An Auckland software company of thirty people routinely sells into New Zealand, Australia and somewhere further afield. That is unremarkable here and it creates a problem larger businesses in bigger markets rarely face: three sets of buyer expectations arriving at a company without a dedicated security function.
The New Zealand customer wants to know you understand the Privacy Act. The Australian customer asks about their own regulatory obligations flowing down. The European or American customer asks for something you have never heard of. Answering each separately consumes more effort than the contracts are worth.
Nathan ISO Consulting implements information security management systems under ISO/IEC 27001:2022 for Auckland organisations across software and technology, financial services, health, professional services and government supply.
Why ISO 27001 matters for Auckland businesses
Certification functions as translation. A JAS-ANZ accredited certificate is recognised internationally through the IAF arrangements, which means one assessed position answers buyers in markets with no knowledge of New Zealand law or of your company. For an exporter selling from a market of five million people into markets of twenty-six million and beyond, that recognition does real commercial work.
Government supply is the second driver. Agencies operate under the Protective Security Requirements and the New Zealand Information Security Manual, and those obligations reach suppliers through contract terms. A supplier able to demonstrate certification alongside NZISM alignment answers a large part of an agency assessment in one submission rather than a sequence of them.
The third is scale of exposure relative to size. Auckland holds the country's concentration of financial services, health technology and consumer platforms, and those businesses hold volumes of personal information disproportionate to their headcount. A breach at a forty-person Auckland business can affect a meaningful fraction of the national population, which is a different risk conversation from the same business in Sydney.
What New Zealand does not have
| There is no New Zealand equivalent to Australia's critical infrastructure security legislation. What exists is guidance from the National Cyber Security Centre, mandatory requirements applying to government agencies through the Protective Security Requirements and the Information Security Manual, and a proposed regime for critical infrastructure that went through public consultation during 2026 but has not been enacted. Material telling Auckland operators that SOCI-style obligations apply here is describing Australian law. Organisations building capability now will be adapting if a regime arrives; those waiting will be starting. |
Legal and regulatory compliance in New Zealand
| Obligation | Who it captures in Auckland | What it requires |
|---|---|---|
| Privacy Act 2020, IPP 5 | Most organisations handling personal information | Security safeguards reasonable in the circumstances against loss, misuse and unauthorised access |
| Notifiable privacy breach obligations | Agencies under the Privacy Act | Notification to the Privacy Commissioner and affected individuals where serious harm is likely, as soon as practicable. No fixed 72-hour deadline applies |
| IPP 3A | Agencies collecting personal information indirectly, in force since May 2026 | Reasonable steps to notify individuals where information was obtained from someone other than them |
| Protective Security Requirements | Government agencies and, by contract, their suppliers | Protective security governance covering information, personnel and physical security |
| New Zealand Information Security Manual | Government agencies and suppliers handling agency information | Technical and procedural controls for government information systems |
| Reserve Bank and FMA expectations | Registered banks, licensed insurers, deposit takers and market participants | Operational resilience and outsourcing arrangements, reaching material service providers by contract |
| Offshore buyer requirements | Exporters selling into Australia, Europe and North America | Recognised assurance that travels across jurisdictions without local explanation |
New Zealand law sets no fixed notification clock. Runbooks imported from European or Australian templates frequently apply the wrong test and the wrong timeframe, and we correct that during implementation.
Auckland business districts and regions
| Auckland location | Business activity | Security driver |
|---|---|---|
| Auckland CBD and Britomart | Financial services, insurance, professional services, corporate head offices | Customer assurance, regulator expectations, offshore parent standards |
| Newmarket and Parnell | Technology, professional services, health administration | Enterprise buyer questionnaires and agency contract terms |
| Grafton and Grey Lynn | Health services, medical research, health technology | Health information handling and research data obligations |
| Takapuna and Smales Farm | Corporate offices, technology, financial services operations | Group security standards and supplier assessments |
| Albany and the North Shore | Software, light manufacturing, distribution technology | Offshore customer requirements and product security expectations |
| Penrose and Mount Wellington | Distribution technology, logistics platforms, manufacturing systems | Operational system exposure alongside corporate networks |
| East Tāmaki and Highbrook | Food manufacturing technology, engineering, warehousing systems | Customer supply chain requirements and traceability systems |
| Airport Oaks and Māngere | Air freight, aviation services, export logistics | Customer assurance and cross-border data handling |
| Ports of Auckland and Wynyard | Terminal systems, marine services, innovation precinct | Operational technology exposure and critical service dependency |
Working with us in Auckland
Scope is settled first, and for Auckland exporters that usually means deciding which product or service the certificate must cover to satisfy offshore buyers rather than covering the whole company. Then the information asset register, a risk assessment run with your leadership, a Statement of Applicability drawn from your own findings, and control work across access, supplier management, development practice, logging, incident handling and technology recovery. Where agency information is involved, we map the control set against NZISM expectations so a single evidence base serves both audiences.
