Ready to get your next system certified and accredited?
Your path to information security accreditation
The details that make the difference
Practical help at every stage
Certification & Accrediation
From risk assessments to ongoing certification reviews, we align to NZISM and other frameworks without adding friction.
- Guidance on developing audit-ready documentation and SSPs
- Long-term support for continuous certification and assurance reviews
- Practical advice and audit-ready support
Setting Bastion information security accreditation apart
Our customers
Latest advisories
Frequently asked questions
Is Certification and Accreditation used outside of Government agencies?
Yes! Do you want to have a clear picture of the security of the systems and suppliers critical to your business? Do you need a consistent method to measure this and provide assurance to your board and key stakeholders? C&A might be for you, or a Security Risk Assessment Process as it's commonly called outside of Government, get in touch today about the right framework for you. We have experience in undertaking assessments and building security programmes aligned with international best practice frameworks including ISO 31000 Risk Management, ISO 27001 Information Security Management Systems, SOC 2, and ITIL.
Is Certification and Accreditation (C&A) mandatory?
New Zealand Government agencies and organisations. are expected to follow the NZISM and undertake C&A, while Crown entities, local government and private sector organisations are encouraged to use the NZISM. Whether it's mandatory for your organisation or not, as a process designed to provide confidence that technologies and suppliers are well-managed and that risks are properly identified and understood, it provides strong value to all forms of organisations.
Why is certification and accreditation important?
Because it gives you peace of mind. Certification and accreditation confirm that your systems are secure, meet required standards, and are officially approved to operate. Helping you avoid risks, protect your people and data, and stay ahead of compliance demands.
How long does the certification process take?
Timeframes vary depending on complexity, but most engagements span several weeks to a few months, including assessment, remediation, and approval.
Can you support us through the full lifecycle?
Absolutely. We offer full spectrum support, from initial assessment and remediation to ongoing compliance monitoring and renewals.
What is a risk assessment?
A risk assessment is a point-in-time assessment of your organisation and/or relevant systems. The process involves in-depth analysis and identification potential threats and vulnerabilities to your organisation and/or systems. The potential likelihood and impact of these risks are assessed, and tailored controls and recommendations are applied and provided to help remediate or mitigate them.
Should I get a risk assessment done?
A risk assessment is applicable to any individual, organisation, or entity that utilises and relies on digital systems, networks, and/or data. Risk assessments can apply to businesses of various sizes, financial institutions, healthcare providers, IT & Cybersecurity professionals, and even government agencies.
When do I get a risk assessment done?
A risk assessment can be initiated at anytime to gain a current understanding of potential risks. However, some key times to start a risk assessment are: Before launching a new system or website, after a security incident or breach, after major regulatory or compliance changes, after major IT infrastructure changes, and finally, risk assessments should be done on a regular basis (e.g., annually) to ensure ongoing compliance and keep up with an ever-evolving threat landscape.
How long does a risk assessment take?
The timeline of a risk assessment will vary depending on the nature of the assessment and the size of the assessment scope. A basic assessment only taking a few days, a standard one ranging from a week or two, to an in-depth one taking 3 weeks or more.
What is the outcome of a risk assessment?
A completed risk assessment will give you a clear understanding of the threats, vulnerabilities, and overall risks your organisation and/or systems face and how to mitigate and/or prevent them. The goal is to help prevent security breaches, ensure you’re compliant with laws and regulations, and prevent financial and reputational harm.
Talk to an expert
Shortland Street,
Auckland 1010 New Zealand
Brandon Street
Wellington 6011 New Zealand
120 Spencer Street
Melbourne 3000 Australia