National Cyber Security Centre (NCSC, part of GCSB) · New Zealand

New Zealand Minimum Cyber Security Standards (MCSS) compliance software

Meet the Minimum Cyber Security Standards — evidence each standard on business-critical and externally facing systems, at the required maturity.

Overview

What NZ MCSS requires

The Minimum Cyber Security Standards, published by New Zealand's National Cyber Security Centre (part of the GCSB), establish the baseline cyber security expectations for GCISO-mandated agencies — the agencies covered by the PSR framework — with adoption open to the wider public sector.

The standards apply to business-critical and externally facing systems and are anchored in a maturity model, the Cyber Security Capability Maturity Model (CS-CMM), with the minimum level set at CMM2 'Planned & Tracked'. Implementation is reported through the PSR assurance process.

For agencies, the practical challenge is demonstrating maturity per standard per system with evidence — exactly the assessment-and-evidence discipline GRCLens provides, alongside the PSR and HISO frameworks it complements.

Who it applies to

  • GCISO-mandated New Zealand government agencies
  • Public-sector organisations voluntarily adopting the standards
  • Suppliers operating business-critical or externally facing systems for agencies
  • Agencies preparing MCSS reporting through PSR assurance

At a glance

  • Issuing body: NCSC (GCSB)
  • Mandate: GCISO-mandated agencies; voluntary adoption welcome
  • Maturity model: CS-CMM — minimum level CMM2 Planned & Tracked
  • Reporting: Via PSR assurance reporting
In the platform

How GRCLens supports NZ MCSS

NZ MCSS runs on the same shared control model as every other framework in GRCLens, so evidence captured once can satisfy several obligations at the same time.

Standard-by-standard assessment

Each minimum standard is assessed with implementation status, maturity evidence, owners and comments.

Scope by system criticality

Evidence is organised around business-critical and externally facing systems, matching the standards' scope.

PSR-aligned reporting

MCSS posture reports sit beside your PSR assessment, ready for the combined assurance reporting cycle.

Maturity evidence

Attach the artefacts that demonstrate CMM2 planned-and-tracked practice — plans, schedules, tracking records — per standard.

Questions

NZ MCSS frequently asked questions

Who must implement the MCSS?

GCISO-mandated agencies are required to implement the standards; other organisations may adopt them voluntarily. Reporting flows through the PSR assurance process.

What maturity level is required?

The minimum is CMM2 'Planned & Tracked' on the CS-CMM maturity model — practices must be planned, resourced and tracked, not ad hoc. GRCLens evidences that per standard.

Which systems are in scope?

Business-critical and externally facing systems, where applicable. The platform lets you scope each standard's assessment to those systems and mark others not applicable with justification.

How do MCSS, PSR and NZISM fit together?

The PSR sets protective security policy, the NZISM details technical controls, and the MCSS sets the minimum cyber baseline reported through PSR assurance. GRCLens runs them from one shared evidence model.

Talk to us about NZ MCSS

Security Solution Consultants provides NZ government cyber advisory alongside the platform, so you can combine tooling with hands-on expertise.

Contact us