ciso.nz
Supplier Assurance Readiness Assessment for NZ Digital Health Suppliers

Be ready when health-sector customers ask about your security.

A fixed-scope assessment that checks whether your governance, evidence, risk, and customer-ready responses are prepared for customer supplier-security reviews, HISO 10029.4 expectations, and NCSC MCSS CS-CMM Level 2 alignment.

For: Suppliers handling health information · SaaS · cloud · software · integration · outsourced technology services
Customer trigger
Supplier evaluation questions
Supplier standard
HISO 10029.4 guidance
Minimum baseline
NCSC MCSS · CS-CMM Level 2
Assessment
Fixed scope · clear findings
Next step
30-minute fit call
I.
Why Customers Ask

Your customers are being encouraged to ask more specific security questions.

For digital health suppliers, supplier security review is no longer just a technical exercise. It is part of the trust conversation with customers. Health-sector customers are being reminded to safeguard health information, review suppliers, and ask practical questions about how supplier systems, services, people, and evidence are managed.

Customer-side tool

Evaluating an IT Supplier

Gives smaller organisations practical questions to ask suppliers about their own security practices and how they protect customer systems and information.

Supplier-side standard

HISO 10029.4

Defines supplier requirements across governance, people, assets, access, backups, incidents, cloud, web, secure development, operations, monitoring, and response.

Minimum baseline

NCSC MCSS CS-CMM Level 2

Sets the minimum cyber maturity expectation, with practical emphasis on access controls and Multi-Factor Authentication.

The common challenge.

Controls may exist, but evidence is often not organised for customer review.

  • The MSP has technical reports, but not customer-ready assurance.
  • The dev team has testing evidence, but not a secure SDLC evidence pack.
  • Policies exist, but they are not mapped to HISO 10029.4.
  • Risks are known informally, but not tracked to treatment and Board decisions.
  • Customer questionnaires are rebuilt from scratch each time.

What customers are expected to ask.

Customers want evidence that security is governed, operated, reviewed, and improved. They may ask about the same practical areas found in Health NZ’s supplier evaluation tool.

  • Who owns information security?
  • What controls apply, and where is the evidence?
  • What gaps remain, and who owns remediation?
  • How are suppliers, incidents, backups, access, and monitoring managed?
  • Can leadership explain the current risk position?
II.
What the Assessment Reviews

A focused assessment of the evidence customers are likely to ask for.

The assessment is deliberately focused. It checks whether the supplier has credible evidence for customer supplier-security questions, HISO 10029.4 supplier expectations, and CS-CMM Level 2 alignment. It does not attempt to build a full compliance system during the assessment.

01

Governance & Responsibility

Who owns information security, how decisions are made, and whether leadership can see current security risk.

02

HISO 10029.4 Applicability

Which supplier requirements appear relevant and what evidence currently exists for them.

03

Customer Assurance Questions

How ready the supplier is to answer common customer security questions with evidence rather than memory.

04

Policies & Procedures

Whether current policies cover the practical areas customers and HISO guidance expect to see.

05

Asset, Endpoint & Patch Evidence

Whether asset registers, endpoint protection, secure configuration, patching, and vulnerability evidence can be produced.

06

Access, MFA & Least Privilege

Whether MFA, privileged access, user access review, and least-privilege controls are evidenced.

07

Backups, Encryption & Logging

Whether backup, restore testing, encryption, logging, monitoring, and alerting evidence is available.

08

Supplier & Third-Party Evidence

Whether important suppliers, implementation partners, and cloud/service providers are assessed and tracked.

09

Incident & Breach Readiness

Whether incident response, customer notification, escalation, and breach-support arrangements are documented.

10

Priority Gap & Roadmap

What needs attention first, who should own it, and what should be addressed over the next 90 days.

III.
How the Assessment Works

A fixed-scope readiness assessment with a clear report and practical next steps.

The assessment is designed as a practical first step. It gives leadership a clear view of what evidence exists, where the important gaps are, and what should be done next before a customer, PHO, provider, procurement team, or Health NZ-aligned buyer asks.

Step 01

Fit call

A 30-minute conversation to understand your context, the customer or regulatory pressure you are facing, and whether this assessment is the right next step.

  • No obligation
  • Confirms fit before any proposal
  • Suitable for suppliers facing customer, HISO, or CS-CMM questions
Step 02

Evidence request and review

You provide existing documents, policies, reports, registers, screenshots, or partner outputs. The review checks what evidence is available and how well it supports customer and HISO expectations.

