Generated by Rank Math SEO, this is an llms.txt file designed to help LLMs better understand and index this website. # Cianaa Technologies: Cianaa is Australian cyber security auditing and assessment company that provides certifications in ISO 27001, ISO 27701, ISO 42001, SOC 2 compliance, PCI DSS compliance and PCI DSS 3DS compliance. The company also provides penetration testing. ## Sitemaps [XML Sitemap](https://cianaatech.com/sitemap_index.xml): Includes all crawlable and indexable pages. ## Posts - [Are You an AI Provider or an AI User? ISO/IEC 42001 Roles Explained](https://cianaatech.com/iso-42001-roles-explained/): ISO/IEC 42001 requires you to determine your role, and that role decides which Annex A controls apply. How to tell whether you are an AI provider, producer, customer or user. - [Cloud AI and ISO/IEC 42001: allocating responsibility before your audit](https://cianaatech.com/iso-42001-cloud-ai-responsibility/): What ISO/IEC 42001 control A.10.2 requires when your AI runs on someone else's cloud, the gaps we find as auditors, and four steps to take before your audit. - [ISO/IEC 42005: What an AI System Impact Assessment Actually Requires](https://cianaatech.com/iso-42005-ai-system-impact-assessment/): A risk assessment asks what could harm the organisation. An AI system impact assessment asks who the organisation could harm. ISO/IEC 42005:2025 is the first international standard devoted to the second question, and it is the implementation detail behind ISO/IEC 42001 clause 6.1.4. - [SAQ Eligibility Is Not a Scoping Tool for Your ROC: PCI SSC FAQ 1331 Explained](https://cianaatech.com/saq-eligibility-not-a-scoping-tool-roc-faq-1331/): Can you use SAQ eligibility criteria to decide which PCI DSS requirements apply in a Report on Compliance? PCI SSC FAQ 1331 says no, unless your acquirer has approved it. Here is what that means. - [Assurance That Matters: Five Tests That Separate Assurance From Reassurance](https://cianaatech.com/assurance-that-matters/): Assurance is one of the most used and least examined words in cybersecurity. Five tests, and one question underneath them, that determine whether an assessment is worth relying on. - [Phishing-Resistant MFA Scored 8.8/10. Traditional MFA Scored 2.0. Here Is Why.](https://cianaatech.com/fido2-webauthn-vs-traditional-mfa-research/): New Cianaa research systematically reviewed 81 studies comparing FIDO2/WebAuthn against SMS, TOTP and push MFA. The security gap is roughly fourfold, and it matters for PCI DSS Requirement 8.5.1. - [How a PCI QSA Reduces Your Risk of Compliance Failures and Breaches](https://cianaatech.com/pci-qsa-services-reduce-compliance-breach-risk/): Most breached organisations believed they were compliant. A PCI QSA closes the gap between compliant on paper and genuinely secure, reducing both compliance-failure and breach risk. - [AI Has Made Phishing Unspottable: Why Awareness Training Is No Longer Enough](https://cianaatech.com/ai-phishing-awareness-training-obsolete/): Generative AI removed every tell that phishing training taught. A cybersecurity assessor explains why user detection can no longer be your primary defence, and what replaces it. - [Compliant but Compromised: Why PCI Compliance Isn’t Stopping Australian Card Fraud](https://cianaatech.com/compliant-but-compromised-australian-card-fraud/): Australia's card fraud hit A$762m even as 90% of large merchants pass PCI DSS. A QSA explains the card-not-present gap and why compliance and fraud detection have drifted apart. - [MFA Under PCI DSS v4.0.1: Requirements 8.4.1, 8.4.2, 8.4.3 and 8.5.1 Explained](https://cianaatech.com/pci-dss-mfa-requirements-8-4-explained/): Since 31 March 2025, MFA is required for everyone accessing the CDE, and the standard now tests how well it is implemented. The three scenarios in 8.4, the 8.5.1 quality rules, and the failure patterns assessors find. - [PCI DSS in the Cloud: Shared Responsibility Without the Blind Spots](https://cianaatech.com/pci-dss-cloud-shared-responsibility/): Your cloud provider's PCI attestation does not make your workload compliant. How responsibility really divides across IaaS, PaaS and SaaS, the documents to collect under 12.8.5, and the cloud pitfalls assessors keep finding. - [PCI DSS Scoping and Segmentation Done Right](https://cianaatech.com/pci-dss-scoping-segmentation-guide/): Scope is where PCI programmes go wrong and where the money is. How scoping works under v4.0.1, the annual confirmation Requirement 12.5.2 demands, segmentation testing under 11.4.5, and the places cardholder data hides. - [What Happens in a PCI DSS QSA Assessment: ROC vs AoC, Timeline and Cost Drivers](https://cianaatech.com/qsa-assessment-walkthrough-roc-aoc-timeline/): A plain-language walkthrough of a QSA assessment: the six phases, what a ROC and AoC actually are, realistic first-year timelines, and the factors that genuinely drive cost. - [Customized Approach vs Defined Approach in PCI DSS v4.0.1: How to Choose](https://cianaatech.com/pci-dss-customized-approach-vs-defined-approach/): PCI DSS v4.0.1 lets you meet requirements the defined way or with your own customized controls. A QSA's honest guide to what the Customized Approach really costs, its restrictions, and when it genuinely makes sense. - [Redirect to a Third Party? You Still Need ASV Scans: PCI SSC FAQ 1604 Explained](https://cianaatech.com/saq-a-asv-scans-redirect-iframe-faq-1604/): Merchants