Mamami's experience.
Turn already solid but informal security practices into an internationally recognized, third-party-verified standard, to satisfy enterprise clients who require it.
ISO 9001
6 months
When two major clients started requiring ISO 27001, knowing how to work securely stopped being enough. It had to be proven, with a recognized, independently verified, non-negotiable standard.
Published with the client's authorization · Certificate verifiable
the challenge
The starting point.
For a software house, data security is never an abstract topic. It's the code you write, the access you manage, the systems you integrate on behalf of people who trust you. Mamami already knew this before certification. It worked securely, complied with regulations, and documented things when needed. But when two major clients began requiring ISO 27001, it became clear that knowing wasn't enough, it had to be demonstrated. Ad hoc documentation and verbal explanations worked, but only up to a point. With increasingly structured clients, the question became inevitable: do you have a certification? And at that point, either you do or you don't.
OUR SOLUTION
What we have done.
✓
Gap analysis of existing security practices, to identify which technical and organizational controls needed strengthening, including areas like security-event monitoring and software testing.
✓
Documentation of processes that already existed in practice but had never been formalized, effective habits built on experience that no one had written down as defined procedures.
✓
Structuring of dedicated working groups and clearly defined responsibilities for standard-specific requirements, such as disaster-recovery simulations.
✓
Audit preparation support throughout the process, working alongside a dedicated project lead on the client side to get the team ready for the certification audit.
It wasn't immediate, but in the end the team understood it wasn't just about getting a certification, it was about working in a more structured and conscious way. That's the difference between a certification you're forced into and one you choose. In the first case, you end up with a document. In the second, something actually changes in how you work every day.
Giorgio Marchetti
CTO @ Mamami
results achieved
What changed after the certificate.
Many more technical and organizational controls were introduced, like a SIEM for security-event monitoring and clearer procedures for daily activities, without slowing down development.
Some clients now ask upfront whether Mamami is certified, and when the answer is yes, the conversation moves straight to the project itself.
Negotiations move faster: clients get to the project's real needs sooner, instead of the company first having to build credibility.
Explaining data protection and access management in detail is no longer necessary. Certification now answers most of those questions on its own, backed by an internationally recognized standard.
read more







