New Zealand has governed cyber security lightly for a long time. Guidance from the National Cyber Security Centre, mandatory rules for government agencies, and for everyone else a set of expectations enforced mainly by customers and insurers rather than by regulators.
That posture is changing. The Cyber Security Strategy 2026–2030 and its accompanying action plan set out an intention to develop a regulatory regime for critical infrastructure, and the Government consulted on exactly that during 2026. Organisations delivering essential services are being told, in reasonably plain language, that cyber resilience is moving from good practice toward regulatory expectation.
ISO/IEC 27001:2022 is the international standard for information security management systems. Certification is issued by certification bodies accredited by JAS-ANZ, the joint accreditation authority for New Zealand and Australia. Nathan ISO Consulting builds information security management systems for New Zealand organisations across every region.
What New Zealand Does Not Have
New Zealand has no equivalent to Australia’s Security of Critical Infrastructure Act. Content that tells you SOCI obligations apply here is describing the wrong country. What New Zealand has is a voluntary framework backed by NCSC guidance, mandatory requirements for government agencies through the Protective Security Requirements and the New Zealand Information Security Manual, and a proposed regime for critical infrastructure that has been through public consultation but is not yet law.
Looking for an ISO 27001 Consultant in New Zealand?
The Frameworks a New Zealand Organisation Actually Encounters
| Framework | What It Is | Who It Applies To |
|---|---|---|
| ISO/IEC 27001:2022 | Certifiable international management system standard, 93 Annex A controls across four themes | Any organisation. The default answer to a customer security questionnaire |
| NZISM | The New Zealand Information Security Manual, issued by the GCSB | Government agencies and, through contract flow-down, their suppliers |
| Protective Security Requirements | The Government's mandatory protective security framework covering governance, information, personnel and physical security | Public sector agencies and contracted providers |
| NCSC guidance | Advisories, critical controls guidance and threat intelligence | All organisations, voluntary |
| SOC 2 | US attestation report issued by an audit firm against trust services criteria | Organisations selling to United States enterprise buyers |
| Sector requirements | Reserve Bank and Financial Markets Authority expectations, health sector rules, and payment scheme requirements | Regulated entities and their material suppliers |
These are not alternatives to one another. A New Zealand software company selling to government agencies and offshore enterprise commonly needs ISO 27001 certification, an ability to demonstrate NZISM alignment, and a SOC 2 report. The ISMS is what makes the other two manageable rather than three separate programmes.
The Legal Obligations Underneath
ISO 27001 is voluntary. Several of the things it helps you handle are not.
Information Privacy Principle 5 requires agencies to protect personal information with security safeguards that are reasonable in the circumstances. Since December 2020 New Zealand has had mandatory notification for privacy breaches likely to cause serious harm, reported to the Office of the Privacy Commissioner and to affected individuals as soon as practicable. Note the wording: New Zealand does not apply a fixed 72-hour clock, and importing a European runbook without adjusting it produces the wrong process.
Financial institutions carry Reserve Bank and Financial Markets Authority expectations around operational resilience and outsourcing. Health providers work within health information privacy rules. Telecommunications operators carry obligations under network security legislation. None of these mandate ISO 27001, and all of them are easier to evidence with it.
For most New Zealand businesses this is where the pressure actually arrives. Government procurement, enterprise supply agreements and cyber insurance applications increasingly require demonstrable security capability, and a certificate answers in one line what would otherwise take a site visit.
Have a customer questionnaire or government tender to respond to?
What We Do, and How the Project Runs
Sixteen to twenty-eight weeks is realistic. Control implementation is the long phase because it involves genuine technical change rather than documentation.
