Strategy meets experience: We give your IT wings!
Dr. Martin Zambaldi is a freelance IT consultant and interim manager for companies in Germany, Austria, Switzerland, and Northern Italy. Focus areas: NIS2, ISO 27001, IT strategy, digitalization, and IT project management.


As an independent IT consultant, I stand on my clients' side – without product interests or conflicts of interest.
Development of a company-specific IT strategy, evaluation of new technologies (incl. AI), and support for strategic IT decisions at management level.
Analysis, revision, and digitalization of business processes following ITIL best practices. Structured requirements gathering and software selection.
Guidance toward ISO 27001 certification, NIS2 implementation, and building security infrastructure (SOC, BCM).
Management of IT projects including change management and stakeholder engagement. Building PMO structures.
Commissioning, steering, and monitoring of external IT service providers. Experience with tenders into the millions.
Building AI management systems per ISO/IEC 42001. Compliance strategies for the EU AI Act.
Data Protection Impact Assessments (Art. 35 GDPR), records of processing activities (Art. 30), and Data Processing Agreements – practical, not just paperwork.
Hourly/daily rate upon request
These three areas currently bring most companies to me – all with regulatory deadlines that are already running or fast approaching.
NIS2 obligates significantly more companies to minimum IT security standards – with personal liability for management. From assessment to full implementation.
NIS2 Supplier Risk Checklist → Article on the NIS2 situation → Check applicability →The AI Act obligates companies, depending on the risk class of their AI applications, to staggered requirements – from transparency obligations to full conformity assessment for high-risk systems. The first deadlines already apply, with further ones phased in through 2027.
AI Act risk classification → Check applicability →The Cyber Resilience Act obligates manufacturers of connected products to report actively exploited vulnerabilities – the first reporting obligation has already applied since 11 September 2026. From the applicability assessment to full implementation of the security requirements by the end of 2027.
Clarify CRA reporting obligation → Check applicability →From the free self-assessment to a concrete engagement – horizontally by topic area, vertically by Free, Focus service and other services. Hover or tap for details.
| IT Strategy | Processes & ITIL | Security & ISO 27001 | Projects & PMO | Vendors | AI & ISO 42001 | Data Protection | |
|---|---|---|---|---|---|---|---|
| Free | IT Strategy Checklist10 questions to assess in 5 minutes where your IT strategy stands – and where action is needed most. View for free → | NIS2 Supplier Risk Checklist10 questions to assess in 5 minutes the NIS2 security risk of an IT supplier. View for free → | Vendor Lock-in Checklist10 questions to assess in 5 minutes your dependency risk on an IT vendor – switching costs, data portability, exit options. View for free → | AI Governance Checklist10 questions to assess in 5 minutes where you stand on the EU AI Act and ISO 42001. View for free → | |||
| Focus | IT Strategy WorkshopA one- to two-day workshop with senior management to develop a prioritized, actionable IT strategy. Inquire →Interim CIO / Head of ITTemporary IT leadership during vacancies, transition phases, or capacity shortages – both operational and at management level. Inquire → | Software Selection & Tender SupportStructured requirements gathering, market screening, and tendering when introducing new software – from requirements to contract negotiation. Inquire → | Internal ISO 27001 AuditConducting the internal audit as an independent, certified Lead Auditor – including audit report and nonconformity management. Inquire →ISO 27001 Certification SupportStructured guidance from gap analysis through to certification readiness – practical, not paper-pushing. Inquire → | IT Project SupportTechnical guidance and quality assurance for ongoing IT projects – from requirements clarification to go-live, independent of the contracted vendor. Inquire → | IT Vendor & Supplier Management ReviewReview of existing IT vendor contracts and management, with recommendations for consolidation and cost control. Inquire → | AI Strategy DevelopmentDeveloping a company-specific AI strategy: identifying and prioritizing meaningful use cases and aligning them with your compliance requirements. Inquire →AI Guideline for Your CompanyA customized AI guideline (Standard or Extended with the Cyber Resilience Act) with concrete recommendations for management and staff. Inquire →Internal ISO 42001 AuditInternal audit of your AI management system by a certified ISO/IEC 42001 Implementer – including audit report. Inquire → | Data Protection Impact Assessment (DPIA)Conducting a Data Protection Impact Assessment (DPIA) under Art. 35 GDPR for high-risk processing such as AI systems, video surveillance, or profiling – including an action plan. Inquire → |
