Compliance of the management system confirmed by certification audit
Valid until 03. August 2028

4. Context of the organization
Compliant
processCentric GmbH demonstrates a clear understanding of the requirements related to environmental protection and information security, the relevant legal, contractual, and other binding obligations, and the market conditions that influence its operations. The scope and structure of the environmental and information security management system comply with the requirements of ISO 14001 and ISO 27001.
|
Chapter 4.1: processCentric GmbH takes into account internal and external issues related to environmental protection and information security | Requirements met |
|
Chapter 4.2: Requirements and expectations of interested parties are determined | Requirements met |
|
Chapter 4.3: processCentric GmbH has defined the scope of the environmental and information security management system | Requirements met |
|
Chapter 4.4: processCentric GmbH has implemented its environmental management system and its ISMS in accordance with the requirements of the standard | Requirements met |

5. Leadership
Compliant
The management of processCentric GmbH is actively committed to environmental protection and information security. It makes key decisions to ensure compliance with relevant legal, contractual, and other binding obligations, as well as to continuously improve environmental and information security performance.
|
Chapter 5.1: Leadership and commitment requirements are met | Requirements met |
|
Chapter 5.2: processCentric GmbH has defined and communicated an environmental and information security policy | Requirements met |
|
Chapter 5.3: Roles and responsibilities for environmental protection and information security are defined and practiced | Requirements met |

6. Planning
Compliant
Environmental and information security objectives, risks, and changes are clearly defined and documented. processCentric GmbH plans orders in a risk-aware and forward-looking manner. This minimizes environmental impacts and reduces security incidents. Customers benefit from sustainable practices and the reliable handling of sensitive information.
|
Chapter 6.1: processCentric GmbH has defined risks for the environment and information security and has taken measures | Requirements met |
|
Chapter 6.2: processCentric GmbH has defined environmental and information security objectives and measures to achieve them | Requirements met |
|
Chapter 6.3: Changes are organized in a structured manner | Requirements met |

7. Support
Compliant
processCentric GmbH ensures that environmental and information security-related tasks are supported by well-trained personnel, appropriate tools, and clear communication. This helps prevent environmental impacts and security incidents, ensures employee competence in handling environmental and information security requirements, and reduces misunderstandings in the implementation of related measures.
|
Chapter 7.1: processCentric GmbH systematically plans resources for environmental and information security management | Requirements met |
|
Chapter 7.2: processCentric GmbH ensures that the necessary competencies for environmental protection and information security are in place | Requirements met |
|
Chapter 7.3: processCentric GmbH creates awareness of environmental protection and information security among employees | Requirements met |
|
Chapter 7.4: processCentric GmbH has clear communication structures regarding environmental protection and information security | Requirements met |
|
Chapter 7.5: processCentric GmbH has securely documented the key foundations of environmental and information security management | Requirements met |

8. Operation
Compliant
processCentric GmbH consistently implements the requirements of environmental and information security management. Employees receive clear instructions for environmentally responsible and secure working practices. Processes are stable, and legal as well as contractual requirements are met. Information security risks are regularly assessed and effectively reduced through targeted measures, while an effective response to environmental emergencies is ensured.
|
Chapter 8.1: processCentric GmbH systematically implements the planning of its environmental and information security management | Requirements met |
|
Chapter 8.2: processCentric GmbH meets the requirements for emergency planning and information security assessment | Requirements met |

9. Performance measurement
Compliant
processCentric GmbH regularly assesses its environmental impacts and identifies potential risks to information security, verifies compliance with relevant environmental and security requirements through internal audits, and summarizes the results in a structured management review. This ensures that environmental and security objectives are achieved, legal and contractual obligations are met, and both ecological performance and protective measures are continuously improved – to the benefit of customers, partners, and the environment.
|
Chapter 9.1: Results are systematically reviewed and analyzed | Requirements met |
|
Chapter 9.2: Regular internal checks and audits ensure consistent quality | Requirements met |
|
Chapter 9.3: processCentric GmbH conducts regular management reviews | Requirements met |

10. Improvement
Compliant
processCentric GmbH embraces the principle of continuous improvement in environmental and information security management by continuously reviewing and purposefully enhancing relevant processes. This allows customers to rely on the responsible use of environmental resources and a high, steadily increasing level of protection for sensitive information.
|
Chapter 10.1: processCentric GmbH ensures continual improvement and further development | Requirements met |
|
Chapter 10.2: processCentric GmbH meets the requirements for the treatment of nonconformities | Requirements met |
|
Chapter 10.3: processCentric GmbH continuously develops the management system | Requirements met |

Annex A, 5
Compliant
processCentric GmbH has implemented comprehensive organizational measures to embed information security within the organization. These include, among others, the introduction and regular review of an information security policy, the clear definition of responsibilities, the implementation of access control procedures, as well as the classification and labeling of information. Furthermore, inventories for information and related assets are maintained, contacts with relevant authorities and stakeholder groups are upheld, and measures for information security in supplier relationships are implemented.

Annex A, 6
Compliant
processCentric GmbH has implemented extensive personnel-related measures to ensure information security. These include security screenings for new employees, the definition of responsibilities in employment contracts, as well as regular training and awareness programs on information security. Furthermore, formalized procedures such as a disciplinary process, clear responsibilities when terminating or changing employment relationships, and binding confidentiality agreements are in place. In addition, rules for secure remote work have been established and a reporting procedure for information security incidents has been introduced.

Annex A, 7
Compliant
processCentric GmbH has implemented comprehensive physical measures to protect information and related assets. These include, among others, secured security perimeters and access controls, the physical monitoring of premises, as well as protective measures against physical and environmental threats. In addition, rules have been established for a tidy working environment, the safe operation and placement of equipment, the protection of assets outside the premises, and the secure management of storage media. Maintenance, cabling, and the secure disposal of equipment and assets are also regulated.

Annex A, 8
Compliant
processCentric GmbH has implemented a wide range of technological measures to ensure information security. These include the protection of end devices, the management of privileged access rights, the restriction of information access, and secure authentication procedures. Furthermore, technical vulnerabilities are systematically managed, data is deleted or encrypted, and logging is performed. These measures are complemented by network and application security, the use of cryptography, and protection against malware.