often assume redirecting to a payment provider removes the need for vulnerability scans. PCI SSC FAQ 1604 says otherwise: SAQ A includes ASV scanning under Requirements 11.3.2 and 11.3.2.1. - [PCI DSS and AI: Protecting Cardholder Data in AI Systems](https://cianaatech.com/pci-dss-and-ai-cardholder-data/): AI is entering payment environments fast. How PCI DSS applies to AI and LLM systems, where cardholder data leaks, and how to keep it safe. - [PCI DSS Compliance for New Zealand Businesses](https://cianaatech.com/pci-dss-compliance-new-zealand/): PCI DSS applies to any New Zealand business that takes card payments. A plain-language guide to merchant levels, SAQs, reducing scope, and v4.0.1. - [The PCI DSS Targeted Risk Analysis (12.3.1), Explained](https://cianaatech.com/pci-dss-targeted-risk-analysis-guide/): The Targeted Risk Analysis is the connective tissue of PCI DSS v4.x. What a 12.3.1 TRA must document, how it differs from 12.3.2, with a worked example and template. - [Client-Side Security: PCI DSS Requirements 6.4.3 and 11.6.1](https://cianaatech.com/pci-dss-client-side-security-6-4-3-11-6-1/): Since 31 March 2025, PCI DSS Requirements 6.4.3 and 11.6.1 are mandatory. How to manage payment page scripts, detect tampering, and stop digital skimming. - [PCI DSS 4.0.1: The Future-Dated Requirements Now in Force](https://cianaatech.com/pci-dss-4-0-1-future-dated-requirements-now-in-force/): Since 31 March 2025 the 51 future-dated PCI DSS v4.0.1 requirements are mandatory. A QSA's guide to what is now enforced, grouped so you can turn it into a work list. - [Cianaa Technologies signs Memorandum of Understanding with SGS Australia and SGS New Zealand](https://cianaatech.com/cianaa-sgs-partnership/): Cianaa Technologies has signed a Memorandum of Understanding with SGS Australia and SGS New Zealand to support the delivery of audit and certification services across New Zealand and Australia. - [Is a Vulnerability Scan a Penetration Test? What PCI DSS, SOC 2 and ISO 27001 Actually Require](https://cianaatech.com/vulnerability-scan-vs-penetration-test/): Companies routinely hand auditors a vulnerability scan and call it a penetration test. They are not the same, and PCI DSS, SOC 2 and ISO 27001 each treat them differently. An auditor's guide to the difference, with the five questions that reveal what you actually bought. - [How Does AI Affect Human Rights, and How Should It Be Governed?](https://cianaatech.com/ai-human-rights-governance-framework/): AI now mediates hiring, healthcare, education, policing and public benefits. A rights-based analysis of where AI presses hardest on internationally recognised human rights, and the ten-pillar governance framework that closes the gap between principle and enforceable accountability. - [Cianaa Technologies Joins Digital Identity NZ](https://cianaatech.com/cianaa-joins-digital-identity-nz/): Cianaa Technologies has been welcomed as a new member of Digital Identity New Zealand (DINZ), the Tech Alliance community advancing New Zealand's digital identity and digital trust ecosystem. - [Cianaa Listed as Independent Security & Privacy Evaluator under NZ’s Digital Identity Trust Framework](https://cianaatech.com/independent-evaluator-digital-identity-trust-framework/): Cianaa Technologies is listed by the New Zealand Government as an independent Security and Privacy evaluator under the Digital Identity Services Trust Framework, led by Dr Rizwan Ahmad. - [Dr Rizwan Ahmad Named MSECB Auditor of the Year 2024 for Asia-Pacific](https://cianaatech.com/msecb-auditor-of-the-year-2024-asia-pacific/): Cianaa founder Dr Rizwan Ahmad has received the MSECB Rron Islami Award as Auditor of the Year 2024 for the Asia-Pacific region, recognising exceptional professionalism and dedication in certification auditing. - [Cianaa Presents at the DINZ DISTF Evaluators Showcase](https://cianaatech.com/distf-evaluators-showcase-2025/): Dr Rizwan Ahmad joined evaluators from Deloitte, The Middleware Group and the Department of Internal Affairs at Digital Identity NZ's DISTF Evaluators Showcase, helping organisations understand the accreditation process. - [EIT Master of IT Students Complete Internships at Cianaa](https://cianaatech.com/eit-master-of-it-internships/): EIT Auckland Master of IT students Jing Su and Ayesh Rodrigo gained hands-on cybersecurity industry experience through internships at Cianaa Technologies in Auckland. - [Cianaa Named as QSA Assessor on Mastercard’s Global SDP Compliance List](https://cianaatech.com/mastercard-sdp-list-qsa-assessor/): Mastercard's SDP Compliant Registered Service Provider List (October 2025) names Cianaa Technologies as the QSA assessor of record for listed provider DebitSuccess Pty Ltd — card-scheme-level recognition of Cianaa's PCI DSS Level 1 assessments. - [New Zealand’s First ISO/IEC 42001 Certification: Datacom’s Datascape, Audited by Cianaa](https://cianaatech.com/datacom-datascape-iso-42001-certification/): Datacom's Datascape is the first New Zealand-based recipient of ISO/IEC 42001:2023 certification for AI management systems, audited by Cianaa's independent auditors with the certificate issued by MSECB. - [How Golomb’s Postulates Help Diagnose Hidden Patterns in Encryption](https://cianaatech.com/how-golombs-postulates-help-diagnose-hidden-patterns-in-encryption/): Golomb's three randomness postulates provide a foundational mathematical