Cy4Gate S.p.A.

Italy|Cyber Intelligence & Cybersecurity|FY2025|Auditor: KPMG S.p.A.|View original report →

Sustainability statement, in full

The complete text of Cy4Gate S.p.A.’s FY2025 sustainability statement is held here – 95 pages, captured from the published report. Every disclosure below also links to its own passage.

ESRS 2 – General Disclosures

GOV-1The role of the administrative, management and supervisory bodies
Reported

The role of the administrative, management and supervisory bodies

Reference: pages 6-9.

The Board of Directors of CY4Gate S.p.A. has nine members: "two hold executive positions, while seven are non-executive directors, three of whom meet the independence requirements" (page 6). No board members represent employees or other workers. Gender composition: 3 of 9 board members are female (33%), consistent across the Board of Auditors and Supervisory Board (33% female, page 9).

An internal Control, Risk and Sustainability Committee (CCRS) has been established "with advisory and proposal functions toward the Board of Directors on sustainability matters" (page 6), covering materiality outcomes, the sustainability plan, ESG reporting, and consultant/function meetings during the year.

Board appointment follows list voting: shareholders holding at least 5% of share capital, individually or jointly, may submit lists (page 6).

GOV-2Information provided to and sustainability matters addressed by the undertaking's administrative, management and supervisory bodies
Reported

Information provided to and sustainability matters addressed by the administrative, management and supervisory bodies

Reference: page 10.

The administrative, management and control bodies "receive regular and updated information on relevant impacts, risks, and opportunities, on the implementation of due diligence procedures, and on the results and effectiveness of the policies, actions, metrics, and objectives adopted to address them" (page 10), sourced from Senior Management, control functions (Risk Management, Compliance, Internal Audit) and external experts. Strategic sustainability information reaches the Board at least annually, at approval of the sustainability report.

During 2025 the CCRS "was informed of the outcome of the double materiality assessment, which it endorsed, and of the development of the sustainability plan 2026-2030" (page 10), and separately discussed anti-corruption/anti-money-laundering updates and the ESG reporting project.

GOV-2(was GOV-3)Integration of sustainability-related performance in incentive schemes
Reported

Integration of sustainability-related performance in incentive schemes

Reference: page 11.

A three-year Stock Grant Plan 2023-2025 (renewal scheduled April 2026) applies to Parent Company executives and certain subsidiary executives, excluding XTN. It carries an "ESG target" tied to obtaining and maintaining Gender Equality Certification at CY4Gate S.p.A. (obtained 2023, renewed 2024/2025, extended to RCS in 2024) (page 11).

For the 2026-2030 update, a new ESG target is planned: 40% of CY4Gate's qualified suppliers assessed against ESG criteria or adhering to the ESG policy by 2026. "The Group does not apply climate-related incentives in the remuneration of members of the administrative, management and supervisory bodies" (page 11). Achievement of the Annual ESG Target grants beneficiaries rights equal to 5% of total rights granted per annual cycle.

GOV-3(was GOV-4)Statement on due diligence
Reported

Statement on due diligence

Reference: page 11.

Due diligence is embedded via the Code of Ethics, the Board-approved Sustainability Plan, and supplier ESG-policy signature and monitoring, "in line with the United Nations Guiding Principles on Business and Human Rights and the OECD Guidelines for Multinational Enterprises" (page 11). The Group runs an annual impact materiality assessment covering sectoral, geographic, organizational, business-model and value-chain context, with employee, customer, supplier, and shareholder involvement.

No single-table cross-reference of the due diligence process steps to specific report sections is given at GOV-4 itself, but an equivalent mapping (governance/strategy integration, stakeholder engagement, impact identification, action, and monitoring) appears under IRO-1 (page 21), naming ESRS 2 GOV-1/2/3, SBM-2, SBM-3, IRO-1, MDR-A, E1-1, E1-3, S1-3, S1-4, G1-3, G1-4, MDR-M, MDR-T, E1-4/9, S1-5/17 and G1-4/6.