| Phase | What Happens |
|---|---|
| Weeks 1–4: Scoping and gap analysis | Which services, systems, locations and people sit inside the ISMS boundary. Scope decisions drive everything downstream and are difficult to change later. Then a written gap register against the 93 Annex A controls and the Clause 4 to 10 requirements. |
| Weeks 3–9: Risk assessment and treatment | Information asset inventory, threat and vulnerability analysis, risk criteria agreed with management, and a risk treatment plan with named owners rather than functions. |
| Weeks 8–11: Statement of Applicability | Every one of the 93 controls addressed with a justification for inclusion or exclusion drawn from your own risk assessment. Auditors examine this document more closely than any other, and template justifications are obvious. |
| Weeks 9–22: Control implementation | Policies, access control, supplier security, secure development, logging and monitoring, incident response, ICT continuity. Where NZISM alignment is also required, we map both against one control set so evidence is produced once. |
| Weeks 20–25: Internal audit and management review | Full internal audit against all clauses and applicable controls, findings closed, documented review with leadership. |
| Weeks 24–28: Certification | Certification body selection from JAS-ANZ accredited bodies, then Stage 1 and Stage 2. We attend both and close out findings ourselves. |
Why New Zealand Organisations Engage Us
Where We Work
Auckland accounts for the largest share of our New Zealand information security work, across software and SaaS, financial services, professional services and health technology. Wellington work is weighted toward government suppliers and organisations facing Protective Security Requirements flow-down.
Christchurch work spans technology, aerospace and manufacturing, with Canterbury’s post-earthquake rebuild having produced an unusually resilience-literate business community. We also work with organisations in Hamilton, Tauranga, Palmerston North, Napier, Hastings, Nelson, Dunedin, Whangārei, New Plymouth, Rotorua, Queenstown and Invercargill. Most of an ISO 27001 project runs remotely, with attendance on site where physical security controls or data centres need assessment in person.
Preparing for an upcoming audit?
Send Us the Questionnaire
If a customer security questionnaire or a government tender triggered this, send it through. Reading the actual requirement is faster than guessing at scope, and occasionally it turns out you need something narrower.
Ready to start your ISO 27001 certification journey?
FAQ'S
Not currently. The Government consulted during 2026 on measures to strengthen critical infrastructure cyber security, including potential legislation, and submissions have closed. Until a regime is enacted, obligations arrive through the Privacy Act, sector rules and contracts rather than dedicated infrastructure legislation.
Only if you also operate a critical infrastructure asset in Australia. New Zealand has no equivalent statute. Guidance suggesting SOCI obligations apply to New Zealand operations is describing Australian law and should be treated with caution.
Annex A of the 2022 edition contains 93 controls grouped into four themes: organisational, people, physical and technological. This replaced the 2013 structure of 114 controls across 14 domains. Material still citing 114 controls predates the current edition.
NZISM is the New Zealand Information Security Manual, issued by the GCSB and mandatory for government agencies. ISO 27001 is a voluntary, certifiable management system standard. Government suppliers often need to demonstrate both, and they map against one another reasonably well.
It supports Information Privacy Principle 5 by demonstrating reasonable security safeguards, but it is not a privacy standard. For privacy management specifically, ISO/IEC 27701:2025 is the applicable standard and can now be certified independently of ISO 27001.
There is no fixed deadline. Where a breach is likely to cause serious harm, you must notify the Privacy Commissioner and affected individuals as soon as practicable after becoming aware. The 72-hour figure comes from the GDPR and does not apply here.
ISO 27001 is more widely recognised in New Zealand, Australian and European procurement, and it is a certifiable standard rather than an attestation report. SOC 2 carries more weight with United States enterprise buyers. Companies selling into both markets frequently hold both.
Yes, and it is common for SaaS companies. The scope statement on your certificate must accurately describe what is covered, and prospective customers will read it, so scope to what you can genuinely evidence rather than to what sounds impressive.
Several JAS-ANZ accredited bodies operate across New Zealand and Australia. We shortlist against your scope, sector and preferred audit approach, and confirm current accreditation coverage before recommending anyone.
Typically 16 to 28 weeks. Control implementation is the longest phase because it involves real technical change. Organisations with mature security practice already in place, or with an existing NZISM alignment programme, move considerably faster.
All of them. Our work concentrates in Auckland, Wellington and Christchurch, with clients in Hamilton, Tauranga, Dunedin, Palmerston North, Napier, Nelson and Whangārei. Most of the project runs remotely, with on-site attendance where physical controls need assessment.
It depends on your certificate scope. If the New Zealand entity, its systems and its people are named within the scope, yes. If not, the scope needs extending. We review certificate wording before assuming either way, because customers read it literally.





















0
Projects
0
Services
0
Clients Serving
0
Countries Serving