NZ Government Approved Supplier

Certification & Accreditation
Made Simple

The compliance platform for NZ critical infrastructure. NZISM system certification, risk management programmes, mandatory incident reporting, and continuous assurance — all in one place.

NZISM Aligned
Essential Eight
ISO 27001
Privacy Act 2020

The Problem

NZ is about to mandate cybersecurity compliance for critical infrastructure

The proposed Cyber Security and Resilience Bill will require ~200 critical infrastructure entities to implement risk management programmes, report incidents within 24 hours, and prove compliance — or face fines up to $5 million and $500K personal liability for directors.

~200

Critical infrastructure entities affected

$5M

Maximum penalty for non-compliance

$500K

Personal director liability

How It Works

Six steps from zero to certified

AccreditAZ manages the full compliance lifecycle — from initial gap analysis to continuous assurance.

1
Assess

Free gap analysis against NZISM, E8, or ISO 27001

2
Remediate

Close gaps with guided workflows, policies & training

3
Certify

Per-system C&A with SSP, SoA & certification memos

4
Report

24/72hr incident reporting with countdown timers

5
Prove

Trust Centre, board reports & director attestations

6
Maintain

Health scores, re-cert alerts & continuous monitoring

The Platform

Everything you need to get certified and stay certified

Replace spreadsheets, Word docs, and manual processes with a single platform that manages the full compliance lifecycle.

System C&A Engine

Per-system NZISM certification and accreditation. Register systems, map controls by classification level, track evidence, manage waivers, and generate SSPs & certification memos.

Common Controls Engine

Implement a control once at the org level — it auto-inherits across every system. First system takes weeks. Tenth system takes hours. No duplicated effort.

Risk Management Programme

Full risk register with 5×5 matrix, treatment plans, and risk owner assignments. Build the mandatory risk management programme the legislation requires.

Incident Reporting

Mandatory 24-hour early warning and 72-hour full reports with live countdown timers, guided templates, timeline tracking, and auto-generated incident references.

Director Accountability

Board-level dashboard with obligation status, personal liability warnings, and digital attestation workflow. Premium board reports delivered automatically each quarter.

Evidence & Policy Library

Upload evidence, link to controls across systems. Policy template library with guided builder, version control, and configurable approval chains.

Supply Chain Portal

Invite suppliers to self-assess against your security requirements. Criticality ratings, risk scoring, and compliance status tracking from a single dashboard.

Integrated Training

Powered by WyzAZ. Complete a training module and it automatically logs evidence against the corresponding compliance control. No other platform does this.

Public Trust Centre

A public-facing compliance status page your customers, auditors, and regulators can visit anytime. Show certifications, frameworks, and training stats — on your terms.

📅

Compliance Calendar

Auto-populated from cert expiry, policy reviews, attestation deadlines. iCal export to Outlook.

Approval Workflows

Configurable chains for evidence, waivers, policies, and risk acceptances. Multi-step sign-off.

🤖

AI Compliance Assistant

Ask questions about NZISM controls, get implementation guidance, and draft policy content — powered by AI.

📊

Health Score

Composite compliance score that degrades over time. Tracks progress and creates urgency across the organisation.

Frameworks

Built for ANZ compliance requirements

Map controls once. Satisfy multiple frameworks. Cross-walking eliminates duplicate work across overlapping requirements.

NZISM

NZ Information Security Manual

Essential Eight

ASD Maturity Model

ISO 27001

Information Security

Privacy Act

NZ Privacy Act 2020

NIST CSF

Cybersecurity Framework

CPS 234

APRA Information Security

SMB1001

SME Cyber Certification

SOC 2

Trust Service Criteria

Free — No credit card required

How ready are you?

Take our 15-minute readiness assessment and get a detailed gap analysis against NZISM, Essential Eight, or ISO 27001. See exactly where you stand — and what it takes to get certified.

Start Your Free Assessment

Consultants charge $5–10K for this. We give it to you for free.

For Directors & Board Members

Board reports so good, directors demand AccreditAZ

Even if compliance work is done elsewhere, the director dashboard and reports are the best in the world. Premium dark-themed board packs — one click, no formatting, no PowerPoint.

Executive Summary

One-page traffic light status across all obligations, compliance score trend, risk posture, and signed attestation. Fits on one printed page.

Quarterly Board Pack

Cover page, table of contents, framework breakdown per system, incident summary, supply chain overview, remediation roadmap, and attestation page.

Liability Defence

The document a lawyer asks for. Every attestation signed, every board report received, compliance trend over your tenure, risk acceptances with rationale.

Regulator Statement

Designed for NCSC, DPMC, or sector regulators. Mirrors mandatory reporting requirements. Timestamped, digitally signed, pure compliance data.

Directors get a free dashboard — no licence required. Reports are auto-delivered quarterly.

Pricing

Simple, transparent pricing

No per-user fees. No surprise costs. Scale by systems, not seats.

Free
$0 /mo

See where you stand. 1 system, 1 framework, 3 users.

  • Free readiness assessment
  • Gap analysis report
  • 1 system, 1 framework
  • Health score tracking
Start Free
Starter
$199 /mo

For organisations starting compliance. Up to 3 systems, 10 users.

  • NZISM control mapping
  • Common Controls Engine
  • SSP & SoA generator
  • Evidence collection
  • Incident reporting
  • Risk register
Get Started
Most Popular
Professional
$499 /mo

For CIEs with multiple systems. Up to 15 systems, unlimited users.

  • Everything in Starter
  • Director dashboard & reports
  • Supply chain portal
  • WyzAZ training integration
  • Multi-framework cross-walk
  • Approval workflows
  • Public Trust Centre
  • Compliance calendar
Get Started
Enterprise
Custom

For consultancies and large agencies. Unlimited systems.

  • Everything in Professional
  • Multi-entity management
  • White-label branding
  • API access
  • SCIM directory sync
  • Dedicated support
Contact Sales

All prices in NZD excl. GST. Annual billing available with 2 months free.

For Consultants & Assessors

Serve 3x the clients with the same team

Stop spending 70% of your time on spreadsheets and boilerplate. AccreditAZ handles the grunt work — you keep the high-value advisory.

$0
Free for consultants

No licence fees. No seat costs. Full platform access for you and your team.

15%
Revenue share

Your clients pay the subscription. You earn 15% of every dollar, every month. 12-month grace period.

Scoped
Engagement access

See only the systems and frameworks you're engaged on. Multiple consultants per entity, fully isolated.

All data hosted in Australia/New Zealand

Your compliance data, evidence, and system security plans never leave the AU/NZ region. No US data transfers. Built for government requirements.