GOV-4(was GOV-5)Risk management and internal controls over sustainability reporting
Reported

Risk management and internal controls over sustainability reporting

Reference: pages 12-13.

The Group operates four controls over the Sustainability Statement: "Control 1 - Timetable... Control 2 - Information flows... Control 3 - Review of consolidated ESRS schedules... Control 4 - Review of Sustainability Statement" (page 12), owned primarily by the Head of Group Accounting, the CFO and the CEO, with business-manager sign-off on data integrity, estimate accuracy, value-chain data availability and timeliness.

Value-chain data is flagged as "the main risk, as it does not fall under the direct control of The Group" (page 12), mitigated through a defined collection method and supplier engagement, plus ESG questions added to supplier registration forms. A centralized repository documents sustainability risks and controls; the double materiality process itself was reviewed "both by the Head of Group Accounting and subsequently by the audit firm" (page 13).

SBM-1Strategy, business model and value chain
Reported

Strategy, business model and value chain

Reference: pages 14-15, 4.

CY4Gate Group is "specialized in the design, development and production of technologies, products, systems and services... capable of meeting the most stringent and modern 'Cyber Intelligence & Cyber Security' requirements" for armed forces, law enforcement and companies (page 1). Group revenue for FY2025 was EUR 101.5 million, with own workforce headcount of 541 (470 Italy, 71 abroad) (page 14-15). Significant product/service groups exceeding 10% of turnover: forensic products, decision intelligence, and cybersecurity solutions; by business line, Decision Intelligence was 44.10% of revenue, Forensic Intelligence 36.43%, Cyber Security 19.48% in 2025 (page 14).

"The Group does not operate in the fossil fuels sector, nor in the production of chemicals, controversial weapons, or the cultivation or production of tobacco" (page 15) - consistent with the Appendix B cross-reference table marking these engagement datapoints "N.A." (page 33). No taxonomy-aligned turnover, capex or opex (0%, page 42-43 per Taxonomy tables).

SBM-2Interests and views of stakeholders
Reported

Interests and views of stakeholders

Reference: pages 21-23.

Stakeholder clusters: "Employees; Top and middle management; Shareholders/Partners; Corporate bodies; Customers; Suppliers; Credit institutions" plus a residual "other" cluster (rating agencies, associations, investment banks, research centers, communities, public institutions, media, universities) (page 21). Engagement channels span shareholder/board meetings, periodic reports, the website, events, and informal channels (newsletters, customer meetings, supplier relations, institutional contacts) (page 22).

Engagement fed the DMA through benchmark analysis, sector/international documentation review, and a questionnaire capturing both inside-out (impact) and outside-in (risk/opportunity) perspectives, the latter from internal top/middle management (page 21). "The stakeholder engagement process validated current strategic choices... although no areas requiring substantial changes to the strategy or business model emerged" (page 23).

SBM-3Material impacts, risks and opportunities and their interaction with strategy and business model
Reported

Material impacts, risks and opportunities and their interaction with strategy and business model

Reference: pages 23-27.

The DMA identified material IROs across five topics: E1 Climate Change, S1 Own workforce, S3 Affected communities, S4 Consumers and end-users, and G1 Business conduct (page 4, page 24-26 IRO tables). Reconciling to the granular row count: E1 5 rows (1 risk, 3 negative impacts, 1 positive impact), S1 16 rows, S3 8 rows, S4 8 rows, G1 7 rows = 44 total (pages 24-27).

The company states explicitly: "the refinement of the assessment methodology... led to the identification of new material IROs, increasing from 18 material impacts identified in 2024 to 25 material impacts in 2025, and from 13 risks and opportunities in 2024 to 19 in 2025" (page 27) - 25+19=44, reconciling exactly with the row count above. "There are no impacts, risks, or opportunities subject to entity-specific disclosures beyond the disclosure requirements provided for by the ESRS" (page 27).

