Engineering Group

Engineering Group

Speciality: Infrastructure and Application Penetration Testing

Rome, Italy 11908 employees
[01] About

Italy-based IT services and consulting company with 6,948 employees and $1.7B revenue; specializes in digital transformation, systems integration, and security services including penetration testing and red team assessments; operates globally with over 80 offices across Europe, US, and South America.

Engineering Group is the Digital Transformation Company, leader in Italy and expanding its global footprint, with around 14,000 associates and with over 80 offices spread across Europe, the United States, and South America and global delivery. The Engineering Group, consisting of over 70 companies in 21 countries, has been supporting the continuous evolution of companies and organizations for more than 40 years, thanks to a deep understanding of business processes in all market segments, fully leveraging the opportunities offered by advanced digital technologies and proprietary solutions. It integrates best-of-breed market solutions, managed services, and continues to expand its expertise through M&As and partnerships with leading technology players. The Group strongly invests both in innovation, through its R&I division, and in human capital, with the internal IT & Management Academy. Engineering is a key player in the creation of digital ecosystems that bridge the gap between different markets, while developing composable solutions that ultimately foster a continuous Business transformation. In 2025, Engineering has achieved the Top Employers Italy certification, the result of a significant growth process for the company, which is constantly committed to enhancing HR policies to create a work environment centered on the well-being of people.
[02] Services
Penetration Testing
Vulnerability Assessment
Technical Security Audit
Ethical Hacking
SOC Management
Incident Management
Security Advisory
Red Team Programs
Digital Transformation Services
AI Platforms
Healthcare Solutions
Quantum Computing
Workforce Management
Technology Platforms
[03] Certifications
UNI EN ISO 9001:2015
ISO/IEC 20000-1:2018
ISO/IEC 27001:2022

ISO/IEC 27001:2022


Origin


ISO/IEC 27001 was developed jointly by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC). The standard evolved from the British Standard BS 7799, first published in 1995, with the first ISO/IEC 27001 version released in 2005. The most recent version, ISO/IEC 27001:2022, was published in October 2022. It was created to provide organizations with a systematic framework for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS), addressing the growing need for standardized approaches to protecting sensitive information in an increasingly digital world.


Industry Value


ISO/IEC 27001 is highly valued in the industry because it demonstrates an organization's commitment to information security through independent, third-party certification. The standard provides credibility and competitive advantage, often serving as a prerequisite for doing business with government agencies and security-conscious organizations. It helps companies systematically identify and manage information security risks, ensure regulatory compliance, and build customer trust. For many industries—particularly finance, healthcare, technology, and cloud services—ISO/IEC 27001 certification has become essential for winning contracts, entering new markets, and demonstrating due diligence in protecting client and organizational data.

ISO/IEC 27017:2015
ISO/IEC 27018:2019
ISO 45001:2018
ISO 14001:2015

ISO 14001:2015 Certification


Important Correction: ISO 14001:2015 is not a cybersecurity or IT certification. It is an Environmental Management System (EMS) standard published by the International Organization for Standardization (ISO) in 2015 as a revision to the original 1996 standard.


You may be thinking of ISO/IEC 27001, which is the international standard for Information Security Management Systems (ISMS). Here's the information about that certification:


ISO/IEC 27001 - Information Security


ISO/IEC 27001 was developed jointly by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC). First published in 2005 and revised in 2013 and 2022, it evolved from the British Standard BS 7799. The standard was created to provide organizations with a systematic framework for managing sensitive information and mitigating cybersecurity risks through documented policies, procedures, and controls.


ISO/IEC 27001 certification is highly valued in the industry because it demonstrates an organization's commitment to protecting information assets and maintaining customer trust. Many organizations require their vendors and partners to hold this certification as proof of adequate security practices. It provides competitive advantages in procurement processes, helps meet regulatory compliance requirements, and offers a structured approach to identifying and managing information security risks in an increasingly digital business environment.

NATO AQAP 2110 Ed. D Ver1
NATO AQAP 2210 Ed. A Ver2
ISO 37001:2016
ISO 14064-1:2018
SA 8000:2014
Gender Equality Certification Uni/pdr 125:2022
ISO 9001:2015 & UNI CEI EN ISO/IEC 27001:2024
[05] Notable Clients
  • Bossoni Group
  • ENGIE
  • Rimini Meeting