A client sends over their supplier security questionnaire, or the cyber insurance renewal lands in the inbox, and buried in the fine print are two names: the Essential Eight and SMB1001. Both sound official, both sound mandatory, and neither comes with a plain explanation of what it is or why your firm is suddenly being asked about it.
The obvious move is to forward the lot to whoever handles your IT and ask which one needs sorting. The answer is both, they do different jobs, and the order you take them in matters more than the choice. Here is the short version of why.
The Essential Eight is a set of eight technical controls from the Australian Signals Directorate, designed to stop the most common ways attackers get into a business, measured against a maturity model. The higher your maturity level, the harder your systems are to break into.
The eight are practical things, not paperwork:
Done properly, the Essential Eight makes a firm hard to breach. It's the technical spine of a well-run setup, and for an accounting firm sitting on client tax records and financial data, that hardening earns its keep. That list is also the most useful thing on this page to act on today: paste the eight into an email to whoever runs your IT and ask where the firm sits on each, in writing.
Here's the catch: when you reach a maturity level, nobody hands you a certificate. There's no logo for the website, and nothing standardised to hand an insurer unless you pay for an independent assessment and pass on the report. The Essential Eight tells you how secure you are. It doesn't show anyone else.
SMB1001 comes at the problem from the other end. It's a cyber security standard built specifically for small and medium businesses, developed by Dynamic Standards International and certified through CyberCert.
Rather than a single bar you clear or miss, SMB1001 runs across five tiers: Bronze, Silver, Gold, Platinum and Diamond. A firm certifies at the tier that matches where it sits today and climbs as it matures.
One distinction matters more than the tier names. Bronze, Silver and Gold are director-attested: your director signs a statement that the controls are in place, and the certificate is issued on that signature. Platinum and Diamond add an independent external audit on top of the director's attestation: someone external verifies the controls before the certificate exists. Both are real certifications carrying different kinds of assurance, and anyone reading your certificate, an insurer especially, knows the difference.
A recognised certificate: a document a partner can attach to a client's security questionnaire or put in front of an insurer, which is exactly what the Essential Eight never hands you.
That certificate carries real weight:
Accounting firms sit under every one of those pressures. Worth being straight about the limits too: at the attested tiers, the certificate is your director's word. That isn't a weakness of the standard, it's the design that makes certification reachable for a twelve-person firm. But it is your director's name on the attestation, and people rely on it, so treat that signature the way you'd treat signing off accounts: on evidence, not on reassurance.
A client's questionnaire or a renewal sitting on your desk now won't wait for either framework. What goes in the box this week is the truthful current state: which of the eight controls are in place today, which your IT provider can answer in writing, and what the firm is working toward, with a date on it. “We operate against the Essential Eight and are working toward SMB1001 certification” is a strong answer when it's true and a fatal one when it isn't, because these answers get relied on and sometimes checked. If the controls genuinely are in place, an attested tier can follow quickly, because at those tiers the signature is the last step, not the first.
Line the two up and the versus dissolves.
The Essential Eight is the work. SMB1001 is the recognised statement of the work. One hardens your systems, the other gives you something to show for it. You want both, and for related reasons.
Picture the two firms that pick a side.
Neither firm is where it thinks it is. One did the work and can't show it; the other can show a bar it barely cleared.
Neither gap stays hidden. It reveals itself at the worst possible moment, which is when someone important is asking.
Put the two together and the gap closes. The higher SMB1001 tiers ask for many of the same technical controls the Essential Eight already covers: multi-factor authentication, managed patching, controlled admin access, and a backup regime that Platinum and Diamond require to be restore-tested at least once a year. At Diamond, the standard also names application control and restricting untrusted Office macros outright, two Essential Eight controls by name. Harden your systems against the Essential Eight and you've built the foundation the certification sits on and speaks for. Work you do for one counts toward the other. They were never opponents. They were always two halves of the same answer.
Both belong in your firm, but they don't arrive at the same time. The technical hardening comes first, because a certificate is only worth what sits underneath it, and at the attested tiers the certificate is your director's signature on exactly that question. Get the sequence backwards and you've bought a receipt for a lock you never fitted.
One more thing before you anchor a plan to the Essential Eight name: the ASD began consulting in June 2026 on replacing it with a new Essentials series, and has said it expects to retire the Essential Eight in about two years. That doesn't make the work disposable. ASD's own line is that organisations already using the Essential Eight “can expect strong alignment with their existing controls and investments”. But a plan written this year should know the name is changing.
The certificate is the cheap part. CyberCert's published pricing at the time of writing is A$95 a year at Bronze, A$195 at Silver and A$395 at Gold, plus tax if applicable. Platinum is A$595 and Diamond A$995, each plus a required audit fee, A$3,000 and A$5,000 respectively.
The real cost is closing whatever gap sits between your current setup and the tier you want to sign for, and that number is different for every firm. For a practice already on business-grade Microsoft licensing, closing it is typically a project measured in weeks, not months. In our experience the early tiers are also a gentler climb than a full Essential Eight maturity uplift, with less disruption to daily work along the way, which is what makes them the right on-ramp rather than a substitute.
Which raises the practical question: does your firm know where it stands on either one today?