WhatsApp contact icon for Nathan ISO Consulting
WhatsApp contact icon for Nathan ISO Consulting

New Zealand has governed cyber security lightly for a long time. Guidance from the National Cyber Security Centre, mandatory rules for government agencies, and for everyone else a set of expectations enforced mainly by customers and insurers rather than by regulators.

That posture is changing. The Cyber Security Strategy 2026–2030 and its accompanying action plan set out an intention to develop a regulatory regime for critical infrastructure, and the Government consulted on exactly that during 2026. Organisations delivering essential services are being told, in reasonably plain language, that cyber resilience is moving from good practice toward regulatory expectation.

ISO/IEC 27001:2022 is the international standard for information security management systems. Certification is issued by certification bodies accredited by JAS-ANZ, the joint accreditation authority for New Zealand and Australia. Nathan ISO Consulting builds information security management systems for New Zealand organisations across every region.

What New Zealand Does Not Have

New Zealand has no equivalent to Australia’s Security of Critical Infrastructure Act. Content that tells you SOCI obligations apply here is describing the wrong country. What New Zealand has is a voluntary framework backed by NCSC guidance, mandatory requirements for government agencies through the Protective Security Requirements and the New Zealand Information Security Manual, and a proposed regime for critical infrastructure that has been through public consultation but is not yet law.

Looking for an ISO 27001 Consultant in New Zealand?

The Frameworks a New Zealand Organisation Actually Encounters

FrameworkWhat It IsWho It Applies To
ISO/IEC 27001:2022Certifiable international management system standard, 93 Annex A controls across four themesAny organisation. The default answer to a customer security questionnaire
NZISMThe New Zealand Information Security Manual, issued by the GCSBGovernment agencies and, through contract flow-down, their suppliers
Protective Security RequirementsThe Government's mandatory protective security framework covering governance, information, personnel and physical securityPublic sector agencies and contracted providers
NCSC guidanceAdvisories, critical controls guidance and threat intelligenceAll organisations, voluntary
SOC 2US attestation report issued by an audit firm against trust services criteriaOrganisations selling to United States enterprise buyers
Sector requirementsReserve Bank and Financial Markets Authority expectations, health sector rules, and payment scheme requirementsRegulated entities and their material suppliers

These are not alternatives to one another. A New Zealand software company selling to government agencies and offshore enterprise commonly needs ISO 27001 certification, an ability to demonstrate NZISM alignment, and a SOC 2 report. The ISMS is what makes the other two manageable rather than three separate programmes.

The Legal Obligations Underneath

ISO 27001 is voluntary. Several of the things it helps you handle are not.

Privacy Act 2020

Information Privacy Principle 5 requires agencies to protect personal information with security safeguards that are reasonable in the circumstances. Since December 2020 New Zealand has had mandatory notification for privacy breaches likely to cause serious harm, reported to the Office of the Privacy Commissioner and to affected individuals as soon as practicable. Note the wording: New Zealand does not apply a fixed 72-hour clock, and importing a European runbook without adjusting it produces the wrong process.

Sector Obligations

Financial institutions carry Reserve Bank and Financial Markets Authority expectations around operational resilience and outsourcing. Health providers work within health information privacy rules. Telecommunications operators carry obligations under network security legislation. None of these mandate ISO 27001, and all of them are easier to evidence with it.

Contractual Obligations

For most New Zealand businesses this is where the pressure actually arrives. Government procurement, enterprise supply agreements and cyber insurance applications increasingly require demonstrable security capability, and a certificate answers in one line what would otherwise take a site visit.

Have a customer questionnaire or government tender to respond to?

What We Do, and How the Project Runs

Sixteen to twenty-eight weeks is realistic. Control implementation is the long phase because it involves genuine technical change rather than documentation.

PhaseWhat Happens
Weeks 1–4: Scoping and gap analysisWhich services, systems, locations and people sit inside the ISMS boundary. Scope decisions drive everything downstream and are difficult to change later. Then a written gap register against the 93 Annex A controls and the Clause 4 to 10 requirements.
Weeks 3–9: Risk assessment and treatmentInformation asset inventory, threat and vulnerability analysis, risk criteria agreed with management, and a risk treatment plan with named owners rather than functions.
Weeks 8–11: Statement of ApplicabilityEvery one of the 93 controls addressed with a justification for inclusion or exclusion drawn from your own risk assessment. Auditors examine this document more closely than any other, and template justifications are obvious.
Weeks 9–22: Control implementationPolicies, access control, supplier security, secure development, logging and monitoring, incident response, ICT continuity. Where NZISM alignment is also required, we map both against one control set so evidence is produced once.
Weeks 20–25: Internal audit and management reviewFull internal audit against all clauses and applicable controls, findings closed, documented review with leadership.
Weeks 24–28: CertificationCertification body selection from JAS-ANZ accredited bodies, then Stage 1 and Stage 2. We attend both and close out findings ourselves.

