ISO 27001 Certification in New Zealand

Yellow circular logo with intertwined abstract shapes next to "Business Continuity Management (BCM).
EASMLens external attack surface management platform logo
NSPM network security policy management logo
PhishLens phishing simulation and awareness logo

ISO 27001 certification gives New Zealand organisations independent proof that they protect information properly, which government agencies, enterprise customers, Australian partners and insurers increasingly ask for. Security Solution Consultants (SSC) helps businesses and public sector suppliers in Auckland, Wellington, Christchurch and across New Zealand build an information security management system (ISMS), align it with New Zealand requirements such as the NZISM and the Protective Security Requirements, and prepare for certification by an accredited certification body.

Unfurling fern frond on an information security binder beside a padlock, representing ISO 27001 certification in New Zealand
ISO 27001 is the internationally recognised way to show New Zealand customers that their information is in safe hands.

Why New Zealand organisations certify to ISO 27001

  • Government contracts. Public sector agencies work to the Protective Security Requirements and the New Zealand Information Security Manual (NZISM), and pass security obligations on to their suppliers. ISO 27001 certification is a widely accepted way for suppliers to show they meet those expectations.
  • Enterprise and trans-Tasman customers. Larger customers in New Zealand and Australia use security questionnaires in procurement. A certificate answers many of those questions in one document.
  • Privacy obligations. Information Privacy Principle 5 of the Privacy Act 2020 requires reasonable security safeguards for personal information, and serious privacy breaches must be notified to the Privacy Commissioner. An ISMS gives you a structured way to meet and evidence those duties.
  • Health sector requirements. Organisations handling health information work to HISO 10029, the Health Information Security Framework, which an ISO 27001 ISMS supports well.
  • Cyber insurance and investors. Insurers and investors look for evidence of mature security governance, and certification provides it.

ISO 27001 and New Zealand security frameworks

New Zealand frameworkHow ISO 27001 helps
Protective Security Requirements (PSR)The PSR sets the government’s expectations for security governance, information, personnel and physical security. An ISMS provides the governance, risk management and continual improvement the PSR expects.
NZ Information Security Manual (NZISM)The NZISM is the technical control baseline for government systems. Many of its controls map to ISO 27001 Annex A, so one control set can support both.
Privacy Act 2020IPP5 security safeguards and notifiable privacy breach duties are supported by access control, incident management and supplier controls in the ISMS.
HISO 10029 Health Information Security FrameworkHealth providers and their suppliers can map HISO 10029 requirements to an ISO 27001 ISMS and evidence both together.
NCSC Minimum Cyber Security StandardsGovernment organisations working to the NCSC minimum standards, such as patching and multi-factor authentication, can track them as controls within the ISMS.

If your obligations sit mainly in government work, we can also assess you directly against the PSR or NZISM. See our cyber security services in New Zealand.

ISO 27001 consultants for New Zealand organisations

  • Gap assessment against ISO/IEC 27001:2022 clauses 4 to 10 and all 93 Annex A controls, with a prioritised plan.
  • ISMS scope that fits your business, including trans-Tasman scopes covering New Zealand and Australian operations.
  • Risk assessment and treatment, Statement of Applicability, policies and procedures written for how New Zealand teams actually work.
  • Control implementation support for Microsoft 365, Google Workspace, AWS and Azure environments, identity and access, supplier security and incident response.
  • Internal audit and management review, run independently of the people who built the ISMS.
  • Certification audit support through Stage 1 and Stage 2 with your chosen certification body.
  • Ongoing ISMS support for surveillance audits, using GRCLens to keep evidence and controls current.

Supplying the New Zealand public sector

Professionals reviewing documents in a meeting room overlooking a hilly harbour city, representing a New Zealand government supplier meeting security requirements
Government agencies pass their security expectations on to the suppliers who handle their information.

When agencies move services to the cloud or outsource information handling, they assess supplier risk and often ask for evidence of an independently audited security program. ISO 27001 certification, together with clear answers about data location, access control, incident notification and subcontractors, makes those assessments faster. We help suppliers prepare that evidence, respond to agency security questionnaires, and map their ISMS to the PSR and NZISM controls the agency cares about.