The New Zealand assessor market is smaller than Australia's and scheduling can be the binding constraint rather than readiness. We start that conversation early, narrow the field to bodies with genuine sector familiarity, and settle terms. Readiness means an internal audit conducted as an external auditor would, findings resolved, and a review recorded. We attend both stages.
Annual internal audits, surveillance preparation and periodic risk reassessment remain ours. New Zealand privacy law has moved twice recently and the critical infrastructure position is still developing, so we track what affects your obligations. Where a new market or customer requires broader scope, we extend it ahead of the contract rather than after a reviewer queries it.
What gets delivered
Where Auckland ISO 27001 projects go wrong
Who certifies you, and where we fit
| We implement. An accredited body certifies. Nathan ISO Consulting builds and implements management systems. We do not issue certificates, and no legitimate consultancy does. Your certificate comes from an independent certification body accredited by JAS-ANZ, the accreditation authority established jointly by the New Zealand and Australian governments. Accredited bodies operate under impartiality rules that prohibit them from certifying a system they helped build, which is precisely why the two roles are separate. Our job is to get you audit-ready, help you select the right accredited body, and stand alongside you through assessment. |
Choosing the accredited body, agreeing what it costs and fixing when it happens are tasks we absorb, weighed against your scope, your sector and the audit style that suits how you work. We sit through Stage 1 and Stage 2 with your team, and clearing whatever is raised falls to us rather than landing on your desk afterwards. One check worth making yourself: confirm on the JAS-ANZ register that the body holds accreditation for your scope. Unaccredited certificates are cheap and fast, and procurement teams decline them often enough to justify the minute it takes.
FAQ'S
No. We are an implementation consultancy. Certificates are issued by independent certification bodies accredited by JAS-ANZ. Accreditation rules prevent a body from certifying a system it helped build, so the consulting and certification roles must stay separate.
A JAS-ANZ accredited certification body of your choosing. We shortlist accredited bodies against your scope and sector, manage the quote process, and attend both audit stages with you. The certificate and the audit decision rest entirely with them.
Check the JAS-ANZ register and confirm the body is accredited for the specific standard and scope you need. Unaccredited certificates are widely available, inexpensive and routinely rejected by procurement teams, which means paying twice and starting over.
No consultancy honestly can, because the decision belongs to an independent auditor. What we can do is run your internal audit the way an external auditor would, close findings before assessment, and attend both stages so issues get resolved in the room.
Not at present. The Government consulted during 2026 on strengthening critical infrastructure cyber security, including possible legislation, and submissions have closed. Until something is enacted, obligations arrive through the Privacy Act, sector requirements and contracts rather than dedicated infrastructure law.
New Zealand sets no fixed deadline. Where serious harm is likely you must notify the Privacy Commissioner and affected individuals as soon as practicable after becoming aware. The 72-hour figure belongs to European law and does not apply here.
The New Zealand Information Security Manual is issued by the GCSB and is mandatory for government agencies. It reaches suppliers through contract terms rather than directly. Where you handle agency information, your agreement determines what applies.
The current count is ninety-three, grouped under four themes. The earlier structure used fourteen domains and a larger number, so a provider quoting that figure is reading from something published before the last revision.
Yes. A certificate from a JAS-ANZ accredited body carries international recognition through the IAF arrangements, which is much of its commercial value for New Zealand exporters selling into markets that know nothing about your company.
Yes, and for Auckland software businesses it is usually the sensible choice. The scope statement must accurately describe what is covered, because offshore buyers read it closely and a certificate excluding the service they are purchasing will be noticed.
For New Zealand, Australian and European buyers, ISO 27001 generally carries further and produces a certificate rather than a report covering one period. SOC 2 matters mainly for United States enterprise customers. Businesses selling both directions often hold both.
Four to seven months for most organisations. Documentation moves quickly; changing how access, logging and supplier arrangements work does not, and that engineering effort sets the schedule. Assessor availability can also affect timing here.
Only the security dimension. Protecting personal information is one principle among thirteen, with the others covering collection, use, disclosure, access and correction. Privacy management has its own standard, certifiable independently since the 2025 revision.
Yes, throughout both islands. Security work is largely location-independent, so most of a project runs remotely, with travel reserved for assessing physical controls and for the certification audit itself.
Send us the questionnaire
If a customer assessment, an agency contract or an offshore buyer's security pack triggered this, send the document. Reading the actual requirement settles scope faster than a discovery conversation.





















0
Projects
0
Services
0
Clients Serving
0
Countries Serving