What these three frameworks are
Essential Eight, SMB1001 and ISO/IEC 27001 are often spoken about as if they are alternatives. They are not. They serve different purposes, sit at different maturity levels, and are demanded by different audiences.
Start with the information you handle, the systems in scope and the exact assurance a customer or regulator requests. A mitigation assessment, a business certificate and a management-system certificate answer different questions. You can coordinate work across frameworks where requirements overlap, but evidence reuse needs a requirement-by-requirement check.
Essential Eight
Australian government baseline
Eight mitigation strategies with maturity levels zero to three. Guidance is public; implementation and assessment can cost money. No ASD certification scheme.
SMB1001:2026
Practical SMB certification
Five levels from Bronze to Diamond, covering people, process and technology. Check the edition, tier, attestation and verification requirements.
ISO/IEC 27001
International enterprise standard
A risk-based information security management system for organisations of any size. Certification applies to a declared scope; Annex A has 93 reference controls.
Independent Australian comparisons confirm that most SMBs are better served starting with SMB1001 as a tiered certifiable standard purpose-built for smaller businesses, while ISO 27001 wins enterprise and international deals and the Essential Eight wins Australian government work, so the three frameworks answer different questions and many businesses need more than one rather than treating them as interchangeable alternatives. XCD IT comparison.
ACSC Essential Eight
The Essential Eight is published by the Australian Signals Directorate (ASD) and the Australian Cyber Security Centre (ACSC). It is a set of eight prioritised mitigation strategies the ACSC considers most effective at reducing the risk of common cyber attacks targeting Australian organisations.
The eight controls
- Application control
- Patch applications
- Configure Microsoft Office macro settings
- User application hardening
- Restrict administrative privileges
- Patch operating systems
- Multi-factor authentication
- Regular backups
Maturity levels
ASD defines maturity levels zero to three. Level zero indicates weaknesses; levels one to three address progressively more capable tradecraft and targeting. Select a target suited to the environment and any applicable requirement. ASD recommends reaching the same maturity across all eight strategies before moving higher. Do not report the whole environment at Level Two because MFA and patching alone meet that level.
ASD is evolving the Essential Eight
ASD's 15 June 2026 announcement described consultation on a proposed Essentials series grounded in the ISM, beginning with Essentials for enterprise IT. That consultation closed on 12 July 2026. Use the published guidance and the version required by your customer; the announcement is not a fixed retirement date or permission to stop current mitigation work. Read ASD's announcement or the Real Bytes explanation.
When Essential Eight is the right answer
- You sell to Commonwealth, state government or critical infrastructure
- You want a published technical baseline with a defined maturity model
- You need clear evidence requirements (the ACSC publishes an Essential Eight Evidence Guide)
- Cyber insurance underwriters are asking about it
Where it falls short
- No ASD certification scheme. Independent assessment may be required by policy, regulation or contract.
- It is a minimum set of preventative measures, not a complete security management system.
- It is designed for internet-connected IT. OT and other environments may need different controls.
ASD opened consultation on a proposed Essentials series grounded in the ISM on 15 June 2026, beginning with Essentials for enterprise IT, and the consultation closed on 12 July 2026, so the Essential Eight is not retired but is evolving into a broader series, and businesses should continue current mitigation work against the published guidance rather than waiting for the final series before acting. ASD, 15 June 2026.
SMB1001:2026
SMB1001 is a multi-tiered cyber security standard from Dynamic Standards International. The official DSI publication page and CyberCert page checked for this guide list SMB1001:2026. DSI gives a release date of 1 September 2025. The edition year is not your business's assessment date.
DSI describes five levels covering progressively broader people, process and technology requirements. Select an appropriate level; completing all five is not mandatory. CyberCert lists external audit fees in addition to subscription fees at Platinum and Diamond. Verify the edition, tier and verification requirements before buying an assessment.
DSI's framework mappings help identify reusable work. They do not prove that an SMB1001 certificate establishes Essential Eight maturity, CMMC status or ISO 27001 conformity. Confirm the tier, scope and evidence a customer accepts before claiming equivalence in a tender.
The five tiers
- Level 1 (Bronze): Foundational preventative requirements; check the current workbook and attestation.
- Level 2 (Silver): Additional preventative measures and the corresponding evidence.
- Level 3 (Gold): Broader risk management across people, process and technology.
- Level 4 (Platinum): More formal governance and external verification requirements.
- Level 5 (Diamond): The highest tier, with the applicable advanced requirements and external verification.
When SMB1001 is the right answer
- You need a tiered business security pathway suited to your scope and resources
- A customer accepts the chosen certification tier and its assurance method
- Your customers (often larger enterprises) are starting to ask for supplier cyber assurance
- You want a ladder you can climb over time, not a one-shot certification
Where it falls short
- Acceptance depends on the customer's requirement; do not assume it replaces an ISO certificate.
