Share this article

What is NZISM? Guide to New Zealand's Information Security Manual
Accelerating security solutions for small businesses Tagore offers strategic services to small businesses. | A partnership that can scale Tagore prioritized finding a managed compliance partner with an established product, dedicated support team, and rapid release rate. | Standing out from competitors Tagore's partnership with Vanta enhances its strategic focus and deepens client value, creating differentiation in a competitive market. |
Organisations working with the New Zealand Government are expected to demonstrate robust information security practices while handling data and systems. NZISM is a mandatory baseline for NZ Government agencies (under the PSR) and supplier/vendor obligations flow contractually from that baseline to the organisations they work with. To support this, the Government Communications Security Bureau (GCSB), through its National Cyber Security Centre (NCSC), developed and maintains the New Zealand Information Security Manual. NZISM contains approximately 1,700 security controls, and understanding how they fit into the Certification and Accreditation (C&A) process can be far more challenging than implementing them.
In this guide, you’ll learn:
- What NZISM expects
- What the C&A process entails
- How NZISM overlaps with ISO/IEC 27001
What is the New Zealand Information Security Manual?
The New Zealand Information Security Manual (NZISM) is the Government’s playbook for protecting information and systems against evolving security and cyber risks. It’s part of the broader Protective Security Requirements (PSR) framework, which establishes expectations for the management of personnel, information, and physical security, as directed by NZ’s Cabinet.
The goal of NZISM is to break down the processes and controls essential for protecting government data, systems, and services. The framework also establishes a consistent approach to assurance across all covered entities.
NZISM requires entities to interpret and implement approximately 1,700 controls organised across 23 chapters ranging from information security to physical security. A common mistake organisations make when pursuing compliance is treating the controls like a checklist. Instead, they need to determine which controls apply based on risk assessments.
NZISM controls also distinguish between baseline requirements and recommended good practices. Baseline requirements use “must” and “must not” statements, while practice recommendations rely on “should” and “should not.” For example:
As an information security framework for government systems, NZISM receives regular updates to cover evolving risks and cyber resilience best practices. The latest update to version 3.9 was in November 2025, reflecting changes in areas such as authentication, access controls, and incident reporting.
{{cta_withimage12="/cta-blocks"}} | Starting compliance ebook
Who must comply with NZISM?
NZISM applies to New Zealand Government departments, agencies and organisations, including systems operated by them or on their behalf. However, the Government also encourages other entities to align with NZISM, including:
- Crown entities
- Local government
- Private sector organisations
Compliance requirements extend beyond the organisation itself. NZISM applies to information and systems operated by or on behalf of NZ Government agencies. This means significant third parties handling agency information or systems fall within its scope even though they aren't government bodies themselves. Third-party obligations are imposed contractually rather than by statute, and flow down only when an agency chooses or is required to write them into a supplier agreement. These obligations are assessed as part of the agency's own certification and accreditation of the system. Any third party collaborating with NZISM covered entities needs to demonstrate compliance throughout the vendor lifecycle, supported by documentation and ongoing assurance rather than a one-time attestation.
Alignment with NZISM is demonstrated through the Certification and Accreditation process, which requires organisations to provide proof of ongoing compliance to maintain accreditation.
NZISM vs ISO 27001
Both NZISM and ISO 27001 take a risk-based approach to managing data security. However, there are notable differences between the two:
The differences are more around structure and level of prescription, but their controls align across many underlying security areas.
{{cta_withimage2="/cta-blocks"}} | ISO 27001 checklist
The NZISM Certification and Accreditation (C&A) process
The NZISM C&A process determines whether an assessed system can be formally accredited to operate and involves four key roles:
- System Owners: Responsible for design, development, system documentation and maintenance, including any requests for recertification and reaccreditation
- Certification Authority: Responsible for reviewing documentation and information to ensure ICT systems meet their description and minimum baseline requirements
- Assessor: Conducts inspections, audits, and reviews as instructed by the Certification Authority
- Accreditation Authority: Reviews the Certification Authority’s recommendation and grants accreditation if the residual risk is within acceptable levels
The assessment consists of five steps:
- Establish scope
- Gap analysis
- Review and initial audit report
- Remediation and implementation
- Final audit
Step 1: Establish scope
The first step of the NZISM C&A process is to establish the scope of your assessment. The goal is to ensure your audit focuses on the right systems and you pick the right controls for your risk environment.
When defining scope, consider the following criteria:
- In-scope systems: Identify the systems, applications, services, and infrastructure that will be included in your assessment. This defines which assets the C&A process will evaluate.