framework for detecting dangerous patterns in pseudorandom sequences used in encryption — helping cryptographers identify weak ciphers before attackers do. - [Securing Credit Card Payments: Best Practices for Protecting User Transactions](https://cianaatech.com/securing-credit-card-payments-best-practices-for-protecting-user-transactions/): This blog outlines essential strategies and best practices to safeguard credit card transactions, ensuring secure payment processing and compliance with industry standards such as PCI DSS - [Why Strong Cipher Suites Are Critical for Secure Credit Card Transmission in PCI DSS Compliance](https://cianaatech.com/why-strong-cipher-suites-are-critical-for-secure-credit-card-transmission-in-pci-dss-compliance/): In today’s digital payment ecosystem, every credit card transaction carries risk. As cardholder data travels across networks, it becomes vulnerable to interception, manipulation, and theft. To mitigate these risks, the Payment Card Industry Data Security Standard (PCI DSS) mandates the use of strong cryptography, particularly through secure protocols and cipher suites, to protect cardholder data during transmission. For organisations handling payment data, understanding the role of cipher suites is not just technical—it is fundamental to achieving and maintaining PCI DSS compliance - [Avoiding Common PCI DSS Pitfalls: A Practical Guide for Businesses (PCI DSS 4.0.1)](https://cianaatech.com/avoiding-common-pci-dss-pitfalls-a-practical-guide-for-businesses-pci-dss-4-0-1/): PCI DSS 4.0.1 is more than a checklist — it’s a framework for building customer trust and protecting payment data. Whether your business is based in Australia or New Zealand, avoiding these pitfalls and embracing continuous compliance will keep your organization secure, resilient, and ready for every audit - [How to Prepare for a PCI DSS QSA Audit: A Step-by-Step Guide for Australian Businesses](https://cianaatech.com/how-to-prepare-for-a-pci-dss-qsa-audit-a-step-by-step-guide-for-australian-businesses/): In Australia's fast-moving digital economy, protecting customer data isn't just good practice—it's a business imperative. For any company that handles card payments, the *Payment Card Industry Data Security Standard (PCI DSS)* is the benchm… - [Why a PCI DSS QSA Audit is Essential for Australian Businesses](https://cianaatech.com/why-australian-businesses-need-a-pci-dss-qsa-audit-australia/): In today’s digital economy, businesses handling credit card information face an ever-present threat of data breaches. To safeguard sensitive cardholder data and maintain consumer trust, the Payment Card Industry Data Security Standard (PCI… - [Optimising Your Success with Tailored PCI DSS Strategies](https://cianaatech.com/strategies/): Now, let’s drill down into specific considerations and tips for different audiences: small businesses, medium-sized businesses, large enterprises, the financial industry, and IT professionals tasked with compliance. - [Card Skimming Attacks and PCI DSS 4.0: Securing E‑Commerce Credit Card Data](https://cianaatech.com/strengthening-ecommerce-security-against-payment-data-theft/): Card skimming has evolved into one of the most significant threats facing e-commerce businesses today. This comprehensive guide explores the nature of digital skimming attacks and examines how PCI DSS 4.0's new requirements provide essentia… - [One Framework, Three Wins: Integrate SOC 2, ISO 27001 & PCI DSS](https://cianaatech.com/one-framework-three-wins-integrate-soc-2-iso-27001-pci-dss/): Managing three compliance frameworks — SOC 2, ISO/IEC 27001, and PCI DSS — often leads to duplicated effort and audit fatigue. Here's how a unified evidence cycle delivers stronger assurance with less overhead. - [Best Practices for Achieving and Maintaining PCI DSS Compliance](https://cianaatech.com/best-practices-for-achieving-and-maintaining-pci-dss-compliance/): Despite the challenges, there are proven strategies and best practices that can make PCI DSS compliance more straightforward. By taking a smart, proactive approach, organizations can simplify the compliance process and even use it as an opp… - [ Why Tokenization Is Essential for Securing Credit Card Data: Benefits for Businesses ](https://cianaatech.com/why-tokenization-is-essential-for-securing-credit-card-data-benefits-for-businesses/): Every company that processes, transmits, or stores credit card numbers faces the challenge of securing this sensitive data. Tokenization has emerged as a powerful technique to protect cardholder information by replacing real card numbers wi… - [Can You Retain Credit Card Numbers in Your Company? A Guide to PCI DSS v4.0 Requirement 3.5.1](https://cianaatech.com/can-you-retain-credit-card-numbers-3-5-1/): We are often asked this question and the companies often wonder: Can we legally and securely retain credit card numbers? The answer is yes—but only under strict conditions defined by the Payment Card Industry Data Security Standard (PCI DSS… - [ISO/IEC 42001:2023 – The New Global Standard for Responsible AI Management](https://cianaatech.com/iso-42001-global-voice-for-artificial-intelligence/): ISO/IEC 42001:2023 is the world’s first international standard dedicated to Artificial Intelligence Management Systems (AIMS). Published in 2023, this standard provides a comprehensive, certifiable framework for organizations to govern the… - [Artificial Intelligence Governance and Compliance Framework-Practical Guide](https://cianaatech.com/42001-guide/): AI governance is becoming the next pillar of enterprise compliance. This practical guide outlines the framework and controls organisations need to deploy AI responsibly and demonstrate accountability under ISO/IEC 42001. - [10 Best Practices for Implementing Level 1 PCI DSS Service into Business-as-Usual Processes](https://cianaatech.com/10-best-practices-for-pci-dss-level-1-compliance-service/): Implementing Level 1 PCI DSS service into your organization's business-as-usual (BAU) processes is essential for maintaining ongoing compliance and safeguarding sensitive cardholder data. - [Tokenization](https://cianaatech.com/tokenisation-of-credit-card-numbers-pan/): Tokenisation replaces sensitive credit card numbers with non-sensitive equivalents — reducing PCI DSS scope without sacrificing payment functionality. A primer on how it works and where it belongs. - [9 Common Cyber Security Challenges in Achieving PCI DSS Compliance](https://cianaatech.com/9-security-challenges/): Complying with PCI DSS can be challenging, especially given the technical complexity and ongoing effort required. Different organizations face different hurdles – a small business might worry about cost, while a large enterprise might strug… - [Quantum Safe Encryption](https://cianaatech.com/quantum-safe-encryption/): In today’s world, data security is paramount as we increasingly rely on technology for our daily lives. With quantum computers on the horizon, traditional encryption methods may soon become vulnerable to attacks. - [Stitch in Time Saves Nine](https://cianaatech.com/stitch-in-time-saves-nine/): In the contemporary digital era, technological advancements have revolutionized business operations. However, these innovations have also introduced a dynamic landscape of cyber threats and vulnerabilities. ## Pages - [AI Role Selector: What Is Your Role Under ISO/IEC 42001?](https://cianaatech.com/iso-42001-ai-role-selector/): .cair-page{width:100vw;position:relative;left:50%;right:50%;margin-left:-50vw !important;margin-right:-50vw !important;max-width:100vw;overflow-x:hidden} - [PCI DSS Pre-Audit Maturity Assessment | Cianaa](https://cianaatech.com/pci-dss-preaudit-maturity-assessment/): .cpm-cta .eyebrow{color:#075A8A;background:#fff;border-color:#BFE3F5} - [Media & Press | Cianaa Technologies](https://cianaatech.com/media/): Cianaa is an independent cybersecurity certification and assessment body headquartered in Auckland, working across New Zealand, Australia, Asia Pacific, Europe, the United States and Canada. Our assessors give journalists clear, credible, conflict-free commentary, backed by original published research. - [Research & Publications | Cianaa Technologies](https://cianaatech.com/research/): Peer-visible, DOI-registered research on AI governance, ISO/IEC 42001 and the evolving legal landscape of artificial intelligence. Every paper is openly licensed and permanently citable. - [The State of ISO/IEC 42001 Adoption in New Zealand & Australia](https://cianaatech.com/iso-42001-adoption-new-zealand-australia/): {"@context": "https://schema.org", "@graph": }, {"@type": "FAQPage", "@id": "https://cianaatech.com/iso-42001-adoption-new-zealand-australia/#faq", "mainEntity": }, {"@type": "BreadcrumbList", "@id": "https://cianaatech.com/iso-42001-adoption-new-zealand-australia/#breadcrumb", "itemListElement": }]} - [ISO 42001 vs NIST AI RMF](https://cianaatech.com/iso-42001-vs-nist-ai-rmf/): Both help organisations manage AI responsibly — but they are different tools. ISO/IEC 42001 is a certifiable management system standard; the NIST AI RMF is a voluntary risk framework. Here is how they compare, when to use each, and how they work best together. - [Complaints & Appeals](https://cianaatech.com/complaints-appeals/): Cianaa Technologies is committed to handling every complaint and appeal fairly, impartially and confidentially — in line with the requirements of ISO/IEC 17021-1. - [Cryptographic Algorithm Deprecation Timeline](https://cianaatech.com/infographics/cryptographic-algorithm-deprecation-timeline/): Algorithm status over time — recommended, transitioning, deprecated and prohibited — incl. the post-quantum migration window. - [Cryptographic Algorithm Selection](https://cianaatech.com/infographics/cryptographic-algorithm-selection/): Choose the right algorithm for encryption, signatures, hashing and key exchange — recommended, conditional and deprecated. - [PCI DSS v4.0 Network Architecture](https://cianaatech.com/infographics/pci-dss-network-architecture/): A reference cardholder-data-environment network — internet, DMZ, CDE and internal segmentation zones. - [PCI DSS v4.0 HSM Key Management Workflow](https://cianaatech.com/infographics/pci-dss-hsm-key-management-workflow/): End-to-end HSM key management — lifecycle stages, key hierarchy, rotation workflows, dual control and audit. - [Infographics](https://cianaatech.com/infographics/): Visual explainers and downloadable reference guides across PCI DSS, ISO 27001, SOC 2 and cryptography. Open any card in a new tab — PDF guides unlock with your work email. - [Key Management Operations Center](https://cianaatech.com/infographics/key-management-operations-center/): A 24/7 operations reference — key lifecycle, incident response, rotation schedule, dual control and