
Making sure you meet your certification requirements
Primarily done via Certification & Accreditation (C&A), continuous certification is an ongoing process of validating and verifying that organisations and their systems maintain a required level of compliance over time, rather than relying solely on one-time exams or periodic audits.
- Ensures you are meeting NZISM continuous certification requirements.
- Helps you identify where you and your systems may not be meeting compliance and how you can improve.
- Done on a frequent, basis to ensure the overall security posture of your organisations and/or systems is up to date and compliant.
Helping you stay certified
The continuous certification process
With you from start, to finish, and beyond
Our team of experts will work hand-in-hand with you and your team to make sure the continuous certification process is as smooth and seamless as possible for you. We’ll first and foremost identify what goals you’re trying to achieve, and using our extensive knowledge and expertise, make sure you achieve them.
- We will assess the current your organisations and system’s current security posture, including identifying key assets, risks, and determine where you currently stand in terms of meeting your certification.
- Expert analysis is performed on a myriad of artefacts, from policy and procedure documentation to technical diagrams and system configurations, to see what you already have going for you, and what can be done better.
- Our detailed assessments are translated into easy-to-read reports detailing what you’ve done well, what can be done better, how to achieve next steps, and where you stand in terms of your certification.
Getting your certification has never been smoother
Your go-to certification provider
Frequently asked questions
What is a Certification & Accreditation (C&A)?
A C&A is a formal and fundamental governance and assurance process used to ensure that information systems meet security requirements and are approved for operation. This is required for New Zealand government agencies and is aligned with the New Zealand Information Security Manual (NZISM)
Why conduct Certification & Accreditation (C&A)?
A C&A provides assurance that information and resources are safeguarded to protect public and national interests and to preserve personal privacy, especially for information systems. A C&A is essential for New Zealand government information systems.
What is the difference between Certification & Accreditation?
Certification: The certification component of a C&A for an ICT system, and any related support services, involves assessing risks, testing controls, and verifying security measures to ensure the system meets required standards before it is approved for use. Accreditation: The accreditation component of a C&A for an ICT system, and any related support services, involves the formal approval to operate/continue to operate an ICT system, after reviewing certification results and the accepting of any residual risks.
Talk to an expert
Shortland Street,
Auckland 1010 New Zealand
Brandon Street
Wellington 6011 New Zealand
120 Spencer Street
Melbourne 3000 Australia