SMB1001 vs Essential Eight is the question that lands the moment someone outside your business asks you to prove your security posture. Usually it is a customer's procurement team, an insurer's renewal questionnaire, or a tender document with a compliance section. The two frameworks get discussed as if you have to pick a side. You don't. One is a certification you can hand over; the other is a technical baseline you get measured against. Which you should do first depends far less on which is "better" and far more on who is asking, and what they actually want to see.
This is a plain comparison of both, what each one costs in money and effort, where they overlap, and a recommended sequence by business size.
What each framework actually is
The Essential Eight is published by the Australian Signals Directorate. It is eight mitigation strategies (application control, patching applications, Microsoft Office macro settings, user application hardening, restricting administrative privileges, patching operating systems, multi-factor authentication, and regular backups) assessed across four maturity levels, ML0 through ML3. The full control wording lives in the Essential Eight Maturity Model on cyber.gov.au.
It is mandatory for one specific group. Since 1 July 2022, non-corporate Commonwealth entities have been required under the Protective Security Policy Framework to implement all eight strategies to at least Maturity Level Two. For everyone else in Australia it is guidance, not law. It still turns up constantly in tenders, contracts and insurance forms, which is why private businesses end up chasing it.
SMB1001 is published by Dynamic Standards International and certified through CyberCert. It has five cumulative tiers: Bronze, Silver, Gold, Platinum and Diamond. It was written specifically for businesses that do not have a security team, and it is structured as a certification rather than an assessment. You end up holding a dated certificate at a named tier. Our SMB1001 tier guide breaks down what sits in each one.
Certification versus maturity model: the difference that matters
This is the distinction most comparisons skip, and it is the one that usually decides the answer.
The ASD does not issue an Essential Eight certificate. There is no official credential. You either self-assess or pay a third party to assess you, and the output is a maturity rating in a report. That report is useful internally and it will satisfy a knowledgeable assessor, but it is not a badge with an expiry date on it.
Your Essential Eight maturity is also measured at your weakest point. The overall level you can claim is the lowest level reached across all eight strategies, so one lagging control caps the entire result. Businesses routinely discover they are ML0 overall despite doing seven of the eight strategies well.
SMB1001 works the other way around. Each tier has a fixed, published control list. You know exactly what "done" looks like before you start, a director signs off through the CyberCert portal at the lower tiers, and you get a certificate you can attach to a tender response. That artefact is the entire reason most SMBs choose it.
SMB1001 vs Essential Eight: cost and effort compared
The Essential Eight has no framework fee at all. Everything you spend goes on implementation and, if you want an independent view, assessment. That sounds cheaper until you look at what ML1 actually asks for. Application control (whitelisting what is allowed to execute on workstations) is a real project in most environments, and it is the strategy that stalls Essential Eight programmes more often than any other.
SMB1001 charges an annual certificate fee that scales with the tier. Industry sources put the 2026 fees at roughly AUD 95 for Bronze, 195 for Silver and 395 for Gold, then a substantial jump to around 3,595 for Platinum and 5,995 for Diamond, all ex GST (Redscale). The jump reflects a genuine change in rigour: Bronze, Silver and Gold are self-attested by a company director, while Platinum and Diamond require an external audit by an Independent Verification Organisation, with audit fees of roughly 3,000 to 8,000 on top of the certificate.
On effort, Bronze is a matter of weeks for most businesses. Gold, at 27 controls in the SMB1001:2026 edition, is a genuine programme of work spanning people, process and technology. Essential Eight ML1 across all eight strategies is comparable to Gold in effort, and you finish it without a certificate.
One number is worth keeping in mind before you commit to an Essential Eight target. In the 2025 Commonwealth Cyber Security Posture Report, 22 per cent of Commonwealth entities reached overall Maturity Level Two, up from 15 per cent in 2024. These are organisations with dedicated security teams, budget, and a legal mandate to get there. If a supplier questionnaire casually asks a 30-person business to "be Essential Eight compliant", that is the context you are working in.
Where they overlap, and where they don't
There is real common ground. Multi-factor authentication, patching, restricting administrative privileges and backups all appear in both frameworks, so work done for one counts towards the other on those controls.
The gaps run in both directions, which is why neither substitutes for the other.
The Essential Eight is deliberately technical. It says nothing about written policies, staff awareness training, incident response planning, cyber insurance or supplier assurance. SMB1001 covers all of those from Gold upward, which matters because governance and human error cause a large share of small-business incidents that no amount of patching addresses.
Going the other way, SMB1001 does not name application control or Microsoft Office macro hardening as specific required controls the way the Essential Eight does. So achieving Gold does not automatically make you ML1, and being assessed at ML1 does not automatically clear Gold. If a contract names one framework, do that framework rather than assuming the other one covers it.
Does the Essential Eight retirement change the answer?
In June 2026 the ASD announced that the Essential Eight will be retired and replaced by a multi-chapter "Essentials" series, beginning with Essentials for Enterprise IT and with further chapters planned for cloud and operational technology. Retirement is staged over roughly two years rather than immediate (Australian Cyber Security Magazine).
The practical reading is not "stop doing the Essential Eight". MFA, patching, admin restriction and tested backups are not going anywhere; the new series reorganises and modernises the guidance rather than discarding the controls. What it does change is the value of spending heavily on an Essential Eight assessment engagement purely to produce evidence for someone else. If evidence is the goal, an SMB1001 certificate is the more durable artefact to be holding right now.
A recommended sequence by business size
Under about 20 staff, no internal IT. Start at Bronze, then move to Silver within the same year. Bronze asks for four things and is achievable quickly. Our SMB1001 Bronze requirements checklist walks through each control and what ticks it.
20 to 100 staff, some IT support, selling to larger customers. Aim for Silver then Gold. Gold's EDR, enforced email authentication and documented incident response are roughly where the shared Essential Eight controls land in spirit, and Gold is the tier procurement teams have started asking for by name.
In a government supply chain, or regulated. Do both. Certify to SMB1001 for the artefact, and run an Essential Eight gap assessment separately, because the tender will ask for the Essential Eight by name and will not accept a substitute. Our Essential Eight guide covers all eight strategies and what each maturity level demands.
Already at Essential Eight ML1 or above. You will clear Silver on day one and most of Gold. Certify anyway; you have done the work and the certificate is the cheap part.
Backups are the control both frameworks refuse to bend on
Regular backups is one of the eight strategies and the only one concerned with recovery rather than prevention. SMB1001 asks for automated backup from Bronze and adds recovery testing at the higher tiers. Both want the same thing in the end: a copy an attacker with administrator credentials cannot destroy, and a restore someone has actually performed this year rather than assumed would work.
The gap we see most often is SaaS data. Businesses back up servers and endpoints, then discover during an assessment that Microsoft 365, Google Workspace and Salesforce have no independent backup behind them, because the providers do not supply one. Keepit covers that layer, and our Essential Eight backup requirements post maps each maturity level's backup controls to what actually satisfies them. For servers, endpoints and virtual workloads, see our backup and disaster recovery solutions.
The short answer
If someone is asking you to prove your security posture, do SMB1001 first. The certificate is what they are actually after, and the tiered structure means you can start small and be credible within weeks.
If someone is asking you to meet a specified technical bar, particularly a government-adjacent contract naming a maturity level, do the Essential Eight, and do it properly rather than claiming a level your weakest strategy does not support.
Most Australian SMBs are in the first camp and have been told they are in the second. If you are not sure which applies to you, talk to us and we will work through the requirement you have actually been handed.