quick reference. - [AICPA Trust Services Criteria](https://cianaatech.com/infographics/aicpa-trust-services-criteria/): The five AICPA Trust Service Criteria that SOC 2 reports are built on. - [Whitepapers](https://cianaatech.com/whitepapers/): Deep-dive reports on PCI DSS, ISO 27001, SOC and the compliance landscape across New Zealand and Australia. - [Company News](https://cianaatech.com/company-news/): Updates from Cianaa Technologies — new accreditations, milestones and what’s new across our assessment and audit practice. - [SOC 1 & SOC 2 Guide](https://cianaatech.com/soc-1-and-soc-2-guide/): What SOC 1 and SOC 2 reports cover, the difference between Type I and Type II, the Trust Services Criteria, and a practical readiness checklist. - [The ISO 27001 Compliance Journey](https://cianaatech.com/infographics/iso-27001-compliance-journey/): From "we should get certified" to holding the certificate — the seven stages, step by step. - [Anatomy of a Strong Password](https://cianaatech.com/infographics/strong-passwords/): Small habits that dramatically reduce the risk of an account takeover. - [Spot a Phishing Email](https://cianaatech.com/infographics/spot-a-phishing-email/): Six red flags to check before you click, reply or download. - [PCI DSS SAQ Selection](https://cianaatech.com/infographics/pci-dss-saq-selection/): Find the right SAQ for your business — a decision guide across all nine SAQ types. - [SOC 2 Type 2 Assessment](https://cianaatech.com/infographics/soc-2-type-2-assessment/): The four phases, the observation-period timeline, and the five Trust Service Criteria. - [Case Studies](https://cianaatech.com/case-studies/): Real outcomes from our independent audits and assessments across PCI, ISO, AI and SOC. Clients are anonymised unless they've chosen to be named. - [How ISO 27001 Certification Works, Step by Step](https://cianaatech.com/how-iso-27001-certification-works/): A clear walk-through from "we should get certified" to holding the certificate — so there are no surprises. - [SOC 2 vs ISO 27001: Which One Does Your Business Need?](https://cianaatech.com/soc-2-vs-iso-27001/): The two most-requested security credentials — and they overlap a lot. Here's how they differ, and how to choose. - [Compliance & Security Glossary](https://cianaatech.com/compliance-glossary/): Plain-English definitions of the certification and cybersecurity terms you'll meet along the way. - [Compliance FAQ](https://cianaatech.com/compliance-faq/): Straight answers to the questions we're asked most — about PCI, ISO, SOC and government assessments. No jargon, no sales pitch. - [Careers](https://cianaatech.com/careers/): Join a 23-person ecosystem of cybersecurity, compliance and AI-governance practitioners delivering ISO 27001, 27701, 42001 and PCI DSS engagements across New Zealand, Australia and the wider Asia-Pacific region. - [ISO 9001 Training: Quality Management System Courses | Cianaa](https://cianaatech.com/training/iso-9001/): Develop your team's ISO 9001:2015 competency with expert-led training covering Quality Management System implementation, internal auditing, and certification preparation. - [ISO 45001 Training: Occupational Health & Safety Management Courses | Cianaa](https://cianaatech.com/training/iso-45001/): Cianaa delivers ISO 45001:2018 training that goes beyond compliance — from awareness for the whole workforce to lead auditor qualification for HSE professionals. Build in-house competency to identify hazards, run real internal audits, and prepare confidently for certification. - [PCI DSS Training: Compliance Courses for Payment Security | Cianaa](https://cianaatech.com/training/pci-dss/): Build your team's PCI DSS knowledge with instructor-led training covering the full PCI DSS v4.0 standard — from foundational awareness through to advanced implementation and QSA exam preparation. - [ISO 14001 Training: Environmental Management System Courses | Cianaa](https://cianaatech.com/training/iso-14001/): Develop your team's ISO 14001:2015 competency with expert-led training covering Environmental Management System (EMS) implementation, compliance obligations, and certification preparation. - [ISO 27701 Training: Privacy Information Management Courses | Cianaa](https://cianaatech.com/training/iso-27701/): Build practical ISO 27701 competency with expert-led training covering Privacy Information Management System (PIMS) implementation, privacy risk management, and integration with ISO 27001. - [ISO 27001 Training: Information Security Management Courses | Cianaa](https://cianaatech.com/training/iso-27001/): Develop your team's ISO/IEC 27001:2022 competency with expert-led training — from foundation awareness and implementation through to internal auditor and lead auditor preparation. - [PCI DSS SAQ Selector | Cianaa](https://cianaatech.com/pci-dss-saq-selector/): Not sure which PCI DSS Self‑Assessment Questionnaire (SAQ) applies to your business? Choosing the wrong SAQ can lead to gaps in compliance, audit failure, or unnecessary cost and effort. - [Privacy Policy](https://cianaatech.com/privacy-policy/): How Cianaa Technologies collects, uses, shares and protects your personal information — for individuals in New Zealand, Australia, the European Union & UK, and the United States. - [ISO/IEC 42001](https://cianaatech.com/iso-iec-42001/): Foundation, Lead Implementer and Lead Auditor certification — delivered by Cianaa as