IRO-1Description of the processes to identify and assess material impacts, risks and opportunities
Reported

Description of the processes to identify and assess material impacts, risks and opportunities

Reference: pages 28-31.

The DMA separates impact materiality (severity x likelihood, scale 1-5, minimum-relevance threshold at scores 1-2 up to very-high at 17-25; topics scoring above the threshold are material) from financial materiality (magnitude x likelihood, material at a relevance score of 12 or above) (pages 30-31). "The list of impacts considered was developed with reference to the guidance contained in RA16 of ESRS 1" (page 28).

For 2025 the methodology moved from a single joint severity/likelihood judgment (used in 2024) to separately scored scale, scope, irremediability and likelihood (page 29), and financial materiality assessment was extended to external stakeholders including shareholders, credit institutions and investment banks (page 30). The DMA "was conducted from October 2025 and concluded in December 2025" (page 50, cross-referenced from E1.SBM-3).

IRO-2Disclosure requirements in ESRS covered by the undertaking's sustainability statement
Reported

Disclosure requirements in ESRS covered by the undertaking's sustainability statement

Reference: pages 4-5, 32-36.

Cy4Gate's IRO-2 section itself (page 32/35) is a brief narrative statement rather than a line-item concordance of all disclosure requirements: "The relevant information is disclosed in a transparent and accessible manner through this document, which contains: the description of the material issues, relevant policies, objectives and metrics, [and] the strategies and actions taken" (page 35). No per-DR reported/omitted table (content index) is printed - classification of the 84 keys in this file was made from the explicit material-topics list, the ESRS 1 Appendix C phase-in omissions table, section headings actually present in the statement, and the Appendix B EU-legislation cross-reference table's "Not material" tags, not from an itemized concordance.

Material topics per the DMA: "E1: Climate Change; S1: Own workforce; S3: Affected communities; S4: Consumers and end users; G1: Business Conduct" (page 4). Under Appendix C of ESRS 1, with a workforce under 750, the Group omits for FY2025: SBM-1 (revenue by ESRS sector), E1-6 (Scope 3), E1-9 (all information), S1-7, S1-12 and part of S1-14 (all information), and S3 and S4 in full (page 4).

E1 – Climate Change

E1-1Transition plan for climate change mitigation
Reported

Transition plan for climate change mitigation

Reference: page 50.

"Currently, a transition plan for climate change mitigation has not been adopted, as the scope for direct intervention on consumption, conditioned by the use of leased properties, is limited" (page 50). Within the 2026-2030 Sustainability Plan the Group has set targets to reduce direct and indirect CO2 emissions below 10 tCO2/EUR million location-based (<13 market-based) by 2026, and below 9/12 respectively by 2030, plus energy consumption below 18 MWh/EUR million by 2026 and 16 by 2030 (page 50).

Planned levers include: switching Scope 2 electricity to 100% renewable Guarantee-of-Origin contracts, rescheduling smart-working days at temperature peaks, server/data-centre energy optimisation, and favouring fully-electric or plug-in vehicles on new leasing contracts for Scope 1 (page 50). No transition-plan investment figures, GHG-neutrality target year, or fossil-fuel exclusion status are given.

E1-2(was covered under ESRS 2 IRO-1)Identification of climate-related risks and scenario analysis
Reported

Identification of climate-related risks and scenario analysis

Back-filled from ESRS 2 SBM-3/IRO-1 within the E1 chapter (E1.SBM-3, E1.IRO-1), where this content is disclosed in the FY2025 report (pages 50-51). This disclosure requirement did not exist under the 2023 ESRS the report was prepared against.

Risk classification (paragraph 15): the DMA identifies a physical risk - extreme weather damage to digital infrastructure, "not assessed as material" but tracked (page 50) - and does not report a material transition risk; "the Group has not screened assets and business activities to determine whether they may be exposed to climate-related transition events" (page 51).

