Running compliance programmes across NZISM, ISO 27001, the Essential Eight, and PSR simultaneously is a reality for many NZ government agencies and their suppliers. Done poorly, it means four separate programmes, four separate evidence libraries, and four separate reporting cycles. Done well, it means one integrated programme that satisfies all four — with most of the work done once.
This guide explains how to structure a multi-framework compliance programme that avoids duplication.
The Core Problem: Siloed Frameworks
The typical failure mode is treating each framework as a separate project. One team manages NZISM. Another handles ISO 27001. Someone else is responsible for Essential Eight. They all collect evidence, run assessments, and report separately.
The result: three assessors interviewing the same people about the same controls in the same quarter. Three evidence libraries storing the same documents with different naming conventions. Three sets of gaps identified — some overlapping, some not — with no unified view of the organisation's actual security posture.
This isn't just inefficient. It actively degrades compliance quality, because gaps in one framework often mirror gaps in others — but they're never connected.
The Control Mapping Foundation
The fix starts with a unified control library. Map every control from every applicable framework into a single repository, with cross-references showing which controls satisfy which requirements.
For example, an access control policy typically satisfies:
- NZISM Chapter 6 (Access Control)
- ISO 27001 Annex A 5.15–5.18 (Access control, Identity management)
- Essential Eight (Restrict Administrative Privileges)
- PSR information security requirements around access to classified information
One policy. One piece of evidence. Four framework requirements met.
The NCSC's published NZISM control guidance and the ACSC's Essential Eight mapping both provide starting points for cross-framework mapping. For ISO 27001, the standard's own Annex A provides a structured control reference.
Organising Evidence Once
Every control requires evidence of implementation. In a siloed approach, teams collect evidence four times. In an integrated approach, evidence is collected once and tagged to all applicable controls.
Practical structure:
- Policies and procedures — one document library, tagged by control reference across all frameworks
- Technical configurations — one set of configuration exports and screenshots, cross-referenced to all applicable controls
- Assessment reports — one assessment cycle per year, covering all framework requirements simultaneously
- Risk register — one risk register, with each risk linked to the control families it affects across all frameworks
The key enabler is tagging. If your evidence management system (whether a spreadsheet, GRC tool, or purpose-built platform like AccreditAZ) allows you to tag each piece of evidence with multiple control references, you collect once and satisfy many.
Assessment Scheduling
With a unified control library and evidence repository, assessment cycles can be consolidated. Rather than four annual assessments (NZISM recertification, ISO 27001 surveillance, Essential Eight maturity assessment, PSR self-assessment), run one integrated assessment covering all frameworks.
The ISO 27001 surveillance audit cycle is annual, with a recertification audit every three years. NZISM accreditation is typically valid for three years. These timelines can be aligned so assessments occur at the same time, using the same evidence, reviewed by the same (or coordinating) assessors.
Reporting Across Frameworks
Leadership, boards, and external stakeholders often need different views of the same compliance data. A minister needs a one-page summary. A board audit committee needs a risk-focused view. An auditor needs control-level detail.
Build your reporting from the integrated control library rather than from each framework separately. A single control status — Implemented, Partially Implemented, Not Implemented — populates all framework reports. You change the lens, not the data.
The New Zealand Government Security Survey (PSR reporting) and GCSB reporting processes both accept agency self-assessments as a starting point. Your integrated assessment data is the source for both.
What This Looks Like in Practice
A medium-sized government agency with NZISM, ISO 27001, and PSR requirements might structure their programme like this:
- Q1: Annual control review — assess all controls in the unified library against current state
- Q2: Gap remediation — address findings from Q1 assessment
- Q3: ISO 27001 surveillance audit (external assessor)
- Q4: PSR self-assessment, GCSB reporting, NZISM review
One programme. Four framework outputs. Evidence collected once. Gaps actioned once.
AccreditAZ is built specifically for this model — a single platform that maps evidence to NZISM, ISO 27001, Essential Eight, and PSR controls simultaneously. Start with a free trial or read about our framework coverage.