WhatsApp contact icon for Nathan ISO Consulting
WhatsApp contact icon for Nathan ISO Consulting

Wellington has one buyer that sets the standard for everyone else. When government agencies raise their expectations of suppliers, the whole market moves, and there is no alternative customer base large enough to sell to instead.

For information security that produces an unusually specific set of demands. Agencies operate under the Protective Security Requirements and the New Zealand Information Security Manual, they carry recordkeeping duties under the Public Records Act that most private businesses have never encountered, and they are answerable under the Official Information Act for material a supplier may be holding on their behalf.

Nathan ISO Consulting implements information security management systems under ISO/IEC 27001:2022 for Wellington organisations across ICT suppliers, consultancies, Crown entities, research institutes and professional services.

Looking for an ISO 27001 Consultant in Wellington?

Why ISO 27001 Matters for Wellington Businesses

Eligibility is the blunt reason. A supplier without demonstrable security capability is screened out at the point where an agency assesses risk, and that happens before anyone reads the technical proposal. For a consultancy or ICT business in this city, the practical question is not whether certification is worth the investment but whether the business can operate at scale without it.

Efficiency is the second. A supplier bidding regularly answers the same security questions repeatedly in slightly different formats. Certification converts that into a single assessed position, and the time recovered across a year of submissions frequently exceeds the cost of maintaining the system.

The third reason is recordkeeping, and it catches suppliers off guard. Public records obligations do not disappear because information sits on a contractor’s systems. Where you create or hold records on an agency’s behalf, disposal, retention and accessibility requirements follow the record rather than the server, and an ISMS built without that in mind will have retention arrangements that conflict with the agency’s obligations.

Three Frameworks That Arrive Together in This City

The Protective Security Requirements set governance expectations across information, personnel and physical security for agencies, reaching suppliers by contract. The Information Security Manual issued by the GCSB provides the technical control baseline for government information systems. The Public Records Act imposes recordkeeping obligations that persist wherever the record physically sits. None of the three is ISO 27001, and none of them replaces it. What certification does is give you one control set and one evidence base to answer all three from, rather than maintaining separate responses for each.

Legal and Regulatory Compliance in New Zealand

ObligationWho It Captures in WellingtonWhat It Requires
Protective Security RequirementsGovernment agencies and, through contract, their suppliersSecurity governance covering information, personnel and physical domains
New Zealand Information Security ManualAgencies and suppliers handling agency information systemsTechnical and procedural controls for government information
Public Records Act 2005Public offices and local authorities, with obligations following records held by contractorsCreation, maintenance, retention, disposal and accessibility of public records
Official Information Act 1982Agencies, with implications for information a supplier holds on their behalfAbility to locate and produce information within statutory timeframes
Privacy Act 2020, IPP 5Organisations handling personal informationSecurity safeguards reasonable in the circumstances
Notifiable privacy breach obligationsAgencies under the Privacy ActNotification where serious harm is likely, as soon as practicable. No fixed deadline applies
Government Procurement RulesSuppliers to agenciesCapability assessment within evaluation, with security frequently among the criteria

Agency obligations reach suppliers through contract rather than directly. The agreement determines what you have taken on, and we read it during scoping because it usually sets the ISMS boundary.

Wellington Precincts and the Wider Region

Wellington LocationBusiness ActivitySecurity Driver
Thorndon and PipiteaGovernment departments, ministries, Crown entitiesPSR governance and NZISM control expectations
Lambton Quay and the CBDICT suppliers, consultancies, legal and financial servicesAgency contract security terms and capability assessment
Te Aro and Cuba QuarterSoftware, digital agencies, design and product businessesAgency assurance questions and offshore customer requirements
Kelburn and the university precinctResearch institutes, tertiary education, science organisationsResearch data, ethics conditions and funding requirements
Newtown and hospital precinctHealth services, medical research, clinical supportHealth information under the Act and the health information code
Petone and SeaviewEngineering, scientific services, manufacturing systemsOperational system exposure and agency contract terms
Porirua and TawaGovernment service delivery, logistics, light industryAgency information handled under contract
Kāpiti CoastProfessional services, technology, light manufacturingRemote working arrangements and agency supply
WairarapaAgriculture, food production, regional servicesCustomer requirements and cross-regional operations

Have an agency security schedule or supplier assessment to respond to?

Our Wellington Delivery Approach

Step One – Scope and Build

The boundary is defined around the services you deliver to agencies rather than around the whole organisation, because that is what a procurement reviewer assesses. Asset cataloguing follows, then a risk assessment run with your leadership, an applicability statement built from your own findings, and the control work itself. Where agency information is involved we cross-reference the control set against NZISM expectations and check that retention arrangements align with the agency’s recordkeeping obligations rather than conflicting with them.

Step Two – Assessment

The New Zealand assessor pool is small and scheduling is frequently the constraint rather than readiness, so that conversation starts early. We narrow the field to bodies familiar with public sector supply, settle commercial terms, and bring you to assessment with the audit complete, findings cleared and the review minuted. Both stages attended.

Step Three – Keeping It Alive

Recurring audit work, surveillance preparation and risk reassessment stay with us. Agency expectations shift as frameworks are revised, and a system built for one contract can quietly stop matching the next. Where a new engagement reaches past your certified scope, we widen it before submission rather than explaining a gap during evaluation.

