Certifications and Compliance

Frameworks, certifications and commitments.

Our foundational framework is the CIS Controls, complemented by NIS2, POPIA and GDPR alignment and Cyber Essentials Plus certification. Maintained by Numata's GRC team and reflecting the Numata Trust Centre document.

Foundational
CIS Controls v8
Certified
Cyber Essentials Plus
Compliant
GDPR and POPIA
Aligned
NIS2 and ISO 27001
Foundational Framework

The frameworks we measure ourselves against.

  • Foundational

    CIS Controls (Center for Internet Security)

    CIS Controls is Numata's foundational framework, selected to measure the scope and maturity of the information security programme. People, process and technology capabilities are aligned to this framework.

  • Aligned

    NIS2 Directive

    Numata's Risk Management Framework aligns with the EU Network and Information Security Directive Version 2, informing controls and response practices.

  • Certified

    Cyber Essentials

    UK government-backed self-assessment certification covering firewalls, secure configuration, access controls, malware protection and patch management. Renewed annually.

  • Certified

    Cyber Essentials Plus

    Advanced certification involving an independent, hands-on technical audit by an accredited external assessor. Includes penetration testing, vulnerability assessments and verification of implemented controls. Renewed annually.

  • Aligned

    ISO/IEC 27001

    Numata's information security programme is aligned to ISO/IEC 27001, informing policies, controls and continuous improvement across the organisation.

  • Aligned

    NIST Cybersecurity Framework

    Numata's cybersecurity practices are mapped to the NIST Cybersecurity Framework functions (Identify, Protect, Detect, Respond, Recover).

Microsoft Partnership

Microsoft designations and team certifications.

  • Certified

    Microsoft Solutions Partner

    Recognised Microsoft Solutions Partner for Modern Work, Security and Infrastructure.

  • Certified

    Microsoft 365 Certified

    Team certifications across Microsoft 365 administration, security and compliance.

  • Certified

    Azure Certified

    Team certifications across Azure administration, security and cloud architecture.

Managed technology partnerships

The tooling partners we hold certifications with.

  • Certified

    Managed operations partner

    Technical and operational certifications across remote monitoring, service automation, backup, business continuity and security tooling.

  • Certified

    Continuity and infrastructure partner

    Technical certifications across business continuity, SaaS protection and managed networking solutions.

Regulatory Compliance

The regulations we are compliant with.

  • Compliant

    GDPR (EU and UK)

    Numata complies with the EU and UK General Data Protection Regulation, including lawful processing, data processing agreements, transparent consent, subject rights and breach notification.

  • Compliant

    POPIA

    Numata complies with the South African Protection of Personal Information Act, including lawful processing conditions, data subject participation rights and information officer responsibilities.

Frequently asked questions

How certifications and compliance are maintained.

All certifications, partnerships and compliance commitments on this page are verified by Numata's Governance, Risk and Compliance team and reviewed on a continuous basis.

Who maintains the certifications and compliance statements on this page?

Numata's Governance, Risk and Compliance (GRC) function maintains this page, working with the CISO, Risk Management Committee and department owners. Updates are published after internal review and evidence sign-off.

How often are certifications and framework alignments reviewed?

Certifications such as Cyber Essentials and Cyber Essentials Plus are renewed annually through independent assessment. Framework alignments (CIS Controls, NIS2, ISO/IEC 27001, NIST CSF) are reviewed on a continuous basis, with formal internal audits conducted multiple times per year.

How do you verify that controls are operating effectively?

The GRC team runs a continuous internal audit programme against the CIS Controls baseline and applicable frameworks. Evidence is collected from tooling, policy owners and process owners, and findings are tracked to closure through the Risk Management Committee.

How are third-party and partner certifications kept current?

Partner designations are tracked by Numata's partner and technical enablement teams. Individual technical certifications are recorded per engineer and refreshed in line with each partner's recertification cycle.

How do you handle changes to regulations such as GDPR, POPIA and NIS2?

The Risk Management Committee monitors regulatory and threat landscape changes. Where a change impacts policy, controls or client obligations, the GRC team updates the relevant policies, notifies affected clients where required and reflects the change on this page.

Can clients request evidence, audit reports or completed questionnaires?

Yes. Existing clients and qualified prospects can request current policy documents, audit summaries, penetration test attestations and completed security questionnaires under NDA through their Numata contact or the Trust Centre documents page.

What happens if a certification lapses or a control fails an audit?

Any lapse or failed control is logged as a finding, assigned an owner and remediation timeline, and tracked through the Risk Management Committee. Status on this page is updated to reflect the current position, and material changes are communicated to affected clients.