The evidence behind what we claim.
One place for the certifications we hold, the partners we are accredited with, and the process documentation your procurement, risk and audit teams tend to ask for. This page is maintained by Numata and describes our own practices. It is not an independent audit report.
- GRC and CISO
- Continuous review
- Under NDA on request
- Since 2004

- Certified
Cyber Essentials Plus
Independent, hands on technical audit by an accredited assessor, covering vulnerability testing and verification of implemented controls. Renewed annually.
- Certified
Cyber Essentials
UK government backed certification across firewalls, secure configuration, access control, malware protection and patching. Renewed annually.
- Foundational
CIS Controls v8
The framework we measure our own programme against. People, process and technology capabilities are mapped to it and audited continuously.
- Aligned
ISO/IEC 27001
Policies, controls and continuous improvement are aligned to the standard across the organisation.
- Aligned
NIST Cybersecurity Framework
Security practice mapped to Identify, Protect, Detect, Respond and Recover.
- Aligned
NIS2 Directive
Our risk management framework aligns to the EU Network and Information Security Directive version 2.
- Compliant
GDPR (EU and UK)
Lawful processing, data processing agreements, subject rights and breach notification.
- Compliant
POPIA
South African Protection of Personal Information Act, including information officer responsibilities.
The platforms we are accredited to run, at partner level.
Microsoft
Solutions Partner. Designations across Modern Work, Security and Infrastructure, with team certifications in Microsoft 365 and Azure administration, security and architecture.
Device and infrastructure partners
Partner network. Device, server and storage supply for managed estates, including the Numata Workplace Device Subscription lifecycle.
Managed operations partners
Certified partner network. Technical certifications across remote monitoring, service automation, backup and security tooling.
Continuity and network partners
Certified partner network. Technical certifications across business continuity, SaaS protection and managed networking solutions.
The policies and plans that govern how we deliver.
Documents are released under NDA through your Numata contact, or on request through the contact page. Each is owned by a named policy owner and reviewed on a continuous cycle.
Governance
- Security Policy
- Risk Management Policy
- Data Governance Policy
- Third-Party Risk Management Policy
- Artificial Intelligence Usage Policy
Operations
- Change Management Policy
- Patch Management Policy
- Vulnerability Management Policy
- Asset Management Policy
- Acceptable Use Policy
Resilience
- Incident Management and Response Plan
- Business Continuity Plan
- Disaster Recovery Plan
- Encryption Policy
- Electronic Data Disposal Policy
Due diligence packs
- Data Processing Agreement
- Sub-Processor List
- Security Questionnaire (SIG Lite / CAIQ)
- Physical Security Policy
- Software Development Lifecycle Policy
Need the documentation pack for a procurement or audit review?
Tell us which documents you need and we will release them under NDA.