| Other services | Board & Committee Briefings on IT Security and ComplianceFocused briefings for boards and senior management on IT security and regulatory compliance – explained clearly for non-technical audiences. Inquire → | Digitalization of Processes and WorkflowsAnalysis of existing business processes and development of a concrete digitalization plan following ITIL best practices – from current-state assessment to implementation support. Inquire →Building an IT Service CatalogStructuring and documenting the IT services offered, including SLAs, for greater transparency toward business departments. Inquire → | NIS2 Applicability & Gap AnalysisClarifying whether and how your company falls under the EU NIS2 Directive, comparing this against your current state, and a prioritized action plan with deadlines. Inquire →Business Continuity Planning (BCM)Developing a business continuity plan so your company is prepared for IT outages and security incidents. Inquire →Information Security Awareness TrainingHands-on security awareness training on phishing, social engineering, and safe everyday behavior – often a mandatory element of ISO 27001 and NIS2. Inquire → | Setting Up a PMODesigning and implementing a PMO structure with standards, reporting, and escalation paths for greater transparency across ongoing IT projects. Inquire →Interim IT Project LeadershipTemporary operational project leadership during capacity shortages or critical project phases. Inquire → | Independent IT Review / Second OpinionNeutral assessment of existing IT systems, contracts, or vendor decisions before a major investment – with no product interests, only yours. Inquire →Tender Preparation & Award SupportPreparation of specifications and tender documents, support through to contract signature. Inquire → | AI Act / CRA Applicability ConsultingClarifying which obligations under the EU AI Act and Cyber Resilience Act specifically apply to your company and products – with a prioritized action plan. Inquire → | Record of Processing Activities (Art. 30 GDPR)Creating or updating the record of processing activities – often the first concrete step toward GDPR compliance. Inquire →Data Processing Agreements (DPA)Reviewing and drafting Data Processing Agreements (DPAs) with service providers and cloud vendors. Inquire → |

As a freelance IT consultant based in Neumarkt (South Tyrol), I combine deep technical know-how with many years of leadership and management experience. My approach is always independent, pragmatic, and focused on tangible client benefit.
After my career at Infineon/Siemens in Munich, my Ph.D., and an Executive MBA, I led IT departments in South Tyrol's public administration and most recently as Head of IT at Raiffeisenverband Südtirol.
Currently certified as ISO 27001 Lead Auditor (VOREST AG, until June 2029) and ISO/IEC 42001 Implementer (DGQ). Active in the DACH region and Northern Italy.
A clear path from the first inquiry to a concrete solution – with no commitment before you know where you stand.
In a non-binding 30-minute conversation we get to know each other and I provide an initial assessment.
Together we capture the current state of your IT, identify risks and define key areas for action.
You receive a clear, transparent proposal – you decide without pressure whether and how we begin.
// Recommendations from fellow students and former colleagues (LinkedIn)
"Dr. Zambaldi was my fellow student in the MBA. Very efficient, serious, quick to grasp things and actively participating. Always helpful – a committed team player."
"Martin is extremely people friendly and always patient. Excellent interpersonal skills – it was a great pleasure working with him."
"Excellent team management, decision making and risk analysis skills. His supportive efforts made the true difference in achieving the project milestones."
"Martin is an interesting and understanding colleague, very approachable. His engagement in training sessions is amazing – an enthusiastic learner."
„It was a great pleasure for me to work with Dr. Martin Zambaldi at Raiffeisenverband Südtirol. Martin combines professional expertise with an exceptionally pleasant and appreciative way of dealing with people.
As Head of the IT and Organization department, he always had an open ear for concerns, thought in a solution-oriented way, and looked for possibilities even where standard approaches reached their limits. I particularly valued his willingness to take on responsibility and his strong personal commitment to finding good solutions – often far beyond what would have been expected.
His team was clearly close to his heart. He fostered collaboration, treated people as equals, and created an environment where people enjoyed working together on challenges.
Anyone who worked with Martin gains a reliable, creative, and committed partner who thinks strategically, acts pragmatically, and approaches even complex challenges with foresight.“
"I had the pleasure of working with Martin in two different contexts in the IT world: first as a colleague, and later with him as my coordinator. In both roles, he consistently demonstrated strong commitment and a focus on teamwork. During the period in which he was my coordinator, I particularly appreciated his servant-leader approach: always oriented toward supporting the team."
"I had the pleasure of working with Dr. Martin Zambaldi for several years, appreciating his professionalism and utmost correctness. A colleague who is always available, precise, and well-prepared."
"Dr. Zambaldi was my fellow student in the MBA. Very efficient, serious, quick to grasp things and actively participating. Always helpful – a committed team player."
"Martin is extremely people friendly and always patient. Excellent interpersonal skills – it was a great pleasure working with him."
