HomeFrameworksNew Zealand
Country guide · New Zealand

Cyber security compliance in New Zealand

New Zealand regulates cybersecurity mostly through government direction and sector regulators rather than one cyber law. Government agencies work to the PSR, the NZISM and, since late 2025, the NCSC Minimum Cyber Security Standards. Financial institutions answer to the Reserve Bank and the FMA, and everyone is covered by a Privacy Act that gained a new principle in May 2026. A critical infrastructure regime has been proposed but not enacted.

At a glance
  • Frameworks listed9
  • Issuing bodies7
  • Framework pages3
  • Platform languagesEnglish and Arabic
  • DeploymentSaaS, private cloud or on-premises
New ZealandChecked Sep 2026
What applies

Cybersecurity and data protection frameworks in New Zealand

Who issues each one and who must comply. Open a framework for its structure, obligations and how GRCLens runs it.

GCSB, through the NCSC

New Zealand Information Security Manual (NZISM) v3.9

Government agencies mandated through the PSR. Encouraged for Crown entities, local government and business. Not law in itself

NZSIS, Government Protective Security Lead

Protective Security Requirements (PSR)

37 mandated government agencies, with 20 mandatory requirements and an annual self-assessment

Open the framework page →
National Cyber Security Centre (NCSC)

Minimum Cyber Security Standards (MCSS)

GCISO-mandated agencies. Ten standards, published 30 October 2025, first reporting period to 30 April 2026

Open the framework page →
Health New Zealand

HISO 10029 Health Information Security Framework

Health organisations and Health NZ suppliers, through contracts rather than legislation

Open the framework page →
Office of the Privacy Commissioner

Privacy Act 2020

Every agency handling personal information. Serious-harm breaches notified as soon as practicable. IPP3A in force from 1 May 2026

Office of the Privacy Commissioner

Biometric Processing Privacy Code 2025

Biometric processing such as facial recognition. New processing from 3 November 2025, existing processing from 3 August 2026

Reserve Bank of New Zealand (RBNZ)

Guidance on Cyber Resilience and cyber data collection

Banks, non-bank deposit takers, insurers and financial market infrastructures. Material cyber incidents within 72 hours

Financial Markets Authority (FMA)

Business continuity and technology systems licence condition

Market services licensees and, since 31 March 2025, CoFI licensees. Material events within 72 hours

Reserve Bank of New Zealand (RBNZ)

BS11 Outsourcing Policy

Large New Zealand-incorporated banks

Which cybersecurity frameworks apply in New Zealand?

Government agencies mandated by Cabinet work to the Protective Security Requirements, which bring in the NZISM and, since 30 October 2025, the NCSC's Minimum Cyber Security Standards. Health organisations and suppliers work to HISO 10029 through their contracts. Banks, insurers and financial market infrastructures answer to the Reserve Bank, and licensed financial service providers to the FMA. Everyone is covered by the Privacy Act 2020.

Is the NZISM law?

No. The NZISM itself says compliance is not required as a matter of law. It is mandated for listed government agencies through Cabinet direction and the PSR, and encouraged for Crown entities, local government and business. The current version is 3.9, first published in April 2025, which aligned password rules with NIST and added phishing-resistant MFA.

What are the Minimum Cyber Security Standards?

Ten standards, published by the NCSC on 30 October 2025, for GCISO-mandated agencies: risk management, security awareness, assets and their importance, secure configuration, patching, multi-factor authentication, least privilege, detecting unusual behaviour, data recovery and response planning. They cover all business-critical and externally facing systems, at a minimum maturity of CS-CMM 2.

The first reporting period ran from 1 November 2025 to 30 April 2026 through the PSR self-assessment tool. The standards do not apply to private businesses, although they are a sensible baseline for suppliers to government.

What changed in privacy law in 2025 and 2026?

The Privacy Amendment Act 2025 added IPP3A, in force from 1 May 2026. When you collect personal information about someone indirectly, you must take reasonable steps to tell them, unless an exception applies. It does not apply to information collected before that date.

The Biometric Processing Privacy Code 2025 applies to facial recognition and other biometric processing, and its grace period for existing systems ended on 3 August 2026. Privacy breaches that cause or are likely to cause serious harm must be notified to the Commissioner and affected people as soon as practicable. There is no 72-hour rule in the Privacy Act, and the maximum fine is $10,000.

What do financial institutions need?

The Reserve Bank's Guidance on Cyber Resilience from 2021 remains its reference, backed by cyber data collection: material cyber incidents are reported within 72 hours. The FMA's business continuity and technology systems licence condition applies to market services licensees and, since 31 March 2025, to financial institution licences, also with 72-hour notification of material events.

The Reserve Bank consulted in 2026 on a draft Operational Resilience Standard under the Deposit Takers Act, which would start on 1 December 2028. It is a draft, not yet a requirement.

Does New Zealand have a critical infrastructure cyber law?

Not yet. In February 2026 the Department of the Prime Minister and Cabinet consulted on a proposed regime covering about 200 entities across seven services, with mandatory incident reporting to the NCSC and risk management programmes. It draws partly on Australia's SOCI Act. Until legislation passes, pages describing a New Zealand SOCI-style law are wrong.

How GRCLens runs New Zealand frameworks together

The PSR, NZISM-aligned MCSS, HISO 10029 and privacy obligations share one control model in GRCLens with ISO/IEC 27001 and NIST CSF, so a health supplier or government contractor evidences each control once. MCSS maturity and reporting periods are tracked as their own indicators. GRCLens can be hosted onshore or run fully on-premises.

Questions

Cyber compliance in New Zealand: common questions

Is the NZISM a legal requirement?

No. It is mandated for listed government agencies through Cabinet direction and the PSR, and encouraged for everyone else. The NZISM states that compliance is not required as a matter of law.

Who must meet the NCSC Minimum Cyber Security Standards?

GCISO-mandated government agencies. Other organisations may adopt them voluntarily.

How fast must a privacy breach be notified in New Zealand?

As soon as practicable, where the breach has caused or is likely to cause serious harm. The Privacy Act has no fixed 72-hour deadline.

When does IPP3A apply?

From 1 May 2026, to personal information collected indirectly on or after that date.

Does New Zealand have a critical infrastructure cyber law?

No. A regime was proposed for consultation in February 2026 but has not been enacted.

Sources

Checked against the issuing bodies' own publications in September 2026. Regulations change, so confirm current requirements with the relevant regulator before relying on them.

Run New Zealand's frameworks on one platform

See GRCLens with your own frameworks loaded. Need hands-on help? Cyber security services in New Zealand from Security Solution Consultants.