- Attestation and independent verification provide different assurance.
- Edition changes, scope, unresolved gaps and ongoing operation still need attention.
Dynamic Standards International released SMB1001:2026 on 1 September 2025 as the current edition, with five tiers from Bronze to Diamond covering progressively broader people, process and technology requirements, and CyberCert lists external audit fees in addition to subscription fees at Platinum and Diamond, so the edition year is the standard release date rather than a business assessment date and the tier and verification method determine what an assessor will actually check. DSI SMB1001:2026.
ISO/IEC 27001
ISO/IEC 27001 is the international standard for information security management systems (ISMS). Published by ISO and IEC, currently in the 2022 edition. It defines requirements for establishing, implementing, maintaining and continually improving an ISMS, plus 93 reference controls in Annex A.
ISO says the standard is suitable for organisations of any size and sector. Adoption and certification are separate decisions: a business can operate an ISMS without buying certification unless an obligation requires it. ISO does not issue certificates itself; certification is performed by a conformity assessment body. Check the body's accreditation and the scope of the resulting certificate.
Define the boundary before collecting policies. A certificate covering one office or service does not automatically cover every related company, product or subcontractor. Record the information, people, locations and dependencies included. The risk assessment and treatment plan determine necessary controls; the Statement of Applicability records inclusion, implementation and justified exclusions. The 93 Annex A controls are a reference set, not a requirement to apply every control identically.
Evidence needs to show the management system operates: assigned risk owners, reviewed changes, access decisions, internal audit, management review and corrective action. A folder of purchased policy templates does not establish effectiveness. Agree readiness, the certification body's audit process and recurring surveillance before committing to a deadline. Sources: ISO's standard overview and BSI's reference-control guidance.
What ISO 27001 covers
- Leadership and governance, scope, policy, roles and responsibilities
- Risk assessment and risk treatment methodology
- Statement of Applicability mapping which Annex A controls are in scope
- Operational controls across organisational, people, physical and technological domains
- Internal audit and management review processes
- Continual improvement
When ISO 27001 is the right answer
- You sell to enterprise customers, internationally, or to regulated industries
- RFPs and tenders require it
- You handle very sensitive data (health, financial, defence supply chain)
- You want a system, not a checklist (ISO 27001 is process-driven, not control-counted)
Where it falls short
- Budget for remediation, internal ownership, assessment and ongoing operation, not just an audit fee.
- Timing depends on existing gaps, scope, operating evidence and audit availability. Obtain a scoped estimate.
- Ongoing overhead. Surveillance audits, internal audits, document control, management review
- Not prescriptive on technical controls. Annex A says "what", not "how"
ISO/IEC 27001:2022 is the current edition of the international information security management system standard with 93 reference controls in Annex A, and ISO says the standard is suitable for organisations of any size and sector, so a business can operate an ISMS without buying certification unless an obligation requires it, and ISO does not issue certificates itself because certification is performed by a conformity assessment body whose accreditation and scope should be checked before relying on the resulting certificate. ISO 27001 overview.
Side-by-side comparison
| Essential Eight | SMB1001:2026 | ISO/IEC 27001 | |
|---|---|---|---|
| Publisher | Australian Signals Directorate | Dynamic Standards International | ISO and IEC |
| Purpose | Prioritised technical mitigations | Tiered business security certification | Information security management system |
| Scope | Internet-connected IT; additional controls may be needed | People, process and technology within the chosen certification scope | Risk-based management system within the declared scope |
| Structure | Eight strategies; maturity levels zero to three | Five levels, Bronze to Diamond; verify the selected edition | Management requirements and 93 Annex A reference controls |
| Assurance | Assessment against the target maturity; not an ASD certificate | Director attestation at lower tiers; external audit fees at Platinum and Diamond | Certification by an independent conformity assessment body |
| Budget | Remediation, licensing, assessment and ongoing operation | Remediation, subscription and any external audit | ISMS operation, remediation, assessment and surveillance |
| Timing | Depends on gaps, scope and approved changes | Depends on selected tier, readiness and assessment availability | Depends on management-system readiness and audit scheduling |
| Evidence | Control implementation, coverage, exceptions and tests | Current tier requirements, attestation and supporting records | Risk assessment, treatment, Statement of Applicability and operating records |
| Maintenance | Review effectiveness and relevant ASD changes | Maintain requirements and check renewal and edition changes | Internal audit, management review and the certification body's surveillance cycle |
How to choose: a practical framework
The right framework is the one that matches your customers, your risk, and what you can sustain. The questions below cut through most of the noise.
Do government contracts always require Essential Eight Maturity Level Two?
