BlogCompliance
September 23, 2026

What is NZISM? Guide to New Zealand's Information Security Manual

Written by
Sarah Cottone
Sr. Content Marketing Manager
Reviewed by
Evan Rowse
GRC Subject Matter Expert

Accelerating security solutions for small businesses 

Tagore offers strategic services to small businesses. 

A partnership that can scale 

Tagore prioritized finding a managed compliance partner with an established product, dedicated support team, and rapid release rate.

Standing out from competitors

Tagore's partnership with Vanta enhances its strategic focus and deepens client value, creating differentiation in a competitive market.

Organisations working with the New Zealand Government are expected to demonstrate robust information security practices while handling data and systems. NZISM is a mandatory baseline for NZ Government agencies (under the PSR) and supplier/vendor obligations flow contractually from that baseline to the organisations they work with. To support this, the Government Communications Security Bureau (GCSB), through its National Cyber Security Centre (NCSC), developed and maintains the New Zealand Information Security Manual. NZISM contains approximately 1,700 security controls, and understanding how they fit into the Certification and Accreditation (C&A) process can be far more challenging than implementing them.

In this guide, you’ll learn:

  • What NZISM expects
  • What the C&A process entails
  • How NZISM overlaps with ISO/IEC 27001

What is the New Zealand Information Security Manual?

The New Zealand Information Security Manual (NZISM) is the Government’s playbook for protecting information and systems against evolving security and cyber risks. It’s part of the broader Protective Security Requirements (PSR) framework, which establishes expectations for the management of personnel, information, and physical security, as directed by NZ’s Cabinet.

The goal of NZISM is to break down the processes and controls essential for protecting government data, systems, and services. The framework also establishes a consistent approach to assurance across all covered entities.

NZISM requires entities to interpret and implement approximately 1,700 controls organised across 23 chapters ranging from information security to physical security. A common mistake organisations make when pursuing compliance is treating the controls like a checklist. Instead, they need to determine which controls apply based on risk assessments.

“NZISM is risk-based for its SHOULD and SHOULD NOT controls, where implementation depth should follow your risk assessment. Its baseline MUST and MUST NOT controls aren't optional based on risk appetite; they apply to every system, and the only way out is a formal dispensation from the Accreditation Authority.”

Evan Rowse

NZISM controls also distinguish between baseline requirements and recommended good practices. Baseline requirements use “must” and “must not” statements, while practice recommendations rely on “should” and “should not.” For example:

Requirement type Examples
Baseline requirement
  • Organisations must implement multi-factor authentication
  • Production systems must not use default or vendor-provided passwords
Good practice
recommendation
  • Systems should be configured to minimise unnecessary data collection
  • User accounts should not be granted privileges beyond their role

As an information security framework for government systems, NZISM receives regular updates to cover evolving risks and cyber resilience best practices. The latest update to version 3.9 was in November 2025, reflecting changes in areas such as authentication, access controls, and incident reporting.

{{cta_withimage12="/cta-blocks"}} | Starting compliance ebook

Who must comply with NZISM?

NZISM applies to New Zealand Government departments, agencies and organisations, including systems operated by them or on their behalf. However, the Government also encourages other entities to align with NZISM, including:

  • Crown entities 
  • Local government
  • Private sector organisations

Compliance requirements extend beyond the organisation itself. NZISM applies to information and systems operated by or on behalf of NZ Government agencies. This means significant third parties handling agency information or systems fall within its scope even though they aren't government bodies themselves. Third-party obligations are imposed contractually rather than by statute, and flow down only when an agency chooses or is required to write them into a supplier agreement. These obligations are assessed as part of the agency's own certification and accreditation of the system. Any third party collaborating with NZISM covered entities needs to demonstrate compliance throughout the vendor lifecycle, supported by documentation and ongoing assurance rather than a one-time attestation.

“Vendors selling to the government often assume NZISM doesn't apply to them because it's written for agencies. It doesn't, directly, but the agency has no choice but to push it into your contract, so you inherit it anyway. Build the foundation before you tender. Retrofitting it after you've won the work is the expensive way to learn this.”

Evan Rowse

Alignment with NZISM is demonstrated through the Certification and Accreditation process, which requires organisations to provide proof of ongoing compliance to maintain accreditation.