- Type of information handled: Determine the type and sensitivity of information each system stores or processes. More sensitive or higher-risk information will require more stringent security measures.
- Other relevant frameworks to align with: Consider other frameworks your systems should align with. For example, New Zealand Government Agencies will also have to align with PSR, which provides the broader security framework for NZISM.
Bonus reads: Key compliance frameworks in Australia and Essential Eight (Australia’s version of NZISM)
Step 2: Gap analysis
Next, assess your existing security posture against NZISM’s criteria. Identify which controls already meet requirements and where gaps need to be addressed. Determine the applicability of each control and the degree of implementation your risk environment requires.
Your risk assessment should include third parties where relevant. NZISM extends to systems operated by or on behalf of government agencies, so verify that they meet relevant NZISM requirements by reviewing their controls and security documentation.
When you’ve identified the gaps, implement missing or incomplete controls based on your risk environment and the sensitivity of the data. Document justifications for any exceptions, partial implementations, and other remediation actions as you go. This evidence forms part of your certification package for the formal assessment.
Step 3: Review and initial audit report
At this stage, the Certification Authority and/or the Assessor, depending on your certification process, will review the certification package and determine whether your implementations meet NZISM standards.
As part of the assessments, they may:
- Interview relevant stakeholders to confirm that security policies and procedures are followed in practice
- Stress test controls to verify their effectiveness
- Identify remaining compliance gaps and areas that may require additional evidence
The findings go into the assessor’s certification report, which serves as the basis for remediation and guides you to cover any gaps before accreditation can be granted.
To maintain the integrity of the assessment, the assessor should not have conflicts of interest during the evaluation. That's one reason NZISM separates the C&A roles.
{{cta_withimage15="/cta-blocks"}} | ISO 27001 templates
Step 4: Remediation and implementation
Once you’ve received the assessor’s certification report, use it to address any identified gaps from the evaluation. Depending on the findings, this can include updating or implementing controls, strengthening policies and procedures, and preparing additional evidence to demonstrate NZISM compliance.
When the remediations are complete, address any residual risks using one of the four risk treatment strategies:
- Mitigate: Implement controls that reduce the likelihood and impact of risk
- Accept: Acknowledge and accept the remaining risk within your defined tolerance levels
- Avoid: Eliminate the risk by stopping or changing the activity that causes it
- Transfer: Shift some of the risk to a third party using contractual agreements or insurance
Continue documenting your remediation work, control implementations, and the rationale behind decisions so you can include the evidence in the accreditation package you submit to the Accreditation Authority.
Step 5: Final audit
For the final audit, the Accreditation Authority will review your fully submitted certification package and then make one of three decisions:
- Full accreditation: The organisation meets NZISM criteria, and residual risks are appropriate for the system and type of information it processes.
- Interim accreditation: The organisation currently can’t meet an NZISM requirement, so it’s granted a time-limited accreditation subject to specified conditions or remediation requirements. This is distinct from a waiver, which is a documented, approved exception to a specific NZISM control.
- Denied: The organisation can’t demonstrate appropriate risk mitigation measures, and isn’t granted accreditation.
Accreditation should be renewed at least every two years. NZISM specifies that once three years has elapsed between accreditations, the authority to operate the system is invalidated, so agencies typically plan reaccreditation on a two-year cycle with a maximum one-year grace period. Between accreditation cycles, organisations are expected to continuously monitor the effectiveness of their risk-based controls, evaluate changes to their risk profile, and update controls as necessary.
It’s critical to use the best automated GRC solutions if you’re aligning with frameworks that have strict control criteria and require ongoing oversight. Platforms like Vanta enable long-term compliance across multiple global security and compliance frameworks by automating risk management, gap remediation, and continuous oversight.
Build the foundation for NZISM compliance with Vanta
In New Zealand’s evolving compliance landscape, relying on manual control checks and scattered spreadsheets is no longer viable when security frameworks increasingly demand demonstrable continuous oversight.
Vanta is the #1 agentic trust management platform that helps you streamline your compliance program with agentic workflows, continuous monitoring, evidence collection, and risk management. You can use the platform’s ISO 27001 software to build a strong foundation for NZISM alignment, while custom framework capabilities can help you add NZISM controls, with support from Vanta’s New Zealand-based GRC team.
Vanta’s compliance management features include:
- 1,400+ automated control tests supported by 400+ integrations
- Vanta AI, which adjusts policies to your operating environment
- Automated access reviews and requests
- Risk management workflows
- Internal audit support
Schedule a custom demo to get a more personalised walkthrough of how Vanta can support your compliance journey.
{{cta_simple2="/cta-blocks"}} | ISO 27001 demo





FEATURED VANTA RESOURCE
The ultimate guide to scaling your compliance program
Learn how to scale, manage, and optimize alongside your business goals.
















.png)