Why New Zealand Organisations Engage Us

  • We do not import Australian frameworks. There is no SOCI Act here, the privacy regime works differently, and NZISM is not the Australian ISM. Content and controls copied across the Tasman create findings.
  • We map NZISM and ISO 27001 together where both apply. Government suppliers frequently need both. Building them as one control set halves the evidence burden.
  • We write the breach runbook to New Zealand law. Serious harm assessment and notification as soon as practicable, not a 72-hour European clock that does not apply here.
  • We scope honestly. A narrow ISMS you can evidence beats a company-wide scope you cannot. Your customers read the scope statement on the certificate.
  • We track the critical infrastructure consultation. If regulation lands, organisations with a functioning ISMS will be adapting rather than starting. We will tell you where the proposals sit rather than selling on a threat that has not materialised.
  • We stay past the certificate. Surveillance preparation, annual risk reassessment and the evidence cycle that keeps certification live.

Where We Work

Auckland accounts for the largest share of our New Zealand information security work, across software and SaaS, financial services, professional services and health technology. Wellington work is weighted toward government suppliers and organisations facing Protective Security Requirements flow-down.

Christchurch work spans technology, aerospace and manufacturing, with Canterbury’s post-earthquake rebuild having produced an unusually resilience-literate business community. We also work with organisations in Hamilton, Tauranga, Palmerston North, Napier, Hastings, Nelson, Dunedin, Whangārei, New Plymouth, Rotorua, Queenstown and Invercargill. Most of an ISO 27001 project runs remotely, with attendance on site where physical security controls or data centres need assessment in person.

Preparing for an upcoming audit?

Send Us the Questionnaire

If a customer security questionnaire or a government tender triggered this, send it through. Reading the actual requirement is faster than guessing at scope, and occasionally it turns out you need something narrower.

Ready to start your ISO 27001 certification journey?

FAQ'S

Not currently. The Government consulted during 2026 on measures to strengthen critical infrastructure cyber security, including potential legislation, and submissions have closed. Until a regime is enacted, obligations arrive through the Privacy Act, sector rules and contracts rather than dedicated infrastructure legislation.

Only if you also operate a critical infrastructure asset in Australia. New Zealand has no equivalent statute. Guidance suggesting SOCI obligations apply to New Zealand operations is describing Australian law and should be treated with caution.

Annex A of the 2022 edition contains 93 controls grouped into four themes: organisational, people, physical and technological. This replaced the 2013 structure of 114 controls across 14 domains. Material still citing 114 controls predates the current edition.

NZISM is the New Zealand Information Security Manual, issued by the GCSB and mandatory for government agencies. ISO 27001 is a voluntary, certifiable management system standard. Government suppliers often need to demonstrate both, and they map against one another reasonably well.

It supports Information Privacy Principle 5 by demonstrating reasonable security safeguards, but it is not a privacy standard. For privacy management specifically, ISO/IEC 27701:2025 is the applicable standard and can now be certified independently of ISO 27001.

There is no fixed deadline. Where a breach is likely to cause serious harm, you must notify the Privacy Commissioner and affected individuals as soon as practicable after becoming aware. The 72-hour figure comes from the GDPR and does not apply here.

ISO 27001 is more widely recognised in New Zealand, Australian and European procurement, and it is a certifiable standard rather than an attestation report. SOC 2 carries more weight with United States enterprise buyers. Companies selling into both markets frequently hold both.

Yes, and it is common for SaaS companies. The scope statement on your certificate must accurately describe what is covered, and prospective customers will read it, so scope to what you can genuinely evidence rather than to what sounds impressive.

Several JAS-ANZ accredited bodies operate across New Zealand and Australia. We shortlist against your scope, sector and preferred audit approach, and confirm current accreditation coverage before recommending anyone.

Typically 16 to 28 weeks. Control implementation is the longest phase because it involves real technical change. Organisations with mature security practice already in place, or with an existing NZISM alignment programme, move considerably faster.

All of them. Our work concentrates in Auckland, Wellington and Christchurch, with clients in Hamilton, Tauranga, Dunedin, Palmerston North, Napier, Nelson and Whangārei. Most of the project runs remotely, with on-site attendance where physical controls need assessment.

It depends on your certificate scope. If the New Zealand entity, its systems and its people are named within the scope, yes. If not, the scope needs extending. We review certificate wording before assuming either way, because customers read it literally.

CONTACT
Reach out to us for any inquiries, collaborations,
or just to say hello!

Contact information for Nathan ISO Consulting

CLIENTELE
Our Valuable Client

WHEN NUMBERS MATTER
Empowering Insights into our Business Performance