What is NZISM 2.4?
In short
NZISM Section 2.4 is the part of the New Zealand Information Security Manual that deals with post-quantum cryptography (PQC). It requires agencies to monitor PQC developments, inventory their cryptographic systems and develop migration plans. No PQC algorithms have yet been approved for NZISM use, and no migration deadline has been set.
What Section 2.4 requires
The NZISM is New Zealand’s government information security manual. Section 2.4 asks agencies to do three things:
- monitor post-quantum cryptography developments
- inventory their cryptographic systems
- develop migration plans.
Preparation is mandated. Migration is not yet dated.
What it does not do yet
- No approved algorithms. NIST finalised ML-KEM (FIPS 203), ML-DSA (FIPS 204) and SLH-DSA (FIPS 205) in August 2024, but no PQC algorithms have been approved for NZISM use.
- No deadline. New Zealand is the only Five Eyes member without a formal PQC migration date.
- No public enforcement mechanism. The DPMC critical infrastructure consultation made no substantive mention of cryptography or of Section 2.4, which we raised in our submission to the DPMC critical infrastructure consultation.
- No position on hybrid versus pure PQC. Other countries have published one. See Same algorithms, different rulebooks.
How it compares
The United States (CNSA 2.0 and Executive Order 14412), the United Kingdom (NCSC), Australia (ASD) and the European Union have all attached dates to their guidance, ranging from 2030 to 2035. The comparison is in The quantum threat and Everyone else just set a date.
How we use it
Kaysec benchmarks against NZISM first, then maps outward to CNSA 2.0, ASD, NCSC and the EU. The Exposure snapshot includes an NZISM 2.4 gap check, and the cryptographic inventory in the full Readiness snapshot is the inventory Section 2.4 asks for. Our public scans of 118 New Zealand critical infrastructure entities, most recently Seven weeks later: NZ critical infrastructure PQC, the June 2026 update, use the same benchmark.