NZISM vs ISO 27001

Both NZISM and ISO 27001 take a risk-based approach to managing data security. However, there are notable differences between the two:

Differentiator NZISM ISO 27001
Data classification Uses NZ classification system:
1. Unclassified
2. IN-CONFIDENCE
3. SENSITIVE
4. RESTRICTED
5. CONFIDENTIAL
6. SECRET
7. TOP-SECRET
Requires an information classification scheme, but doesn’t prescribe labels or tiers, letting organisations determine what’s appropriate
Cryptography Highly prescriptive, with a chapter specifying algorithms, protocols, and implementation Requires a documented policy on cryptography, but allows organisations to determine appropriate measures
Certification Agencies undergo the NZISM Certification and Accreditation (C&A) process with verification from the Certification Authority. The Accreditation Authority makes the accreditation decision Organisations undergo a third-party audit conducted by an accredited body
Framework
structure
Provides a detailed catalogue of security controls that organisations evaluate for applicability based on risk Defines requirements for a formal information security management system (ISMS) that organisations use to assess information security risks, with Annex A providing a reference control set

The differences are more around structure and level of prescription, but their controls align across many underlying security areas.

“NZISM runs a very large control catalog. ISO 27001 Annex A gives you 93 controls at a fairly high level of abstraction, NZISM goes much deeper into the operational detail. Organisations pursuing both can use ISO 27001 to set up the management system foundation, and NZISM to guide the detailed safeguards underneath it.”

Evan Rowse

{{cta_withimage2="/cta-blocks"}} | ISO 27001 checklist

The NZISM Certification and Accreditation (C&A) process

The NZISM C&A process determines whether an assessed system can be formally accredited to operate and involves four key roles:

  1. System Owners: Responsible for design, development, system documentation and maintenance, including any requests for recertification and reaccreditation
  2. Certification Authority: Responsible for reviewing documentation and information to ensure ICT systems meet their description and minimum baseline requirements
  3. Assessor: Conducts inspections, audits, and reviews as instructed by the Certification Authority
  4. Accreditation Authority: Reviews the Certification Authority’s recommendation and grants accreditation if the residual risk is within acceptable levels

The assessment consists of five steps:

  1. Establish scope
  2. Gap analysis
  3. Review and initial audit report
  4. Remediation and implementation
  5. Final audit

Step 1: Establish scope

The first step of the NZISM C&A process is to establish the scope of your assessment. The goal is to ensure your audit focuses on the right systems and you pick the right controls for your risk environment.

When defining scope, consider the following criteria:

  • In-scope systems: Identify the systems, applications, services, and infrastructure that will be included in your assessment. This defines which assets the C&A process will evaluate.
  • Type of information handled: Determine the type and sensitivity of information each system stores or processes. More sensitive or higher-risk information will require more stringent security measures.
  • Other relevant frameworks to align with: Consider other frameworks your systems should align with. For example, New Zealand Government Agencies will also have to align with PSR, which provides the broader security framework for NZISM.

Bonus reads: Key compliance frameworks in Australia and Essential Eight (Australia’s version of NZISM)

Step 2: Gap analysis

Next, assess your existing security posture against NZISM’s criteria. Identify which controls already meet requirements and where gaps need to be addressed. Determine the applicability of each control and the degree of implementation your risk environment requires.

Your risk assessment should include third parties where relevant. NZISM extends to systems operated by or on behalf of government agencies, so verify that they meet relevant NZISM requirements by reviewing their controls and security documentation.

When you’ve identified the gaps, implement missing or incomplete controls based on your risk environment and the sensitivity of the data. Document justifications for any exceptions, partial implementations, and other remediation actions as you go. This evidence forms part of your certification package for the formal assessment.

Step 3: Review and initial audit report

At this stage, the Certification Authority and/or the Assessor, depending on your certification process, will review the certification package and determine whether your implementations meet NZISM standards.

As part of the assessments, they may:

  • Interview relevant stakeholders to confirm that security policies and procedures are followed in practice
  • Stress test controls to verify their effectiveness
  • Identify remaining compliance gaps and areas that may require additional evidence

The findings go into the assessor’s certification report, which serves as the basis for remediation and guides you to cover any gaps before accreditation can be granted.

To maintain the integrity of the assessment, the assessor should not have conflicts of interest during the evaluation. That's one reason NZISM separates the C&A roles.

{{cta_withimage15="/cta-blocks"}} | ISO 27001 templates

Step 4: Remediation and implementation

Once you’ve received the assessor’s certification report, use it to address any identified gaps from the evaluation. Depending on the findings, this can include updating or implementing controls, strengthening policies and procedures, and preparing additional evidence to demonstrate NZISM compliance.