Protecting health information

Clinician holding a tablet with a secure records interface in a hospital corridor, representing protecting health information in New Zealand
Health information is among the most sensitive data any organisation holds.

Health providers, health technology companies and suppliers to Health New Zealand handle information where a breach causes real harm. We help health organisations build an ISO 27001 ISMS that also evidences HISO 10029 requirements, with particular attention to access to clinical systems, supplier access, logging, and incident response that meets Privacy Act notification duties.

How certification works in New Zealand

  1. Choose an accredited certification body. In New Zealand and Australia, certification bodies are accredited by JAS-ANZ, the Joint Accreditation System of Australia and New Zealand, or another member of the International Accreditation Forum.
  2. Build and operate the ISMS. Scope, risk assessment, Statement of Applicability, controls, and enough operation to produce evidence.
  3. Internal audit and management review. Required by clauses 9.2 and 9.3 before certification.
  4. Stage 1 audit. The auditor reviews documentation and readiness.
  5. Stage 2 audit. The auditor tests whether the ISMS works in practice. Success leads to a certificate, usually valid for three years with annual surveillance audits.

Because accreditation is joint across both countries, one certificate covers a trans-Tasman scope. SSC prepares you for certification; the certificate itself is issued by the independent certification body. For a broader view of the standards we support, see security certification and accreditation services.

Common gaps we see in New Zealand organisations

  • Cloud services outside the asset register. SaaS tools adopted by individual teams, with no owner, access review or supplier assessment.
  • Multi-factor authentication with exceptions. Enforced for most staff but not for administrators, service accounts or remote access.
  • Supplier security assumed, not checked. Managed service providers with broad administrator access and no contractual security or notification terms.
  • Incident response without privacy steps. Technical plans that do not include assessing serious harm and notifying the Privacy Commissioner.
  • Backups that have never been restored. Backup jobs that run every night but have not been tested end to end.

Each of these is a common audit finding, and each is fixable well before the certification audit when the gap assessment finds it early.

What you receive

  • A gap assessment report and prioritised implementation plan
  • ISMS scope, policy, objectives, risk method, risk register and treatment plan
  • A Statement of Applicability covering all 93 Annex A controls, mapped to NZISM, PSR or HISO 10029 where relevant
  • Proportionate policies and procedures
  • An independent internal audit and management review records
  • Support through the Stage 1 and Stage 2 audits and any corrective actions

Timeframes and cost

Most of the effort sits in building and operating the ISMS rather than in the audits. A focused scope with existing security practices can reach the Stage 1 audit within a few months; larger or multi-site scopes take longer. Costs depend on scope, number of staff and sites, and how much is already in place. Our guide to ISO 27001 certification costs explains the cost components, which follow the same structure in New Zealand.

ISO 27001 certification in Auckland, Wellington and Christchurch

We support organisations in Auckland, Wellington, Christchurch, Hamilton, Tauranga, Dunedin and across New Zealand, with on-site workshops where they help and remote work where they do not. For a wider security review before certification, see our cyber security audit in Auckland and our guide on how to choose a cybersecurity consultant in New Zealand. Organisations in Australia should see ISO 27001 certification in Australia.

SSC is itself certified to ISO/IEC 27001, so we prepare you from experience. Contact us to scope your certification.

Frequently asked questions

Independent certification bodies accredited for ISO/IEC 27001, usually by JAS-ANZ, the Joint Accreditation System of Australia and New Zealand. Consultants such as SSC prepare you for certification but do not issue certificates.

No law requires it for private organisations. It is often expected in government, enterprise and health sector procurement, and it helps you meet Privacy Act 2020 security obligations and supplier requirements.

The PSR and NZISM apply to government agencies and flow to their suppliers through contracts. Many NZISM controls map to ISO 27001 Annex A, so a certified ISMS provides strong evidence and a structure for meeting the rest.

Yes. JAS-ANZ accreditation covers both countries, and the ISMS scope can include operations on both sides of the Tasman.

It depends on scope and starting point. A focused scope with good existing practices can be ready for the Stage 1 audit within a few months, with Stage 2 following once the ISMS has operated long enough to produce evidence.

Not always, but health providers and suppliers are expected to meet HISO 10029. Building an ISO 27001 ISMS is an efficient way to meet and evidence those requirements while gaining an internationally recognised certificate.