Integrated Management System Policy

Effective from 24 July 2026

CCLab Kft. and the testing laboratories operating as its independent organisational units, 'CCLab – The Agile Cybersecurity Laboratory' (hereinafter: Laboratory or Laboratories), strive to ensure the long-term satisfaction of their customers (Clients) as a reliable partner.

CCLab Kft. and its testing laboratories are committed to adhering to the professional and ethical standards set out by the EUCC (European Common Criteria) cybersecurity certification scheme. To this end, we apply ethical and security principles in line with the expectations of the QIMA Group and the QIMA CODE OF ETHICS, as well as the provisions set out in the IBSZ00_Information Security Policy. As an integral part of these ethical standards, the management of CCLab Kft. is committed to promoting gender equality, diversity and a discrimination-free working environment. Our key objective is to integrate the principles of gender balance and equal opportunities at all levels of the organisation, which we achieve through the objectives and measures set out in this policy.

The primary task of the Laboratories is to provide testing (assessment) results based on objective evaluation methods to our Clients (Customers). The Laboratories carry out the activities specified in the accreditation certificate, as well as professional support (assistance) services relating to testing (assessment) outside the scope of accreditation. CCLab Kft. and the Laboratories carry out all their tasks whilst bearing in mind the requirements of independence and impartiality, which are maintained at a personal level throughout the projects.

The scope of the Laboratories' technical support activities is strictly limited. Given that the Laboratories are required to carry out conformity assessments in an impartial and independent manner, the scope of professional client support (assistance) activities may extend solely to supporting the preparation of documents necessary for conformity assessment, as defined by the relevant standard or in accordance with the prescribed terminological requirements (e.g. developer documents). In light of the above, when providing technical support, no employee of the Laboratory may, nor may they have previously, been involved in the design, manufacture, commissioning, maintenance or distribution of a product assessed or tested by the Laboratory. The term 'consultancy' referred to in the relevant regulations and marketing materials must therefore be interpreted exclusively in accordance with the details set out above.

Consequently, and in view of the fact that, during the course of professional support activities, all data must be provided by the client, self-review is ruled out as a potential threat to impartiality.

The service standards of CCLab Kft. and the Laboratory comply at all times with the applicable regulations and the requirements of the Supervisory Authorities and Clients (Customers).

As part of our operations, we regularly set objectives relating to quality, information security and the use of artificial intelligence (AI), and we continuously plan for and monitor the achievement of these objectives.

Our Integrated Management System (covering quality, information security, equal opportunities and AI) objectives:

  • our services should meet the requirements agreed in advance with our Customers (Clients),
  • our services are delivered within the timeframe agreed with the Customer (Client) and at an economically optimal cost,
  • the business information of our customers (clients) and any information provided to us must be kept secure,
  • continuous efforts to identify and mitigate circumstances related to climate change,
  • continuous compliance with the regulations applicable to us, and the successful attainment and maintenance of accreditation from an external accreditation body,
  • striving to achieve an average customer satisfaction rating of at least 4.5 out of 5 in our future projects as well,
  • to carry out our work in an impartial, independent and neutral manner, free from external influence (whether commercial, financial or otherwise), and on a strictly professional basis, in the interests of our customers (clients),
  • adherence to the principles of work ethics and ensuring gender equality,
  • ensuring that employees' professional knowledge is up to date and of a high standard
  • cooperating effectively with supervisory bodies and certification authorities, in particular, but not exclusively, for the purposes of the proper implementation of the requirements of the relevant assessment scheme or system, and the monitoring and accreditation of such implementation,
  • the use of AI-based systems in a transparent, ethical and risk-proportionate manner.

In order to achieve the above Integrated Management System objectives, we set out the following measures relating to work ethics and gender equality in the context of the organisation's operations:

