Support for compliance with the Digital Identity Act

We help digital identity service providers understand and meet security obligations under New Zealand’s Digital Identity Services Trust Framework Act.
Talk to an expert
Digital Identity Services Trust Framework Act

As recognised assessors by the Digital Identity Services Trust Framework (DISTF) Authority, we support providers in demonstrating compliance with trust, security, and privacy obligations.

The Digital Identity Services Trust Framework Act is a New Zealand law designed to build a secure and trustworthy digital identity ecosystem. This can involve evaluations for the Trust Framework Authority (TFA), which oversees the accreditation and compliance of digital identity services within a specific jurisdiction or ecosystem, such as Identity Providers (IdPs). The framework sets standards for how organisations manage digital identity services, ensuring privacy, security, and user control.

  • Assesses you against the requirements of the framework and associated obligations
  • Identifies gaps and areas of improvement to resolve for framework compliance
  • Helps you maintain compliance and adapt to changes in the regulatory environment, ensuring long-term success in the digital identity ecosystem
Service detail

Achieving compliance

As part of our DISTF assessment process, our services include security and privacy evaluations to help organisations meet the requirements of the framework.

Keeping compliant

Ensuring you meet the requirements, and more

Our expert team will use their deep knowledge as recognised assessors to help you fully understand the requirements and obligations associated with the framework, and how to meet them.

  • We will perform detailed security and privacy evaluations to help assess you against the requirements of the framework
  • Verify compliance with legal, privacy, and security standards through structured evaluations and formal reporting
  • Work with you post-assessment to ensure you’re continuing to comply
Our delivery process

Supporting you in your journey

Our team of recognised assessors will work hand-in-hand with you and your team to ensure your DISTF assessment is a smooth and seamless process.
Structured Evaluations
Post-scoping we review documents and interview staff to assess framework compliance.
Testing & Validation
Controls are tested after mapping to risks, considering both likelihood and impact.
Results & Recommendations
Key findings are identified and presented in concise reports, along with remediation actions.
Benefits

Keeping you ahead of the curve

Our seasoned experts will help you navigate the security requirements of the framework and provide you with expert advice for long-term success.
Assurance experts
Delivered end-to-end by qualified professionals with the experience to help you suceed.
Deep understanding
Our team understands the DISTF Act and stays current with evolving requirements and obligations.
An ongoing partnership
We help you on the assessment journey, supporting you before and beyond the audit.
What comes next

Compliance is just the start

We believe that good security is an ongoing process and is therefore committed to helping organisations along their journeys, from initial assessment, to ongoing assurance, we are there every step of the way.

  • We’ll conduct regular assessments to verify ongoing adherence to security, privacy, and operational requirements
  • Ensure different digital identity services work together seamlessly while maintaining a high level of trust
  • Help you prepare for and adapt to any changes in the regulatory environment as part of post-certification activities
Talk to an expert
Compliance Management Programme
We help you design, embed and manage compliance programmes that support your legal, contractual and governance obligations.
Privacy Impact Assessment
We help you identify how personal information is collected, stored and shared across your organisation, and provide practical steps to manage privacy risk.
Frequently asked questions

Frequently asked questions

From risk assessment to rapid response - we’re with you every step of the way.

What is an Independent Security Evaluation?

An Independent Security Evaluation determines if requirements of the TFA, as defined in the Digital Identity Service Trust Framework Rules, have been met. Conducting the security evaluation involves following a risk-based analysis approach, which will help to determine whether appropriate controls are implemented and operational to help mitigate any potential security risks.

What is the outcome of a DISTF audit?

Post-audit, you’ll receive a report detailing compliance status, the overall security risk position, control effectiveness, and major findings, along with planned mitigations for associated risks, and expected remediation timelines.

Who should undergo a DISTF audit?

Key entities that should look at getting audited under this framework are digital identity providers, government agencies, and credential services. To ensure compliance, build trust, and meet accreditation requirements.

Contact us

Talk to an expert

Please call our office number during normal business hours or submit a form below
Where to find us
If you experience a security breach outside normal working hours, please complete the form and we will respond as soon as possible.