption, and the consistent reduction of our CO₂ emissions.

All staff members are regularly made aware of environmental protection issues.

Environmental Officer: Pauline Theek
Telephone: +49 173 6703450
Email: [email protected]

Health and Safety at Work

Occupational health and safety is a key prerequisite for healthy, motivated and creative staff, as well as for our company’s competitiveness. We are therefore committed to promoting, supporting and further developing systematic and consistent prevention measures in the field of occupational health and safety, as well as the human-centred design of workplaces.

It was therefore only natural to seek certification to the internationally recognised ISO 45001 standard.

The aim of this management system is to identify and assess work-related risks and to derive appropriate preventive measures. This includes, in particular, the further development of measures to create safe and healthy working conditions. Certification is based on an internationally recognised standard.

Occupational Health and Safety Officer: Tanja Dirven
Telephone: +49 231 5599 5012
Email: [email protected]

Occupational Health and Safety Officer for Occupational Medicine: Sora Kim
Telephone: +49 231 5599 8332
Email: [email protected]