In NZISM conversations, certification and accreditation are frequently conflated. Agencies talk about "getting certified" when they mean accreditation. Vendors talk about "NZISM accreditation" when they mean their product has been assessed. The manual treats the two as distinct processes with different outputs, different actors, and different legal weight. Understanding the distinction is the foundation of a compliant C&A programme.
---
Certification — the Technical Assessment
Certification is the process of independently assessing a system against NZISM controls to determine whether it meets the required security standard. It is a technical and procedural evaluation that produces a certification report — a documented assessment of the system's compliance posture, residual risks, and any conditions on operation.
Key characteristics of certification:
- It is performed by a qualified assessor — either an internal party with the appropriate competence, or an external GCSB-recognised assessor for higher-classification systems
- It assesses a specific system at a point in time against the NZISM controls applicable to that system's classification and risk profile
- The output is an assessment report, not an operating authority
- It can be conducted iteratively — a system can be assessed as part of a development lifecycle before it handles live data
- Certification findings are addressed through remediation or risk acceptance before accreditation
The certification report is the evidence base on which the accreditation decision is made. A system without a current certification report cannot be legitimately accredited.
Accreditation — the Authority to Operate
Accreditation is the formal decision to authorise a system to operate, made by the accreditation authority on the basis of the certification report. It is a risk acceptance decision, not a technical assessment. The accrediting official accepts the residual risk of operating the system, including any unclosed findings from certification.
Key characteristics of accreditation:
- It is performed by the agency's accreditation authority — typically the Chief Executive, or a delegated senior officer who has the authority to accept risk on behalf of the agency
- It is a documented decision — the Statement of Accreditation or equivalent records what was assessed, what risks are accepted, any conditions of operation, and the accreditation period
- It is time-limited — accreditations have an expiry, typically one to three years depending on system risk
- It can be conditional — the accreditation authority may authorise operation subject to conditions being met within a specified timeframe
- It can be withdrawn — if the risk picture changes materially, the accreditation authority can revoke the operating authority
Accreditation is the point at which the agency's senior leadership formally accepts accountability for the cyber risk of the system. This is why the Cyber Security and Resilience Bill's personal liability provisions for directors and officers are directly relevant to the accreditation decision.
Who Does What
| Role | Certification | Accreditation |
|---|---|---|
| Who performs it | Technical assessor (internal or external) | Accreditation authority (CE or delegate) |
| What they produce | Certification report with findings | Statement of Accreditation / operating authority |
| What it requires | Technical knowledge of NZISM controls | Authority to accept risk on behalf of the agency |
| When it expires | When the system changes materially or time limit reached | At the accreditation period end |
| Who can do it | Qualified assessor — GCSB-recognised for higher classifications | Agency head or formally delegated officer |
The Accreditation Boundary
Before either certification or accreditation can proceed, the accreditation boundary must be defined. The boundary describes exactly what is in scope — which systems, which networks, which data stores, which user populations, which third-party connections. Everything inside the boundary is assessed and accredited; everything outside it is a dependency that must be addressed separately.
Getting the boundary wrong is one of the most common early failures in a C&A programme. A boundary that is too narrow excludes dependencies that create real risk. A boundary that is too broad makes the assessment unmanageable.
The boundary is documented in the System Security Plan and reviewed as part of both certification and accreditation. Changes to the system that cross the boundary — a new cloud integration, a new data feed, a new user category — trigger a reassessment.
Continuous Accreditation vs Point-in-Time
The traditional NZISM approach is a point-in-time cycle: certify the system, accredit it for a period, recertify when the period expires. The limitation of this model is that systems change continuously — configuration changes, new software versions, new users, new integrations — and the accreditation status can drift away from the actual system state between reviews.
The shift toward continuous certification addresses this by treating the C&A programme as an ongoing control rather than a periodic event. Evidence is collected continuously, findings are remediated in real time, and the accreditation authority receives regular status reports rather than a single annual document. The practical framework for continuous certification is covered in NZISM Continuous Certification: Moving Beyond the Point-in-Time Audit.
What Vendors Mean by Accreditation
The term is also used outside the agency C&A context. Vendors talk about their products being "NZISM accredited" or "accredited for use in NZ government environments." This is different from the agency accreditation described above.
Product-level accreditation or evaluation means the product has been assessed against relevant NZISM technical requirements — typically cryptographic standards, evaluated product lists, or GCSB-approved product assessments. It means the product is approved for use in building a NZISM-compliant system; it does not mean the system using the product is itself accredited. That assessment still falls to the agency.
The Step-by-Step Process
- Define the accreditation boundary — what is in scope
- Develop the System Security Plan — document the control implementation
- Conduct certification assessment — technical evaluation by a qualified assessor
- Receive certification report — findings, residual risks, conditions
- Remediate or risk-accept findings — close critical findings, formally accept residual risk
- Prepare accreditation brief for the authority — plain-language summary of risk posture
- Accreditation authority makes the decision — sign the Statement of Accreditation
- Operate within conditions — manage ongoing compliance and conditions of accreditation
- Reassess on expiry or material change — restart the cycle
The full lifecycle, step by step, is covered in The NZISM Certification Process: Step by Step.
Start a free AccreditAZ trial to manage your C&A lifecycle — certification evidence, accreditation tracking, and ongoing compliance in one platform.
External references: