The Pay Gap

South Africa · paygap.co.za · 22 vendors

A research and advisory firm that helps organisations understand and address their gender pay gap.

Resilience scores

Technology vendors

Insights

Last updated 2026-07-30 · revision 66

22 direct vendors, 249 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 4/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

The Pay Gap's migration readiness is assessed as medium-low, largely due to a critical lack of information regarding its internal technology stack. Without data on whether its systems are cloud-native, containerized, or based on microservices, it is impossible to accurately gauge the technical effort and complexity involved in a migration. The regulatory environment presents significant challenges, with POPIA, GDPR, SOC2, and ISO 27001 all requiring assessment. These regulations, particularly POPIA and GDPR, impose explicit data residency requirements and strict rules for cross-border data transfers, which would add substantial complexity and cost to any cloud migration strategy. While the company utilizes 40 services and has a geographically diverse set of vendor HQ countries (7 unique), the actual number of distinct vendors and the extent of vendor lock-in are unknown. This ambiguity, combined with the potential for numerous dependencies from 40 services, could complicate migration efforts. Financial stability, with 100% revenue concentration in South Africa, could also pose a risk to funding large-scale migration projects if the local market faces economic downturns. Overall, the significant unknowns in technology and the high regulatory burden are the primary impediments to a higher migration readiness score.

Compliance

4 in-scope frameworks identified; showing 3.

POPIA — Assessment Required

Primary data protection law in South Africa and directly applies to The Pay Gap as a South African company processing personal information.

POPIA is the primary data protection law in South Africa and directly applies to The Pay Gap as a South African company. Risk level is High because: (1) It's mandatory for all South African entities processing personal information, (2) Non-compliance can result in fines up to R10 million or 10 years imprisonment, (3) The Information Regulator has been actively enforcing since full implementation in 2021, (4) Consulting companies typically process significant amounts of personal information from clients and employees, (5) Compliance requires comprehensive data governance frameworks.

ISO 27001 (source) — Assessment Required

Highly relevant for consulting companies as it demonstrates systematic information security management and is often required in client contracts.

ISO 27001 is highly relevant for consulting companies as it demonstrates systematic information security management. Risk level is Medium because: (1) Consulting companies handle sensitive client information requiring protection, (2) Many client contracts require ISO 27001 certification or equivalent security standards, (3) Lack of certification can limit business opportunities, (4) Information security incidents can severely damage consulting firm reputation and client trust, (5) While voluntary, it's increasingly expected in the consulting industry.

GDPR (source) — Assessment Required

Applies extraterritorially to any processing of EU/EEA personal data regardless of company location; relevant if the company processes personal data of EU/EEA residents through client engagements, employee data, or business relationships.

While The Pay Gap is headquartered in South Africa (outside EU/EEA), as a consulting company they may process personal data of EU/EEA residents through client engagements, employee data, or business relationships. GDPR applies extraterritorially to any processing of EU/EEA personal data regardless of company location. The risk level is Medium because: (1) Non-compliance fines can be up to 4% of global annual turnover or €20M, (2) Consulting companies often handle client data which may include EU personal data, (3) South African companies increasingly work with EU clients, (4) Enforcement has been active globally since 2018.

Financials

Three-year financials

Financial Resilience Score: 5/10

The organization's resilience is characterized by its mission-driven relevance and lean operational model. As a digital platform, it likely operates with low overhead costs, making it more adaptable to economic shifts than traditional businesses. Its core value lies in its data network effects, where the accumulation of salary data increases the platform's utility and social impact. However, the entity faces financial risks due to its reliance on non-recurring funding sources like grants and donations. Unlike a commercial enterprise with a subscription model, its stability depends on the continued interest of third-party funders or the successful execution of a data-monetization strategy. The long-term viability is contingent on maintaining user trust and data integrity.

Key strengths: Mission-Driven Relevance, Lean Operational Model, Data as an Asset, Data Network Effects

Risk factors: Funding Dependency, Reliance on inconsistent funding streams, Lack of recurring revenue, Data privacy and integrity risks

Revenue by geography

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report