AccreditAZ

← All articles

Risk Management · 6 min read · Published 2 April 2026 · Reviewed 17 August 2026

Supplier and Third-Party Security Under NZISM: What Agencies Must Do

NZISM requires agencies to extend their security requirements to suppliers handling government information. Here's what the framework requires, how to structure supplier assessments, and what a vendor questionnaire should cover.

Government agencies don't operate in isolation. Cloud providers, managed service providers, software vendors, consultants, and contractors all routinely access government systems and information. Under NZISM, agencies are responsible for ensuring these suppliers meet appropriate security standards — even though the agency doesn't directly control their security posture.

This is one of the most practically complex areas of NZISM compliance. It requires a structured approach to supplier assessment, contracting, and ongoing assurance.

What NZISM Requires

NZISM's supply chain and outsourcing requirements cover:

Security requirements in contracts — agencies must include security requirements in contracts with suppliers who handle official information or access government systems. These requirements should reference NZISM where applicable and specify what controls the supplier is required to maintain.

Supplier assessment before engagement — before engaging a supplier, the agency should assess their security posture. This includes reviewing the supplier's own compliance certifications (ISO 27001, etc.), requesting evidence of relevant controls, and assessing the risk they represent.

Ongoing assurance — supplier security is not a one-time assessment. Agencies need processes for monitoring supplier security posture, including periodic re-assessments and review of any security incidents affecting the supplier.

Exit and transition planning — contracts with suppliers should include provisions for secure data return or destruction when the engagement ends.

The New Zealand Government Procurement guidance reinforces these requirements from a procurement perspective.

Cloud Services and the NZISM Cloud Framework

Cloud computing creates specific challenges for NZISM compliance. When an agency uses a cloud service to host, process, or transmit government information, the cloud provider becomes a supplier requiring assessment.

The GCSB has published specific guidance on cloud computing under NZISM, including approved cloud security configurations and requirements for different classification levels. Key considerations:

Major cloud providers including Microsoft, Amazon Web Services, and Google Cloud have obtained certifications relevant to NZISM requirements. The New Zealand government cloud guidance provides a framework for assessing cloud service suitability.

Structuring Supplier Assessments

A risk-based approach to supplier assessment tiers suppliers by the risk they represent:

Tier 1 — High risk: Suppliers with access to RESTRICTED or above information, or with administrative access to critical systems. Require: ISO 27001 certification or equivalent, detailed security questionnaire, reference checks, contractual security requirements, annual re-assessment.

Tier 2 — Medium risk: Suppliers with access to SENSITIVE or IN-CONFIDENCE information, or with limited system access. Require: security questionnaire, review of certifications, contractual requirements, biennial re-assessment.

Tier 3 — Low risk: Suppliers providing services with no access to government information. Standard procurement security requirements, periodic review.

What a Vendor Security Questionnaire Should Cover

A vendor security questionnaire for government supplier assessment should cover:

AccreditAZ includes a vendor questionnaire module — send security questionnaires to suppliers, track responses, and link supplier risk assessments to your NZISM compliance posture. Learn more.

Manage your NZISM, ISO 27001, Essential Eight and PSR compliance in one place.

Start free trial →