Compliance Frameworks
Compliance that wins business, not just ticks boxes.
Maps every SMB1001 control to your current posture, collects evidence automatically from your connected tools, and tells you exactly what is missing.
SMB1001
Five tiers. One platform. Start wherever you are.
The platform tracks your progress across every tier simultaneously. Implement controls in any order; the platform maps them to the tier they satisfy as you go.
Foundation controls: MFA, patch management, and basic access control. Self-attested. No external auditor required.
Expands into email security, backup, and endpoint protection. Still self-attested, but evidence is verified against tool outputs.
The most commonly requested certification tier. Requires a CyberCert-accredited assessor review. Evidence pack compiled automatically by the platform.
Advanced controls for organisations with elevated risk profiles: supply chain risk, penetration testing, and board-level governance.
The highest SMB1001 tier. SOC-equivalent rigour for organisations in regulated sectors or critical supply chains.
Control counts are cumulative. Diamond includes all 39 controls from Bronze through Diamond.
Framework support
Standards and frameworks. One evidence library.
SMB1001
39 controls across 5 tiers
The primary cybersecurity standard for NZ small and medium businesses. All five tiers from Bronze through Diamond are managed from a single view. Progress across every tier is tracked simultaneously so you always know your next milestone.
ISO 27001:2022
93 Annex A controls
Statement of Applicability management built into the platform. Assign implementation status, attach evidence, and track progress against all 93 Annex A controls. Evidence collected for SMB1001 is automatically mapped to its ISO 27001 equivalent where controls overlap.
NZISM v3.9
Classified and unclassified profiles
For organisations operating in or supplying to New Zealand government. NZISM controls are managed alongside SMB1001 and ISO 27001 from the same interface, with separate reporting where required by the agency or procurement process.
SOC 2
Trust Services Criteria
Type I and Type II assurance reporting against the AICPA Trust Services Criteria. Manage your security, availability, confidentiality, processing integrity, and privacy controls from the same evidence library used for your other frameworks.
NIST CSF 2.0
6 functions, 22 categories
The updated NIST Cybersecurity Framework, increasingly referenced in NZ and AU enterprise procurement. Map your existing controls to the Govern, Identify, Protect, Detect, Respond, and Recover functions.
ISO 42001:2023
AI management system controls
The international standard for AI management systems. As AI becomes embedded in business operations, ISO 42001 provides the governance framework for responsible development, deployment, and monitoring of AI tools.
How it works
From posture baseline to issued certificate.
Most organisations approach certification backwards. They pick a target tier, read the control list, and then try to work out what evidence they have. That process takes months and wastes time on controls that are already covered.
CyberGrape starts from what you have. Connect your tools, and the platform maps your current posture to the control framework automatically. You see your gaps on day one, and evidence arrives continuously as your tools report in, not assembled manually before every assessment.
Connect your existing tools. The platform maps every control to your current posture automatically. No manual survey or spreadsheet required.
Every gap is ranked by effort and impact. A prioritised remediation roadmap tells you what to fix first to reach your target tier in the shortest time.
As you implement controls, evidence arrives automatically from your connected tools. Patch compliance from NinjaOne. Training records from uSecure. No manual uploads for what your tools already capture.
When you are ready to certify, the platform generates your evidence pack in the format your certifier needs. What used to take weeks of preparation takes minutes.
For Gold and above, a CyberCert-accredited assessor reviews your evidence pack. CyberGrape works with CyberCert to take your readiness through to an issued certificate and verifiable digital badge.
Certification is not a point-in-time achievement. The platform monitors your controls continuously so you know the moment something drifts, not at your annual renewal conversation.
Automated evidence
Your tools are already collecting evidence. The platform maps it.
Every piece of evidence pulled from a connected integration is automatically mapped to the controls it satisfies across SMB1001, ISO 27001, and NZISM simultaneously. When a control is covered, it is marked. When it lapses, you are alerted.
Average across CyberGrape clients at Gold certification
Policies, procedures, meeting minutes, and vendor agreements must be uploaded directly. The platform shows exactly which controls need manual evidence and what format the assessor expects.
Common questions.
CyberGrape currently supports SMB1001 (all five tiers from Bronze to Diamond), ISO 27001:2022 Statement of Applicability, and NZISM v3.9, all from a single platform. SOC 2, NIST CSF 2.0, and ISO 42001 are coming soon. Controls are mapped across standards and frameworks where they overlap, so evidence collected for one often satisfies another.
SMB1001 is New Zealand's small-and-medium business cybersecurity standard, developed by NZCS. It provides five certification tiers (Bronze through Diamond) that demonstrate your security posture to clients, insurers, and regulators. Gold certification is increasingly required by enterprise procurement and government supply chains.
Most businesses reach SMB1001 Gold within 4–8 weeks using the CyberGrape Platform, depending on how many controls are already in place. The platform maps your current posture automatically so you can see exactly where you stand from day one. There is no preliminary discovery phase before the work can begin.
Bronze and Silver are self-attested: you declare compliance and the platform verifies your evidence against connected tool outputs. Gold, Platinum, and Diamond require a CyberCert-accredited assessor to review your evidence pack. CyberGrape works with CyberCert to coordinate that process once your evidence is ready.
When you connect your existing security tools (such as CrowdStrike, NinjaOne, PowerDMARC, or uSecure), the platform pulls evidence directly from them and maps it to the relevant compliance controls. No manual uploads are needed for the controls your tools already cover. Evidence that requires manual attachment, such as policies, procedures, and meeting minutes, can be uploaded directly in the platform.
No. CyberGrape manages SMB1001, ISO 27001, and NZISM from a single platform. Where controls overlap across standards and frameworks, evidence collected for one is automatically mapped to the others. You manage one evidence library, not three.
The platform continues to monitor your controls after certification. If a control drifts out of compliance: a patch policy lapses, a training completion rate drops, you are alerted immediately. Your certification remains current, and renewals are straightforward because evidence is collected continuously rather than assembled from scratch at renewal time.
Ready to see your compliance gaps?
Connect your tools and the platform maps your controls automatically. Know exactly where you stand against your target tier in minutes.

