Cybersecurity

Australian cyber security standards compared

The Essential Eight, SMB1001, ISO 27001, SOC 2 and IRAP get discussed as if a business has to pick one. They answer different questions and they are asked for by different people. This page explains what each one is, what it actually requires, and which one the request in front of you is really about.

The five

What each standard is, and what it does for you

Read this against whoever is asking. A government tender, an enterprise procurement team and a business insurer want three different documents, and only one of these produces the one they mean.

Essential Eight

What it is. A maturity model published by the Australian Signals Directorate. Eight mitigation strategies, each assessed at Maturity Level Zero through Three. It is free to read, it is self-assessed, and it is the language of Australian government and public sector work.

What it does for you. Reduces risk from the attacks that actually happen, and answers government-adjacent requirements. It produces no certificate, so it cannot on its own satisfy a client who wants third party evidence.

SMB1001

What it is. An Australian certification standard for businesses under two hundred people, maintained by Dynamic Standards International. Five tiers, Bronze through Diamond, each adding controls. Currently SMB1001:2026, revised annually.

What it does for you. Produces a certificate at a cost proportional to a smaller business. It is the practical answer when a client questionnaire, tender or insurer wants proof and ISO 27001 is out of reach.

ISO 27001

What it is. The international standard for an information security management system. It certifies the management system rather than a control list: risk assessment, documented policy, defined ownership, internal audit and continual improvement, audited by an accredited body.

What it does for you. Opens enterprise and overseas procurement, where it is frequently named outright. It is the largest undertaking of the five and the one with the longest useful life once achieved.

SOC 2

What it is. An American attestation report produced by a licensed auditor against five trust services criteria. Type I reports design at a point in time, Type II reports operation across a period, usually six to twelve months.

What it does for you. Expected by United States customers and by software buyers. If your customers are American or you sell software, this is often the specific document being requested, and ISO 27001 will not substitute for it.

IRAP

What it is. An Australian Signals Directorate programme under which endorsed assessors evaluate systems against the Information Security Manual. It is an assessment of a system, not a certificate for a company.

What it does for you. Required to handle Australian government data at classified levels. If you are bidding for federal work involving protected data, this is the pathway, and the Essential Eight is the groundwork underneath it.

Side by side

How the five compare on the things that decide

The row that settles most conversations is the first one. Everything else follows from whether you need to reduce risk or prove something to somebody else.

Essential Eight SMB1001 ISO 27001 SOC 2 IRAP
Produces a certificate No, self-assessed Yes, five tiers Yes, accredited audit No, an audit report No, a system assessment
Who asks for it Australian government and public sector Australian clients, insurers, tenders Enterprise and overseas procurement United States customers, software buyers Federal government, protected data
Best fit Any size, government-adjacent Under 200 people Mid-market to enterprise Software and services businesses Government suppliers
What is assessed Eight controls at four maturity levels A control set per tier A management system Controls operating over a period A system against the ISM
Typical effort Weeks at Level One, quarters at Level Two Weeks to months by tier Six to twelve months Three to twelve months Months, plus remediation
Ongoing obligation Continuous evidence to stay current Annual, standard revises yearly Surveillance audits, three year cycle Annual report Reassessment on change
Covered by existing licences Largely yes at Level One Largely yes at lower tiers Partly, the system is the work Partly Partly

Choosing

Two questions settle it

Businesses arrive asking which framework is best. That is the wrong question and it has no answer. These two questions have answers.

Are you reducing risk or proving something?

If nobody is asking and you want to be harder to attack, the Essential Eight is the most efficient starting point in Australia and costs nothing to adopt. If a third party wants evidence, you need something that certifies, and the Essential Eight alone will not do it.

Risk versus evidence

Who is doing the asking?

Australian government points to the Essential Eight and IRAP. Australian clients and insurers accept SMB1001. Enterprise and overseas procurement names ISO 27001. American customers and software buyers mean SOC 2. Read the actual request, because the wording almost always names the answer.

Read the request

How we help

Choosing and reaching the right one

We are vendor funded, so the service costs your business nothing. We are not an audit firm and we do not certify you, which is why we can be straight about which standard you need.

01

Read the requirement with you

The tender clause, questionnaire or insurer wording. This alone resolves most cases, and it regularly shows that a business is scoping a far larger standard than it was asked for.

02

Assess what you already meet

The five overlap heavily. Work done for one counts towards the others, so the assessment establishes your position across all of them rather than just the one in question.

03

Sequence them so nothing is wasted

SMB1001 first and ISO 27001 later is a sensible path. ISO 27001 first when enterprise sales depend on it. The Essential Eight underneath either when government work is in view.

04

Close the gaps with what you own

Most lower tier and Level One controls are configuration inside Microsoft 365 or Google Workspace. We do this before recommending any purchase.

05

Evidence it continuously

Every one of these needs evidence that the controls operate, not that they exist. Platform tooling collects it continuously so audits and renewals are reports rather than projects.

Common questions

Questions about the standards

What Australian businesses ask us

What is ISO 27001?

The international standard for an information security management system. Rather than checking a list of controls, it certifies that you run a system for managing security: risk assessment, documented policy, clear ownership, internal audit and continual improvement. Certification comes from an accredited body and typically takes six to twelve months. It is the standard most often named in enterprise and overseas procurement.

What is SOC 2?

An American attestation report produced by a licensed auditor against five trust services criteria: security, availability, processing integrity, confidentiality and privacy. Type I covers design at a point in time. Type II covers operation over a period, usually six to twelve months, and is what most customers mean. It is a report rather than a certificate, and it is what United States customers and software buyers expect.

What is IRAP?

The Information Security Registered Assessors Program, run by the Australian Signals Directorate. Endorsed assessors evaluate a system against the Information Security Manual. It assesses a system rather than certifying a company, and it is the pathway for handling Australian government data at classified levels.

Which cyber security certification do we need in Australia?

It depends entirely on who is asking. Government and public sector work points to the Essential Eight and, for protected data, IRAP. Australian clients, tenders and insurers generally accept SMB1001. Enterprise and overseas buyers name ISO 27001. American customers mean SOC 2. Read the request before choosing a framework.

Is ISO 27001 or SOC 2 better?

Neither, they serve different markets. ISO 27001 is an international certification of a management system and is the common language in Europe, Asia and Australian enterprise. SOC 2 is an American audit report and is what United States buyers ask for. Businesses selling into both markets often end up doing both, and the underlying control work overlaps substantially.

Can one project cover more than one standard?

Largely yes. The control work overlaps heavily, so evidence gathered for one carries into the others. Sequencing matters: certifying SMB1001 first and moving to ISO 27001 later reuses most of the effort, whereas starting with the largest standard and working backwards does not.

We are vendor funded and completely free to your business. Always focused on the right outcome.

Send us the requirement and we will tell you which one it means.

Most businesses scoping a cyber standard are aiming at a bigger one than they were asked for. Answer six questions, or send us the clause, and we will tell you which standard it means and what you already meet.

Book a Call

Independent guidance at no cost to your business.

Read further on this

The pages and articles that answer the next question a buyer usually asks.