WhatsApp contact icon for Nathan ISO Consulting
WhatsApp contact icon for Nathan ISO Consulting

An Auckland software company of thirty people routinely sells into New Zealand, Australia and somewhere further afield. That is unremarkable here and it creates a problem larger businesses in bigger markets rarely face: three sets of buyer expectations arriving at a company without a dedicated security function.

The New Zealand customer wants to know you understand the Privacy Act. The Australian customer asks about their own regulatory obligations flowing down. The European or American customer asks for something you have never heard of. Answering each separately consumes more effort than the contracts are worth.

Nathan ISO Consulting implements information security management systems under ISO/IEC 27001:2022 for Auckland organisations across software and technology, financial services, health, professional services and government supply.

Why ISO 27001 matters for Auckland businesses

Certification functions as translation. A JAS-ANZ accredited certificate is recognised internationally through the IAF arrangements, which means one assessed position answers buyers in markets with no knowledge of New Zealand law or of your company. For an exporter selling from a market of five million people into markets of twenty-six million and beyond, that recognition does real commercial work.

Government supply is the second driver. Agencies operate under the Protective Security Requirements and the New Zealand Information Security Manual, and those obligations reach suppliers through contract terms. A supplier able to demonstrate certification alongside NZISM alignment answers a large part of an agency assessment in one submission rather than a sequence of them.

The third is scale of exposure relative to size. Auckland holds the country's concentration of financial services, health technology and consumer platforms, and those businesses hold volumes of personal information disproportionate to their headcount. A breach at a forty-person Auckland business can affect a meaningful fraction of the national population, which is a different risk conversation from the same business in Sydney.

What New Zealand does not have

There is no New Zealand equivalent to Australia's critical infrastructure security legislation. What exists is guidance from the National Cyber Security Centre, mandatory requirements applying to government agencies through the Protective Security Requirements and the Information Security Manual, and a proposed regime for critical infrastructure that went through public consultation during 2026 but has not been enacted. Material telling Auckland operators that SOCI-style obligations apply here is describing Australian law. Organisations building capability now will be adapting if a regime arrives; those waiting will be starting.

Legal and regulatory compliance in New Zealand

ObligationWho it captures in AucklandWhat it requires
Privacy Act 2020, IPP 5Most organisations handling personal informationSecurity safeguards reasonable in the circumstances against loss, misuse and unauthorised access
Notifiable privacy breach obligationsAgencies under the Privacy ActNotification to the Privacy Commissioner and affected individuals where serious harm is likely, as soon as practicable. No fixed 72-hour deadline applies
IPP 3AAgencies collecting personal information indirectly, in force since May 2026Reasonable steps to notify individuals where information was obtained from someone other than them
Protective Security RequirementsGovernment agencies and, by contract, their suppliersProtective security governance covering information, personnel and physical security
New Zealand Information Security ManualGovernment agencies and suppliers handling agency informationTechnical and procedural controls for government information systems
Reserve Bank and FMA expectationsRegistered banks, licensed insurers, deposit takers and market participantsOperational resilience and outsourcing arrangements, reaching material service providers by contract
Offshore buyer requirementsExporters selling into Australia, Europe and North AmericaRecognised assurance that travels across jurisdictions without local explanation

New Zealand law sets no fixed notification clock. Runbooks imported from European or Australian templates frequently apply the wrong test and the wrong timeframe, and we correct that during implementation.

Auckland business districts and regions

Auckland locationBusiness activitySecurity driver
Auckland CBD and BritomartFinancial services, insurance, professional services, corporate head officesCustomer assurance, regulator expectations, offshore parent standards
Newmarket and ParnellTechnology, professional services, health administrationEnterprise buyer questionnaires and agency contract terms
Grafton and Grey LynnHealth services, medical research, health technologyHealth information handling and research data obligations
Takapuna and Smales FarmCorporate offices, technology, financial services operationsGroup security standards and supplier assessments
Albany and the North ShoreSoftware, light manufacturing, distribution technologyOffshore customer requirements and product security expectations
Penrose and Mount WellingtonDistribution technology, logistics platforms, manufacturing systemsOperational system exposure alongside corporate networks
East Tāmaki and HighbrookFood manufacturing technology, engineering, warehousing systemsCustomer supply chain requirements and traceability systems
Airport Oaks and MāngereAir freight, aviation services, export logisticsCustomer assurance and cross-border data handling
Ports of Auckland and WynyardTerminal systems, marine services, innovation precinctOperational technology exposure and critical service dependency

Working with us in Auckland

Design and build

Scope is settled first, and for Auckland exporters that usually means deciding which product or service the certificate must cover to satisfy offshore buyers rather than covering the whole company. Then the information asset register, a risk assessment run with your leadership, a Statement of Applicability drawn from your own findings, and control work across access, supplier management, development practice, logging, incident handling and technology recovery. Where agency information is involved, we map the control set against NZISM expectations so a single evidence base serves both audiences.

Reaching the certificate

The New Zealand assessor market is smaller than Australia's and scheduling can be the binding constraint rather than readiness. We start that conversation early, narrow the field to bodies with genuine sector familiarity, and settle terms. Readiness means an internal audit conducted as an external auditor would, findings resolved, and a review recorded. We attend both stages.

Life after the audit

Annual internal audits, surveillance preparation and periodic risk reassessment remain ours. New Zealand privacy law has moved twice recently and the critical infrastructure position is still developing, so we track what affects your obligations. Where a new market or customer requires broader scope, we extend it ahead of the contract rather than after a reviewer queries it.

