
Certifications
We maintain relevant certifications to ensure our clients and partners have the highest level of confidence that we are aligned with industry best practices and deliver innovative, secure and sustainable solutions.
In January 2025, we achieved our fourth consecutive SOC 2 Type II attestation covering both software development and our ‘Run by Endava’ operations.
System and Organization Controls (SOC) 2 is a comprehensive reporting framework put forth by the American Institute of Certified Public Accountants (AICPA) in which independent, third-party auditors carry out an assessment and subsequent testing of controls relating to the Trust Services Criteria (TSC) of security, availability, processing integrity, confidentiality and privacy.
Endava’s Quality Management System (QMS) is certified to the ISO 9001 standard. Our QMS is embedded within the Endava Adaptive Model (TEAM) and ensures consistent delivery of high-quality digital products and services. Internal audits and cross-project reviews provide continued monitoring and improvement throughout the project lifecycle, helping us uphold the highest standards in delivery excellence.
We continue expanding the reach of our environmental management system and reinforcing our commitment to responsible, sustainable operations.
In FY2025, we successfully completed the supervision audit for the ISO 14001 certification in 9 locations across Romania and Moldova, ensuring ongoing compliance. In December 2025 our UK legal entity also achieved the ISO 14001 certification, further strengthening the consistency of our environmental practices.
Download ISO 14001 certificates for our legal entities: UK, Romania, Moldova
We have implemented and continue to uphold a robust Anti-Bribery Management System that fully meets the requirements of ISO 37001. In November 2024, we were proud to receive ISO 37001 certification for Endava UK, marking a significant milestone in our commitment to the highest standards of ethical conduct.
Our Anti-Bribery & Anti-Corruption Policy underscores Endava's unwavering stance of zero tolerance towards bribery and corruption, whether by our employees or any intermediaries acting on our behalf.
Our Business Continuity Management System (BCMS) is certified to the ISO 22301:2019 international standard on Business Continuity, affirming our commitment to proactive continuity planning and resilience. The BCMS encompasses detailed continuity plans for our people, processes and technologies across our global operations.
Recognising the growing complexity of hybrid work environments, our strategy addresses location-independent risks such as cyber threats, geopolitical instability, natural disasters and local infrastructure vulnerabilities. These risk assessments are integrated in our mitigation strategies to ensure continuity of service under a range of scenarios.
We are actively expanding our Information Security Management System (ISMS) in alignment with the ISO 27001 standard across our global delivery locations. At the end of June 2025, approximately 60% of Endava legal entities achieved the ISO 27001 certification.
This certification attests to the strength of our security practices, demonstrating robust controls that are designed to mitigate risks, prevent unauthorised access, and protect confidentiality, integrity and availability of data across our systems.
Download our ISO 27001 certification for Endava UK Limited and contact us for certifications from other locations.
Since April 2024, Endava has maintained Cyber Essentials Certification, a UK government backed programme administered by the National Cyber Security Centre. The certification confirms that we meet fundamental cyber security requirements and are protected against a wide range of common cyber threats. We successfully renewed our certification in April 2025, underscoring our ongoing commitment to security best practices.
Our Berlin office (part of Endava GMBH) and Timisoara office (part of Endava Romania SRL) are registered Trusted Information Security Assessment Exchange (TISAX) participants. TISAX is an internationally recognised standard for data security in the automotive industry. TISAX is a registered trademark and governed by ENX Association.
ISO 22301
We have a comprehensive Business Continuity Management System (BCMS) in accordance with ISO 22301:2019, the international standard for business continuity. It requires tangible plans for delivery locations and IT systems in case of disasters. Our plans are in place and cover a wide array of impact scenarios, ensuring we are well prepared for potential disruptions. By maintaining an agile and adaptive approach to risk assessment and mitigation, we aim to safeguard our operations and ensure continuity of service, regardless of geopolitical developments.

ISO 27001
We continue to expand our Information Security Management System (ISMS) certification to ISO 27001 to all our delivery locations and activities. Successfully maintaining and extending the ISO 27001 attests to our robust security practices and comprehensive risk management approach.
The certification confirms the controls we have in place for the in-scope systems that are designed to mitigate risks, prevent unauthorised access, and maintain the confidentiality, integrity and availability of data.
Download our ISO 27001 certification for Endava UK Limited and contact us for certifications from other locations.

ISO 14001
We are also continuing to maintain our environmental management system across Romania and Moldova. In FY2024, we successfully completed the supervision audit for ISO 14001 certification in 11 locations across the two countries, ensuring ongoing compliance. In FY2024, 48% of Endavans worked in ISO 14001-certified locations.
Download ISO 14001 certificates for our legal entities: Romania, Moldova

ISO 9001
Our intelligent Quality Management System (QMS) is certified to ISO 9001. Through QMS, we ensure the quality of our digital products and services. Our quality assurance process is incorporated into our delivery framework, The Endava Adaptive Model (TEAM). Additionally, our internal audit process and cross-project reviews provide operational monitoring throughout projects to help ensure the highest quality delivery.

SOC 2 Type II Attestation
Since 2021, we have annually undergone SOC 2 Type II audits for operational effectiveness.
In January 2024, we successfully completed our SOC 2 Type II attestation for software development and ‘Run by Endava’ operations for the third year running. This achievement highlights our commitment to the most rigorous controls to ensure data security, availability and confidentiality.
The trust services criteria, developed by the American Institute of Certified Public Accountants (AICPA), are ‘gold standards’ for assessing service provider security.
SOC 2 Type II Attestation
Since 2021, we have annually undergone SOC 2 Type II audits for operational effectiveness.
In January 2024, we successfully completed our SOC 2 Type II attestation for software development and ‘Run by Endava’ operations for the third year running. This achievement highlights our commitment to the most rigorous controls to ensure data security, availability and confidentiality.
The trust services criteria, developed by the American Institute of Certified Public Accountants (AICPA), are ‘gold standards’ for assessing service provider security.
CyberEssentials
In April 2024, Endava became Cyber Essentials Certified. Cyber Essentials certifies organisations through annual assessments that they have the proper level of cyber security protection. This certification is backed by the UK government and overseen by the National Cyber Security Centre.

Trusted Information Security Assessment Exchange (TISAX) Certifications
Our Berlin and Timisoara offices hold Trusted Information Security Assessment Exchange (TISAX) certifications. The TISAX certification is an internationally recognized standard for data security in the automotive industry.
Trusted Information Security Assessment Exchange (TISAX) Certifications
Our Berlin and Timisoara offices hold Trusted Information Security Assessment Exchange (TISAX) certifications. The TISAX certification is an internationally recognized standard for data security in the automotive industry. TISAX is a registered trademark and governed by ENX Association.