Methodology (paragraph 16): physical risk is assessed "during the risk assessment conducted under ISO 27001," following the ATR Model (identification, analysis, treatment, monitoring), concentrated on Data Centers/Server Farms exposure to earthquakes, floods, fires and weather events (page 51).

Scenario analysis (paragraph 17): explicitly not performed - "the identification of transition events and the assessment of exposure and sensitivity have not been based on high-emission climate scenario analyses, and no climate assumptions are included in the financial statements" (page 51). Per CLAUDE.md, absence of item 17 detail is not a gap where no scenario analysis was used.

E1-3(was covered under ESRS 2 SBM-3)Resilience in relation to climate change
Reported

Resilience in relation to climate change

Back-filled from ESRS 2 SBM-3 within the E1 chapter (E1.SBM-3), where this content is disclosed in the FY2025 report (page 50). This disclosure requirement did not exist under the 2023 ESRS the report was prepared against.

No formal ESRS-defined resilience analysis is described. The company states qualitatively that "the Group's business model, current assets, and operating sites present an overall low level of exposure to climate risks, demonstrating a high degree of resilience" (page 50), and that "the majority of identified impacts and risks do not directly influence the business model or corporate strategy in the short, medium, or long term" (page 50).

Adaptive capacity evidence: infrastructure security measures (backup generators, data-centre hardening) to preserve service continuity, and "Cy4gate and all companies controlled by Cy4gate have all-risks property insurance coverage extended to catastrophic risks, covering both buildings and movable assets, including additional costs" (page 51). No uncertainty areas or financial-flexibility analysis under paragraph 19(b)/(c) are separately quantified.

E1-4(was E1-2)Policies related to climate change mitigation and adaptation
Reported

Policies related to climate change mitigation and adaptation

Reference: page 51.

Environmental protection is stated as "one of the general ethical principles guiding the Group's conduct," embedded in the Code of Ethics as "a formal and strategic commitment that goes beyond mere regulatory compliance" (page 51). Within the 2025 update of the MOG 231/2001, CY4Gate adopted a procedure covering identification of parties within the environmental system, general environmental protection measures, phases/records, and information flows to the Supervisory Body.

RCS additionally holds an integrated quality/environment/health/safety policy, with its Environmental Management System certified to UNI EN ISO 14001, renewed in 2025 (page 51). No named policy owner or GHG-neutrality/1.5C commitment is stated at policy level.

E1-5(was E1-3)Actions and resources in relation to climate change policies
Reported

Actions and resources in relation to climate change policies

Reference: pages 51-52.

2025 actions: expanded GHG/energy measurement using directly-measured rather than estimated data; ISO 14001 certification maintained for RCS; adoption of Protocol PT6 "Occupational Health and Safety Management and Environmental Protection" in the 31/07/2025 MOG 231/2001 update; periodic climate risk assessment under ISO 27001; participation in "Mi illumino di meno" (21/02/2025); and support for "100 trees planted in the Treedom forest, contributing to a reduction of 17 tons of CO2" (page 52).

"Although the Group has not yet defined specific consumption and emission reduction targets," the 2026-2030 Sustainability Plan sets a 2026/2030 target of not exceeding sector-average emissions and energy intensity per revenue, intended to support a transition-plan evaluation by 2030 (page 52). No resourcing (budget/FTE) figures are quantified for these actions.

E1-6(was E1-4)Targets related to climate change mitigation and adaptation
Reported

Targets related to climate change mitigation and adaptation

Reference: pages 52-53.

Two quantified targets from a 2025 baseline: (1) Mitigation - direct+indirect CO2 emissions per EUR million revenue, baseline 10.12 tCO2/EUR million location-based / 13.97 market-based, target <10/<13 by 2026 and <9/<12 by 2030; (2) Energy - consumption per EUR million revenue, baseline 18.84 MWh/EUR million, target <18 by 2026 and <16 by 2030 (page 52-53).