When the remediations are complete, address any residual risks using one of the four risk treatment strategies:

  1. Mitigate: Implement controls that reduce the likelihood and impact of risk
  2. Accept: Acknowledge and accept the remaining risk within your defined tolerance levels
  3. Avoid: Eliminate the risk by stopping or changing the activity that causes it
  4. Transfer: Shift some of the risk to a third party using contractual agreements or insurance

Continue documenting your remediation work, control implementations, and the rationale behind decisions so you can include the evidence in the accreditation package you submit to the Accreditation Authority.

Step 5: Final audit

For the final audit, the Accreditation Authority will review your fully submitted certification package and then make one of three decisions:

  1. Full accreditation: The organisation meets NZISM criteria, and residual risks are appropriate for the system and type of information it processes.
  2. Interim accreditation: The organisation currently can’t meet an NZISM requirement, so it’s granted a time-limited accreditation subject to specified conditions or remediation requirements. This is distinct from a waiver, which is a documented, approved exception to a specific NZISM control.
  3. Denied: The organisation can’t demonstrate appropriate risk mitigation measures, and isn’t granted accreditation.

Accreditation should be renewed at least every two years. NZISM specifies that once three years has elapsed between accreditations, the authority to operate the system is invalidated, so agencies typically plan reaccreditation on a two-year cycle with a maximum one-year grace period. Between accreditation cycles, organisations are expected to continuously monitor the effectiveness of their risk-based controls, evaluate changes to their risk profile, and update controls as necessary.

It’s critical to use the best automated GRC solutions if you’re aligning with frameworks that have strict control criteria and require ongoing oversight. Platforms like Vanta enable long-term compliance across multiple global security and compliance frameworks by automating risk management, gap remediation, and continuous oversight.

Build the foundation for NZISM compliance with Vanta

In New Zealand’s evolving compliance landscape, relying on manual control checks and scattered spreadsheets is no longer viable when security frameworks increasingly demand demonstrable continuous oversight.

Vanta is the #1 agentic trust management platform that helps you streamline your compliance program with agentic workflows, continuous monitoring, evidence collection, and risk management. You can use the platform’s ISO 27001 software to build a strong foundation for NZISM alignment, while custom framework capabilities can help you add NZISM controls, with support from Vanta’s New Zealand-based GRC team.

Vanta’s compliance management features include:

  • 1,400+ automated control tests supported by 400+ integrations
  • Vanta AI, which adjusts policies to your operating environment
  • Automated access reviews and requests
  • Risk management workflows
  • Internal audit support

Schedule a custom demo to get a more personalised walkthrough of how Vanta can support your compliance journey.

{{cta_simple2="/cta-blocks"}} | ISO 27001 demo

Access Review Stage Content / Functionality
Across all stages
  • Easily create and save a new access review at a point in time
  • View detailed audit evidence of historical access reviews
Setup access review procedures
  • Define a global access review procedure that stakeholders can follow, ensuring consistency and mitigation of human error in reviews
  • Set your access review frequency (monthly, quarterly, etc.) and working period/deadlines
Consolidate account access data from systems
  • Integrate systems using dozens of pre-built integrations, or “connectors”. System account and HRIS data is pulled into Vanta.
  • Upcoming integrations include Zoom and Intercom (account access), and Personio (HRIS)
  • Upload access files from non-integrated systems
  • View and select systems in-scope for the review
Review, approve, and deny user access
  • Select the appropriate systems reviewer and due date
  • Get automatic notifications and reminders to systems reviewer of deadlines
  • Automatic flagging of “risky” employee accounts that have been terminated or switched departments
  • Intuitive interface to see all accounts with access, account accept/deny buttons, and notes section
  • Track progress of individual systems access reviews and see accounts that need to be removed or have access modified
  • Bulk sort, filter, and alter accounts based on account roles and employee title
Assign remediation tasks to system owners
  • Built-in remediation workflow for reviewers to request access changes and for admin to view and manage requests
  • Optional task tracker integration to create tickets for any access changes and provide visibility to the status of tickets and remediation
Verify changes to access
  • Focused view of accounts flagged for access changes for easy tracking and management
  • Automated evidence of remediation completion displayed for integrated systems
  • Manual evidence of remediation can be uploaded for non-integrated systems
Report and re-evaluate results
  • Auditor can log into Vanta to see history of all completed access reviews
  • Internals can see status of reviews in progress and also historical review detail
FEATURED VANTA RESOURCE

The ultimate guide to scaling your compliance program

Learn how to scale, manage, and optimize alongside your business goals.