CORPORATE POLICY FOR QUALITY MANAGEMENT AND INFORMATION SECURITY

PAT, a company within the Zucchetti Group, has been developing automated, customer-centric applications and solutions for service management and support for private companies and public institutions for over 30 years. Its product portfolio has been expanded to include open-source solutions for configuring bespoke applications for IT governance, asset management and facility management.

As part of its mission (...We invest our experience and technology in serving our clients’ business processes...), PAT emphasises its commitment to pursuing excellence in the services and solutions it offers to clients; to achieve this objective, the company is constantly striving to foster expertise and innovation, with the aim of fully satisfying clients and fostering the professional development of its staff and resources.

PAT’s focus and commitment are therefore directed towards all aspects of corporate quality, the development of its people, information security and business continuity, recognising these as key factors in the company’s success.

PAT is fully aware of its role and responsibilities towards its customers and staff; consequently, for many years it has been committed to the continuous improvement of its performance, undergoing audits by third parties who have recognised and ‘certified’ the quality of its ‘modus operandi’, its commitment to regulatory compliance and its ability to fully meet customers’ requests and expectations.

For this reason, this Integrated Policy serves as a reliable, transparent and effective communication tool, through which PAT informs customers, employees, suppliers and partners about its activities, performance, key aspects, programmes and objectives relating to quality, information security and business continuity.

Furthermore, PAT has been identified by the National Cybersecurity Agency as a NIS2 essential operator, operating in the ‘Digital Infrastructure’ sector as a provider of cloud computing services and in the ‘ICT Service Management’ sector as a provider of managed services. This designation entails the obligation to implement appropriate technical and organisational measures to manage cybersecurity risks, as well as to promptly notify the competent authority of any significant incidents.

 

SCOPE OF APPLICATION

PAT is certified to:

- ISO 9001 for the following activities: “The design, development and implementation of software applications for Enterprise Service Management, Customer Relationship Management, IT Governance, Asset and Facility Management, supported by integrated AI components, together with the provision of professional and support services.”
- ISO 27001, extended to include the ISO 27017 and ISO 27018 guidelines, for the following activities: “Design, development and implementation of software applications, including the provision of professional and support services, such as information systems management services for cloud-based solutions”.

 

PRINCIPLES

The principles that guide PAT in its activities are:

- Meeting customers’ expectations and needs is the cornerstone of PAT’s vision;
- Egaging staff as our most valuable resource, ensuring a safe, healthy and motivating working environment that places the utmost value on each individual’s contribution;
- Compliance with laws, current regulations and contractual clauses;
- Raising staff awareness of the Integrated Management System (QMS and ISMS) in order to achieve the desired results more efficiently;
- Data security and continuity: the security standards ensuring the integrity, availability and confidentiality of customer data are guaranteed by organisational measures and data centres certified to the highest standards;
- Cyber risk management and NIS2 compliance: as a NIS2 essential operator, PAT implements technical and organisational measures proportionate to the risk in order to protect its information and network systems, ensure operational resilience and fulfil its obligations to report significant incidents to ACN’s CSIRT;
- Need-to-know principle: information must be accessible only to those who have a legitimate need for it and the necessary authorisation;
- Qualified Suppliers: ensuring that suppliers provide a high-quality service;
- Continuous improvement: by evaluating past experiences and performance, projects and management systems must be continuously improved;
- Sustainability: PAT is committed to contributing to sustainable development, integrating this commitment into its business model;
- Ethics and integrity: PAT is committed to conducting its business in accordance with the highest ethical standards, not tolerating acts of corruption and operating in compliance with the laws and regulations applicable to projects carried out both in Italy and abroad;
- Organisational Model 231: through its organisational model, PAT is committed to preventing the company from incurring administrative or criminal liability for offences committed by employees or senior management in the interests of the company.