Both targets are tied to named actions (develop an emissions monitoring plan; develop an energy consumption monitoring plan). No absolute (non-intensity) emissions target, GHG-neutrality year, or third-party validation (e.g. SBTi) is disclosed, and no Scope 3 target is given, consistent with the Scope 3 phase-in omission at E1-6.

E1-7(was E1-5)Energy consumption and mix
Reported

Energy consumption and mix

Reference: page 53.

FY2025 total energy consumption related to own operations: 4,166.91 MWh (down from 7,223.23 MWh in 2024), of which 4,118.85 MWh from fossil sources (98.85%, down from 99.71%) and 48.06 MWh from renewable sources (1.15%, up from 0.29%) (page 53). No nuclear-source consumption. "Energy from renewable sources is represented by guarantees of origin certificates. The Group does not produce energy" (page 53).

Consumption is "calculated on the basis of measured and estimated values," with estimates for smaller entities (e.g. XTN) apportioned via a CY4GATE employee-count proportionality coefficient (page 53). No breakdown by high-climate-impact-sector activity is given (none applies).

E1-8(was E1-6)Gross Scopes 1, 2, 3 and Total GHG emissions
Reported

Gross Scopes 1, 2, 3 and Total GHG emissions

Reference: pages 54-55.

FY2025 Scope 1 (gross): 633.91 tCO2e (2024: 1,068.99). Scope 2 location-based: 392.76 tCO2e; market-based: 784.91 tCO2e (2024: 437.74 / 837.18). Combined Scope 1+2 location-based: 1,026.68 tCO2e; market-based: 1,418.82 tCO2e (2024: 1,506.43 / 1,905.87) (page 54). Emissions intensity: location-based 10.11 tCO2/EUR million and market-based 13.97 tCO2/EUR million in 2025, down from 20.06 and 25.37 in 2024 (page 55).

"33% of total energy, or 100% for Tykelab and DARS, comes from renewable sources, with guarantees of origin certificates" (page 55). No biogenic CO2 emissions were identified. Scope 3 GHG emissions are not disclosed: the phase-in omissions table (page 4) lists "Gross Scopes 1, 2, 3 and Total GHG emissions - Scope 3 GHG emission" as an Appendix C omission for the Group's under-750-employee workforce.

E1-9(was E1-7)GHG removals and GHG mitigation projects financed through carbon credits
Reported

GHG removals and GHG mitigation projects financed through carbon credits

Reference: page 56.

Nil return, stated directly: "The Group does not use carbon credits or greenhouse gas removal and storage activities" (page 56). No GHG removal projects, carbon-credit purchases or cancellations, or beyond-value-chain mitigation are reported, consistent with the absence of a formal transition plan and the "gross" nature of the emissions figures at E1-6.

E1-10(was E1-8)Internal carbon pricing
Reported

Internal carbon pricing

Reference: page 56.

Nil return, stated directly: "The Group does not use internal carbon pricing mechanisms" (page 56). No shadow price, internal carbon fee, or scope of application is disclosed, since none is in use.

E1-11(was E1-9)Anticipated financial effects from material physical and transition risks and potential climate-related opportunities
Omitted

S1 – Own Workforce

S1-1Policies related to own workforce
Reported

The Group's policies

Reference: pages 57-58.

Named policies: work-life balance (smart working, 8 days/month remote, 12 for new mothers in year one), adequate wages ("Global Grading" benchmark via Willis Towers Watson), gender equality (certification at CY4Gate since 2023, RCS since 2024, both renewed 2025), and occupational health and safety, aligned with "Legislative Decree No. 81/2008" and UNI-INAIL guidelines (pages 57-58). Policy owners are named as the CEO and HR Director; policies apply to all employees in Italy, Spain and France.

Explicit gaps are stated: "the Group has not formalized specific policies explicitly addressing human trafficking, forced or compulsory labor, and child labor," though these are "not considered relevant for the Group," and "the Group does not have formalized policies explicitly addressing the grounds of discrimination," beyond a specific gender-identity policy (page 58).