a PECB partner. - [About Us](https://cianaatech.com/about-us/): Cianaa is a leading Australasian company specialising in cybersecurity compliance and accreditation. We disrupt the legacy model of audit work, replacing assumptions with evidence-driven findings that hold up under scrutiny. Cianaa operates as Cianaa Technologies (New Zealand, NZBN 9429041553831) and Cianaa Assurance Pty Ltd (Australia, ABN 87 685 534 838). - [Contact](https://cianaatech.com/contact/): Whether you're preparing for a PCI DSS or ISO assessment, enrolling in training, or just exploring your options, our certified specialists are here to help. We reply to every enquiry within one business day. - [ISO/IEC 42001 Lead Auditor](https://cianaatech.com/iso-42001-lead-auditor-course-ai-management-system-audit/): Gain the skills and knowledge to audit Artificial Intelligence Management Systems (AIMS) in line with international standards. Learn to plan, conduct and manage AI system audits using recognised audit principles and best practices. - [ISO/IEC 42001 Lead Implementer](https://cianaatech.com/iso-iec-42001-lead-implementer/): The ISO/IEC 42001 Lead Implementer course is a comprehensive training programme that prepares professionals to design, implement and manage an Artificial Intelligence Management System (AIMS) in alignment with the ISO/IEC 42001 standard. This globally recognised certification enables participants to ensure that AI systems are responsible, ethical, secure and compliant with international best practices. - [ISO/IEC 42001 Foundation](https://cianaatech.com/iso-iec-42001-foundation/): The ISO/IEC 42001 Foundation training course is designed for professionals who want to understand and implement an Artificial Intelligence Management System (AIMS) in alignment with the ISO/IEC 42001 international standard. Whether you are new to AI systems or looking to enhance your professional qualifications, this training offers a clear pathway to earning your ISO/IEC 42001 Foundation certification. - [Corporate Social Responsibility](https://cianaatech.com/corporate-social-responsibility-cianaatech/): Building trustworthy, resilient and sustainable digital futures — across ethics, privacy, people, planet and community. - [Global Code Of Conduct](https://cianaatech.com/global-code-of-conduct/): Empowering global connections for inspiring cross-cultural and jurisdictional harmony. - [Impartiality](https://cianaatech.com/impartiality/): Independent, objective and unbiased in every assessment — because impartiality is the foundation of credible certification. - [Home](https://cianaatech.com/): Helping you achieve ISO 27001, PCI DSS, SOC 2 and other certifications with confidence and ease. - [Meet Our Team](https://cianaatech.com/meet-our-team/): Empowering Excellence: Our Exceptional Team Drives Innovation and Success. A focused leadership core, a credentialed bench of subject matter experts, an established external auditor network, and a tertiary-institute internship pipeline — built for breadth, designed for depth. - [Insights](https://cianaatech.com/security-insights/): With a relentless focus on identifying, analyzing, and mitigating cyber risks, cybersecurity research is the cornerstone of digital defense strategies. - [Terms & Conditions](https://cianaatech.com/terms-conditions/): The terms on which Cianaa Technologies provides this website, and the conditions that apply to our audit, assessment and certification services. - [Partners](https://cianaatech.com/partners/): Cianaa and partners — strengthening cybersecurity for all. Together with our trusted partners, Cianaa is dedicated to creating a safer digital environment through collaboration, scalable security frameworks, and a full slate of B2B training programs across PCI DSS and ISO management standards. - [Training](https://cianaatech.com/training/): } ## Services - [Cloud Security Certification & Attestation](https://cianaatech.com/services/cloud-security-certification/): {"@context": "https://schema.org", "@graph": , "url": "https://cianaatech.com/services/cloud-security-certification/", "description": "Independent ISO/IEC 27017, ISO/IEC 27018 and BSI C5 cloud-security audits and attestation from a conflict-free certification body."}, {"@type": "FAQPage", "@id": "https://cianaatech.com/services/cloud-security-certification/#faq", "mainEntity": }, {"@type": "BreadcrumbList", "@id": "https://cianaatech.com/services/cloud-security-certification/#breadcrumb", "itemListElement": }]} - [SOC 2 Audit Duration Calculator](https://cianaatech.com/services/soc-2-audit-duration-calculator/): Get an indicative estimate of the auditor effort for your SOC 2 Type 1 and Type 2 examination — based on the people in scope and the Trust Services Categories you include. - [ISO 27701:2025 Transition Guide](https://cianaatech.com/services/iso-27701-2025-transition/): Cianaa provides independent auditors for certification across New Zealand and Australia. We assess and certify — impartially, without consulting — and we can schedule your ISO 27701:2025 transition alongside your existing audit programme. - [ISO Audit Duration Calculator](https://cianaatech.com/services/audit-duration-calculator/): Get an indicative estimate of the audit time (mandays) for your ISO certification — initial, surveillance and recertification — based on IAF MD 5, ISO/IEC 27006, ISO/IEC 27706 and ISO/IEC 42006. - [ISO 27001:2022 Internal Audit](https://cianaatech.com/services/iso-27001-internal-audit/): Internal audits are a mandatory part of ISO/IEC 27001 (Clause 9.2). Learn what an internal audit involves, how to run one — and download our free, ready-to-use internal audit checklist. - [ISO/IEC 27701 Certification](https://cianaatech.com/services/iso-27701-certification/): ISO/IEC 27701 is the global benchmark for managing personal information. Certify your Privacy Information Management System — standalone under the new 2025 edition, or integrated with your ISO/IEC 27001 ISMS — and prove, through independent certification, that you handle personal data responsibly. Stage 1 + Stage 2 audit, surveillance, recertification. - [Introduction to ISO 27001:2022](https://cianaatech.com/services/iso-27001-certification/): A plain-English guide to the world's leading information security standard — what it is, its key benefits, the mandatory clauses, the Annex A controls, who needs it, and how organisations achieve certification. - [ISO 13485 Certification Services | Medical Devices QMS | Cianaa](https://cianaatech.com/services/iso-13485-certification/): ISO 13485 is the international quality management standard for medical devices. Cianaa helps manufacturers, suppliers, and distributors achieve and maintain certification — demonstrating safety, quality, and regulatory compliance to customers and authorities. - [ISO 22000 Certification Services | Food Safety Management | Cianaa](https://cianaatech.com/services/iso-22000-certification/): ISO 22000 is the international standard for Food Safety Management Systems. Cianaa helps food businesses across the supply chain achieve certification — demonstrating systematic food safety controls to customers, retailers, and regulators. - [SOC 3 Assessment: Public Trust Report Guide | Cianaa](https://cianaatech.com/services/soc-3-assessment/): A SOC 3 report gives you a publicly shareable seal of assurance based on the same Trust Services Criteria as SOC 2 — without disclosing the detailed controls your clients and competitors can read in a full SOC 2 report. - [SOC 2 Assessment: Type I & Type II Guide | Cianaa](https://cianaatech.com/services/soc-2-assessment/): A SOC 2 report is the market-standard evidence of your organisation's security posture. Cianaa's experienced auditors guide you through Type I and Type II assessments — efficiently and without disrupting operations. - [PCI 3DS Compliance Experts | Qualified 3DS Assessors | Cianaa](https://cianaatech.com/services/pci-3ds-compliance-experts/): /* ===== PREMIUM UPGRADES ===== */ - [PCI 3DS Risk Management: Complete Guide | Cianaa](https://cianaatech.com/services/pci-3ds-risk-management/): /* ===== PREMIUM UPGRADES ===== */ - [3DS Certification: A Complete Guide | Cianaa](https://cianaatech.com/services/3ds-certification/): /* ===== PREMIUM UPGRADES ===== */ - [PCI Compliance Checklist: Check Where You Stand (PCI DSS v4.0.1)](https://cianaatech.com/services/pci-compliance-checklist/): .cpa-ms-titles{display:flex;align-items:center;gap:10px;flex-wrap:wrap;margin-bottom:4px} - [PCI Compliance Assistance: Expert Help from Gap to Certification](https://cianaatech.com/services/pci-compliance-assistance/): Cianaa Technologies provides end-to-end PCI DSS compliance assistance for businesses at every stage — whether you are starting from scratch, preparing for a QSA audit, or maintaining year-round compliance. - [PCI Compliance Levels Explained: Which Level Is Your Business?](https://cianaatech.com/services/pci-compliance-levels/): A complete guide to the 4 PCI DSS merchant levels — what they mean, who they apply to, and exactly what validation each level requires. - [What is PCI Compliance? The Complete Business Guide](https://cianaatech.com/services/what-is-pci-compliance/): Everything you need to know about PCI DSS compliance — requirements, merchant levels, costs, and how to protect your business from payment card data breaches. In plain terms: if your business takes card payments, PCI compliance is not optional. Cianaa supports businesses across Asia Pacific, Europe, and North America with QSA-led PCI DSS assessments. - [Payment Card Industry](https://cianaatech.com/services/achieve-pci-dss-compliance/): A PCI QSA (Qualified Security Assessor) is a company the PCI Security Standards Council has trained, tested and authorised to independently assess an organisation against PCI DSS and to issue the official Report on Compliance (ROC) and Attestation of Compliance (AoC). Only a registered QSA can validate PCI DSS compliance at this level, which is why banks, acquirers and card schemes rely on QSA assessments as trusted, independent proof. - [SWIFT Assessment Services](https://cianaatech.com/services/swift-assessment-services-for-the-banking-sector/): Cianaa Technologies — Your Trusted SWIFT CSP Assessor. Cianaa is proud to be a certified SWIFT CSP Assessor, offering independent, expert-led assessments that help banks meet compliance, strengthen security, and pass attestation. Coverage across New Zealand, Australia, Asia Pacific, Europe, USA and Canada. - [ISO 9001 Certification Services](https://cianaatech.com/services/iso-9001-certification/): To keep your certification credible and free of conflicts, our team focuses exclusively on auditing and certification. Whether you are a small business, a mid-sized company, or a large enterprise, our ISO 9001 certification