Credentials and documentation

The evidence behind what we claim.

One place for the certifications we hold, the partners we are accredited with, and the process documentation your procurement, risk and audit teams tend to ask for. This page is maintained by Numata and describes our own practices. It is not an independent audit report.

Maintained by
GRC and CISO
Cadence
Continuous review
Release
Under NDA on request
Independent
Since 2004
Numata governance and risk documentation in review
Certifications

What we are certified against, and what we are aligned to.

  • Certified

    Cyber Essentials Plus

    Independent, hands on technical audit by an accredited assessor, covering vulnerability testing and verification of implemented controls. Renewed annually.

  • Certified

    Cyber Essentials

    UK government backed certification across firewalls, secure configuration, access control, malware protection and patching. Renewed annually.

  • Foundational

    CIS Controls v8

    The framework we measure our own programme against. People, process and technology capabilities are mapped to it and audited continuously.

  • Aligned

    ISO/IEC 27001

    Policies, controls and continuous improvement are aligned to the standard across the organisation.

  • Aligned

    NIST Cybersecurity Framework

    Security practice mapped to Identify, Protect, Detect, Respond and Recover.

  • Aligned

    NIS2 Directive

    Our risk management framework aligns to the EU Network and Information Security Directive version 2.

  • Compliant

    GDPR (EU and UK)

    Lawful processing, data processing agreements, subject rights and breach notification.

  • Compliant

    POPIA

    South African Protection of Personal Information Act, including information officer responsibilities.

Partners

The platforms we are accredited to run, at partner level.

  • Microsoft

    Solutions Partner. Designations across Modern Work, Security and Infrastructure, with team certifications in Microsoft 365 and Azure administration, security and architecture.

  • Device and infrastructure partners

    Partner network. Device, server and storage supply for managed estates, including the Numata Workplace Device Subscription lifecycle.

  • Managed operations partners

    Certified partner network. Technical certifications across remote monitoring, service automation, backup and security tooling.

  • Continuity and network partners

    Certified partner network. Technical certifications across business continuity, SaaS protection and managed networking solutions.

Documentation

The policies and plans that govern how we deliver.

Documents are released under NDA through your Numata contact, or on request through the contact page. Each is owned by a named policy owner and reviewed on a continuous cycle.

Governance

  • Security Policy
  • Risk Management Policy
  • Data Governance Policy
  • Third-Party Risk Management Policy
  • Artificial Intelligence Usage Policy

Operations

  • Change Management Policy
  • Patch Management Policy
  • Vulnerability Management Policy
  • Asset Management Policy
  • Acceptable Use Policy

Resilience

  • Incident Management and Response Plan
  • Business Continuity Plan
  • Disaster Recovery Plan
  • Encryption Policy
  • Electronic Data Disposal Policy

Due diligence packs

  • Data Processing Agreement
  • Sub-Processor List
  • Security Questionnaire (SIG Lite / CAIQ)
  • Physical Security Policy
  • Software Development Lifecycle Policy

Need the documentation pack for a procurement or audit review?

Tell us which documents you need and we will release them under NDA.

Request the pack