S1-2Processes for engaging with own workforce and workers' representatives about impacts
Reported

Processes for engaging with own workforce and workers' representatives about impacts

Reference: page 58.

"At present, the Group does not have a formalized written procedure; however, it is committed to actively listening to its own workforce through regular consultations and structured dialogue" via site meetings and company-level discussions (page 58). Formalisation "had been planned... by 2025" but, "following regulatory developments and emerging priorities of the Group, the implementation will be assessed in future reporting periods" (page 58) - the gap is stated directly rather than left unexplained.

S1-2(was S1-3)Processes to remediate negative impacts and channels for own workforce to raise concerns
Reported

Processes to remediate negative impacts and channels for own workforce to raise concerns

Reference: page 58.

The Group operates "fully anonymous reporting channels that allow employees to report any type of issue," analysed to determine remediation actions, with a follow-up verification step once a cause is removed (page 58). Reports route through a whistleblowing platform and/or "an impartial and specifically trained person/function," or the Chair of the Supervisory Body (OdV). "The Group has adopted and applies a procedure for the protection of whistleblowers" (page 58).

S1-3(was S1-4)Taking action on material impacts on own workforce
Reported

Taking action on material impacts on own workforce

Reference: pages 58-59.

Three named 2025 actions: a training plan built from a prior needs assessment (short term); a smart-working policy giving "at least 2 days of smart working per week" (short term); and Gender Equality Certification, obtained 2023-2024 and renewed in 2025 for the Group's main companies (short, medium and long term) (pages 58-59). No resourcing (budget/FTE) figures accompany these actions, and no effectiveness metric is attached at S1-4 itself (tracked separately at S1-13 to S1-17).

S1-4(was S1-5)Targets related to own workforce
Reported

Targets related to own workforce

Reference: page 59.

Three targets: (1) Gender equality (PdR 125) - maintain Gender Equality Certification for CY4Gate and RCS over the next three years, monitored via internal audits; (2) Skills development - promote specialised technical-skills training via collaboration with universities and public institutions; (3) Work-life balance - maintain the flexible smart-working policy, "monitored... on a semi-annual basis, based on attendance evaluation" (page 59). Employees were involved in target-setting through training, email communications and surveys. No numeric target level or end-date is set beyond the certification/policy continuation itself.

S1-5(was S1-6)Characteristics of the undertaking's employees
Reported

Characteristics of the undertaking's employees

Reference: pages 59-60.

Headcount at 31 December 2025: 541 total (448 men, 93 women; 2024: 552, 456 men, 96 women) (page 59). By country, only Italy meets the 50-employee/10% reporting threshold: 470 employees in 2025 (485 in 2024); France and Spain are below threshold and not separately shown (page 59-60). By contract type (2025): 534 permanent, 7 fixed-term; 519 full-time, 22 part-time (page 60). "During 2025, the number of employees (headcount) who left the Group amounted to 74... The Group's turnover rate is equal to 13.7%" (page 60).

S1-6(was S1-7)Characteristics of non-employee workers
Omitted
S1-7(was S1-8)Collective bargaining coverage and social dialogue
Reported

Collective bargaining coverage and social dialogue

Reference: page 61.

"100% of the Group's employees are covered by collective labor agreements" for the reportable population (Italy, meeting the country threshold); coverage is shown as 80-100% with a 100% rate specifically stated (page 61). Workplace representation is reported as 0% - "The Group has not entered into agreements with its employees for representation by a European Works Council (EWC)... or a Works Council of a European Cooperative Society (SCE)" (page 61).

S1-8(was S1-9)Diversity metrics
Reported

Diversity metrics

Reference: page 62.

Top Management gender split (executives reporting directly to the CEO), 2025: 21 male (84%), 4 female (16%) of 25 total, versus 20/80% male and 5/20% female in 2024 (page 62). Age-group breakdown of the workforce, 2025: 94 employees under 30, 338 aged 30-50, 109 over 50 (2024: 103 / 339 / 110) (page 62).

