New Zealand Minimum Cyber Security Standards (MCSS) compliance software
Meet the Minimum Cyber Security Standards — evidence each standard on business-critical and externally facing systems, at the required maturity.
What NZ MCSS requires
The Minimum Cyber Security Standards, published by New Zealand's National Cyber Security Centre (part of the GCSB), establish the baseline cyber security expectations for GCISO-mandated agencies — the agencies covered by the PSR framework — with adoption open to the wider public sector.
The standards apply to business-critical and externally facing systems and are anchored in a maturity model, the Cyber Security Capability Maturity Model (CS-CMM), with the minimum level set at CMM2 'Planned & Tracked'. Implementation is reported through the PSR assurance process.
For agencies, the practical challenge is demonstrating maturity per standard per system with evidence — exactly the assessment-and-evidence discipline GRCLens provides, alongside the PSR and HISO frameworks it complements.
Who it applies to
- GCISO-mandated New Zealand government agencies
- Public-sector organisations voluntarily adopting the standards
- Suppliers operating business-critical or externally facing systems for agencies
- Agencies preparing MCSS reporting through PSR assurance
At a glance
- Issuing body: NCSC (GCSB)
- Mandate: GCISO-mandated agencies; voluntary adoption welcome
- Maturity model: CS-CMM — minimum level CMM2 Planned & Tracked
- Reporting: Via PSR assurance reporting
How GRCLens supports NZ MCSS
NZ MCSS runs on the same shared control model as every other framework in GRCLens, so evidence captured once can satisfy several obligations at the same time.
Standard-by-standard assessment
Each minimum standard is assessed with implementation status, maturity evidence, owners and comments.
Scope by system criticality
Evidence is organised around business-critical and externally facing systems, matching the standards' scope.
PSR-aligned reporting
MCSS posture reports sit beside your PSR assessment, ready for the combined assurance reporting cycle.
Maturity evidence
Attach the artefacts that demonstrate CMM2 planned-and-tracked practice — plans, schedules, tracking records — per standard.
NZ MCSS frequently asked questions
Who must implement the MCSS?
GCISO-mandated agencies are required to implement the standards; other organisations may adopt them voluntarily. Reporting flows through the PSR assurance process.
What maturity level is required?
The minimum is CMM2 'Planned & Tracked' on the CS-CMM maturity model — practices must be planned, resourced and tracked, not ad hoc. GRCLens evidences that per standard.
Which systems are in scope?
Business-critical and externally facing systems, where applicable. The platform lets you scope each standard's assessment to those systems and mark others not applicable with justification.
How do MCSS, PSR and NZISM fit together?
The PSR sets protective security policy, the NZISM details technical controls, and the MCSS sets the minimum cyber baseline reported through PSR assurance. GRCLens runs them from one shared evidence model.
One platform, many obligations
Talk to us about NZ MCSS
Security Solution Consultants provides NZ government cyber advisory alongside the platform, so you can combine tooling with hands-on expertise.
Contact us