The short answer: the Essential Eight is a set of eight technical controls from the Australian Signals Directorate. You are assessed against it, not certified. SMB1001 is a five-tier certification built for small and medium businesses, covering technical controls plus policies and staff training. ISO/IEC 27001 is the international standard for running a complete information security management system, certified by an independent auditor.
They are not competitors. They overlap heavily on the basics: patching, multi-factor authentication, admin rights and backups. Work done for one counts towards the others. For most small businesses the sensible order is: get the Essential Eight basics in place, certify to SMB1001 to prove it, and move to ISO 27001 when clients, tenders or growth require it.
Side by side
| Essential Eight | SMB1001 | ISO/IEC 27001 | |
|---|---|---|---|
| Published by | Australian Signals Directorate (ASD) | Dynamic Standards International (DSI) | ISO and IEC (international) |
| Current version | Essential Eight Maturity Model | SMB1001:2026, revised every year | ISO/IEC 27001:2022 |
| What it is | 8 technical mitigation strategies | Tiered cyber security certification for SMBs | Requirements for an information security management system |
| Levels | Maturity Levels One to Three | Levels 1 to 5, often called Bronze to Diamond (7 to 39 controls) | Certified or not certified |
| Proof | Assessment against the maturity model, no certificate | Certificate from a Dynamic Standard Certifier such as CyberCert. Levels 1 to 3 are self-attested; Levels 4 and 5 need independent verification | Certificate from an accredited certification body after an external audit |
| Renewal | Ongoing, re-assessed as you choose | Every year (a certificate is valid for one year) | Typically a three-year cycle with yearly surveillance audits |
| Covers policies and people | Very little | Yes: policies, staff training, governance | Fully: risk management, leadership, suppliers, audits |
| Built for | Government agencies, adopted widely by business | Small and medium businesses | Organisations of any size |
| Who asks for it | Government clients, cyber insurers | Supply chains, insurers, clients | Enterprise clients, government, tenders, overseas customers |
The Essential Eight is mandatory for Australian federal government agencies. For private businesses, all three are voluntary, but customers and insurers increasingly ask for one of them.
Where they overlap
The four core controls appear in all three, so doing them well once moves you forward on every standard. The table shows where each Essential Eight control sits in the other two.
| Essential Eight control | SMB1001 (2026 edition) | ISO/IEC 27001:2022 Annex A |
|---|---|---|
| Patch applications | Automatic updates and patches from Level 1 (Bronze) | 8.8 Management of technical vulnerabilities |
| Patch operating systems | Automatic updates and patches from Level 1 (Bronze) | 8.8 Management of technical vulnerabilities |
| Multi-factor authentication | MFA on email from Level 2 (Silver); on all business apps from Level 3 (Gold); on VPN, remote access and data stores at Level 4 (Platinum) | 8.5 Secure authentication |
| Restrict administrative privileges | No admin rights on employee accounts from Level 2 (Silver) | 8.2 Privileged access rights |
| Regular backups | Backups with an offline copy from Level 1 (Bronze); a full restore test plan at Level 4 (Platinum) | 8.13 Information backup |
| Application control | Level 5 (Diamond) only | 8.7 Protection against malware |
| Configure Microsoft Office macros | Level 5 (Diamond) only | 8.9 Configuration management |
| User application hardening | No equivalent control | 8.9 Configuration management; 8.23 Web filtering |
ISO 27001 does not prescribe settings the way the Essential Eight does. It asks you to choose controls based on your risks, so an auditor will accept the Essential Eight as strong evidence for these Annex A controls. SMB1001 is updated every year (the 2027 edition applies from 1 January 2027), so always check the current edition for exact control numbers.
What each one adds
The Essential Eight goes deepest on a small set of technical controls. Its maturity levels say exactly how fast you must patch, which accounts need MFA and how admin rights are controlled. It says almost nothing about policies, suppliers or staff behaviour.
SMB1001 adds the business side that small companies usually miss: written policies (for example, invoice fraud and acceptable use), staff security training, individual user accounts, email protection such as SPF, DKIM and DMARC, and from the 2026 edition an AI use policy and cyber insurance at Gold. It also gives you a certificate customers recognise, at a cost and effort level that suits a small business.
ISO 27001 adds the management system that keeps everything working over time: a formal risk assessment and treatment plan, leadership commitment, supplier security, incident management, internal audits, management reviews and continual improvement. It covers 93 controls across organisational, people, physical and technological areas. It is the standard larger clients and overseas customers recognise.
One gap to know about: SMB1001 Gold is not the same as Essential Eight Maturity Level One. Application control and Office macro settings only appear at SMB1001's top level (Diamond), and user application hardening is not covered at all. If a government client asks for Essential Eight, check the specific controls rather than assuming your SMB1001 certificate covers them.
Why this matters more in the age of AI
Artificial intelligence has raised the stakes for every business. Staff now use AI assistants to draft emails, summarise documents and analyse data, while attackers use the same technology to write convincing phishing messages, clone voices and find weaknesses faster. Strong security foundations are no longer optional; they are what make it safe to adopt AI at all.
