In this article
What each framework covers
E8
Essential Eight
Eight technical mitigation strategies from the Australian Cyber Security Centre (ACSC), part of the Australian Signals Directorate. Built for federal government first, then adapted into four maturity levels (ML0 to ML3) the rest of the country can use. You self-assess against the ACSC's published criteria. No certificate, no audit, no annual fee.
SMB1001
SMB1001
A five-tier certification standard (Bronze, Silver, Gold, Platinum, Diamond) from Dynamic Standards International, formerly Cyber Security Certification Australia. CyberCert operates the certification. It is aimed squarely at small and medium businesses. Your own director attests Bronze, Silver and Gold; Platinum and Diamond need a third-party audit. First published 2023, now on its 2026 edition.
ISO 27001
ISO/IEC 27001
The international standard for an information security management system (ISMS), published by ISO and IEC. In force globally since 2005, most recently revised in 2022. No tiers: you either hold the certificate or you don't. An accredited third-party body always audits it, on a three-year cycle with annual surveillance audits in between.
How they compare on cost and audit
The differences that decide it are who publishes each one, how you prove it, what it costs, and who accepts it as evidence.
Who runs it
- Essential Eight
- Australian Signals Directorate (ACSC). Sovereign cyber authority.
- SMB1001
- Dynamic Standards International (DSI), formerly CSCAU. Private Australian standards body. Sister entity CyberCert operates certification.
- ISO 27001
- ISO and IEC, the international standards bodies. Independently accredited certification bodies run the audits (JAS-ANZ accredits them in Australia).
How you prove it
- Essential Eight
- Self-assessment against ACSC criteria. No certificate. Often used as evidence inside cyber-insurance renewals and supplier-security questionnaires.
- SMB1001
- Bronze, Silver and Gold: self-attested by a company director. Platinum and Diamond: third-party audit. Annual recertification for all tiers.
- ISO 27001
- Third-party audit by an accredited certification body. Three-year certificate cycle, annual surveillance audits. No self-attest pathway.
Tier or maturity model
- Essential Eight
- Four maturity levels: ML0 (partial or missing), ML1, ML2, ML3. Your overall maturity equals your weakest of the eight control scores, not the average.
- SMB1001
- Five tiers from Bronze to Diamond. Each tier adds controls on top of the previous. 6 controls at Bronze, 35 at Diamond.
- ISO 27001
- Single binary state (certified or not), but the certificate covers a defined Statement of Applicability that scopes which controls are in play for your organisation.
Direct cost in 2026
- Essential Eight
- Free. ACSC publishes the model. Audit and assessment cost is your time and your IT spend on the controls themselves.
- SMB1001
- Annual certification fee per organisation, AU ex GST: $95 (Bronze), $195 (Silver), $395 (Gold), $3,595 (Platinum), $5,995 (Diamond). The standard text itself is paywalled at USD $99 to $1,000 with usage-based pricing.
- ISO 27001
- First-audit cost typically AU $15,000 to $50,000 depending on scope and certifier. Standard text sold by ISO at roughly AU $150 fixed.
Update cadence
- Essential Eight
- Maturity model revised every few years. Last major revision November 2023; minor updates more often.
- SMB1001
- Annual editions (2023, 2025, 2026). Genuinely faster cadence than the alternatives.
- ISO 27001
- 5 to 10 year revision cycles. Current edition 2022, predecessor 2013.
Recognised by Australian Government
- Essential Eight
- Yes. ACSC publishes it. Cited in federal cyber strategy, sector regulator guidance, and many procurement panels.
- SMB1001
- Not in primary legislation. As of April 2026, it is not named in the Cyber Security Act 2024, and not in the Security of Critical Infrastructure (SOCI) Act risk-management rules. Cyber Security Certification Australia asked Government to add it in a 2024 submission. The 2025 SOCI amendments did not add it.
- ISO 27001
- Yes. Specifically named in CIRMP Rules for some critical-infrastructure sectors. Required by Right Fit For Risk and several other government accreditation regimes.
Recognised by cyber insurers
- Essential Eight
- De facto baseline language used in most Australian renewal questionnaires. ML1 typically clears a renewal without raised flags.
- SMB1001
- Managed service provider (MSP) marketing claims insurer recognition. We could not find one named Australian insurer that publishes SMB1001 as a documented premium-discount input.
- ISO 27001
- Universally recognised. Often clears whole questionnaire sections instead of itemised answers.
Those costs are the certification or audit fee only. Meeting the controls costs you more every time: technical work, software and staff hours.
