Legal

Terms & Conditions

The terms on which Cianaa Technologies provides this website, and the conditions that apply to our audit, assessment and certification services.

Last updated: 29 August 2026. These Terms apply to Cianaa Technologies (New Zealand) and Cianaa Assurance Pty Ltd (Australia) (together “Cianaa”, “we”, “us”, “our”). They govern your use of this website and set out the general conditions attaching to our services. Individual engagements are governed by a separate signed agreement, which prevails over these Terms if the two conflict.

1. Who we are

Cianaa is an independent cybersecurity certification and assessment body. We operate across New Zealand and Australia through two related entities: Cianaa Technologies, registered in New Zealand, and Cianaa Assurance Pty Ltd, registered in Australia.

We act as auditors and assessors. We have been a Qualified Security Assessor (QSA) company on the PCI Security Standards Council register since 2014, and we conduct management system audits against ISO/IEC standards. Our registered office is Level 1/69 Ben Lomond Crescent, Pakuranga Heights, Auckland 2010, New Zealand.

2. Acceptance and changes

By accessing or using this website you agree to these Terms. If you do not accept them, please do not use the site.

We may update these Terms from time to time. The version published here is the version in force, and the date at the top shows when it last changed. Material changes affecting an active engagement will be notified to the client directly rather than by website update alone.

3. Using this website

You may view, download and print material from this site for your own information and internal business use.

You must not:

  • use the site in any way that is unlawful, or that could damage, disable or impair it;
  • attempt to gain unauthorised access to the site, its server, or any connected system or network;
  • conduct security testing, vulnerability scanning or penetration testing against this site without our prior written permission;
  • republish, sell or redistribute our material commercially, or present it as your own;
  • use automated means to harvest content or personal information from the site.
Security testing: we welcome responsible disclosure of security issues affecting this website. Please write to info@cianaatech.com before conducting any testing.

4. Intellectual property

All content on this site, including text, graphics, layout, reports, templates, guides and tools, is owned by Cianaa or licensed to us, and is protected by copyright and other intellectual property rights.

The Cianaa name, logo and the strapline “Assurance That Matters” are our marks. You may not use them without our written permission, except where you are a certified client using a certification mark under the conditions in section 6.

Standards referenced on this site, including the ISO/IEC standards and the PCI Data Security Standard, remain the property of their respective owners. We reference them as an assessment body. We do not sell or license them.

5. Services and engagements

Information on this site describes our services in general terms. It is not an offer capable of acceptance, and nothing on this site creates a contract between us.

An engagement begins only when scope, fees, timing and responsibilities are agreed in a written proposal or agreement signed by both parties. That document, together with any accreditation or scheme rules that apply to the work, governs the engagement. Where it conflicts with these Terms, that document prevails.

Our audits and assessments are conducted on a sampling basis at a point in time. They provide reasonable, not absolute, assurance. An audit or assessment is not a guarantee that a system is secure, that a breach will not occur, or that every non-conformity has been identified.

6. Certification conditions

Where we grant certification, the following conditions apply to the certified client, consistent with ISO/IEC 17021-1 and the rules of the relevant scheme.

Maintaining certification

  • You must continue to fulfil the requirements of the standard you are certified against, including where the standard is revised.
  • You must inform us without delay of changes that may affect your certified management system, including changes to legal status, ownership, organisation, management, contact address, scope, or the system itself.
  • You must make all necessary arrangements for the conduct of audits, including access to records, personnel, sites, equipment and, where required, observers or accreditation body witnesses.
  • You must keep records of complaints relating to your certified scope and make them available to us on request.

Use of certification marks

  • Certification marks may only be used within the certified scope and in the form we provide.
  • You must not use certification in a way that brings us or the certification scheme into disrepute, and must not make statements that are misleading or unauthorised.
  • A certification of a management system must not be presented as certification of a product, service or person.
  • On suspension, withdrawal or expiry of certification, you must stop using all reference to certification and return or destroy certification documents as we direct.