S1-9(was S1-10)Adequate wages
Reported

Adequate wages

Reference: page 62.

"All employees receive remuneration in line with the levels provided for by the applicable CCNL, ensuring adequacy with respect to sectoral and regulatory reference parameters. In no country do employees earn below the reference threshold for adequate remuneration" (page 62). No numeric wage-gap-to-benchmark figure is given beyond this qualitative confirmation.

S1-10(was S1-11)Social protection
Not Material
S1-11(was S1-12)Persons with disabilities
Omitted
S1-12(was S1-13)Training and skills development metrics
Reported

Training and skills development metrics

Reference: pages 62-63.

Performance-review participation, 2025: 86.83% of male employees (389 of 448), 93.55% of female employees (87 of 93), 88% overall (476 of 541) - up sharply from 33-41% in 2024 (page 62-63). Average training hours per employee, 2025: 7 (male), 4 (female), 6 overall - down from 10/24/12 in 2024, explained by "the update of the Training Plan to be implemented over the two-year period 2025-2026" (page 63).

S1-13(was S1-14)Health and safety metrics
Reported

Health and safety metrics

Reference: pages 63-64.

"100% of employees are covered by a health management system, as provided for under the applicable CCNL. No cases of death were recorded" (page 63). "In 2025... 2 accidents were recorded, with a work-related accident rate equal to 2.15 per million hours worked," calculated on estimated standard hours of 1,720 per employee; recordable work-related illness cases and days lost to injury/illness/death were both 0 (page 63-64).

The Appendix C phase-in omissions table (page 4) also names "Health and Safety" among items the Group omits given its under-750-employee workforce; read together with the figures actually disclosed above, the omission is understood to cover only the further sub-datapoints (e.g. by employee category or geography) rather than the headline metrics reported here.

S1-14(was S1-15)Work-life balance metrics
Reported

Work-life balance metrics

Reference: page 64.

"All employees are entitled to leave for family reasons pursuant to social policy and/or collective labor agreements" - 100% entitlement across genders (page 64). Take-up in 2025: 3% of male employees, 13% of female employees, 3% of the total (up from 2%, 4% and 3% respectively in 2024, with 2024 Group figures "estimated based on the projection of the parent company's figures") (page 64).

S1-15(was S1-16)Compensation metrics (pay gap and total compensation)
Reported

Compensation metrics (pay gap and total compensation)

Reference: page 64.

"In 2025, the average pay gap will be -0.75%, a reduction compared to 2024, when it stood at -1.72%," calculated as the difference between average gross hourly wages of male and female workers as a percentage of the male wage level (page 64). The CEO pay ratio (highest-paid individual's annual total remuneration to median employee remuneration) is 4.34 in 2025, versus 4.23 in 2024 (page 64).

S1-16(was S1-17)Incidents, complaints and severe human rights impacts
Reported

Incidents, complaints and severe human rights impacts

Reference: page 64.

Nil return: "No reports relating to incidents of discrimination, including harassment or complaints submitted through the designated channels, were recorded in both 2024 and 2025" (page 64). No fines, sanctions or severe human-rights-incident figures are separately reported (none arose).

G1 – Business Conduct

G1-1Business conduct policies and corporate culture
Reported

Business conduct policies and corporate culture

Reference: pages 66-69.

The Code of Ethics, updated July 2025, is "the cornerstone of the system of values and principles that guide The Group's actions," structured into general ethical principles, internal-relations principles, and third-party-relations principles, and applies "at all levels of the organization" (page 66). Certified management systems cover quality (ISO 9001), environment (ISO 14001, RCS), information security (ISO 27001, CY4Gate/RCS/XTN) and a GDPR-aligned data-protection policy with an appointed DPO (page 66-67).

