Be ready when health-sector customers ask about your security.
A fixed-scope assessment that checks whether your governance, evidence, risk, and customer-ready responses are prepared for customer supplier-security reviews, HISO 10029.4 expectations, and NCSC MCSS CS-CMM Level 2 alignment.
Your customers are being encouraged to ask more specific security questions.
For digital health suppliers, supplier security review is no longer just a technical exercise. It is part of the trust conversation with customers. Health-sector customers are being reminded to safeguard health information, review suppliers, and ask practical questions about how supplier systems, services, people, and evidence are managed.
Evaluating an IT Supplier
Gives smaller organisations practical questions to ask suppliers about their own security practices and how they protect customer systems and information.
HISO 10029.4
Defines supplier requirements across governance, people, assets, access, backups, incidents, cloud, web, secure development, operations, monitoring, and response.
NCSC MCSS CS-CMM Level 2
Sets the minimum cyber maturity expectation, with practical emphasis on access controls and Multi-Factor Authentication.
The common challenge.
Controls may exist, but evidence is often not organised for customer review.
- The MSP has technical reports, but not customer-ready assurance.
- The dev team has testing evidence, but not a secure SDLC evidence pack.
- Policies exist, but they are not mapped to HISO 10029.4.
- Risks are known informally, but not tracked to treatment and Board decisions.
- Customer questionnaires are rebuilt from scratch each time.
What customers are expected to ask.
Customers want evidence that security is governed, operated, reviewed, and improved. They may ask about the same practical areas found in Health NZ’s supplier evaluation tool.
- Who owns information security?
- What controls apply, and where is the evidence?
- What gaps remain, and who owns remediation?
- How are suppliers, incidents, backups, access, and monitoring managed?
- Can leadership explain the current risk position?
A focused assessment of the evidence customers are likely to ask for.
The assessment is deliberately focused. It checks whether the supplier has credible evidence for customer supplier-security questions, HISO 10029.4 supplier expectations, and CS-CMM Level 2 alignment. It does not attempt to build a full compliance system during the assessment.
Governance & Responsibility
Who owns information security, how decisions are made, and whether leadership can see current security risk.
HISO 10029.4 Applicability
Which supplier requirements appear relevant and what evidence currently exists for them.
Customer Assurance Questions
How ready the supplier is to answer common customer security questions with evidence rather than memory.
Policies & Procedures
Whether current policies cover the practical areas customers and HISO guidance expect to see.
Asset, Endpoint & Patch Evidence
Whether asset registers, endpoint protection, secure configuration, patching, and vulnerability evidence can be produced.
Access, MFA & Least Privilege
Whether MFA, privileged access, user access review, and least-privilege controls are evidenced.
Backups, Encryption & Logging
Whether backup, restore testing, encryption, logging, monitoring, and alerting evidence is available.
Supplier & Third-Party Evidence
Whether important suppliers, implementation partners, and cloud/service providers are assessed and tracked.
Incident & Breach Readiness
Whether incident response, customer notification, escalation, and breach-support arrangements are documented.
Priority Gap & Roadmap
What needs attention first, who should own it, and what should be addressed over the next 90 days.
A fixed-scope readiness assessment with a clear report and practical next steps.
The assessment is designed as a practical first step. It gives leadership a clear view of what evidence exists, where the important gaps are, and what should be done next before a customer, PHO, provider, procurement team, or Health NZ-aligned buyer asks.
Fit call
A 30-minute conversation to understand your context, the customer or regulatory pressure you are facing, and whether this assessment is the right next step.
- No obligation
- Confirms fit before any proposal
- Suitable for suppliers facing customer, HISO, or CS-CMM questions
Evidence request and review
You provide existing documents, policies, reports, registers, screenshots, or partner outputs. The review checks what evidence is available and how well it supports customer and HISO expectations.
- Evidence-based review
- Uses what already exists
- No hands-on system access required unless agreed
Readout and assessment report
You receive a written readiness report, evidence map, priority gap register, and 90-day improvement roadmap that leadership can use for decision-making.
- Clear findings
- Customer-ready evidence view
- Practical next-step roadmap
Clear-scope assessment commitment
The assessment produces agreed written findings and a practical roadmap based on the evidence provided. It does not guarantee that every control is implemented or that any customer, regulator, or buyer will reach a particular outcome.
Start with a practical supplier assurance assessment.
Supplier Assurance Readiness Assessment
A fixed-scope assessment for NZ digital health suppliers that need to understand whether their current governance, evidence, and customer responses are ready for supplier-security review, HISO 10029.4 expectations, and CS-CMM Level 2 alignment questions.
| Item | Detail | What it means |
|---|---|---|
| Assessment | Fixed scope | Evidence request, review, findings, gap register, and 90-day improvement roadmap. |
| Format | Remote-first | Designed to minimise disruption while still producing useful written findings. |
| Output | Written report | Leadership receives a clear view of current evidence, gaps, priorities, and recommended next steps. |
| Next step | Fit call | A short call confirms whether the assessment is appropriate before any engagement is proposed. |
Who this assessment is for.
- NZ digital health suppliers handling health information.
- SaaS, cloud, software, integration, device, platform, outsourced, or managed technology suppliers.
- Suppliers preparing for customer questionnaires, PHO/provider review, procurement review, Board concern, HISO 10029.4 expectations, or CS-CMM Level 2 questions.
- Organisations that need a clear baseline before deciding what to fix first.
- Teams willing to provide existing evidence for review.
Who this assessment is not for.
- Organisations wanting hands-on IT implementation.
- Teams looking for an outsourced MSP, penetration tester, live incident responder, or legal adviser.
- Suppliers expecting guaranteed compliance or guaranteed customer approval.
- Teams unwilling to provide evidence or make responsible people available.
- Organisations that only want generic policy templates.
Not sure whether the assessment is the right next step?
Book a short fit call. We will discuss the customer or HISO-related pressure you are facing, what evidence currently exists, and whether a fixed-scope readiness assessment would be useful.
Assessment and advice, not hands-on implementation.
The assessment protects independence and clarity by reviewing governance and evidence without becoming the client’s implementer.
What ciso.nz does.
Reviews evidence, identifies gaps, provides written findings, recommends priorities, and explains what credible evidence should look like.
What the client owns.
Provides available evidence, confirms context, makes responsible people available, and decides what to do with the findings.
What specialists do.
MSP, MDR, pen test, appsec, cloud, privacy/legal, and incident response partners perform any specialist implementation or technical services under direct client engagement.
One senior adviser on the work.

Founder, ciso.nz
- DoctoralPhD, Computer Science — IoT & SIP Security
- SecurityCISSP · CISA · CRISC · CISM · CCSP
- PrivacyCIPP/US · CIPP/E
- AuditISO 27001 / 27701 / 42001 Lead Auditor
- PriorChief Information Security Officer · Chief Privacy Officer
The practice is intentionally focused on supplier assurance for digital health organisations: the work of translating security obligations, customer review questions, operational evidence, and leadership accountability into clear assessment findings and practical next steps.
The role is not to replace the MSP, dev team, MDR provider, pen tester, or incident response partner. The assessment role is to define what credible evidence looks like, review what is currently available, identify gaps, and report the current position clearly to leadership.
That is often the useful first step before customer reviews become urgent: not a pile of documents, but a practical and evidence-based view of where things stand and what should happen next.
Start with an assessment fit call.
No obligation.
The fit call is a 30-minute conversation to confirm whether your organisation is facing customer, Board, procurement, HISO 10029.4, or CS-CMM Level 2 questions — and whether a Supplier Assurance Readiness Assessment is the right next step.
Book an Assessment Fit Call →