Suspension and withdrawal

We may suspend, reduce the scope of, or withdraw certification where a client fails to meet certification requirements, obstructs an audit, misuses certification marks, or fails to resolve non-conformities within the agreed period. We maintain publicly accessible information about the status of certifications we have issued, and will confirm the validity of a given certificate on request.

7. Impartiality

We are an independent body. We do not provide consultancy on the design, implementation or maintenance of a management system that we audit or certify, and we do not provide internal audit services to organisations we certify. This separation is a requirement of ISO/IEC 17021-1 and it is fundamental to the value of our work.

Our full position is set out on our impartiality page and in our global code of conduct. If you believe our impartiality has been compromised, tell us through the process in section 14.

8. Online tools and guides

This site provides free tools and reference material, including the SAQ selector, pre-audit self checks, calculators, checklists and guidance articles.

These are provided for general information only. They are not advice, and they are not an audit, assessment or certification. A result produced by a tool on this site carries no assurance value, cannot be presented to an acquirer, regulator or customer as evidence of compliance, and does not commit us to any finding in a subsequent engagement. Always confirm your obligations with a qualified assessor and with the current text of the applicable standard.

9. Confidentiality

We treat information obtained during an engagement as confidential, and our personnel are bound by confidentiality obligations. We will not disclose client information to a third party without written consent, except where disclosure is required by law, by an accreditation body, or by the rules of the certification scheme. Where the law requires disclosure, we will tell the client unless we are prohibited from doing so.

Information about the existence and scope of a certification we have granted is not confidential, and may be published or confirmed on request.

10. Third party links

This site links to third party sites, including standards bodies, accreditation bodies and partner organisations. Those links are provided for convenience. We do not control those sites, we are not responsible for their content, and a link does not imply endorsement.

11. Disclaimers

This website and its content are provided as is. To the extent permitted by law, we make no warranty that the site will be uninterrupted or error free, or that its content is complete, current or fit for a particular purpose. Standards, regulations and threats change, and material on this site may not reflect the most recent position.

Consumer rights: nothing in these Terms limits rights that cannot be excluded by law, including under the New Zealand Consumer Guarantees Act 1993 and Fair Trading Act 1986, or the Australian Consumer Law. Where you acquire services for business purposes, the parties agree that those consumer guarantee regimes do not apply to the extent the law permits that agreement.

12. Limitation of liability

To the extent permitted by law, we are not liable for indirect or consequential loss, or for loss of profit, revenue, data, goodwill or anticipated savings, arising from your use of this website or its free tools.

Liability arising from a paid engagement is governed by the signed agreement for that engagement, which sets any applicable cap. Nothing in these Terms excludes liability for fraud, or for any other liability that cannot lawfully be excluded.

13. Privacy

Our handling of personal information is set out in our Privacy Policy, which covers the New Zealand Privacy Act 2020, the Australian Privacy Act 1988, the EU and UK GDPR, and applicable United States privacy law. That policy forms part of these Terms.

14. Complaints and appeals

If you are dissatisfied with our service, a certification decision, or the conduct of an audit, we want to hear about it. Complaints and appeals are handled under a documented process that meets ISO/IEC 17021-1, and are reviewed by people who were not involved in the decision being challenged.

Submit a complaint or appeal through our complaints and appeals page, or write to info@cianaatech.com.

15. Governing law

These Terms are governed by the law of New Zealand, and the New Zealand courts have non exclusive jurisdiction over any dispute arising from them or from your use of this website.

Where services are delivered by Cianaa Assurance Pty Ltd, the governing law and jurisdiction stated in the signed engagement agreement applies to that engagement.

16. Contact

Questions about these Terms can be sent to:

Cianaa Technologies
Level 1/69 Ben Lomond Crescent, Pakuranga Heights, Auckland 2010, New Zealand
Email: info@cianaatech.com
Phone: +64 9 390 4252