Security leader reviewing a monitored control environment

Trust Centre.

Our security posture, made clear for the teams who need to verify it.

View our posture ↘

Proof before promises

We apply the same standard to ourselves.

Before you trust us with your compliance program, see how we run our own.

Our Trust Centre publishes DCMS's security posture (the same standards we help clients achieve, applied to ourselves).

For vendor risk and procurement teams across South Africa and other markets who need a trust centre before signing, this page answers the questions your security review will ask first: certifications held, data-handling practices, sub-processors, and incident response commitments.

Due diligence scope

What you can verify.

A direct route to the evidence your procurement and vendor risk teams need.

01

Certification status

Verify our current certification standing, including ISO 27001.

Security assurance
02

Data handling

Review how information is accessed, protected, and managed.

Control practices
03

Sub-processors

Understand the third parties that support our service delivery.

Supplier oversight
04

Incident response

Review the commitments that guide our response to security events.

Response readiness
DCMS consultants reviewing governance and security evidence
Evidence-led assurance

Built for review

Due diligence without the runaround.

Security documentation should help your team reach a decision, not create another queue. We provide a direct path to the material required for a structured vendor review.

  • 01Clear ownershipRequests go to the team responsible for the evidence.
  • 02Relevant documentationReceive the material that matches your review scope.
  • 03Evidence attachedQuestionnaires are returned populated and evidenced.

Documentation request

Need something specific?

Do you have a specific vendor questionnaire to complete? Contact us, and we'll return it - populated and evidenced.

Request documentation ↗

Direct answers

Trust questions, answered.

Does DCMS publish its certification status?

Yes. DCMS publishes its certification status, including ISO 27001, on its Trust Centre, demonstrating that we apply the same standards we help clients achieve to our own operations, so prospective clients can verify this before signing an engagement.

Can vendor risk teams review security documentation?

Yes. DCMS's Trust Centre publishes its security posture and internal controls. It also offers direct access to its SOC 2 report and security documentation, allowing vendor risk teams to complete due diligence without a lengthy manual questionnaire process.

How can I request DCMS's SOC 2 report?

Request DCMS's SOC 2 report directly through the Trust Centre page — submit a vendor questionnaire or documentation request there, and it will be returned populated and evidenced, without needing a separate sales conversation first.