All posts

SMB1001 vs Essential Eight vs ISO 27001: Which Does Your Business Actually Need?

Three frameworks, three very different price tags and purposes — here's a plain-language breakdown of what actually separates them.

The one-line answer

These three frameworks aren't competing options where one is simply "better." They're built for different business sizes and different reasons for needing one in the first place — the right choice depends on your size, your industry, and whether someone specific is actually asking you for a framework by name.

Essential Eight — the free, narrowly technical baseline

Essential Eight is the Australian Government's own set of mitigation strategies, developed by the Australian Signals Directorate's Cyber Security Centre (ACSC) — it's an Australian framework, not an American one, despite the naming sounding similar to some US standards. It's free to implement, and it's deliberately narrow: eight specific technical control areas (patching, multi-factor authentication, application control, restricting admin privileges, and the like), scored across four maturity levels. It doesn't touch governance, policy, or risk management — just technical hardening.

It's also dated. Essential Eight was designed in 2017 for on-premises enterprise IT, and the ASD has confirmed it's being progressively retired over the next two years in favour of a new "Essentials" framework built around cloud, SaaS, and threats the original eight controls weren't designed for. The underlying controls — patching, MFA, backups — remain sound practice and aren't going anywhere, but it's worth knowing the framework itself has a shelf life. For now, it's still the right starting point for very small businesses, think under 10 staff, with no external party demanding a specific certification yet — Essential Eight Maturity Level 1 is a sensible, low-cost baseline.

SMB1001 — tiered, and broader than a technical checklist

SMB1001 sits in the gap Essential Eight and ISO 27001 don't cover well: a small-to-medium business, roughly in the 10-50 staff range, that needs to show someone — a bigger customer, a government tender, an insurer — that it takes security seriously, without the time and cost of a full ISO 27001 audit.

Where Essential Eight is purely technical, SMB1001 is broader and tiered across five levels — Bronze through Diamond. Bronze covers basic hygiene (firewalls, antivirus, patching, backups); Silver adds people and email controls (MFA, password managers, email authentication, an invoice fraud policy); Gold introduces real governance — written policies, staff training, and documented evidence; Platinum and Diamond bring in external audit verification, vulnerability scanning, and eventually penetration testing and incident response drills. By Diamond, it's arguably closer in spirit to ISO 27001 than to its own Bronze tier. Bronze through Gold can typically be self-assessed; Platinum and Diamond expect independent verification.

Where it doesn't fit well: heavily regulated industries like finance, legal, or health. If your regulator already expects a specific framework, align to that one — not SMB1001. It's also not designed for businesses much above roughly 50 staff.

ISO/IEC 27001 — a risk-management system, not a checklist

ISO 27001 works differently from the other two. Rather than a fixed list of controls, it requires you to build a full Information Security Management System (ISMS) — a risk assessment methodology, a Statement of Applicability mapping your controls against the standard's Annex A, documented policies, and an ongoing cycle of internal audits and management review. Certification itself requires an accredited external auditor across two audit stages, followed by annual surveillance audits and full recertification every three years.

It's the one enterprise customers, government panels, and regulators are most likely to actually name. It's rigorous, and it costs meaningfully more in time and money than SMB1001 or Essential Eight. If a specific customer or regulator requires ISO 27001 by name, that's the framework to pursue — not a substitute.

Side-by-side comparison

Framework Best for Typical cost Externally recognised by
Essential Eight Under 10 staff, no external requirement yet Free to implement Australian Government agencies & contracts
SMB1001 10-50 staff, non-regulated, needs credible proof fast Low — self-certifiable at lower tiers Emerging — MSPs, some tenders & customers
ISO/IEC 27001 Enterprise customers or regulators naming it specifically High — accredited external audit required Global — enterprise, government, most regulators

The one-question shortcut

If you only ask yourself one thing, ask this: has a specific external party — a customer, regulator, insurer, or tender — named a specific framework? If yes, that's your answer regardless of size or cost. If no, and you're a small, non-regulated business that just wants credible proof of security, SMB1001 is usually the most accessible starting point.

Frameworks aren't a status symbol — they're a tool for a specific job. Picking the wrong one wastes time and money; picking the right one solves the actual problem you have. Our security assessments cover all three, and if you're not sure which applies to you, that's a five-minute conversation, not a sales pitch.

Not sure which framework fits your business?

A short, no-pressure scoping call is the fastest way to find out — no sales pitch, just a conversation.

Book a consultation