← SecureAZ Blog

Security Awareness · 5 min read · Published 24 April 2026 · Reviewed 17 August 2026

NCSC NZ Approved Supplier: What It Means for Your Security Training

SecureAZ holds NCSC NZ approved supplier status. Here's what that means for NZ government agencies and businesses that need NCSC-aligned cybersecurity awareness training.

When a NZ government agency, council, or Crown entity needs to buy cybersecurity training, it doesn't start with a Google search. It starts with the approved supplier register. The National Cyber Security Centre maintains a list of suppliers who have met its requirements — and being on that list matters.

SecureAZ holds NCSC NZ approved supplier status. Here's what that actually means, why it matters to government agencies, and what it signals to private sector organisations choosing a training provider.

What NCSC Approved Supplier Status Means

The NCSC (National Cyber Security Centre) sits within the Government Communications Security Bureau (GCSB). Its mandate covers protecting NZ's most significant organisations — government agencies, critical infrastructure operators, and nationally important businesses.

Approved supplier status means SecureAZ has demonstrated that our training content, delivery platform, and security practices meet the NCSC's requirements. It's not a self-declared certification — it's an externally assessed status that enables direct procurement by government agencies.

For NZ government agencies, working with an NCSC-approved supplier simplifies the procurement process and provides assurance that the training aligns with the frameworks they're required to follow: NZISM, PSR, and NCSC guidelines.

NZISM Control 3.2.18.C.01 — The Specific Requirement

The NZ Information Security Manual is the foundational document for government information security. Control 3.2.18.C.01 specifically requires the CISO to be responsible for overseeing the development and operation of information security awareness and training programs within the agency.

This isn't a suggestion — it's a mandatory control for government agencies. And it places the accountability at the CISO level, meaning a failed or inadequate training programme is a governance failure, not just an operational gap.

For agencies subject to NZISM, working with an approved supplier like SecureAZ provides direct assurance that the training programme satisfies this control. The compliance documentation we produce maps directly to what NZISM auditors expect to see.

What NCSC-Aligned Training Looks Like

The NCSC publishes guidance on what effective security awareness training should cover for NZ organisations. The key elements:

NZ-specific threat content — IRD phishing, NZ Post parcel scams, NZ bank impersonation, ACC and NZTA lures. Generic content from offshore providers misses the specific social engineering techniques targeting Kiwi organisations.

Phishing simulations — the NCSC consistently identifies phishing as the primary threat vector in its annual threat reports. Simulations translate awareness training into measurable behaviour change.

Incident reporting culture — staff need to know not just what a phishing email looks like, but exactly what to do when they receive one. The NCSC's guidance emphasises creating a blame-free reporting culture.

Regular refreshers — the NCSC's guidance aligns with the PSR requirement for ongoing, regular training rather than annual tick-box exercises.

Why Private Sector Organisations Should Care

NCSC approved supplier status isn't just relevant to government. For private sector organisations, it's a signal that the training provider has been independently assessed against rigorous NZ security standards.

For companies that:

  • Work with government agencies as suppliers or contractors
  • Are in sectors the NCSC designates as nationally significant (energy, finance, health, telecommunications)
  • Hold ISO 27001 or are pursuing cyber insurance
  • Want assurance that their training meets NZ's highest security standards

...NCSC alignment is meaningful assurance.

The Practical Difference in Training Quality

The gap between NCSC-aligned training and generic cybersecurity awareness content is most visible in the examples. When a NZ staff member sees a simulated phishing email claiming to be from the IRD with a tax refund, or a fake NZ Post parcel delivery notification, it's immediately recognisable as relevant. When they see a generic US-bank phishing example, it's abstract.

Research on phishing simulation effectiveness consistently shows that localised, contextually relevant training produces significantly better retention and behaviour change than generic content.

Government Procurement Pathways

For NZ government agencies looking to deploy security awareness training, SecureAZ is accessible through standard government procurement channels. Approved supplier status means no additional vetting process is required — agencies can proceed directly to engagement.

Contact us at hello@secureaz.com or start a free trial at app.secureaz.com/signup. We'll provide documentation confirming our NCSC approved supplier status and a compliance mapping to NZISM Control 3.2.18.C.01 for your records.

External references: