Back to insights Cyber security

Essential Eight vs SMB1001 vs ISO 27001: Which Does Your Business Need?

By Hassan Sillem, Director · 5 October 2026
Insource IT team discussing cyber security frameworks in a client meeting

The short answer: the Essential Eight is a set of eight technical controls from the Australian Signals Directorate. You are assessed against it, not certified. SMB1001 is a five-tier certification built for small and medium businesses, covering technical controls plus policies and staff training. ISO/IEC 27001 is the international standard for running a complete information security management system, certified by an independent auditor.

They are not competitors. They overlap heavily on the basics: patching, multi-factor authentication, admin rights and backups. Work done for one counts towards the others. For most small businesses the sensible order is: get the Essential Eight basics in place, certify to SMB1001 to prove it, and move to ISO 27001 when clients, tenders or growth require it.

Side by side

Essential EightSMB1001ISO/IEC 27001
Published byAustralian Signals Directorate (ASD)Dynamic Standards International (DSI)ISO and IEC (international)
Current versionEssential Eight Maturity ModelSMB1001:2026, revised every yearISO/IEC 27001:2022
What it is8 technical mitigation strategiesTiered cyber security certification for SMBsRequirements for an information security management system
LevelsMaturity Levels One to ThreeLevels 1 to 5, often called Bronze to Diamond (7 to 39 controls)Certified or not certified
ProofAssessment against the maturity model, no certificateCertificate from a Dynamic Standard Certifier such as CyberCert. Levels 1 to 3 are self-attested; Levels 4 and 5 need independent verificationCertificate from an accredited certification body after an external audit
RenewalOngoing, re-assessed as you chooseEvery year (a certificate is valid for one year)Typically a three-year cycle with yearly surveillance audits
Covers policies and peopleVery littleYes: policies, staff training, governanceFully: risk management, leadership, suppliers, audits
Built forGovernment agencies, adopted widely by businessSmall and medium businessesOrganisations of any size
Who asks for itGovernment clients, cyber insurersSupply chains, insurers, clientsEnterprise clients, government, tenders, overseas customers

The Essential Eight is mandatory for Australian federal government agencies. For private businesses, all three are voluntary, but customers and insurers increasingly ask for one of them.

Where they overlap

All three share the same core; each adds a different layerShared core, required in all threePatching · Multi-factor authentication · Limited admin rights · BackupsEssential Eight: depthApplication controlOffice macro settingsUser application hardeningExact patching timeframesMaturity Levels One to ThreeSMB1001: the business sidePolicies and staff trainingEmail: SPF, DKIM and DMARCAI use policy (2026, Gold)Five levels, 7 to 39 controlsCertificate, renewed yearlyISO 27001: the full systemRisk assessment and treatmentLeadership and management reviewSupplier securityInternal auditsExternal audit and certificate

The four core controls appear in all three, so doing them well once moves you forward on every standard. The table shows where each Essential Eight control sits in the other two.

Essential Eight controlSMB1001 (2026 edition)ISO/IEC 27001:2022 Annex A
Patch applicationsAutomatic updates and patches from Level 1 (Bronze)8.8 Management of technical vulnerabilities
Patch operating systemsAutomatic updates and patches from Level 1 (Bronze)8.8 Management of technical vulnerabilities
Multi-factor authenticationMFA on email from Level 2 (Silver); on all business apps from Level 3 (Gold); on VPN, remote access and data stores at Level 4 (Platinum)8.5 Secure authentication
Restrict administrative privilegesNo admin rights on employee accounts from Level 2 (Silver)8.2 Privileged access rights
Regular backupsBackups with an offline copy from Level 1 (Bronze); a full restore test plan at Level 4 (Platinum)8.13 Information backup
Application controlLevel 5 (Diamond) only8.7 Protection against malware
Configure Microsoft Office macrosLevel 5 (Diamond) only8.9 Configuration management
User application hardeningNo equivalent control8.9 Configuration management; 8.23 Web filtering

ISO 27001 does not prescribe settings the way the Essential Eight does. It asks you to choose controls based on your risks, so an auditor will accept the Essential Eight as strong evidence for these Annex A controls. SMB1001 is updated every year (the 2027 edition applies from 1 January 2027), so always check the current edition for exact control numbers.

What each one adds

The Essential Eight goes deepest on a small set of technical controls. Its maturity levels say exactly how fast you must patch, which accounts need MFA and how admin rights are controlled. It says almost nothing about policies, suppliers or staff behaviour.

SMB1001 adds the business side that small companies usually miss: written policies (for example, invoice fraud and acceptable use), staff security training, individual user accounts, email protection such as SPF, DKIM and DMARC, and from the 2026 edition an AI use policy and cyber insurance at Gold. It also gives you a certificate customers recognise, at a cost and effort level that suits a small business.

ISO 27001 adds the management system that keeps everything working over time: a formal risk assessment and treatment plan, leadership commitment, supplier security, incident management, internal audits, management reviews and continual improvement. It covers 93 controls across organisational, people, physical and technological areas. It is the standard larger clients and overseas customers recognise.

One gap to know about: SMB1001 Gold is not the same as Essential Eight Maturity Level One. Application control and Office macro settings only appear at SMB1001's top level (Diamond), and user application hardening is not covered at all. If a government client asks for Essential Eight, check the specific controls rather than assuming your SMB1001 certificate covers them.

Why this matters more in the age of AI

Artificial intelligence has raised the stakes for every business. Staff now use AI assistants to draft emails, summarise documents and analyse data, while attackers use the same technology to write convincing phishing messages, clone voices and find weaknesses faster. Strong security foundations are no longer optional; they are what make it safe to adopt AI at all.