The Documentation You Receive

  • Scope statement. Wording covering the agency services driving the project, phrased so an evaluator accepts it without requesting clarification.
  • Asset catalogue. Everything you hold, where it sits, who can reach it, and what follows if it were lost or disclosed.
  • Risk assessment and treatment plan. Threat and vulnerability work with criteria endorsed by leadership and treatments carrying named owners.
  • Applicability statement. All ninety-three controls positioned with reasoning traceable to your own risk findings.
  • Recordkeeping alignment. Retention and disposal arrangements checked against the public records obligations attaching to agency information you hold.
  • Audit and review pack. Complete internal audit with findings closed and verified, plus minutes showing each required review input was addressed.

Where Wellington ISO 27001 Projects Go Wrong

  • Retention schedules set without reference to the recordkeeping obligations attaching to agency information, creating a direct conflict
  • Scope drawn around the organisation rather than the services the agency is buying, which fails at the first procurement review
  • NZISM treated as something to reference rather than map, so the supplier cannot show which controls satisfy which expectations
  • Reasoning for control decisions borrowed from a precedent document, which assessors working this market spot within minutes
  • Subcontracted delivery left outside the ISMS boundary even though agency information passes through it
  • Access reviews never performed, still the most commonly raised finding we see

Preparing for an upcoming audit?

Who Certifies You, and Where We Fit

We implement. An accredited body certifies.

Nathan ISO Consulting builds and implements management systems. We do not issue certificates, and no legitimate consultancy does. Your certificate comes from an independent certification body accredited by JAS-ANZ, the accreditation authority established jointly by the New Zealand and Australian governments. Accredited bodies operate under impartiality rules that prohibit them from certifying a system they helped build, which is precisely why the two roles are separate. Our job is to get you audit-ready, help you select the right accredited body, and stand alongside you through assessment.

Selecting the accredited body, negotiating the fee and fixing the dates are things we take on, matched to your scope, your sector and the audit approach that fits your operation. Our people are present for Stage 1 and Stage 2, and anything the assessor raises becomes our task rather than a list handed back when they leave. Do one check independently: confirm the JAS-ANZ register shows that body accredited for your scope. Unaccredited certificates are inexpensive and quick to obtain, and procurement teams turn them away often enough to make the check worth a minute.

Send Us the Contract

If an agency agreement or a security schedule prompted this, send the document. Reading the actual clause settles scope more precisely than a discovery conversation, particularly where recordkeeping obligations are involved.

Ready to start your ISO 27001 certification journey?

FAQ'S

No. We are an implementation consultancy. Certificates are issued by independent certification bodies accredited by JAS-ANZ. Accreditation rules prevent a body from certifying a system it helped build, so the consulting and certification roles must stay separate.

A JAS-ANZ accredited certification body of your choosing. We shortlist accredited bodies against your scope and sector, manage the quote process, and attend both audit stages with you. The certificate and the audit decision rest entirely with them.

Check the JAS-ANZ register and confirm the body is accredited for the specific standard and scope you need. Unaccredited certificates are widely available, inexpensive and routinely rejected by procurement teams, which means paying twice and starting over.

No consultancy honestly can, because the decision belongs to an independent auditor. What we can do is run your internal audit the way an external auditor would, close findings before assessment, and attend both stages so issues get resolved in the room.

The obligations rest with the public office, but they follow the records wherever those records are held. Where you create or hold records on an agency’s behalf, retention, disposal and accessibility requirements reach your systems through the contract.

Published by the GCSB, the manual binds government agencies directly. Suppliers pick it up through their contracts instead. If agency information systems pass through your hands, the agreement itself sets out which sections you must meet.

Not by itself, since they are different frameworks with different structures. A certified system supplies most of the underlying capability, and we map the two so you can demonstrate coverage without maintaining separate evidence for each.

Indirectly but practically. Agencies must locate and produce information within statutory timeframes, and where a supplier holds it the agency depends on your ability to retrieve it. Systems designed without that capability create problems for your client.

There is no set number of hours here. If serious harm looks likely, the Commissioner and the people affected must be told without undue delay. Teams applying a 72-hour rule have brought European law to a New Zealand problem.

There are ninety-three across four themes. The previous arrangement ran to fourteen domains with a higher total, so anyone citing that number is reading from pre-revision material.

Sixteen to thirty weeks in most cases. Writing policy is fast; reconfiguring access, logging and supplier arrangements is not, and that engineering effort dictates the schedule. Booking an assessor can add to the end.

Yes, and for consultancies bidding into specific agency work it is often sensible. The scope wording must accurately describe what is covered, because evaluators read it closely and a certificate excluding the service being procured will be noticed.

Nothing is in force. A consultation on lifting critical infrastructure cyber resilience ran through 2026 and closed to submissions. Absent legislation, what binds you comes from privacy law, agency frameworks and whatever your contracts specify.

Yes, including the Hutt Valley, Porirua, Kāpiti and the Wairarapa. Security work is largely location-independent, so most of a project runs remotely with travel reserved for physical control assessment and the audit itself.

CONTACT
Reach out to us for any inquiries, collaborations,
or just to say hello!

Contact information for Nathan ISO Consulting

CLIENTELE
Our Valuable Client

WHEN NUMBERS MATTER
Empowering Insights into our Business Performance