In the rapidly evolving gaming industry, trust and security play a crucial role. Promatic Group, a leader in gaming machine production and software for online casinos, has once again renewed its ISO 9001 and ISO/IEC 27001 certifications. We spoke with Paweł Dudzik, Head of IT Infrastructure at Promatic, responsible for certification, about the importance of these standards, the certification process, and the benefits for clients.
1. What are ISO certifications and why did Promatic implement them?
Paweł Dudzik: ISO certifications are international standards that define best practices for quality management and information security. ISO 9001 focuses on product and process quality, while ISO/IEC 27001 addresses information protection. In our industry, where system stability and user data security are critical, these certifications are not just prestigious—they are a practical tool ensuring compliance with global standards.
2. How do these two certifications differ, and what do they mean for Promatic?
PD: ISO 9001 guarantees that our products and processes meet the highest quality standards—this applies to both gaming machines and software. ISO/IEC 27001 ensures information security—not only for players’ data but also for casino operators and business partners. This is a significant added value, especially when working with regulated markets and demanding operators.
3. Who conducts the certification and how long does it take?
PD: Certification is performed by independent bodies, in our case IQS CERT, operating under the Polish Centre for Accreditation (PCA) standards. The process can take from several months to a year—first we align our processes with the standard, then undergo an internal audit, and finally an external auditor evaluates our systems. It’s a very detailed process, but the results speak for themselves.
4. How often must ISO certifications be renewed, and what does recertification involve?
PD: Certificates are valid for three years, but we undergo an annual surveillance audit to verify ongoing compliance. Every three years, a more comprehensive recertification audit occurs, reviewing not only conformity with the standards but also whether the company implements improvements and continuously enhances processes.
5. How do you indicate ISO certification on your products?
PD: ISO certifications apply to the company’s management system, not individual products. We do not mark the machines directly, but we provide information in technical documentation, on our website, and in marketing materials. This ensures operators and partners know that our games and technologies meet international standards.
6. Is obtaining and maintaining ISO certification costly?
PD: Certification requires investment—not just financial, but also organizational. It involves implementing procedures, conducting training, and continuously improving processes. On the other hand, lacking certification could mean losing market opportunities, especially since ISO/IEC 27001 is often a prerequisite for collaboration with many gaming operators. So it’s more of an investment in business stability than a cost.
7. What are the tangible benefits of ISO certification for operators and players?
PD: For casino operators, ISO certifications guarantee collaboration with a provider that follows international standards, simplifying compliance and minimizing operational risk. For players, it ensures that our games are stable and secure, supported by verified systems and procedures.
8. How is information security managed under ISO/IEC 27001?
PD: We implement encryption systems, access control procedures, cybersecurity monitoring, and regular penetration testing. This ensures that both operators’ and players’ data are protected to the highest standards.
9. Why do some companies fail ISO audits?
PD: Industry data shows that 20–30% of companies fail their first ISO audit. Common reasons include incomplete process documentation, failure to follow standards in practice, and inadequate quality or information security procedures. At Promatic, we ensure our management systems are fully integrated into the organization—not just “on paper.”
10. Does Promatic plan to pursue additional certifications?
PD: We will continue to maintain and develop ISO certifications, but we are also evaluating other standards that could differentiate us internationally, especially in compliance, cybersecurity, and ESG (Environmental, Social, Governance).
With increasing regulatory requirements, such as the EU CSRD directive, ESG compliance is becoming increasingly important. Gaming clients and operators increasingly expect business partners to adhere to sustainability and social responsibility standards, facilitating global collaboration.
11. Can ISO certifications be used as part of a marketing strategy?
PD: Absolutely! ISO certifications are proof of quality and security, and a strong selling point for casino operators seeking reliable and trusted partners.
“ISO certifications are not just a formality—they are a real market differentiator that builds trust and opens doors to new contracts. Clients expect high standards, and we can confirm this with certified quality and security,” says Piotr Pamięta, Marketing Director at Promatic.
Increasingly, casino operators require ISO 27001 from their suppliers. Certification helps us enter new markets. Combined with the high quality of our games and technology, it strengthens our competitive advantage.
ISO 9001 and ISO/IEC 27001 are not only proof of standard compliance but also a tangible advantage in the gaming industry, enabling collaboration with key operators, enhancing security, and building trust in the Promatic brand.
“ISO is the foundation of a stable gaming business—not just prestige, but real benefits for operators and players,” concludes Piotr Fedak, CEO of Promatic Group.