Maintain NZISM certification over time

We support agencies and vendors in meeting NZISM continuous certification requirements, with regular reviews, updates, and assurance reporting.
Talk to an expert
Continuous Certification

Making sure you meet your certification requirements

Primarily done via Certification & Accreditation (C&A), continuous certification is an ongoing process of validating and verifying that organisations and their systems maintain a required level of compliance over time, rather than relying solely on one-time exams or periodic audits.

  • Ensures you are meeting NZISM continuous certification requirements.
  • Helps you identify where you and your systems may not be meeting compliance and how you can improve.
  • Done on a frequent, basis to ensure the overall security posture of your organisations and/or systems is up to date and compliant.
Service detail

Helping you stay certified

Our continuous certification process helps ensure that organisations are aware of and meeting their certification requirements, whilst also using our deep expertise to identify any gaps, areas of improvement, and providing pragmatic recommendations to help remediate and improve

The continuous certification process

With you from start, to finish, and beyond

Our team of experts will work hand-in-hand with you and your team to make sure the continuous certification process is as smooth and seamless as possible for you. We’ll first and foremost identify what goals you’re trying to achieve, and using our extensive knowledge and expertise, make sure you achieve them.

  • We will assess the current your organisations and system’s current security posture, including identifying key assets, risks, and determine where you currently stand in terms of meeting your certification.
  • Expert analysis is performed on a myriad of artefacts, from policy and procedure documentation to technical diagrams and system configurations, to see what you already have going for you, and what can be done better.
  • Our detailed assessments are translated into easy-to-read reports detailing what you’ve done well, what can be done better, how to achieve next steps, and where you stand in terms of your certification.
Our delivery process

Getting your certification has never been smoother

We follow a structured yet seamless process when it comes to delivering continuous certification services such as C&As. Our deep expertise is combined with industry best practices and standards such as NZISM to ensure you get high-quality and repeatable outcomes.
Workshops & Initial Assessment
Post-scoping, we run joint workshops to understand your organisation, systems, and goals.
Risks & Controls Assessments
Risks are assessed and controls are tested and applied to remediate and mitigate threats.
Reporting & Certification
Our detailed findings are presented in concise reports with certification memos provided to demonstrate compliance.
Benefits

Your go-to certification provider

Bastion is a key player in the certification of vital systems. From private sector to government agencies, we have both the regulatory and technical know-how to help you get certified.
Proven track record
Bastion has successfully certified and re-certified a myriad of systems for various organisations and entities.
Deep expertise
From an in-depth understanding of various IT and security frameworks and standards e.g., NZISM, NIST, ISO and more, to robust technical skills.
Tailored solutions
We work in tandem with you and your team and develop a comprehensive understanding of your organisation and systems.
What comes next

Going beyond the certification

Bastion is dedicated to ensuring that you’re ahead of the curve when it comes to obtaining and maintaining your certifications. We’ll not only help you get your certifications but also give you the tools and guidance you need to make the re-certification process feel like second nature.

  • Ensure you meet industry standards for certification e.g., NZISM.
  • Provide you with pragmatic and practical recommendations and advice to help you remediate any gaps.
  • Help you get ready and be there for future re-certifications, making the process easier for you going forward.
Talk to an expert
Executive and Board Security Governance Training
We train executives and boards on their cybersecurity oversight role — focusing on risk framing, accountability, and key governance responsibilities.
Instructor Led ISO27001 Training
This instructor-led course equips participants with the knowledge and skills needed to become certified to lead, plan, and conduct ISO 27001 audits.
Frequently asked questions

Frequently asked questions

From risk assessment to rapid response - we’re with you every step of the way.

What is a Certification & Accreditation (C&A)?

A C&A is a formal and fundamental governance and assurance process used to ensure that information systems meet security requirements and are approved for operation. This is required for New Zealand government agencies and is aligned with the New Zealand Information Security Manual (NZISM)

Why conduct Certification & Accreditation (C&A)?

A C&A provides assurance that information and resources are safeguarded to protect public and national interests and to preserve personal privacy, especially for information systems. A C&A is essential for New Zealand government information systems.

What is the difference between Certification & Accreditation?

Certification: The certification component of a C&A for an ICT system, and any related support services, involves assessing risks, testing controls, and verifying security measures to ensure the system meets required standards before it is approved for use. Accreditation: The accreditation component of a C&A for an ICT system, and any related support services, involves the formal approval to operate/continue to operate an ICT system, after reviewing certification results and the accepting of any residual risks.

Contact us

Talk to an expert

Please call our office number during normal business hours or submit a form below
Where to find us
If you experience a security breach outside normal working hours, please complete the form and we will respond as soon as possible.