 

OBJECTIVES OF THE INTEGRATED MANAGEMENT SYSTEM

The objectives of the Company Policy within PAT’s Integrated Management System are:

- To strive for the full satisfaction of the needs and expectations of relevant stakeholders;
- To constantly monitor the internal and external environment in which it operates;
- To guarantee its customers the constant availability of personnel, processes and technologies to support the services provided, in accordance with the defined Service Level Agreements (SLAs);
- To comply with applicable laws and regulations, contractual requirements, standards and company procedures;
- To maintain a high standard of product quality;
- To raise suppliers’ awareness of quality, information security and business continuity issues, whilst always requiring compliance with the policies adopted by the Company;
- To ensure business continuity for assets and processes critical to service delivery, minimising the impact on the business in the event of a crisis and ensuring a rapid return to normal operations;
- To use the best available technology in achieving the company’s objectives;
- To protect information and personal data from unauthorised access;
- To minimise the risk of loss and/or unavailability of processed data or unauthorised disclosure, by planning and managing activities to ensure business continuity;
- To protect information assets and personal data within the cloud environment;
- Develop and maintain an Integrated Management System as a tool for achieving objectives, fulfilling commitments and promoting the continuous improvement of business processes;
- Carry out risk analyses and assess vulnerabilities and associated threats in order to identify and implement the necessary corrective and security measures;
- Periodically review the Policy, Objectives, targets and related implementation programmes, as well as the Company Management System, ensuring they are adequately publicised within the organisation;
- Carry out internal audits to ensure compliance with the requirements of the Integrated Management System, taking all necessary corrective actions;
- Comply with the obligations set out in the NIS2 Regulation, as a critical entity identified by ACN, by implementing and maintaining cybersecurity risk management measures proportionate to the level of risk, the size of the organisation and the potential impact of incidents;
- Ensure the timely notification of significant incidents to ACN, in accordance with the deadlines and procedures set out in the NIS Decree and the decisions of the competent authority;
- Ensure the security of the digital supply chain by verifying that suppliers and ICT service providers adopt appropriate security measures consistent with the NIS2 requirements;
- Strengthen the capacity to detect, manage and respond to cyber incidents, including through cooperation with CSIRT Italia and the relevant national authorities;
- Promote a culture of cybersecurity at all levels of the organisation, through structured staff training and awareness programmes on cyber risks and the obligations arising from the NIS2 regulations;
- Promote the implementation, understanding and awareness of the Integrated Management System within the organisation;
- Strengthen information, education and training activities, involving all staff and making them aware of their individual obligations and the importance of their every action in achieving the expected results, as well as their responsibilities;
- Periodically monitor the effectiveness of the Integrated Management System, including through management review

 

The Management, 29 May 2026

UNI EN ISO 9001:2015

 

Pat has successfully passed the ISO 9001:2015 Quality Certification review, securing the issuance of the new certificate!

A certified company is better positioned to strengthen and expand relationships with existing clients and to acquire new ones—both nationally and internationally—thanks to an improved external image.

We’d like to highlight the importance of holding certifications, as they are often required to participate in specific tenders and public procurements. Certifications are a mark of quality, reliability, and competence.

The year-end audit, conducted by the certification body Certiquality, confirmed that the requirements set out by the standard are met, and that PAT has correctly implemented the necessary organizational and operational processes.

The renewal of this certification once again confirms our ability to maintain a high standard of service quality and to consistently and effectively meet customer expectations, while achieving significant improvements in organizational efficiency and the quality of our products and services.

The ISO certification represents an important validation for both the company and our clients. It demonstrates the use of proper professional tools and the compliance of our process management systems with the standards defined by international technical regulations.

Resources, competence, awareness, communication, and documented information are the core principles on which the certification is based.

You can view PAT’s certification here.

UNI EN ISO 27011:2022

 

PAT places strategic importance on the secure handling of information and recognizes the need to develop, maintain, monitor, and continuously improve an Information Security Management System (ISMS) in accordance with the ISO/IEC 27001:2022 standard, as well as guidelines ISO/IEC 27017 and ISO/IEC 27018.

Achieving ISO 27001 certification demonstrates that PAT has implemented an ISMS compliant with international standards, ensuring the confidentiality, integrity, and availability of data, and protecting critical information from both internal and external threats.

Obtaining ISO 27001 certification involves several key steps, including risk assessment, implementation of control measures, internal audits, and an external audit conducted by an accredited certification body.

You can view PAT’s certification issued by the certification body Certiquality here