What gets delivered

  • Scope statement. Wording covering the products, services and markets driving the project, phrased so an offshore buyer reads it as sufficient without explanation.
  • Asset catalogue. Everything you hold, its location, who has access, and what would follow if it were lost or disclosed.
  • Risk assessment and treatment plan. Threat and vulnerability work with criteria agreed at leadership level and treatments owned by named people.
  • Applicability statement. Every one of the ninety-three controls given a position, with reasoning that traces back to your own risk findings instead of a precedent document.
  • Breach response procedure. Built to the New Zealand serious harm test and the obligation to notify as soon as practicable, not to an imported fixed deadline.
  • Audit and review pack. A complete internal audit with every issue closed and confirmed, alongside minutes showing the review addressed each required input.

Where Auckland ISO 27001 projects go wrong

  • Breach runbooks lifted from European templates, applying a 72-hour clock that New Zealand law does not impose and omitting the serious harm assessment it does.
  • Scope drawn across the whole company when offshore buyers only care about one product, making the project larger and slower than it needed to be.
  • Australian regulatory frameworks assumed to apply, particularly critical infrastructure obligations that have no New Zealand equivalent.
  • Control justifications assembled from a template, which the small pool of local assessors recognises immediately.
  • Supplier assurance skipped despite offshore development, cloud hosting and contracted support all sitting inside Annex A expectations.
  • Access reviews never performed, still the most frequently raised finding we see.

Who certifies you, and where we fit

We implement. An accredited body certifies.

Nathan ISO Consulting builds and implements management systems. We do not issue certificates, and no legitimate consultancy does. Your certificate comes from an independent certification body accredited by JAS-ANZ, the accreditation authority established jointly by the New Zealand and Australian governments. Accredited bodies operate under impartiality rules that prohibit them from certifying a system they helped build, which is precisely why the two roles are separate. Our job is to get you audit-ready, help you select the right accredited body, and stand alongside you through assessment.

Choosing the accredited body, agreeing what it costs and fixing when it happens are tasks we absorb, weighed against your scope, your sector and the audit style that suits how you work. We sit through Stage 1 and Stage 2 with your team, and clearing whatever is raised falls to us rather than landing on your desk afterwards. One check worth making yourself: confirm on the JAS-ANZ register that the body holds accreditation for your scope. Unaccredited certificates are cheap and fast, and procurement teams decline them often enough to justify the minute it takes.

FAQ'S

No. We are an implementation consultancy. Certificates are issued by independent certification bodies accredited by JAS-ANZ. Accreditation rules prevent a body from certifying a system it helped build, so the consulting and certification roles must stay separate.

A JAS-ANZ accredited certification body of your choosing. We shortlist accredited bodies against your scope and sector, manage the quote process, and attend both audit stages with you. The certificate and the audit decision rest entirely with them.

Check the JAS-ANZ register and confirm the body is accredited for the specific standard and scope you need. Unaccredited certificates are widely available, inexpensive and routinely rejected by procurement teams, which means paying twice and starting over.

No consultancy honestly can, because the decision belongs to an independent auditor. What we can do is run your internal audit the way an external auditor would, close findings before assessment, and attend both stages so issues get resolved in the room.

Not at present. The Government consulted during 2026 on strengthening critical infrastructure cyber security, including possible legislation, and submissions have closed. Until something is enacted, obligations arrive through the Privacy Act, sector requirements and contracts rather than dedicated infrastructure law.

New Zealand sets no fixed deadline. Where serious harm is likely you must notify the Privacy Commissioner and affected individuals as soon as practicable after becoming aware. The 72-hour figure belongs to European law and does not apply here.

The New Zealand Information Security Manual is issued by the GCSB and is mandatory for government agencies. It reaches suppliers through contract terms rather than directly. Where you handle agency information, your agreement determines what applies.

The current count is ninety-three, grouped under four themes. The earlier structure used fourteen domains and a larger number, so a provider quoting that figure is reading from something published before the last revision.

Yes. A certificate from a JAS-ANZ accredited body carries international recognition through the IAF arrangements, which is much of its commercial value for New Zealand exporters selling into markets that know nothing about your company.

Yes, and for Auckland software businesses it is usually the sensible choice. The scope statement must accurately describe what is covered, because offshore buyers read it closely and a certificate excluding the service they are purchasing will be noticed.

For New Zealand, Australian and European buyers, ISO 27001 generally carries further and produces a certificate rather than a report covering one period. SOC 2 matters mainly for United States enterprise customers. Businesses selling both directions often hold both.

Four to seven months for most organisations. Documentation moves quickly; changing how access, logging and supplier arrangements work does not, and that engineering effort sets the schedule. Assessor availability can also affect timing here.

Only the security dimension. Protecting personal information is one principle among thirteen, with the others covering collection, use, disclosure, access and correction. Privacy management has its own standard, certifiable independently since the 2025 revision.

Yes, throughout both islands. Security work is largely location-independent, so most of a project runs remotely, with travel reserved for assessing physical controls and for the certification audit itself.

Send us the questionnaire

If a customer assessment, an agency contract or an offshore buyer's security pack triggered this, send the document. Reading the actual requirement settles scope faster than a discovery conversation.

CONTACT
Reach out to us for any inquiries, collaborations,
or just to say hello!

Contact information for Nathan ISO Consulting

CLIENTELE
Our Valuable Client

WHEN NUMBERS MATTER
Empowering Insights into our Business Performance