"Excellent team management, decision making and risk analysis skills. His supportive efforts made the true difference in achieving the project milestones."
"Martin is an interesting and understanding colleague, very approachable. His engagement in training sessions is amazing – an enthusiastic learner."
„It was a great pleasure for me to work with Dr. Martin Zambaldi at Raiffeisenverband Südtirol. Martin combines professional expertise with an exceptionally pleasant and appreciative way of dealing with people.
As Head of the IT and Organization department, he always had an open ear for concerns, thought in a solution-oriented way, and looked for possibilities even where standard approaches reached their limits. I particularly valued his willingness to take on responsibility and his strong personal commitment to finding good solutions – often far beyond what would have been expected.
His team was clearly close to his heart. He fostered collaboration, treated people as equals, and created an environment where people enjoyed working together on challenges.
Anyone who worked with Martin gains a reliable, creative, and committed partner who thinks strategically, acts pragmatically, and approaches even complex challenges with foresight.“
"I had the pleasure of working with Martin in two different contexts in the IT world: first as a colleague, and later with him as my coordinator. In both roles, he consistently demonstrated strong commitment and a focus on teamwork. During the period in which he was my coordinator, I particularly appreciated his servant-leader approach: always oriented toward supporting the team."
"I had the pleasure of working with Dr. Martin Zambaldi for several years, appreciating his professionalism and utmost correctness. A colleague who is always available, precise, and well-prepared."
Over 25 years of IT practice at management level.
A comparison of NIS2 implementation in Italy, Austria and Germany – deadlines, authorities, and what it means for companies active in all three countries.
Legal situation, four assessment criteria, and case studies from the DACH region, France and Italy.
I look forward to your inquiry – whether for a concrete project or an initial consultation.
Andreas Hofer Straße 7
39044 Neumarkt (BZ), South Tyrol – Italy
DACH region & Northern Italy · Remote worldwide
In a non-binding 30-minute conversation, I explain my approach and we explore how I can support your company.
Request free consultation
Martin Zambaldi
Freelance IT Consultant (Sole Trader)
Trading name: MAZ Digital Consulting
Via Andreas Hofer 7
39044 Egna / Neumarkt (BZ)
South Tyrol – Italy
E-Mail: business@zambaldi.eu
Phone: +39 335 1315264
Partita IVA: 03335190215
Codice Fiscale: ZMBMTN75H01A952O
Activity (ATECO Code): 622010 – IT consulting
The activity as a freelance IT consultant is not subject to any legally regulated chamber membership or licensing requirement in Italy. It is a free, unregulated profession pursuant to Italian Legislative Decree 70/2003 and Law 4/2013.
The contents of this website have been created with the greatest care. No guarantee is given for the accuracy, completeness, or timeliness of the content. No liability is assumed for external links; their operators are solely responsible for their content.
All contents of this website (texts, images, graphics, logo) are protected by copyright. Reproduction or use requires explicit written consent.
I am not obligated nor willing to participate in dispute resolution proceedings. The EU Online Dispute Resolution platform was shut down on 20 July 2025.
Last updated: July 2026
Dr. rer. nat. Martin Zambaldi, MBA · MAZ Digital Consulting
Andreas Hofer Straße 7 · 39044 Neumarkt (BZ) · Italien
E-Mail: business@zambaldi.eu
This website uses the analytics service Umami (Umami Software Inc.) for anonymized, cookie-free traffic measurement – no cookies, no permanent IP storage, and no cross-device or cross-site recognition. Legal basis: legitimate interest in privacy-friendly traffic measurement (Art. 6(1)(f) GDPR).
When you send an email, your details are stored to process your request. The email infrastructure is operated by Hosteurope GmbH, Cologne. Legal basis: Art. 6 GDPR.
Information submitted via these forms (name, company, email, phone, answers) is processed by a server-side script on the Hosteurope server and forwarded by email to business@zambaldi.eu – without database storage. Submission requires your consent. To protect against automated abuse, your IP address is temporarily cached for a maximum of one hour and then automatically deleted. Legal basis: Art. 6(1)(b) GDPR in conjunction with your consent; for abuse protection Art. 6(1)(f) GDPR (legitimate interest).
Website and email services are hosted by Hosteurope GmbH, Cologne. Server log files are deleted after max. 7 days. Legal basis: Art. 6(1)(f) GDPR.
Email content is confidential. Any distribution is prohibited. If you are not the intended recipient, please notify the sender and delete the email.
Access, rectification, erasure, restriction, portability, objection (Art. 15–21 GDPR). Contact: business@zambaldi.eu. Complaints: www.garanteprivacy.it
July 2026