Wellington has one buyer that sets the standard for everyone else. When government agencies raise their expectations of suppliers, the whole market moves, and there is no alternative customer base large enough to sell to instead.
For information security that produces an unusually specific set of demands. Agencies operate under the Protective Security Requirements and the New Zealand Information Security Manual, they carry recordkeeping duties under the Public Records Act that most private businesses have never encountered, and they are answerable under the Official Information Act for material a supplier may be holding on their behalf.
Nathan ISO Consulting implements information security management systems under ISO/IEC 27001:2022 for Wellington organisations across ICT suppliers, consultancies, Crown entities, research institutes and professional services.
Looking for an ISO 27001 Consultant in Wellington?
Why ISO 27001 Matters for Wellington Businesses
Eligibility is the blunt reason. A supplier without demonstrable security capability is screened out at the point where an agency assesses risk, and that happens before anyone reads the technical proposal. For a consultancy or ICT business in this city, the practical question is not whether certification is worth the investment but whether the business can operate at scale without it.
Efficiency is the second. A supplier bidding regularly answers the same security questions repeatedly in slightly different formats. Certification converts that into a single assessed position, and the time recovered across a year of submissions frequently exceeds the cost of maintaining the system.
The third reason is recordkeeping, and it catches suppliers off guard. Public records obligations do not disappear because information sits on a contractor’s systems. Where you create or hold records on an agency’s behalf, disposal, retention and accessibility requirements follow the record rather than the server, and an ISMS built without that in mind will have retention arrangements that conflict with the agency’s obligations.
Three Frameworks That Arrive Together in This City
The Protective Security Requirements set governance expectations across information, personnel and physical security for agencies, reaching suppliers by contract. The Information Security Manual issued by the GCSB provides the technical control baseline for government information systems. The Public Records Act imposes recordkeeping obligations that persist wherever the record physically sits. None of the three is ISO 27001, and none of them replaces it. What certification does is give you one control set and one evidence base to answer all three from, rather than maintaining separate responses for each.
Legal and Regulatory Compliance in New Zealand
| Obligation | Who It Captures in Wellington | What It Requires |
|---|---|---|
| Protective Security Requirements | Government agencies and, through contract, their suppliers | Security governance covering information, personnel and physical domains |
| New Zealand Information Security Manual | Agencies and suppliers handling agency information systems | Technical and procedural controls for government information |
| Public Records Act 2005 | Public offices and local authorities, with obligations following records held by contractors | Creation, maintenance, retention, disposal and accessibility of public records |
| Official Information Act 1982 | Agencies, with implications for information a supplier holds on their behalf | Ability to locate and produce information within statutory timeframes |
| Privacy Act 2020, IPP 5 | Organisations handling personal information | Security safeguards reasonable in the circumstances |
| Notifiable privacy breach obligations | Agencies under the Privacy Act | Notification where serious harm is likely, as soon as practicable. No fixed deadline applies |
| Government Procurement Rules | Suppliers to agencies | Capability assessment within evaluation, with security frequently among the criteria |
Agency obligations reach suppliers through contract rather than directly. The agreement determines what you have taken on, and we read it during scoping because it usually sets the ISMS boundary.
Wellington Precincts and the Wider Region
| Wellington Location | Business Activity | Security Driver |
|---|---|---|
| Thorndon and Pipitea | Government departments, ministries, Crown entities | PSR governance and NZISM control expectations |
| Lambton Quay and the CBD | ICT suppliers, consultancies, legal and financial services | Agency contract security terms and capability assessment |
| Te Aro and Cuba Quarter | Software, digital agencies, design and product businesses | Agency assurance questions and offshore customer requirements |
| Kelburn and the university precinct | Research institutes, tertiary education, science organisations | Research data, ethics conditions and funding requirements |
| Newtown and hospital precinct | Health services, medical research, clinical support | Health information under the Act and the health information code |
| Petone and Seaview | Engineering, scientific services, manufacturing systems | Operational system exposure and agency contract terms |
| Porirua and Tawa | Government service delivery, logistics, light industry | Agency information handled under contract |
| Kāpiti Coast | Professional services, technology, light manufacturing | Remote working arrangements and agency supply |
| Wairarapa | Agriculture, food production, regional services | Customer requirements and cross-regional operations |
Have an agency security schedule or supplier assessment to respond to?
Our Wellington Delivery Approach
The boundary is defined around the services you deliver to agencies rather than around the whole organisation, because that is what a procurement reviewer assesses. Asset cataloguing follows, then a risk assessment run with your leadership, an applicability statement built from your own findings, and the control work itself. Where agency information is involved we cross-reference the control set against NZISM expectations and check that retention arrangements align with the agency’s recordkeeping obligations rather than conflicting with them.