services are tailored to help you streamline operations, reduce risks, and build lasting trust with your customers — across New Zealand, Australia, Asia Pacific, Europe, USA, Canada and CEMEA. - [ISO 45001 Certification](https://cianaatech.com/services/iso-45001-certification/): The international standard for Occupational Health and Safety Management Systems. Reduce workplace incidents, meet legal obligations, and demonstrate commitment to employee wellbeing — Stage 1 + Stage 2 audit, surveillance, recertification. - [ISO/IEC 42001 Artificial Intelligence Management Systems Certification](https://cianaatech.com/services/iso-iec-42001-certification-for-responsible-ai-management/): Cianaa’s auditors conducted the certification audit behind New Zealand’s first ISO/IEC 42001 certification. Datacom’s Datascape, the AI enabled platform used by more than 90 councils across Australia and New Zealand, was certified to ISO/IEC 42001:2023 following an audit by Cianaa’s independent auditors, with the certificate issued by MSECB. - [Penetration Assessment](https://cianaatech.com/services/penetration-testing/): Protect your business from cyber threats with expert penetration testing services. Discover vulnerabilities, ensure compliance, and strengthen your security posture. We offer professional penetration testing services designed to run real-world simulated attacks to unearth vulnerabilities that could cause devastating loss before attackers find them. - [Essential Eight](https://cianaatech.com/services/aus-government-essential-eight/): A government standard guideline to improve the cybersecurity of organisations. Protect your business from cyber threats with the Australian Cyber Security Centre's Essential Eight. It provides a roadmap for organizations to prioritize their cybersecurity efforts, ensuring focus on the most critical risks. Cianaa supports Australia, New Zealand and Asia Pacific. - [ISO and Privacy Certifications](https://cianaatech.com/services/iso-certifications/): The global economy is constantly changing and companies must navigate a volatile business environment in order to succeed. Cianaa supports the full stack of ISO Management System Certifications — covering New Zealand, Australia, Asia Pacific, Europe, USA and Canada under ISO/IEC 17021 conformity assessment principles. - [SOC Compliance Assessment Services](https://cianaatech.com/services/soc-assessment/): Protect your data, prove your integrity, and meet regulatory demands with confidence — your path to seamless SOC 1, SOC 2, and SOC 3 compliance starts here. Cianaa supports merchants and service providers across New Zealand, Australia, Asia Pacific, Europe, USA and Canada. - [TFA Evaluation](https://cianaatech.com/services/tfa-evaluation/): A due diligence approach to improve the effectiveness of the controls within the government sector. The Digital Identity Services Trust Framework is designed to establish a digital identity environment that is both secure and reliable — individuals can confidently share their information knowing it's protected. Cianaa is a Trusted Authority Evaluator (TFA) for New Zealand government services. - [NZ Government Assurance](https://cianaatech.com/services/nz-govt-assurance/): A due diligence approach to improve the effectiveness of the controls within the government sector. A government standard to improve the cybersecurity of organisations — an objective and independent assessment improves critical posture of security and reduces the risk. Cianaa provides assurance services for the New Zealand public sector under NZISM, ISO 27001, ISO 27701 and PCI DSS. - [PCI 3DS Assessment](https://cianaatech.com/services/pci-3ds-assessment/): Your business handles sensitive payment data daily. Don't let compliance gaps put your reputation, finances, or customer trust at risk. Cianaa is a Qualified PCI 3DS Assessor securing EMV® 3-D Secure environments — ACS, DS, and 3DSS — across New Zealand, Australia, Asia Pacific, Europe, USA, and Canada. - [ISO/IEC 27001 Information Security Management Systems Certification](https://cianaatech.com/services/iso27001/): ISO/IEC 27001 Certification is an international language of TRUST. Protect your organization's information security for compliance and trust — Stage 1 + Stage 2 audit, surveillance, recertification. Plan-Do-Check-Act framework supported by certified auditors and cybersecurity experts. - [Integrated Audit Approach](https://cianaatech.com/services/integrated-audit-approach/): A specialist in integrated audit for compliance brings a strategic advantage to organizations by offering a unified approach to meeting regulatory, governmental and operational standards. Conducting a multi-audit approach can significantly reduce costs by streamlining resources and minimising redundancies — combining multiple audits into a single, integrated engagement. ## Trusted Clients' Logos - [Plan b](https://cianaatech.com/trusted-client-logo/logo-eight/) - [xplor](https://cianaatech.com/trusted-client-logo/logo-seven/) - [Humm](https://cianaatech.com/trusted-client-logo/logo-six/) - [Spark](https://cianaatech.com/trusted-client-logo/logo-five/) - [Data Com](https://cianaatech.com/trusted-client-logo/logo-four/) - [Illion](https://cianaatech.com/trusted-client-logo/logo-three/) - [Fidelity](https://cianaatech.com/trusted-client-logo/logo-two/) - [CCL](https://cianaatech.com/trusted-client-logo/logo-one/)