As recognised assessors by the Digital Identity Services Trust Framework (DISTF) Authority, we support providers in demonstrating compliance with trust, security, and privacy obligations.
The Digital Identity Services Trust Framework Act is a New Zealand law designed to build a secure and trustworthy digital identity ecosystem. This can involve evaluations for the Trust Framework Authority (TFA), which oversees the accreditation and compliance of digital identity services within a specific jurisdiction or ecosystem, such as Identity Providers (IdPs). The framework sets standards for how organisations manage digital identity services, ensuring privacy, security, and user control.
- Assesses you against the requirements of the framework and associated obligations
- Identifies gaps and areas of improvement to resolve for framework compliance
- Helps you maintain compliance and adapt to changes in the regulatory environment, ensuring long-term success in the digital identity ecosystem
Achieving compliance
Keeping compliant
Ensuring you meet the requirements, and more
Our expert team will use their deep knowledge as recognised assessors to help you fully understand the requirements and obligations associated with the framework, and how to meet them.
- We will perform detailed security and privacy evaluations to help assess you against the requirements of the framework
- Verify compliance with legal, privacy, and security standards through structured evaluations and formal reporting
- Work with you post-assessment to ensure you’re continuing to comply
Supporting you in your journey
Keeping you ahead of the curve
Frequently asked questions
What is an Independent Security Evaluation?
An Independent Security Evaluation determines if requirements of the TFA, as defined in the Digital Identity Service Trust Framework Rules, have been met. Conducting the security evaluation involves following a risk-based analysis approach, which will help to determine whether appropriate controls are implemented and operational to help mitigate any potential security risks.
What is the outcome of a DISTF audit?
Post-audit, you’ll receive a report detailing compliance status, the overall security risk position, control effectiveness, and major findings, along with planned mitigations for associated risks, and expected remediation timelines.
Who should undergo a DISTF audit?
Key entities that should look at getting audited under this framework are digital identity providers, government agencies, and credential services. To ensure compliance, build trust, and meet accreditation requirements.
Talk to an expert
51 Shortland Street,
Auckland 1010 New Zealand
10 Brandon Street
Wellington 6011 New Zealand
120 Spencer Street
Melbourne 3000 Australia