CyberGrape – cyber security certification and GRC platform for small business

NZISM v3.9

NZISM accreditation managed where your evidence already lives.

Structured certification workflow, automated evidence mapping, and audit-ready reporting for NZ government suppliers and agencies. Managed alongside SMB1001 and ISO 27001 from a single platform.

See compliance frameworks

Government agencies

Manage NZISM compliance across multiple systems and classification levels from a single view, with separate reporting for each accreditation scope.

IT service providers

Demonstrate your security posture to NZ government procurement teams. A structured NZISM assessment replaces the ad-hoc questionnaires most suppliers still rely on.

Cloud providers

Prove your platform meets NZ government security requirements across classified and unclassified profiles with auditor-ready evidence packs.

Platform capabilities

Purpose-built for NZ government accreditation.

AI-assisted

Applicability scoping

Intelligent scoping identifies which controls apply to your system based on classification level and system profile. Focus only on the controls that matter for your specific accreditation.

Full lifecycle

Certification lifecycle management

Structured workflow from initiation through certification and ongoing maintenance. Role-based transitions ensure the right people approve each stage, with every action logged immutably.

Real-time

Control assessment dashboard

Visual progress tracking across all NZISM control sections. Real-time compliance scoring and gap identification, with direct links to the evidence items supporting each control assessment.

Flexible

Enterprise and system scope

Support for both enterprise-wide and system-specific certifications. Inherited controls are tracked separately from system-specific obligations, reducing duplication across multiple accreditation scopes.

Governance

Immutable audit trail

Every action is logged with timestamp and user identity. The complete audit history is available for governance reviews and can be exported for agency or assessor inspection.

Automated

Audit-ready reporting

Generate certification reports, compliance summaries, and evidence packs in the format the assessing authority expects. What used to take weeks of manual document assembly takes minutes.

Certification lifecycle

Every stage from initiation to ongoing maintenance.

NZISM accreditation is not a single event. The platform manages the full lifecycle: from initial scoping and evidence collection through assessor review, certification, and continuous compliance monitoring.

01

Initiation

  • Draft
  • Submitted
  • Under Review
02

Assessment

  • Assessment In Progress
  • Assessment Complete
03

Certification

  • Pending Approval
  • Certified
  • Conditionally Certified
04

Maintenance

  • Active
  • Re-certification Required
  • Expired

Control coverage

Full NZISM control set. Intelligent applicability filtering.

The platform covers the complete NZISM control set across all security domains. Applicability is filtered automatically based on your system's classification level and profile, so assessors only see the controls that matter for your specific accreditation.

  • Information Security Governance
  • Personnel Security
  • Physical Security
  • Information Security
  • Communications Security
  • System Acquisition and Development
  • Access Control
  • Incident Management
50%

faster time to accreditation

Average reduction in assessment time vs manual programmes

Classification levels supported

UNCLASSIFIED
IN CONFIDENCE
SENSITIVE
RESTRICTED

SECRET and above requires additional configuration. Contact us to discuss your requirements.

Common questions about NZISM.

Ready to simplify your NZISM accreditation?

Connect your tools and the platform maps your control coverage automatically. Know where you stand from day one.

See compliance frameworks