Frameworks, certifications and commitments.
Our foundational framework is the CIS Controls, complemented by NIS2, POPIA and GDPR alignment and Cyber Essentials Plus certification. Maintained by Numata's GRC team and reflecting the Numata Trust Centre document.
- CIS Controls v8
- Cyber Essentials Plus
- GDPR and POPIA
- NIS2 and ISO 27001
The frameworks we measure ourselves against.
- Foundational
CIS Controls (Center for Internet Security)
CIS Controls is Numata's foundational framework, selected to measure the scope and maturity of the information security programme. People, process and technology capabilities are aligned to this framework.
- Aligned
NIS2 Directive
Numata's Risk Management Framework aligns with the EU Network and Information Security Directive Version 2, informing controls and response practices.
- Certified
Cyber Essentials
UK government-backed self-assessment certification covering firewalls, secure configuration, access controls, malware protection and patch management. Renewed annually.
- Certified
Cyber Essentials Plus
Advanced certification involving an independent, hands-on technical audit by an accredited external assessor. Includes penetration testing, vulnerability assessments and verification of implemented controls. Renewed annually.
- Aligned
ISO/IEC 27001
Numata's information security programme is aligned to ISO/IEC 27001, informing policies, controls and continuous improvement across the organisation.
- Aligned
NIST Cybersecurity Framework
Numata's cybersecurity practices are mapped to the NIST Cybersecurity Framework functions (Identify, Protect, Detect, Respond, Recover).
Microsoft designations and team certifications.
- Certified
Microsoft Solutions Partner
Recognised Microsoft Solutions Partner for Modern Work, Security and Infrastructure.
- Certified
Microsoft 365 Certified
Team certifications across Microsoft 365 administration, security and compliance.
- Certified
Azure Certified
Team certifications across Azure administration, security and cloud architecture.
The tooling partners we hold certifications with.
- Certified
Managed operations partner
Technical and operational certifications across remote monitoring, service automation, backup, business continuity and security tooling.
- Certified
Continuity and infrastructure partner
Technical certifications across business continuity, SaaS protection and managed networking solutions.
The regulations we are compliant with.
- Compliant
GDPR (EU and UK)
Numata complies with the EU and UK General Data Protection Regulation, including lawful processing, data processing agreements, transparent consent, subject rights and breach notification.
- Compliant
POPIA
Numata complies with the South African Protection of Personal Information Act, including lawful processing conditions, data subject participation rights and information officer responsibilities.
How certifications and compliance are maintained.
All certifications, partnerships and compliance commitments on this page are verified by Numata's Governance, Risk and Compliance team and reviewed on a continuous basis.
Who maintains the certifications and compliance statements on this page?
Numata's Governance, Risk and Compliance (GRC) function maintains this page, working with the CISO, Risk Management Committee and department owners. Updates are published after internal review and evidence sign-off.
How often are certifications and framework alignments reviewed?
Certifications such as Cyber Essentials and Cyber Essentials Plus are renewed annually through independent assessment. Framework alignments (CIS Controls, NIS2, ISO/IEC 27001, NIST CSF) are reviewed on a continuous basis, with formal internal audits conducted multiple times per year.
How do you verify that controls are operating effectively?
The GRC team runs a continuous internal audit programme against the CIS Controls baseline and applicable frameworks. Evidence is collected from tooling, policy owners and process owners, and findings are tracked to closure through the Risk Management Committee.
How are third-party and partner certifications kept current?
Partner designations are tracked by Numata's partner and technical enablement teams. Individual technical certifications are recorded per engineer and refreshed in line with each partner's recertification cycle.
How do you handle changes to regulations such as GDPR, POPIA and NIS2?
The Risk Management Committee monitors regulatory and threat landscape changes. Where a change impacts policy, controls or client obligations, the GRC team updates the relevant policies, notifies affected clients where required and reflects the change on this page.
Can clients request evidence, audit reports or completed questionnaires?
Yes. Existing clients and qualified prospects can request current policy documents, audit summaries, penetration test attestations and completed security questionnaires under NDA through their Numata contact or the Trust Centre documents page.
What happens if a certification lapses or a control fails an audit?
Any lapse or failed control is logged as a finding, assigned an owner and remediation timeline, and tracked through the Risk Management Committee. Status on this page is updated to reflect the current position, and material changes are communicated to affected clients.