  • all employees must place particular emphasis on complying with and monitoring compliance with cybersecurity requirements, and on avoiding breaches, in accordance with the provisions of their employment contract and the Information Security Policy; failure to comply will result in sanctions;
  • In accordance with the QIMA Group Code of Ethics and its awareness training programmes, as well as the provisions of the Information Security Policy, we encourage the reporting of personal security incidents and the use of such reports in cybersecurity awareness programmes,
  • In line with the QIMA Group Code of Ethics and Fair Labour operating policy, we provide dedicated human resources and appropriate expertise to achieve gender equality objectives,
  • we regularly collect gender-disaggregated data on our employees, on the basis of which we prepare an annual report on progress in equal opportunities,
  • we place great emphasis on awareness-raising courses and training in the area of equal opportunities to avoid unconscious gender bias,
  • we strongly support measures that promote work-life balance and the maintenance of an inclusive organisational culture,
  • we ensure gender balance and equal opportunities in recruitment processes, career development, and in leadership and decision-making roles,
  • we apply a zero-tolerance policy towards all forms of gender-based violence and sexual harassment,
  • we integrate gender dimensions – where relevant – into our research, teaching and professional content,
  • we strictly prohibit any form of fraud; therefore, employees are obliged to report any activity or suspicion that is deceptive, aims to gain unauthorised profit or jeopardises the integrity of the certification process,
  • we carry out continuous self-monitoring through internal audits, data analysis, corrective actions and management reviews,
  • where non-conformities are identified, we designate the relevant departments with the appropriate authority to implement corrective measures and improve our procedures,
  • we pay particular attention to the systems and documentation that support our work processes,
  • management is committed to applying leading-edge best practice, as well as to the quality of tests (assessments) carried out for the Customer (Client) and to the accuracy and reliability of the test (assessment) results,
  • management ensures that CCLab Kft. staff are familiar with the principles and procedures of the Integrated Management System and the quality-related documentation, and that they apply the quality policy and related procedures in their work,
  • we ensure that employees receive regular professional training,
  • we work continuously to safeguard information security in order to prevent and avert security incidents (both external and internal) that lead to information leaks through espionage or deliberate disclosure, and to prevent deliberate or accidental errors or damage;
  • we develop plans and procedures to manage any incidents that may occur, taking into account the specific characteristics of the systems to be protected and bearing in mind the requirements of business continuity,
  • we ensure the physical and logical protection of our infrastructure and assets using state-of-the-art technical equipment and skilled professionals,
  • we operate a system based on comprehensive risk assessment, the primary aim of which is to identify and evaluate potential sources of danger and threats. Should risks arise, we take immediate action to minimise or eliminate them,
  • we take measures to prevent risk factors and incidents from occurring,
  • we use state-of-the-art IT solutions to enhance security,
  • we regard familiarisation with, compliance with and enforcement of the relevant legislation, regulations and data protection laws as a top priority,
  • we expect our suppliers and subcontractors to comply with the security guidelines we set out, to maintain their objectivity and impartiality, and to work in an environment that is secure from both a physical and IT perspective,
  • we constantly seek opportunities to introduce more efficient and reliable procedures and tools,
  • we carry out regular audits to ensure that our information security objectives are met and that all relevant instructions and procedures are fully complied with by those concerned,
  • management is committed to continuously developing the collaborative infrastructure and providing state-of-the-art work tools (which facilitate employees' efficient work),
  • management ensures that an organisational structure and organisational processes are established in which individual tasks, powers and responsibilities are clearly defined,
  • management ensures that the Integrated Management System continues to function properly, even when changes to the Integrated Management System are planned and implemented,
  • management draws colleagues' attention to the importance of meeting customer, statutory and other regulatory requirements,
  • management ensures that testing and service provision are carried out impartially, independently and neutrally, free from external influence, and does not allow commercial, financial or other pressures to jeopardise impartiality,
  • the use of AI systems must not compromise the impartiality, independence and professional reliability of testing and conformity assessment activities; they must not, on their own, be used to make assessment decisions in laboratory activities.

The management of CCLab Kft. is committed to ensuring compliance with the CIA (confidentiality, integrity, availability) as follows:

  • Employees working in any organisational unit of CCLab Kft. are obliged to treat as confidential any information obtained during conformity assessment procedures. All parties in a legal relationship with CCLab Kft. must be informed of the scope of data to be treated as confidential, as well as the rules governing confidentiality and the consequences of breaching them.
  • Management shall ensure that employees protect the information and data obtained during conformity assessment procedures against damage, destruction, erasure, alteration and unauthorised access, and shall provide the necessary conditions for this by establishing an appropriate IT infrastructure.
  • CCLab Kft. shall not disclose any information, data or documents to third parties without a lawful court order or an official request from a competent authority relating to CCLab Kft., its employees and/or its clients. Data, information and documents belonging to the client may only be disclosed with the client's written authorisation and within the scope and in the manner specified in that authorisation.
  • All employees are obliged to safeguard any confidential information and trade secrets that come to their knowledge in connection with their employment, both during their employment and after its termination. Furthermore, they are obliged to ensure that such confidential information does not become known to or accessible by any third party.
  • During the course of their work, AI-based systems may only be used in compliance with the confidentiality, integrity and availability requirements set out above.

The Chief Executive Officer of CCLab Kft. declares that he is committed to ensuring that the operations of CCLab – The Agile Cybersecurity Laboratory comply with ISO 9001, ISO/IEC 17025, ISO/IEC TS 23532-1, ISO/IEC 19896-1, ISO/IEC 19896-3, ISO/IEC 27001 and ISO/IEC 42001, as well as the EUCC and the related State-of-the-Art documents. It is also committed to complying with and ensuring compliance with the requirements of these standards, and to the continuous improvement of the effectiveness of the Integrated Management System.

Budapest, 24 July 2026

Ferenc Tamás Molnár
Chief Executive Officer

The QIMA Group’s and Management’s commitment to quality, information security, responsible AI use, and equal opportunities objectives

Related documents

Code of Ethics
open docs
Fair Labour Policy
open docs
Integrált Menedzsment Rendszer Politika
open docs