SMB1001, Bronze to Diamond
These are the controls in the SMB1001 standard, taken from Cyber Security Certification Australia's own 2024 submission to the Department of Home Affairs. Each tier adds controls to the one below it. Costs are Australian dollars per organisation per year, excluding GST.
-
Bronze (Level 1)
$95 a year · 6 controls · Director attested
Six controls: engage technical support, install a firewall and anti-virus, patch automatically, change passwords routinely, and keep a backup strategy.
-
Silver (Level 2)
$195 a year · 14 controls · Director attested
Eight more on top of Bronze. Encryption (TLS) on your public sites, no admin rights on ordinary user accounts, individual logins, a password manager, and multi-factor authentication (MFA) on email. Then non-disclosure agreements, an invoice-fraud policy and a visitor register.
-
Gold (Level 3)
$395 a year · 22 controls · Director attested
Another eight. Server patching, MFA on business apps and social accounts, a written cyber security policy, and an incident-response plan. Then secure document and device disposal, an asset register, and staff awareness training.
-
Platinum (Level 4)
$3,595 a year · 28 controls · External audit
Six more, and the first tier an external auditor checks. External vulnerability scanning, MFA on stored data, on the virtual private network (VPN) and on remote desktop (RDP), remote-access credential management, and business insurance.
-
Diamond (Level 5)
$5,995 a year · 35 controls · External audit
Seven more. Encryption at rest, application control, disabling untrusted Office macros, and penetration and social-engineering testing. Then supplier digital trust, police vetting for administrators, and tabletop training on the incident-response plan.
Which one fits your business
Two questions settle it. How big are you, and has anyone outside the business named a specific framework? An insurer, a large customer or a regulator all count.
-
If you are
Microbusiness, under 10 staff
We'd pick
Essential Eight ML1 self-assessment, no certificate
At under 10 staff, you almost certainly have no regulatory or insurance reason to hold a certificate. The work to reach Essential Eight ML1 is the work either way: MFA, patching, backups, awareness training, and keeping admin accounts separate. Run the free self-assessment, fix what it finds, and revisit certification if a client or an insurer ever asks for one.
-
If you are
10 to 30 staff, no specific compliance driver
We'd pick
Essential Eight ML1, with the SMB1001 control set as an internal checklist
Your insurer probably isn't asking for a SMB1001 certificate. Neither are your customers, and the certificate gets you nothing on the regulatory side. The controls inside Bronze and Silver are broadly sound and worth putting in place, so use the framework as a checklist rather than a credential. If you do want something to show a customer or a broker, get Essential Eight ML1 evidence first. That's the language they already speak.
-
If you are
10 to 50 staff, you have an insurer or large customer asking
We'd pick
Essential Eight ML1 as substance, ISO 27001 if the customer is paying you to hold it
If a customer's procurement gate, an insurer's questionnaire or a regulator's accreditation scheme names a specific framework, do that one. ISO 27001 is the credential large enterprise customers and federal government procurement actually recognise. SMB1001 is occasionally accepted in supply-chain conversations. Treat any claim of broad insurer or procurement recognition with scepticism, and ask for a named, published policy before you pay for the certificate.
-
If you are
20 to 50 staff in a regulated industry: legal, finance, health, training
We'd pick
Essential Eight ML2, with ISO 27001 if your sector regulator or your major clients require it
Your regulator is almost certainly speaking Essential Eight or ISO 27001, not SMB1001. Law firms, accountants, allied health, financial services, registered training organisations and aged-care providers all face frameworks built on one of those two. SMB1001 may help you organise internally, but the evidence your regulator accepts is in another framework. Run the Essential Eight self-assessment first. The answer tells you whether the gap to ML2 is small enough to handle in-house, or big enough to be a project.
-
If you are
50+ staff, formal compliance program, board reporting
We'd pick
ISO 27001, with the Essential Eight controls inside it
At this size, ISO 27001 is the credential that opens enterprise procurement and clears insurer questionnaires without follow-up. An ISO 27001 management system will absorb the Essential Eight controls anyway. SMB1001 is not designed for this scale, and the parties whose sign-off you need won't know it.
Sources
- SMB1001 control set and certification pricing: CSCAU 2024 submission to the Department of Home Affairs, Annex A. homeaffairs.gov.au
- Password rotation and modern password guidance: NIST SP 800-63B Revision 4, August 2025. pages.nist.gov
- Cyber Security Act 2024 (no. 98 of 2024). legislation.gov.au
- ACSC Essential Eight Maturity Model. cyber.gov.au
- ISO/IEC 27001:2022 information security management systems. iso.org