The controls these frameworks require are the same controls that make AI safe to use. Tools such as Microsoft 365 Copilot can see everything the user can see, so loose permissions turn into instant data exposure. Clear policies decide which AI tools are approved and what information may be shared with them. And when attackers move faster, patching, multi-factor authentication and backups become the difference between an incident and a crisis.
| AI-era risk | Control that reduces it | Where the frameworks require it |
|---|---|---|
| An AI assistant surfaces files staff should not see | Least-privilege access, limited admin rights, regular access reviews | Essential Eight, SMB1001 from Level 2, ISO 27001 access controls |
| Staff paste client or financial data into unapproved AI tools | An approved AI tools list, an AI use policy, staff training | SMB1001:2026 AI use policy from Level 3 (Gold), ISO 27001 policies and awareness training |
| Highly convincing AI-written phishing and invoice fraud | Multi-factor authentication, email authentication (SPF, DKIM, DMARC), awareness training | All three |
| Voice-cloned "urgent payment" requests | Verified payment procedures and invoice fraud policies | SMB1001 policies, ISO 27001 procedures |
| Attackers using AI to find and exploit weaknesses faster | Fast patching, application control, endpoint detection | Essential Eight, SMB1001 (EDR from Level 3), ISO 27001 vulnerability management |
| AI-assisted ransomware | Tested, offline backups | All three |
In short, a business that has done the work for the Essential Eight, SMB1001 or ISO 27001 is far better prepared to adopt AI safely. For organisations building or deploying AI at scale, ISO/IEC 42001, the international standard for AI management systems, builds on the same management approach as ISO 27001.
Which one should you do first?
The right starting point depends less on your size and more on who needs proof. If nobody is asking yet, don't wait: the Essential Eight basics stop most common attacks, and they are the foundation for both certifications.
Our story: why an IT company certified itself
At Insource IT we advise businesses on cyber security every day, so we decided to hold ourselves to the same standard. We certified to ISO 27001 first, then to SMB1001 Gold (Level 3). Nobody forced us to: no client or insurer had asked. We did it to formalise how we run security inside our own business.
It took us under six months to reach ISO 27001. Two things made that possible. Most of the technical controls were already in place, because we run them for our clients and for ourselves. And it had leadership focus: it was a top priority with dedicated time, not a side project for whoever had a spare afternoon.
The hard part was not the technology. It was the paperwork and the thinking behind it. Writing policies that describe what we actually do, keeping the evidence up to date, and building a proper risk register with treatment plans and regular management reviews took far more effort than any firewall or patching change. That is the part most businesses underestimate.
What changed afterwards:
- Client trust. Clients hand us admin access to their systems. Being able to show independent certification makes that conversation much easier.
- Internal discipline. Clearer processes, fewer surprises and better records. Audits now confirm what we do instead of disrupting it.
- New work. Certification has helped us win clients who need a provider they can show their own customers and insurers.
Our one piece of advice: own it at the top. Security certification fails when it is handed to IT as a project. It works when the business owner treats it as part of how the company is run.
"We spend our days helping clients protect their businesses, so it was only right to prove we do the same. Getting ISO 27001 was less about technology and more about leadership. Once leadership takes responsibility, everything else follows."
Hassan Sillem, Director, Insource IT
Frequently asked questions
Is the Essential Eight mandatory for private businesses?
No. It is mandatory for Australian federal government agencies. Private businesses adopt it voluntarily, often because government clients or cyber insurers ask for it.
Can you get certified to the Essential Eight?
No. There is no official Essential Eight certificate. Businesses are assessed against the maturity model, usually by an IT provider or auditor. If you need a certificate, SMB1001 or ISO 27001 are the options.
Is SMB1001 Gold the same as Essential Eight Maturity Level One?
No. They overlap on patching, MFA, admin rights and backups, but SMB1001 only requires application control and Office macro settings at its top level (Diamond), and does not include user application hardening.
Does SMB1001 count towards ISO 27001?
It helps. The SMB1001 standard describes its five levels as a foundation and pathway towards ISO/IEC 27001, and the technical work and many policies carry over. ISO 27001 still requires a full management system, a risk assessment and an external audit.
Which should a small business do first?
Start with the Essential Eight basics, then certify to SMB1001 to prove them. Move to ISO 27001 when larger clients, tenders or overseas customers require it.
How long does ISO 27001 take?
It depends on how much is already in place. Insource IT reached ISO 27001 in under six months because most technical controls were already running. Businesses starting from scratch should expect longer.
How often do you renew?
SMB1001 certificates are valid for one year, so you re-certify annually. ISO 27001 certificates typically run on a three-year cycle with yearly surveillance audits. The Essential Eight has no certificate, so you re-assess as your environment changes.
Do these frameworks help with AI security?
Yes. AI assistants work with whatever data and permissions a user already has, so the access controls, policies, training and patching these frameworks require are the foundation for using AI safely. SMB1001:2026 also requires a policy for the responsible and secure use of AI from Level 3 (Gold).