The controls these frameworks require are the same controls that make AI safe to use. Tools such as Microsoft 365 Copilot can see everything the user can see, so loose permissions turn into instant data exposure. Clear policies decide which AI tools are approved and what information may be shared with them. And when attackers move faster, patching, multi-factor authentication and backups become the difference between an incident and a crisis.

AI-era riskControl that reduces itWhere the frameworks require it
An AI assistant surfaces files staff should not seeLeast-privilege access, limited admin rights, regular access reviewsEssential Eight, SMB1001 from Level 2, ISO 27001 access controls
Staff paste client or financial data into unapproved AI toolsAn approved AI tools list, an AI use policy, staff trainingSMB1001:2026 AI use policy from Level 3 (Gold), ISO 27001 policies and awareness training
Highly convincing AI-written phishing and invoice fraudMulti-factor authentication, email authentication (SPF, DKIM, DMARC), awareness trainingAll three
Voice-cloned "urgent payment" requestsVerified payment procedures and invoice fraud policiesSMB1001 policies, ISO 27001 procedures
Attackers using AI to find and exploit weaknesses fasterFast patching, application control, endpoint detectionEssential Eight, SMB1001 (EDR from Level 3), ISO 27001 vulnerability management
AI-assisted ransomwareTested, offline backupsAll three

In short, a business that has done the work for the Essential Eight, SMB1001 or ISO 27001 is far better prepared to adopt AI safely. For organisations building or deploying AI at scale, ISO/IEC 42001, the international standard for AI management systems, builds on the same management approach as ISO 27001.

Which one should you do first?

Who is asking for proof decides where to startWho is asking for proof of your security?If a government client asksEssential Eight assessmentAim for the maturity levelnamed in the contractIf insurers or customers askSMB1001, Silver or GoldEssential Eight basics first,then certify to prove themIf enterprise or tenders askISO 27001 certificationReuse your SMB1001 andEssential Eight workNobody asking yet? The usual path: Essential Eight basics, then SMB1001, then ISO 27001

The right starting point depends less on your size and more on who needs proof. If nobody is asking yet, don't wait: the Essential Eight basics stop most common attacks, and they are the foundation for both certifications.

Our story: why an IT company certified itself

At Insource IT we advise businesses on cyber security every day, so we decided to hold ourselves to the same standard. We certified to ISO 27001 first, then to SMB1001 Gold (Level 3). Nobody forced us to: no client or insurer had asked. We did it to formalise how we run security inside our own business.

It took us under six months to reach ISO 27001. Two things made that possible. Most of the technical controls were already in place, because we run them for our clients and for ourselves. And it had leadership focus: it was a top priority with dedicated time, not a side project for whoever had a spare afternoon.

The hard part was not the technology. It was the paperwork and the thinking behind it. Writing policies that describe what we actually do, keeping the evidence up to date, and building a proper risk register with treatment plans and regular management reviews took far more effort than any firewall or patching change. That is the part most businesses underestimate.

What changed afterwards:

  • Client trust. Clients hand us admin access to their systems. Being able to show independent certification makes that conversation much easier.
  • Internal discipline. Clearer processes, fewer surprises and better records. Audits now confirm what we do instead of disrupting it.
  • New work. Certification has helped us win clients who need a provider they can show their own customers and insurers.

Our one piece of advice: own it at the top. Security certification fails when it is handed to IT as a project. It works when the business owner treats it as part of how the company is run.

"We spend our days helping clients protect their businesses, so it was only right to prove we do the same. Getting ISO 27001 was less about technology and more about leadership. Once leadership takes responsibility, everything else follows."

Hassan Sillem, Director, Insource IT

Frequently asked questions

Is the Essential Eight mandatory for private businesses?

No. It is mandatory for Australian federal government agencies. Private businesses adopt it voluntarily, often because government clients or cyber insurers ask for it.

Can you get certified to the Essential Eight?

No. There is no official Essential Eight certificate. Businesses are assessed against the maturity model, usually by an IT provider or auditor. If you need a certificate, SMB1001 or ISO 27001 are the options.

Is SMB1001 Gold the same as Essential Eight Maturity Level One?

No. They overlap on patching, MFA, admin rights and backups, but SMB1001 only requires application control and Office macro settings at its top level (Diamond), and does not include user application hardening.

Does SMB1001 count towards ISO 27001?

It helps. The SMB1001 standard describes its five levels as a foundation and pathway towards ISO/IEC 27001, and the technical work and many policies carry over. ISO 27001 still requires a full management system, a risk assessment and an external audit.

Which should a small business do first?

Start with the Essential Eight basics, then certify to SMB1001 to prove them. Move to ISO 27001 when larger clients, tenders or overseas customers require it.

How long does ISO 27001 take?

It depends on how much is already in place. Insource IT reached ISO 27001 in under six months because most technical controls were already running. Businesses starting from scratch should expect longer.

How often do you renew?

SMB1001 certificates are valid for one year, so you re-certify annually. ISO 27001 certificates typically run on a three-year cycle with yearly surveillance audits. The Essential Eight has no certificate, so you re-assess as your environment changes.

Do these frameworks help with AI security?

Yes. AI assistants work with whatever data and permissions a user already has, so the access controls, policies, training and patching these frameworks require are the foundation for using AI safely. SMB1001:2026 also requires a policy for the responsible and secure use of AI from Level 3 (Gold).

Official references

Free security standards review

Not sure which standard fits your business?

Book a free 30-minute review. We'll tell you where you stand against the Essential Eight and SMB1001, and the fastest path to certification.

We are certified to ✓ ISO/IEC 27001 ✓ SMB1001 Gold (Level 3) and implement the Essential Eight for our clients