Skip to content

Essential Eight, SMB1001, ISO 27001: which cyber framework fits your business?

Three frameworks come up in Australian small-business cyber conversations, and the marketing around them makes all three look interchangeable. They are not. Unless an insurer, a customer or a regulator has named a specific one, start with the Essential Eight.

Where CCP sits

CCP holds ISO/IEC 27001:2022 certification, issued by BSI under certificate IS 840964. That makes it a standard we have run, not one we have read about. We are not a certification body, and we don't audit anyone against ISO 27001 or the Essential Eight. Nor are we a CyberCert partner: SMB1001 certification isn't something we sell. Take what follows as an IT operator's read of the three frameworks, not as legal advice or a compliance opinion.

What each one covers

What the Essential Eight, SMB1001 and ISO 27001 each cover.

E8

Essential Eight

Eight technical mitigation strategies from the Australian Cyber Security Centre (ACSC), part of the Australian Signals Directorate. Built for federal government first, then adapted into four maturity levels (ML0 to ML3) the rest of the country can use. You self-assess against the ACSC's published criteria. No certificate, no audit, no annual fee.

SMB1001

SMB1001

A five-tier certification standard (Bronze, Silver, Gold, Platinum, Diamond) from Dynamic Standards International, formerly Cyber Security Certification Australia. CyberCert operates the certification. It is aimed squarely at small and medium businesses. Your own director attests Bronze, Silver and Gold; Platinum and Diamond need a third-party audit. First published 2023, now on its 2026 edition.

ISO 27001

ISO/IEC 27001

The international standard for an information security management system (ISMS), published by ISO and IEC. In force globally since 2005, most recently revised in 2022. No tiers: you either hold the certificate or you don't. An accredited third-party body always audits it, on a three-year cycle with annual surveillance audits in between.

Side by side

How Essential Eight, SMB1001 and ISO 27001 compare on cost and audit.

The differences that decide it are who publishes each one, how you prove it, what it costs, and who accepts it as evidence.

E8

Essential Eight

Who runs it
Australian Signals Directorate (ACSC). Sovereign cyber authority.
How you prove it
Self-assessment against ACSC criteria. No certificate. Often used as evidence inside cyber-insurance renewals and supplier-security questionnaires.
Tier or maturity model
Four maturity levels: ML0 (partial or missing), ML1, ML2, ML3. Your overall maturity equals your weakest of the eight control scores, not the average.
Direct cost in 2026
Free. ACSC publishes the model. Audit and assessment cost is your time and your IT spend on the controls themselves.
Update cadence
Maturity model revised every few years. Last major revision November 2023; minor updates more often.
Recognised by Australian Government
Yes. ACSC publishes it. Cited in federal cyber strategy, sector regulator guidance, and many procurement panels.
Recognised by cyber insurers
De facto baseline language used in most Australian renewal questionnaires. ML1 typically clears a renewal without raised flags.

SMB1001

SMB1001

Who runs it
Dynamic Standards International (DSI), formerly CSCAU. Private Australian standards body. Sister entity CyberCert operates certification.
How you prove it
Bronze, Silver and Gold: self-attested by a company director. Platinum and Diamond: third-party audit. Annual recertification for all tiers.
Tier or maturity model
Five tiers from Bronze to Diamond. Each tier adds controls on top of the previous. 6 controls at Bronze, 35 at Diamond.
Direct cost in 2026
Annual certification fee per organisation, AU ex GST: $95 (Bronze), $195 (Silver), $395 (Gold), $3,595 (Platinum), $5,995 (Diamond). The standard text itself is paywalled at USD $99 to $1,000 with usage-based pricing.
Update cadence
Annual editions (2023, 2025, 2026). Genuinely faster cadence than the alternatives.
Recognised by Australian Government
Not in primary legislation. As of April 2026, it is not named in the Cyber Security Act 2024, and not in the Security of Critical Infrastructure (SOCI) Act risk-management rules. Cyber Security Certification Australia asked Government to add it in a 2024 submission. The 2025 SOCI amendments did not add it.
Recognised by cyber insurers
Managed service provider (MSP) marketing claims insurer recognition. We could not find one named Australian insurer that publishes SMB1001 as a documented premium-discount input.

ISO 27001

ISO 27001

Who runs it
ISO and IEC, the international standards bodies. Independently accredited certification bodies run the audits (JAS-ANZ accredits them in Australia).
How you prove it
Third-party audit by an accredited certification body. Three-year certificate cycle, annual surveillance audits. No self-attest pathway.
Tier or maturity model
Single binary state (certified or not), but the certificate covers a defined Statement of Applicability that scopes which controls are in play for your organisation.
Direct cost in 2026
First-audit cost typically AU $15,000 to $50,000 depending on scope and certifier. Standard text sold by ISO at roughly AU $150 fixed.
Update cadence
5 to 10 year revision cycles. Current edition 2022, predecessor 2013.
Recognised by Australian Government
Yes. Specifically named in CIRMP Rules for some critical-infrastructure sectors. Required by Right Fit For Risk and several other government accreditation regimes.
Recognised by cyber insurers
Universally recognised. Often clears whole questionnaire sections instead of itemised answers.

Those costs are the certification or audit fee only. Meeting the controls costs you more every time: technical work, software and staff hours.

SMB1001 close look

What SMB1001 requires at each tier, Bronze to Diamond.

These are the controls in the SMB1001 standard, taken from Cyber Security Certification Australia's own 2024 submission to the Department of Home Affairs. Each tier adds controls to the one below it. Costs are Australian dollars per organisation per year, excluding GST.

Bronze (Level 1)

$95 per year · 6 controls · Director attested

Six controls: engage technical support, install a firewall and anti-virus, patch automatically, change passwords routinely, and keep a backup strategy.

Silver (Level 2)

$195 per year · 14 controls · Director attested

Eight more on top of Bronze. Encryption (TLS) on your public sites, no admin rights on ordinary user accounts, individual logins, a password manager, and multi-factor authentication (MFA) on email. Then non-disclosure agreements, an invoice-fraud policy and a visitor register.

Gold (Level 3)

$395 per year · 22 controls · Director attested

Another eight. Server patching, MFA on business apps and social accounts, a written cyber security policy, and an incident-response plan. Then secure document and device disposal, an asset register, and staff awareness training.

Platinum (Level 4)

$3,595 per year · 28 controls · External audit

Six more, and the first tier an external auditor checks. External vulnerability scanning, MFA on stored data, on the virtual private network (VPN) and on remote desktop (RDP), remote-access credential management, and business insurance.

Diamond (Level 5)

$5,995 per year · 35 controls · External audit

Seven more. Encryption at rest, application control, disabling untrusted Office macros, and penetration and social-engineering testing. Then supplier digital trust, police vetting for administrators, and tabletop training on the incident-response plan.

What to flag before you pay

  • Routine password changes are still a Bronze control. The US National Institute of Standards and Technology told organisations to stop forcing scheduled password rotation. That guidance, NIST SP 800-63B Revision 4, has been in force since August 2025. Level 2 then adds a password manager, which leaves the rotation requirement one tier below it contradicting the tier above.
  • A Gold-certified business is not required to have MFA on remote desktop. Remote desktop without MFA is one of the most common ways ransomware gets in, and has been for years. SMB1001 puts MFA on RDP, VPN and stored data at Level 4, which costs $3,595 a year and is externally audited. Below that, a certificate holder can run remote desktop on a password alone and still hold the badge.
  • The Essential Eight alignment claim only goes so far. SMB1001 markets itself as aligned with the Essential Eight. Application control and disabling untrusted Office macros are both ML1 strategies, and neither appears in SMB1001 until Level 5. Awareness training waits until Level 3. Gold covers a real part of ML1 without being equivalent to it.

SMB1001's Steering Committee includes credible academic and policy figures, Professor Ryan Ko among them, and its annual revision cadence is faster than the Essential Eight's. Until those three points are fixed, we wouldn't treat the certificate as evidence of how well a business is actually protected.

Pick by buyer profile

Which framework fits your size and your obligations.