  • Evidence-based review
  • Uses what already exists
  • No hands-on system access required unless agreed
Step 03

Readout and assessment report

You receive a written readiness report, evidence map, priority gap register, and 90-day improvement roadmap that leadership can use for decision-making.

  • Clear findings
  • Customer-ready evidence view
  • Practical next-step roadmap

Clear-scope assessment commitment

The assessment produces agreed written findings and a practical roadmap based on the evidence provided. It does not guarantee that every control is implemented or that any customer, regulator, or buyer will reach a particular outcome.

IV.
Assessment Offer

Start with a practical supplier assurance assessment.

Supplier Assurance Readiness Assessment

A fixed-scope assessment for NZ digital health suppliers that need to understand whether their current governance, evidence, and customer responses are ready for supplier-security review, HISO 10029.4 expectations, and CS-CMM Level 2 alignment questions.

ItemDetailWhat it means
AssessmentFixed scopeEvidence request, review, findings, gap register, and 90-day improvement roadmap.
FormatRemote-firstDesigned to minimise disruption while still producing useful written findings.
OutputWritten reportLeadership receives a clear view of current evidence, gaps, priorities, and recommended next steps.
Next stepFit callA short call confirms whether the assessment is appropriate before any engagement is proposed.

Who this assessment is for.

  • NZ digital health suppliers handling health information.
  • SaaS, cloud, software, integration, device, platform, outsourced, or managed technology suppliers.
  • Suppliers preparing for customer questionnaires, PHO/provider review, procurement review, Board concern, HISO 10029.4 expectations, or CS-CMM Level 2 questions.
  • Organisations that need a clear baseline before deciding what to fix first.
  • Teams willing to provide existing evidence for review.

Who this assessment is not for.

  • Organisations wanting hands-on IT implementation.
  • Teams looking for an outsourced MSP, penetration tester, live incident responder, or legal adviser.
  • Suppliers expecting guaranteed compliance or guaranteed customer approval.
  • Teams unwilling to provide evidence or make responsible people available.
  • Organisations that only want generic policy templates.

Not sure whether the assessment is the right next step?

Book a short fit call. We will discuss the customer or HISO-related pressure you are facing, what evidence currently exists, and whether a fixed-scope readiness assessment would be useful.

Book an Assessment Fit Call
V.
Assessment Boundary

Assessment and advice, not hands-on implementation.

The assessment protects independence and clarity by reviewing governance and evidence without becoming the client’s implementer.

You

What ciso.nz does.

Reviews evidence, identifies gaps, provides written findings, recommends priorities, and explains what credible evidence should look like.

Client

What the client owns.

Provides available evidence, confirms context, makes responsible people available, and decides what to do with the findings.

Partners

What specialists do.

MSP, MDR, pen test, appsec, cloud, privacy/legal, and incident response partners perform any specialist implementation or technical services under direct client engagement.

VI.
The Advisor

One senior adviser on the work.

Aldo Febro
Aldo Febro, PhD
Supplier Assurance Readiness Advisor
Founder, ciso.nz
  • DoctoralPhD, Computer Science — IoT & SIP Security
  • SecurityCISSP · CISA · CRISC · CISM · CCSP
  • PrivacyCIPP/US · CIPP/E
  • AuditISO 27001 / 27701 / 42001 Lead Auditor
  • PriorChief Information Security Officer · Chief Privacy Officer

The practice is intentionally focused on supplier assurance for digital health organisations: the work of translating security obligations, customer review questions, operational evidence, and leadership accountability into clear assessment findings and practical next steps.

The role is not to replace the MSP, dev team, MDR provider, pen tester, or incident response partner. The assessment role is to define what credible evidence looks like, review what is currently available, identify gaps, and report the current position clearly to leadership.

That is often the useful first step before customer reviews become urgent: not a pile of documents, but a practical and evidence-based view of where things stand and what should happen next.

Aldo Febro · Auckland · 2026
VII · Next

Start with an assessment fit call.
No obligation.

The fit call is a 30-minute conversation to confirm whether your organisation is facing customer, Board, procurement, HISO 10029.4, or CS-CMM Level 2 questions — and whether a Supplier Assurance Readiness Assessment is the right next step.

Book an Assessment Fit Call
01
Confirm context
Customer questionnaire, procurement, PHO/provider review, Board concern, HISO 10029.4 expectation, or CS-CMM Level 2 expectation.
02
Check evidence readiness
Whether your current evidence is organised, incomplete, or not yet mapped to customer expectations.
03
Decide next step
If there is a fit, the next step is a fixed-scope Supplier Assurance Readiness Assessment.