Governance instruments: the Organization, Management and Control Model (MOG 231/2001, updated 2025, four sections and five annexes); the Anti-Corruption Code (updated 2025), overseen by a Coordination and Consultation Body and a Whistleblowings Committee reporting semi-annually; and an Anti-Money Laundering Code (updated 2025) with a dedicated function (pages 67-68). A whistleblowing platform ensures anonymous, confidential reporting, with "no retaliation against good faith reporters" (page 69). Functions most exposed to corruption risk: "Human Resources, Sales, Marketing, and Procurement" (page 69).

G1-2Management of relationships with suppliers
Reported

Management of relationships with suppliers

Reference: page 70.

"The payment policy is currently not managed through a Group procedure; however, each company... seeks to ensure compliance with contractually agreed payment terms" (page 70). Suppliers registered in Cy4gate's vendor register must sign a "Commitment to social responsibility for ethical and sustainable development," and the Group runs ongoing regulatory-compliance and certification checks on suppliers (page 70). The 2026-2030 Sustainability Plan targets an increased share of suppliers assessed on ESG criteria or adhering to Cy4gate's ESG Policy.

G1-2(was G1-3)Prevention and detection of corruption and bribery
Reported

Prevention and detection of corruption and bribery

Reference: pages 70-71.

"All companies of The Group have been subject to a corruption risk assessment over the last two years, covering 100% of the Group's operating sites" (page 70). "To date, no cases of active or passive corruption have emerged within The Group" (page 70). Training under Model 231/anti-corruption/whistleblowing reaches the Board of Directors, Board of Statutory Auditors, Executives, Middle Managers, Employees and Apprentices; "Training is provided to 100% of functions at risk" (page 70).

The Whistleblowings Committee reports semi-annually to the Coordination Body on activities and Action Plan status for corruption-relevant conduct (page 70). Functions identified as most exposed: commercial, procurement/supplier selection, institutional relations, tender participation, and HR selection/management (page 70).

G1-3(part of MDR-T/GDR-T disclosures)Targets related to business conduct
Reported

Targets related to business conduct

Back-filled from the G1 chapter, where business-conduct effectiveness is tracked as part of MDR-T rather than as a numbered disclosure requirement (page 70-71). G1-3 became a standalone DR only in the 2025/2026 ESRS. The report's own due-diligence table cross-references "ESRS 2 MDR-M, ESRS 2 MDR-T... ESRS G1-4/6" under "Monitoring the effectiveness of these efforts and communicating the results" (page 21).

Cy4Gate does not disclose a numeric business-conduct target. Consistent with MDR-T's effectiveness-in-absence-of-target limb, it tracks: a corruption risk assessment covering "100% of the Group's operating sites" over the last two years (page 70); anti-corruption training delivered to "100% of functions at risk" (page 70); ISO 37001 (Anti-Corruption Management System) certification obtained for CY4Gate in 2025 (page 71); and maintenance of "CY4Gate S.p.A.'s legality rating with a score of three stars, corresponding to the maximum obtainable score" (page 71). Semi-annual Whistleblowings Committee reporting on Action Plan progress provides ongoing monitoring (page 70).

G1-4Incidents of corruption or bribery
Reported

Incidents of corruption or bribery

Reference: page 71.

Nil return: "The Group has not identified any cases of active or passive corruption, violations of procedures, or, consequently, the application of sanctions" (page 71). 2025 actions cited: maintaining the legality rating (three stars, maximum score); updating the 231 Model for CY4Gate and RCS; and obtaining ISO 37001 certification for CY4Gate's Anti-Corruption Management System (page 71). "No convictions for violations of laws against active and passive corruption have been recorded" (page 71).

G1-5Political influence and lobbying activities
Not Material
G1-6Payment practices
Reported

Payment practices

Reference: pages 71-72.

Payment terms are set in purchase orders, generally "payment upon presentation of an invoice and subject to authorization for payment by the requesting function" (page 71-72). The average payment-time metric is not yet available: "The average time taken by the undertaking to pay an invoice from the date on which the contractual or legal payment term begins... is not available and is expected to be measured from 2026" (page 72). "There are currently no legal proceedings pending due to payment delays" (page 72).