We help suppliers navigate onboarding and annual audit

We help suppliers meet security and privacy requirements for All-of-Government Marketplace onboarding, including annual assurance deliverables.
Talk to an expert
All of Government Marketplace

Security, privacy and assurance support for Marketplace suppliers

We help Marketplace suppliers meet onboarding and audit expectations for Information Security Professional Services. Whether you're submitting your first listing or preparing for an annual refresh, we work alongside you to ensure your security documentation is accurate, compliant and aligned to All-of-Government standards.

  • Support for Marketplace onboarding, attestation and listing submissions
  • Security input into privacy and assurance documentation
  • Guidance on AoG audit requirements and expected controls
Service detail

Helping you navigate marketplace security requirements

From planning to audit, we guide you through every step of the Marketplace security process with tailored security, privacy and assurance support.

What to expect from our support

Simple, structured, no-surprises guidance

We help you understand what the Marketplace expects, identify gaps in your current documentation and streamline your submissions. Whether it's uplift, remediation or annual review, our support is structured to meet your timelines and reduce admin overhead.

  • Hands-on support for Marketplace onboarding and attestations
  • Security narrative development for privacy and assurance statements
  • Documentation reviews aligned with NZISM and government frameworks
Our delivery process

Structured support tailored to assurance

From initial alignment to audit sign-off, our process ensures suppliers meet Marketplace requirements without unnecessary complexity.
Review & readiness check
We start with a review of your existing documentation, gaps and timelines.
Remediation and uplift
We support you to plan what’s missing, from policy documents to risk assessments.
Submission & support
We help prepare for your Marketplace submission, provide assurance statements and stand by to assist with any follow-up queries.
Benefits

Why work with us

From strategy to sign-off, we’ve helped dozens of suppliers navigate the AoG Marketplace with confidence.
One stop shop
We deliver technical, privacy and assurance guidance all under one roof, with experience across multiple Marketplace catalogues.
Proven government experience
Our team has supported onboarding and renewals for some of the country’s most trusted providers, with clear documentation and minimal friction.
Trusted by procurement
We understand how government buyers think and what they expect. Our documentation stands up to scrutiny and speeds the process.
What comes next

Expand your security coverage

From onboarding to uplift and ongoing compliance, we’re with you every step of the way.

  • Get help preparing for your next annual assurance review
  • Extend your security maturity beyond Marketplace minimums
  • Explore support for additional government frameworks or catalogues
Talk to an expert
Executive and Board Security Governance Training
We train executives and boards on their cybersecurity oversight role — focusing on risk framing, accountability, and key governance responsibilities.
Advanced OSINT Training Course
This hands-on course teaches advanced open-source intelligence techniques, tools, and tradecraft for investigations, threat profiling, and situational awareness
Frequently asked questions

Frequently asked questions

From risk assessment to rapid response - we’re with you every step of the way.

What is the All-of-Government Marketplace?

The AoG Marketplace is a government procurement platform that connects public sector agencies with pre-approved service providers across a range of professional services, including information security.

Do I need an Information Security Assurance Plan to supply to government?

Yes, most public sector engagements require assurance deliverables aligned with NZISM, such as a System Security Plan, Privacy Impact Assessment, or ongoing assurance reporting.

How can Bastion help with NZISM requirements?

We provide advisory and documentation services to help you meet NZISM controls, respond to audit requests, and align with the standards required for onboarding and annual assurance.

What kind of services are included in the Information Security catalogue?

The catalogue includes services like security risk assessments, architecture reviews, training, privacy services, and vCISO support - all delivered by experienced providers like Bastion.

Contact us

Talk to an expert

Please call our office number during normal business hours or submit a form below
Where to find us
If you experience a security breach outside normal working hours, please complete the form and we will respond as soon as possible.