Cyber security compliance in New Zealand
New Zealand regulates cybersecurity mostly through government direction and sector regulators rather than one cyber law. Government agencies work to the PSR, the NZISM and, since late 2025, the NCSC Minimum Cyber Security Standards. Financial institutions answer to the Reserve Bank and the FMA, and everyone is covered by a Privacy Act that gained a new principle in May 2026. A critical infrastructure regime has been proposed but not enacted.
- Frameworks listed9
- Issuing bodies7
- Framework pages3
- Platform languagesEnglish and Arabic
- DeploymentSaaS, private cloud or on-premises
Cybersecurity and data protection frameworks in New Zealand
Who issues each one and who must comply. Open a framework for its structure, obligations and how GRCLens runs it.
New Zealand Information Security Manual (NZISM) v3.9
Government agencies mandated through the PSR. Encouraged for Crown entities, local government and business. Not law in itself
Protective Security Requirements (PSR)
37 mandated government agencies, with 20 mandatory requirements and an annual self-assessment
Open the framework page →Minimum Cyber Security Standards (MCSS)
GCISO-mandated agencies. Ten standards, published 30 October 2025, first reporting period to 30 April 2026
Open the framework page →HISO 10029 Health Information Security Framework
Health organisations and Health NZ suppliers, through contracts rather than legislation
Open the framework page →Privacy Act 2020
Every agency handling personal information. Serious-harm breaches notified as soon as practicable. IPP3A in force from 1 May 2026
Biometric Processing Privacy Code 2025
Biometric processing such as facial recognition. New processing from 3 November 2025, existing processing from 3 August 2026
Guidance on Cyber Resilience and cyber data collection
Banks, non-bank deposit takers, insurers and financial market infrastructures. Material cyber incidents within 72 hours
Business continuity and technology systems licence condition
Market services licensees and, since 31 March 2025, CoFI licensees. Material events within 72 hours
BS11 Outsourcing Policy
Large New Zealand-incorporated banks
Which cybersecurity frameworks apply in New Zealand?
Government agencies mandated by Cabinet work to the Protective Security Requirements, which bring in the NZISM and, since 30 October 2025, the NCSC's Minimum Cyber Security Standards. Health organisations and suppliers work to HISO 10029 through their contracts. Banks, insurers and financial market infrastructures answer to the Reserve Bank, and licensed financial service providers to the FMA. Everyone is covered by the Privacy Act 2020.
Is the NZISM law?
No. The NZISM itself says compliance is not required as a matter of law. It is mandated for listed government agencies through Cabinet direction and the PSR, and encouraged for Crown entities, local government and business. The current version is 3.9, first published in April 2025, which aligned password rules with NIST and added phishing-resistant MFA.
What are the Minimum Cyber Security Standards?
Ten standards, published by the NCSC on 30 October 2025, for GCISO-mandated agencies: risk management, security awareness, assets and their importance, secure configuration, patching, multi-factor authentication, least privilege, detecting unusual behaviour, data recovery and response planning. They cover all business-critical and externally facing systems, at a minimum maturity of CS-CMM 2.
The first reporting period ran from 1 November 2025 to 30 April 2026 through the PSR self-assessment tool. The standards do not apply to private businesses, although they are a sensible baseline for suppliers to government.
What changed in privacy law in 2025 and 2026?
The Privacy Amendment Act 2025 added IPP3A, in force from 1 May 2026. When you collect personal information about someone indirectly, you must take reasonable steps to tell them, unless an exception applies. It does not apply to information collected before that date.
The Biometric Processing Privacy Code 2025 applies to facial recognition and other biometric processing, and its grace period for existing systems ended on 3 August 2026. Privacy breaches that cause or are likely to cause serious harm must be notified to the Commissioner and affected people as soon as practicable. There is no 72-hour rule in the Privacy Act, and the maximum fine is $10,000.
What do financial institutions need?
The Reserve Bank's Guidance on Cyber Resilience from 2021 remains its reference, backed by cyber data collection: material cyber incidents are reported within 72 hours. The FMA's business continuity and technology systems licence condition applies to market services licensees and, since 31 March 2025, to financial institution licences, also with 72-hour notification of material events.
The Reserve Bank consulted in 2026 on a draft Operational Resilience Standard under the Deposit Takers Act, which would start on 1 December 2028. It is a draft, not yet a requirement.
Does New Zealand have a critical infrastructure cyber law?
Not yet. In February 2026 the Department of the Prime Minister and Cabinet consulted on a proposed regime covering about 200 entities across seven services, with mandatory incident reporting to the NCSC and risk management programmes. It draws partly on Australia's SOCI Act. Until legislation passes, pages describing a New Zealand SOCI-style law are wrong.
How GRCLens runs New Zealand frameworks together
The PSR, NZISM-aligned MCSS, HISO 10029 and privacy obligations share one control model in GRCLens with ISO/IEC 27001 and NIST CSF, so a health supplier or government contractor evidences each control once. MCSS maturity and reporting periods are tracked as their own indicators. GRCLens can be hosted onshore or run fully on-premises.
Official portals and publications
Cyber compliance in New Zealand: common questions
Is the NZISM a legal requirement?
No. It is mandated for listed government agencies through Cabinet direction and the PSR, and encouraged for everyone else. The NZISM states that compliance is not required as a matter of law.
Who must meet the NCSC Minimum Cyber Security Standards?
GCISO-mandated government agencies. Other organisations may adopt them voluntarily.
How fast must a privacy breach be notified in New Zealand?
As soon as practicable, where the breach has caused or is likely to cause serious harm. The Privacy Act has no fixed 72-hour deadline.
When does IPP3A apply?
From 1 May 2026, to personal information collected indirectly on or after that date.
Does New Zealand have a critical infrastructure cyber law?
No. A regime was proposed for consultation in February 2026 but has not been enacted.
Sources
Checked against the issuing bodies' own publications in September 2026. Regulations change, so confirm current requirements with the relevant regulator before relying on them.

Run New Zealand's frameworks on one platform
See GRCLens with your own frameworks loaded. Need hands-on help? Cyber security services in New Zealand from Security Solution Consultants.