Two questions settle it. How big are you, and has anyone outside the business named a specific framework? An insurer, a large customer or a regulator all count.

  • If you are

    Microbusiness, under 10 staff

    We'd pick

    Essential Eight ML1 self-assessment, no certificate

    At under 10 staff, you almost certainly have no regulatory or insurance reason to hold a certificate. The work to reach Essential Eight ML1 is the work either way: MFA, patching, backups, awareness training, and keeping admin accounts separate. Run the free self-assessment, fix what it finds, and revisit certification if a client or an insurer ever asks for one.

  • If you are

    10 to 30 staff, no specific compliance driver

    We'd pick

    Essential Eight ML1, with the SMB1001 control set as an internal checklist

    Your insurer probably isn't asking for a SMB1001 certificate. Neither are your customers, and the certificate gets you nothing on the regulatory side. The controls inside Bronze and Silver are broadly sound and worth putting in place, so use the framework as a checklist rather than a credential. If you do want something to show a customer or a broker, get Essential Eight ML1 evidence first. That's the language they already speak.

  • If you are

    10 to 50 staff, you have an insurer or large customer asking

    We'd pick

    Essential Eight ML1 as substance, ISO 27001 if the customer is paying you to hold it

    If a customer's procurement gate, an insurer's questionnaire or a regulator's accreditation scheme names a specific framework, do that one. ISO 27001 is the credential large enterprise customers and federal government procurement actually recognise. SMB1001 is occasionally accepted in supply-chain conversations. Treat any claim of broad insurer or procurement recognition with scepticism, and ask for a named, published policy before you pay for the certificate.

  • If you are

    20 to 50 staff in a regulated industry: legal, finance, health, training

    We'd pick

    Essential Eight ML2, with ISO 27001 if your sector regulator or your major clients require it

    Your regulator is almost certainly speaking Essential Eight or ISO 27001, not SMB1001. Law firms, accountants, allied health, financial services, registered training organisations and aged-care providers all face frameworks built on one of those two. SMB1001 may help you organise internally, but the evidence your regulator accepts is in another framework. Run the Essential Eight self-assessment first. The answer tells you whether the gap to ML2 is small enough to handle in-house, or big enough to be a project.

  • If you are

    50+ staff, formal compliance program, board reporting

    We'd pick

    ISO 27001, with the Essential Eight controls inside it

    At this size, ISO 27001 is the credential that opens enterprise procurement and clears insurer questionnaires without follow-up. An ISO 27001 management system will absorb the Essential Eight controls anyway. SMB1001 is not designed for this scale, and the parties whose sign-off you need won't know it.

Free self-assessment

Start with the framework Australia is already aligned on.

Take the Essential Eight self-assessment before you pick.

Eight questions, one for each of the eight controls. You get an estimated maturity level (ML0 to ML3) and a branded PDF you can hand to your board, your broker or an auditor. Whichever framework you settle on, the answers tell you where you sit today, in the language Australian institutions already speak. No email required.

Take the self-assessment

Before you commit

Common questions about the Essential Eight, SMB1001 and ISO 27001.

Is SMB1001 a recognised Australian Government standard?
Does SMB1001 actually get you a cyber insurance discount?
Are the controls inside SMB1001 actually any good?
Why start with the Essential Eight rather than a certificate?
Can a SMB1001 Gold certificate substitute for Essential Eight ML1?
Where does ISO 27001 fit for a 30-person business?

Sources

  • SMB1001 control set and certification pricing: CSCAU 2024 submission to the Department of Home Affairs, Annex A. homeaffairs.gov.au
  • Password rotation and modern password guidance: NIST SP 800-63B Revision 4, August 2025. pages.nist.gov
  • Cyber Security Act 2024 (no. 98 of 2024). legislation.gov.au
  • ACSC Essential Eight Maturity Model. cyber.gov.au
  • ISO/IEC 27001:2022 information security management systems. iso.org

The qualifier

Let's see if we're a fit.

Seven questions, one moment of your time. We'd rather tell you now than three months in.

Step 1 of 7

How big is your team?

Counting everyone: staff, contractors, anyone with an account.

See if we're a fit