The New Zealand assessor pool is small and scheduling is frequently the constraint rather than readiness, so that conversation starts early. We narrow the field to bodies familiar with public sector supply, settle commercial terms, and bring you to assessment with the audit complete, findings cleared and the review minuted. Both stages attended.
Recurring audit work, surveillance preparation and risk reassessment stay with us. Agency expectations shift as frameworks are revised, and a system built for one contract can quietly stop matching the next. Where a new engagement reaches past your certified scope, we widen it before submission rather than explaining a gap during evaluation.
The Documentation You Receive
Where Wellington ISO 27001 Projects Go Wrong
Preparing for an upcoming audit?
Who Certifies You, and Where We Fit
We implement. An accredited body certifies.
Nathan ISO Consulting builds and implements management systems. We do not issue certificates, and no legitimate consultancy does. Your certificate comes from an independent certification body accredited by JAS-ANZ, the accreditation authority established jointly by the New Zealand and Australian governments. Accredited bodies operate under impartiality rules that prohibit them from certifying a system they helped build, which is precisely why the two roles are separate. Our job is to get you audit-ready, help you select the right accredited body, and stand alongside you through assessment.
Selecting the accredited body, negotiating the fee and fixing the dates are things we take on, matched to your scope, your sector and the audit approach that fits your operation. Our people are present for Stage 1 and Stage 2, and anything the assessor raises becomes our task rather than a list handed back when they leave. Do one check independently: confirm the JAS-ANZ register shows that body accredited for your scope. Unaccredited certificates are inexpensive and quick to obtain, and procurement teams turn them away often enough to make the check worth a minute.
Send Us the Contract
If an agency agreement or a security schedule prompted this, send the document. Reading the actual clause settles scope more precisely than a discovery conversation, particularly where recordkeeping obligations are involved.
Ready to start your ISO 27001 certification journey?
FAQ'S
No. We are an implementation consultancy. Certificates are issued by independent certification bodies accredited by JAS-ANZ. Accreditation rules prevent a body from certifying a system it helped build, so the consulting and certification roles must stay separate.
A JAS-ANZ accredited certification body of your choosing. We shortlist accredited bodies against your scope and sector, manage the quote process, and attend both audit stages with you. The certificate and the audit decision rest entirely with them.
Check the JAS-ANZ register and confirm the body is accredited for the specific standard and scope you need. Unaccredited certificates are widely available, inexpensive and routinely rejected by procurement teams, which means paying twice and starting over.
No consultancy honestly can, because the decision belongs to an independent auditor. What we can do is run your internal audit the way an external auditor would, close findings before assessment, and attend both stages so issues get resolved in the room.
The obligations rest with the public office, but they follow the records wherever those records are held. Where you create or hold records on an agency’s behalf, retention, disposal and accessibility requirements reach your systems through the contract.
Published by the GCSB, the manual binds government agencies directly. Suppliers pick it up through their contracts instead. If agency information systems pass through your hands, the agreement itself sets out which sections you must meet.
Not by itself, since they are different frameworks with different structures. A certified system supplies most of the underlying capability, and we map the two so you can demonstrate coverage without maintaining separate evidence for each.
Indirectly but practically. Agencies must locate and produce information within statutory timeframes, and where a supplier holds it the agency depends on your ability to retrieve it. Systems designed without that capability create problems for your client.
There is no set number of hours here. If serious harm looks likely, the Commissioner and the people affected must be told without undue delay. Teams applying a 72-hour rule have brought European law to a New Zealand problem.
There are ninety-three across four themes. The previous arrangement ran to fourteen domains with a higher total, so anyone citing that number is reading from pre-revision material.
Sixteen to thirty weeks in most cases. Writing policy is fast; reconfiguring access, logging and supplier arrangements is not, and that engineering effort dictates the schedule. Booking an assessor can add to the end.
Yes, and for consultancies bidding into specific agency work it is often sensible. The scope wording must accurately describe what is covered, because evaluators read it closely and a certificate excluding the service being procured will be noticed.
Nothing is in force. A consultation on lifting critical infrastructure cyber resilience ran through 2026 and closed to submissions. Absent legislation, what binds you comes from privacy law, agency frameworks and whatever your contracts specify.
Yes, including the Hutt Valley, Porirua, Kāpiti and the Wairarapa. Security work is largely location-independent, so most of a project runs remotely with travel reserved for physical control assessment and the audit itself.





















0
Projects
0
Services
0
Clients Serving
0
Countries Serving