NZISM v3.9
NZISM accreditation managed where your evidence already lives.
Structured certification workflow, automated evidence mapping, and audit-ready reporting for NZ government suppliers and agencies. Managed alongside SMB1001 and ISO 27001 from a single platform.
Government agencies
Manage NZISM compliance across multiple systems and classification levels from a single view, with separate reporting for each accreditation scope.
IT service providers
Demonstrate your security posture to NZ government procurement teams. A structured NZISM assessment replaces the ad-hoc questionnaires most suppliers still rely on.
Cloud providers
Prove your platform meets NZ government security requirements across classified and unclassified profiles with auditor-ready evidence packs.
Platform capabilities
Purpose-built for NZ government accreditation.
Applicability scoping
Intelligent scoping identifies which controls apply to your system based on classification level and system profile. Focus only on the controls that matter for your specific accreditation.
Certification lifecycle management
Structured workflow from initiation through certification and ongoing maintenance. Role-based transitions ensure the right people approve each stage, with every action logged immutably.
Control assessment dashboard
Visual progress tracking across all NZISM control sections. Real-time compliance scoring and gap identification, with direct links to the evidence items supporting each control assessment.
Enterprise and system scope
Support for both enterprise-wide and system-specific certifications. Inherited controls are tracked separately from system-specific obligations, reducing duplication across multiple accreditation scopes.
Immutable audit trail
Every action is logged with timestamp and user identity. The complete audit history is available for governance reviews and can be exported for agency or assessor inspection.
Audit-ready reporting
Generate certification reports, compliance summaries, and evidence packs in the format the assessing authority expects. What used to take weeks of manual document assembly takes minutes.
Certification lifecycle
Every stage from initiation to ongoing maintenance.
NZISM accreditation is not a single event. The platform manages the full lifecycle: from initial scoping and evidence collection through assessor review, certification, and continuous compliance monitoring.
Initiation
- Draft
- Submitted
- Under Review
Assessment
- Assessment In Progress
- Assessment Complete
Certification
- Pending Approval
- Certified
- Conditionally Certified
Maintenance
- Active
- Re-certification Required
- Expired
Control coverage
Full NZISM control set. Intelligent applicability filtering.
The platform covers the complete NZISM control set across all security domains. Applicability is filtered automatically based on your system's classification level and profile, so assessors only see the controls that matter for your specific accreditation.
- Information Security Governance
- Personnel Security
- Physical Security
- Information Security
- Communications Security
- System Acquisition and Development
- Access Control
- Incident Management
faster time to accreditation
Average reduction in assessment time vs manual programmes
Classification levels supported
SECRET and above requires additional configuration. Contact us to discuss your requirements.
Common questions about NZISM.
The New Zealand Information Security Manual (NZISM) is the government's security policy and technical guidance for protecting information and systems. It provides security controls and guidelines that organisations must follow when handling government data. NZISM is maintained by the GCSB and is the primary reference for NZ government security accreditation.
Government agencies, contractors, and suppliers handling government data typically need NZISM accreditation. This includes IT service providers, cloud providers, and any organisation processing classified or sensitive government information. Many procurement processes now require evidence of NZISM compliance before a contract can be awarded.
The platform supports all NZISM classification levels from UNCLASSIFIED through to RESTRICTED. Control applicability is automatically adjusted based on your system's classification profile, so you are only assessed against the controls that apply to your specific accreditation scope.
The platform manages the full certification lifecycle through structured, role-based workflow stages, from initial draft through assessment, conditional certification, and active maintenance. Each stage transition is logged with timestamp and user identity, creating an immutable audit trail. Re-certification triggers are tracked automatically so nothing lapses unexpectedly.
Yes. CyberGrape manages SMB1001, ISO 27001, and NZISM from a single platform with a shared evidence library. Where controls overlap across frameworks, evidence collected for one is automatically credited to the others. You manage one evidence library, not three separate programmes.
Timeline depends on system complexity and the classification level being sought. For unclassified systems with good existing security controls, accreditation can be achieved in 8 to 12 weeks. Higher classification levels typically require more extensive assessment and evidence review. CyberGrape's assessment dashboard shows your progress and gaps from day one so you can plan accordingly.
Ready to simplify your NZISM accreditation?
Connect your tools and the platform maps your control coverage automatically. Know where you stand from day one.

