In this article
What each framework covers
E8
Essential Eight
Eight security measures from the Australian Cyber Security Centre (ACSC), which is part of the Australian Signals Directorate. The ACSC wrote them for federal government first. The maturity model has four levels, from Maturity Level 0 (ML0) to ML3, and any business can use it. You check your own business against the published criteria. There is no certificate, no audit and no annual fee.
SMB1001
SMB1001
A certification standard for small and medium businesses, with five tiers: Bronze, Silver, Gold, Platinum and Diamond. Dynamic Standards International (DSI) publishes it. DSI was formerly Cyber Security Certification Australia (CSCAU), and a related company, CyberCert, issues the certificates. For Bronze, Silver and Gold, a director of your business signs a declaration that the controls are in place. Platinum and Diamond need an external auditor. The first edition came out in 2023, and the current edition is 2026.
ISO 27001
ISO/IEC 27001
The international standard for an information security management system (ISMS). An ISMS is the set of policies, risk assessments and reviews a business uses to run its security. Two international standards bodies, ISO and IEC, publish it. The first edition came out in 2005 and the current edition is 2022. There are no tiers, so you hold the certificate or you do not. An accredited external auditor always does the check. The certificate lasts three years, with a smaller audit each year in between.
How they compare on cost and audit
Four differences matter most: who publishes each framework, how you prove you meet it, what it costs, and who accepts it as evidence.
Who runs it
- Essential Eight
- The Australian Signals Directorate, through the ACSC. This is the Australian Government agency responsible for cyber security.
- SMB1001
- Dynamic Standards International (DSI), formerly CSCAU. It is a private Australian standards body. A related company, CyberCert, issues the certificates.
- ISO 27001
- ISO and IEC, the international standards bodies. Accredited certification bodies do the audits. In Australia, JAS-ANZ accredits those bodies.
How you prove it
- Essential Eight
- You assess your own business against the ACSC criteria. There is no certificate. You often give the result as evidence when you renew cyber insurance or answer a customer's security questionnaire.
- SMB1001
- Bronze, Silver and Gold: a company director signs a declaration. Platinum and Diamond: an external auditor checks the business. Every tier renews each year.
- ISO 27001
- An accredited external auditor checks the business. The certificate lasts three years, with an audit every year in between. You cannot certify yourself.
Tiers or levels
- Essential Eight
- Four maturity levels: ML0 (controls partly done or missing), ML1, ML2 and ML3. Your overall level is your lowest score across the eight controls, not the average.
- SMB1001
- Five tiers from Bronze to Diamond. Each tier adds controls to the tier below. Bronze has 6 controls and Diamond has 35.
- ISO 27001
- No tiers. You are certified or you are not. A document called the Statement of Applicability lists the controls that apply to your business, and the certificate covers that list.
Direct cost in 2026
- Essential Eight
- Free. The ACSC publishes the model at no cost. You pay for the staff time and the IT work to put the controls in place.
- SMB1001
- An annual certification fee per organisation, in Australian dollars excluding GST: $95 (Bronze), $195 (Silver), $395 (Gold), $3,595 (Platinum), $5,995 (Diamond). You also buy the standard document, for USD $99 to $1,000 depending on how you use it.
- ISO 27001
- The first audit typically costs AU $15,000 to $50,000, depending on the size of the audit and the certification body. ISO sells the standard document for about AU $150.
How often it changes
- Essential Eight
- The ACSC revises the maturity model every few years. The last major revision was in November 2023. Smaller updates come more often.
- SMB1001
- A new edition most years (2023, 2025, 2026). It changes faster than the other two.
- ISO 27001
- A new edition every 5 to 10 years. The current edition is 2022, and the one before it was 2013.
Recognised by the Australian Government
- Essential Eight
- Yes. The ACSC publishes it. The federal cyber security strategy, industry regulators and many government purchasing panels refer to it.
- SMB1001
- Not in law. As of April 2026, the Cyber Security Act 2024 does not name it. The Security of Critical Infrastructure (SOCI) Act risk management rules do not name it either. CSCAU asked the Government to add it in a 2024 submission. The 2025 SOCI amendments did not add it.
- ISO 27001
- Yes. The critical infrastructure risk management program (CIRMP) rules name it for some critical infrastructure sectors. Right Fit For Risk and several other government accreditation schemes require it.
Recognised by cyber insurers
- Essential Eight
- Most Australian insurance renewal questionnaires ask about Essential Eight controls, even when they do not use the name. At ML1, a renewal typically goes through without extra questions.
- SMB1001
- Some managed service providers (MSPs) say insurers recognise it. We could not find an Australian insurer that publishes SMB1001 as a reason to lower your premium.
- ISO 27001
- Insurers recognise it worldwide. A certificate often answers whole sections of a questionnaire, so you do not answer each question one by one.