No. Confirm the exact agency or contract requirement, including system scope, target maturity, assessment method and accepted evidence. A supplier requirement may include the ISM or an independent assessment. Essential Eight is not a certificate and does not automatically satisfy those separate obligations.
Does an enterprise or international customer always require ISO 27001?
No. Ask the customer which assurance it accepts. Where ISO/IEC 27001:2022 certification is required, verify the certificate's scope, validity and certification body. Do not assume an SMB1001 certificate or an Essential Eight assessment can replace it without written acceptance.
Can a small business use ISO 27001?
Yes. ISO says the standard applies to organisations of any size and sector. Decide on scope, risk, customer requirements and capacity to operate the management system. Headcount alone is not a reason to reject ISO 27001 or to pursue it.
Does SMB1001 certification prove Essential Eight maturity?
No. The frameworks overlap, but their requirements and assessment methods differ. Reuse policies, configuration records and tests where they meet the exact requirement, then assess each framework separately. A control mapping identifies overlap; it does not establish automatic equivalence.
Do regulated businesses have to obtain all three frameworks?
No. Determine the legislation, regulator and contractual requirements that actually apply. These frameworks can support security work, but none automatically establishes Privacy Act, APRA or critical infrastructure compliance. Keep any additional obligations and evidence separate.
Will certification guarantee cyber insurance or a lower premium?
No. Cover, exclusions and pricing depend on the insurer's terms and the organisation's risk. Use current evidence to answer the actual application questions. A certificate does not guarantee cover, remove exclusions or replace accurate disclosure.
A realistic Australian SMB pathway
Use a requirements-led sequence rather than a fixed multi-year calendar. A customer may need a particular assessment now; a business with a limited scope may already have much of the evidence. Plan milestones around the gaps, operational dependencies and decision-makers, not a promise that every company certifies on the same timetable.
Define the obligation
Record the customer clause, information, system boundary and required assurance. Confirm what the customer will accept before buying an assessment.
Close immediate exposure
Prioritise access, patching, unsupported systems and recoverability. Select an appropriate Essential Eight target where relevant; all eight strategies need evidence.
Build a reusable evidence register
Give each control an owner, implementation record, test date and gap decision. Map it separately to each framework rather than copying a compliance status.
Obtain the required assurance
Use the SMB1001 tier or ISO certification scope the business needs. Keep implementation support separate from the independent assessment where required.
Operate and review
Plan access reviews, restore tests, supplier changes and framework updates. Include recurring internal effort and assessment costs in the operating budget.
Common mistakes
Choosing a framework without reading the contract
A familiar certificate may not satisfy the requested assurance. Confirm the exact version, scope and assessment method before committing to an uplift.
Treating a mapping as automatic compliance
Similar control names can have different coverage, evidence or testing requirements. Record full, partial and missing coverage honestly.
Calling an Essential Eight assessment a certificate
ASD does not operate an Essential Eight certification scheme. State the assessed maturity, scope, date, assessor and known exceptions instead.
Ignoring independent verification requirements
CyberCert lists external audit fees for Platinum and Diamond. Check the current scheme and edition; do not substitute director attestation where verification is required.
Treating every Annex A control as mandatory
ISO 27001 requires risk-based control selection and a Statement of Applicability. Consider the reference controls, justify inclusion or exclusion and add controls where the risks require them.
Ending the work when the certificate arrives
Controls need ongoing ownership, review and evidence. Budget for staff changes, supplier changes, incident lessons and the applicable reassessment cycle.
Our recommendation: match the required outcome
Use Essential Eight for relevant mitigation maturity, SMB1001 where a suitable tiered business certificate is accepted, and ISO 27001 where an ISMS or its certification is required. A written customer requirement takes priority over a preferred framework. Confirm the edition and scope before quoting a compliance status.
Reuse operational evidence without overstating equivalence. An access review, restore test or supplier assessment may support more than one framework when its scope and test method match. Keep a separate requirements mapping, document partial coverage and make known exceptions visible to the decision-maker. Certification cannot guarantee that an incident will not occur.
Built for SMBs
Five tiers from Bronze to Diamond. Choose a scope and tier your business can operate and maintain.
Confirm customer acceptance
Ask which certificate, tier, scope and supporting evidence the customer will accept before relying on it.
Implementation support
Real Bytes can help scope controls and evidence. Independent assessment and certification remain separate activities.
Sources checked 4 October 2026: ASD maturity model, DSI SMB1001 edition, CyberCert certification requirements and ISO 27001 overview.
Explore SMB1001 CertificationGet help choosing and implementing
Real Bytes implements Essential Eight, SMB1001 and prepares clients for ISO 27001 certification across Australia. We map your existing controls to the framework you actually need, not the one that sounds most expensive.

Remote Support