Built for NZISM C&A · ISO 27001 · Essential Eight

Your compliance programme,
finally under control

The New Zealand system certification and accreditation workspace for government agencies, suppliers, and assessors — with structured C&A workflows, risk tracking, evidence management, and board-ready reports.

Version-aware NZISM C&A workflow
ISO 27001
Essential Eight
Hosted in NZ
Privacy Act 2020

Current regulatory context

3.9

Current NZISM version

published by the NCSC and required as the current baseline for prescribed agencies undertaking applicable system work

Consultation

Critical-infrastructure reform

DPMC consulted in 2026 on potential cyber-security regulation; proposals remain subject to policy and Cabinet decisions

Evidence

Defensible governance

system owners and governance teams need a current record of scope, risks, controls, evidence, decisions, and assurance

Regulatory proposals are not current law. AccreditAZ helps organisations maintain the evidence and workflow needed for current assurance obligations.

The C&A Pipeline

A structured path from system registration to accreditation

AccreditAZ breaks the certification and accreditation process into clear phases with gate checks. Know exactly where every system stands — and what's needed to move forward.

1
Initiation

Document system purpose, boundaries, and stakeholders

2
Characterisation

Classify data, users, and system components

3
Risk Assessment

Identify threats, vulnerabilities, and residual risks

4
Controls

Map, assess, and evidence each required control

5
Certification

Assessor sign-off that controls are in place

6
Accreditation

Formal approval + exportable compliance report

Annual re-certification built in

When a cycle completes, start a new one with one click. Previous cycles are archived and preserved — so you always have a complete history for auditors.

The Platform

Everything compliance in one portal

Replace the spreadsheets, shared drives, and email chains with a single platform that manages your full compliance lifecycle.

Systems & C&A Pipeline

Register systems, assign frameworks, and work through a structured certification pipeline with gate checks. Know the status of every system at a glance.

Control Library & Common Controls

Implement a control once — it applies across every system that shares it. Evidence attached to a common control satisfies multiple frameworks simultaneously. No duplicate effort.

Risk Register

Full risk register with 5×5 likelihood/impact matrix, treatment plans (Accept, Mitigate, Transfer, Avoid), risk owners, and review scheduling. The risk management programme your legislation requires.

Incident Management

Log, triage, and track security incidents from detection to closure. Timeline entries, severity ratings, owner assignments, and a post-incident review workflow. Fully auditable.

Evidence Vault & Policy Library

Upload evidence, set expiry dates, and link directly to controls across systems. Manage policies with version history and review cycles. Expiring evidence flagged automatically.

Director & Board Reports

Board-ready compliance reports with plain-language summaries — no technical jargon. Compliance score, open risks, incidents, and policy status. Scheduled email delivery to directors.

Supplier Risk Management

Track third-party vendors by criticality, record security assessments, attach supplier documentation, and set review schedules. Know your supply chain risk at a glance.

Waivers & Exceptions

Formally document control exceptions with residual risk justification, approver sign-off, and expiry dates. Every waiver is tracked and flagged when it lapses. Auditors love this.

Roles, Scoping & Multi-Org Access

Invite internal staff, external assessors, and auditors with scoped access — limit to specific systems, set expiry dates, assign roles (Admin, Assessor, Auditor, Read-only). One login, multiple organisations.

📋

Audit Log

Every action logged with timestamp, user, and IP. Exportable CSV for external audits.

📊

Scheduled Reports

Compliance summaries delivered by email weekly, monthly, or quarterly — automatically.

🤖

Az AI Assistant

Built-in AI support agent. Ask about NZISM controls, get guidance, raise a support ticket — inside the portal.

🔐

MFA & Magic Links

Passwordless magic link login with optional TOTP MFA. Enforce MFA org-wide from settings.

Frameworks

Built for ANZ compliance requirements

Map controls once — satisfy multiple frameworks. AccreditAZ identifies overlapping controls so you never do the same work twice.

NZISM

NZ Information Security Manual

Primary
ISO 27001

Information Security Mgmt

Essential Eight

ACSC Maturity Model

PCI-DSS

Payment Card Industry

SOC 2

Trust Service Criteria

NIST CSF

Cybersecurity Framework

NZCSA

NZ Cyber Security Assessment

Custom

Bring your own framework

A single system can span multiple frameworks. Evidence reused across all applicable controls.

For Directors & Boards

The compliance report your board will actually read

Director-level reports with plain-language summaries — no jargon, no technical detail, just the compliance posture information a board member needs to fulfil their governance duties.

Compliance Score

Overall posture — percentage of controls implemented, open risks by rating, policy review status. One number, full context.

Risk Summary

Open risks by rating (Critical / High / Medium / Low), treatment status, and overdue items flagged clearly for board awareness.

Incident Status

Open and recently closed incidents, severity breakdown, average resolution time. The paper trail directors need for liability protection.

Scheduled Delivery

Reports emailed automatically to directors on your schedule — weekly, monthly, or quarterly. No chasing the CISO for a PDF.

Start your free account

Directors can be added as read-only users — no licence required.

For Consultants & Assessors

Manage multiple client engagements from one login

AccreditAZ uses a global identity model — your single account gives you access to every client organisation you're engaged with, each completely isolated from the others.

One login
Multiple organisations

Log in once. An org picker shows every client engagement you're active in. Switch between them without logging out.

Scoped
System-level access control

Clients can limit your view to just the systems you're engaged on. Assessor and auditor roles give you the right level of access — no more, no less.

Expiry
Time-limited access

Engagement access can have an expiry date set by the client. Access automatically lapses — no manual revocation needed. Clean, auditable.

Hosted in New Zealand

The core application and database are hosted on an Auckland VPS, with infrastructure details maintained in the platform architecture.

TLS + MFA

TLS protects browser traffic. Magic-link and password authentication support optional TOTP MFA.

Privacy Act-aligned operations

Operated under NZ law, with documented access, deletion, and privacy-request processes.

Pricing

Simple, transparent pricing

No per-user fees. No surprise costs. Start free, scale when you're ready.

Free
$0 /mo

Free for a limited time. No credit card.

For organisations getting started. Run a real system through the full C&A process before spending a dollar.

  • 1 system, 1 framework
  • Full C&A pipeline
  • Risk register
  • Evidence library
  • Up to 3 users
Start Free
Starter
$199 /mo

NZD excl. GST

For organisations actively working through certification across a handful of systems.

  • Up to 5 systems
  • All frameworks
  • Common Controls Engine
  • Incident management
  • Waivers & exceptions
  • Up to 10 users
  • Scheduled reports
Get Started
Most Popular
Professional
$499 /mo

NZD excl. GST

For organisations managing multiple systems across multiple frameworks — the full platform, no limits.

  • 50 systems included
  • All frameworks
  • Unlimited users
  • Director & board reports
  • Supplier risk module
  • Multi-org consultant access
  • Priority support
Get Started
Enterprise
Custom

Talk to us

For large agencies, consultancies managing multiple clients, or organisations with bespoke requirements.

  • Everything in Professional
  • Custom frameworks
  • SSO / Entra ID
  • API access
  • Dedicated support
  • SLA guarantee
Contact Sales

All prices in NZD excl. GST · Annual billing available with ~20% discount · AUD pricing available

Not sure which plan? Start free — upgrade anytime, no lock-in.

Guided onboarding · No credit card · First system in minutes

See AccreditAZ against your actual NZISM programme

Book a short walkthrough, then use a guided workspace to register your first system, select the current framework, and see the next actions.