These costs are only the certification or audit fees. You also pay to put the controls in place, in technical work, software and staff time.
SMB1001, Bronze to Diamond
These are the controls in the SMB1001 standard. They come from Cyber Security Certification Australia's own 2024 submission to the Department of Home Affairs. Each tier adds controls to the tier below it. Costs are in Australian dollars, per organisation, per year, excluding GST.
-
Bronze (Level 1)
$95 a year · 6 controls · Director signs
Six controls. Have a technical support provider, a firewall and anti-virus. Install security updates automatically, change passwords on a schedule, and have a backup plan.
-
Silver (Level 2)
$195 a year · 14 controls · Director signs
Eight more controls on top of Bronze. Your public websites use encryption (TLS), and everyday user accounts have no administrator rights. Each person has their own login and a password manager. Email needs multi-factor authentication (MFA), which is a second check after the password, such as a code on your phone. You also need non-disclosure agreements, an invoice fraud policy and a visitor register.
-
Gold (Level 3)
$395 a year · 22 controls · Director signs
Another eight controls. Install security updates on servers, and add MFA to business apps and social media accounts. Write a cyber security policy and an incident response plan, which tells staff what to do during an attack. Dispose of documents and devices securely, keep a register of your IT equipment, and train staff to recognise attacks.
-
Platinum (Level 4)
$3,595 a year · 28 controls · External audit
Six more controls, and the first tier that an external auditor checks. Scan your systems from the internet for known weaknesses. Add MFA to stored data, the virtual private network (VPN) and remote desktop (RDP). Control the logins used for remote access, and hold business insurance.
-
Diamond (Level 5)
$5,995 a year · 35 controls · External audit
Seven more controls. Encrypt stored data, use application control to block unapproved software, and turn off untrusted Office macros. Pay for penetration testing and social engineering testing, where testers try to break in or trick your staff. Check the security of your suppliers, get police checks for your administrators, and practise your incident response plan.
Which one fits your business
Two questions decide it. How big is your business? And has an insurer, a large customer or a regulator named a specific framework?
-
If you are
Microbusiness, under 10 staff
We'd pick
Essential Eight ML1 self-assessment, no certificate
With under 10 staff, you almost certainly have no legal or insurance reason to hold a certificate. The work to reach Essential Eight ML1 is the same either way: MFA, security updates, backups, staff training and separate administrator accounts. Do the free self-assessment and fix what it finds. Look at certification again if a customer or an insurer asks for it.
-
If you are
10 to 30 staff, no specific compliance reason
We'd pick
Essential Eight ML1, with the SMB1001 controls as an internal checklist
Your insurer is probably not asking for an SMB1001 certificate, and your customers probably are not either. Regulators do not ask for it. The controls in Bronze and Silver are mostly sound, so use them as a checklist and do not pay for the certificate. If a customer or an insurance broker wants evidence, start with Essential Eight ML1. That is the framework they already ask about.
-
If you are
10 to 50 staff, and an insurer or large customer is asking
We'd pick
Essential Eight ML1 for the controls, and ISO 27001 if a paying customer requires it
If a customer's purchasing rules, an insurer's questionnaire or a regulator's accreditation scheme names a framework, do that one. Large companies and federal government buyers recognise ISO 27001. A few customers accept SMB1001 from their suppliers. If someone tells you insurers or buyers widely recognise a certificate, ask for a named, published policy before you pay for it.
-
If you are
20 to 50 staff in a regulated industry: legal, finance, health, training
We'd pick
Essential Eight ML2, with ISO 27001 if your regulator or your major customers require it
Your regulator almost certainly uses the Essential Eight or ISO 27001, not SMB1001. Law firms, accountants, allied health, financial services, registered training organisations and aged care providers all have rules built on one of those two. SMB1001 can help you organise the work, but your regulator accepts evidence in a different framework. Do the Essential Eight self-assessment first. The result tells you if you can close the gap to ML2 yourself, or if it needs a project.
-
If you are
50+ staff, a formal compliance program and security reports to the board
We'd pick
ISO 27001, with the Essential Eight controls inside it
At this size, large customers expect ISO 27001 before they buy from you, and insurers accept it without extra questions. An ISO 27001 management system includes the Essential Eight controls anyway. SMB1001 was not designed for businesses this size, and the insurers and customers who assess you will not recognise it.
Sources
- SMB1001 control set and certification pricing: CSCAU 2024 submission to the Department of Home Affairs, Annex A. homeaffairs.gov.au
- Password rotation and modern password guidance: NIST SP 800-63B Revision 4, August 2025. pages.nist.gov
- Cyber Security Act 2024 (no. 98 of 2024). legislation.gov.au
- ACSC Essential Eight Maturity Model. cyber.gov.au
- ISO/IEC 27001:2022 information security management systems. iso.org