All insights
Cyber compliance

SMB1001 vs the Essential Eight: why your firm needs both

A client sends over their supplier security questionnaire, or the cyber insurance renewal lands in the inbox, and buried in the fine print are two names: the Essential Eight and SMB1001. Both sound official, both sound mandatory, and neither comes with a plain explanation of what it is or why your firm is suddenly being asked about it.

Nathan James
Founder, Worktopia
10 August 20267 min read
SMB1001 and the Essential Eight
Two halves of the same answer.

The obvious move is to forward the lot to whoever handles your IT and ask which one needs sorting. The answer is both, they do different jobs, and the order you take them in matters more than the choice. Here is the short version of why.

What is the Essential Eight?

The Essential Eight is a set of eight technical controls from the Australian Signals Directorate, designed to stop the most common ways attackers get into a business, measured against a maturity model. The higher your maturity level, the harder your systems are to break into.

The eight are practical things, not paperwork:

1
Application control, so only approved software runs
2
Patch applications
3
Patch operating systems
4
Restrict Microsoft Office macros
5
User application hardening
6
Restrict administrative privileges
7
Multi-factor authentication
8
Regular backups

Done properly, the Essential Eight makes a firm hard to breach. It's the technical spine of a well-run setup, and for an accounting firm sitting on client tax records and financial data, that hardening earns its keep. That list is also the most useful thing on this page to act on today: paste the eight into an email to whoever runs your IT and ask where the firm sits on each, in writing.

Here's the catch: when you reach a maturity level, nobody hands you a certificate. There's no logo for the website, and nothing standardised to hand an insurer unless you pay for an independent assessment and pass on the report. The Essential Eight tells you how secure you are. It doesn't show anyone else.

Get the full picture
The Essential Eight, explained for accounting firms
Read →

What is SMB1001?

SMB1001 comes at the problem from the other end. It's a cyber security standard built specifically for small and medium businesses, developed by Dynamic Standards International and certified through CyberCert.

Rather than a single bar you clear or miss, SMB1001 runs across five tiers: Bronze, Silver, Gold, Platinum and Diamond. A firm certifies at the tier that matches where it sits today and climbs as it matures.

One distinction matters more than the tier names. Bronze, Silver and Gold are director-attested: your director signs a statement that the controls are in place, and the certificate is issued on that signature. Platinum and Diamond add an independent external audit on top of the director's attestation: someone external verifies the controls before the certificate exists. Both are real certifications carrying different kinds of assurance, and anyone reading your certificate, an insurer especially, knows the difference.

Need the tier detail?
SMB1001 explained for accounting firms
Read →

What SMB1001 gives you

A recognised certificate: a document a partner can attach to a client's security questionnaire or put in front of an insurer, which is exactly what the Essential Eight never hands you.

That certificate carries real weight:

The Queensland Law Society supports SMB1001 and recommends its members “work towards achieving Gold certification as a reasonable standard for robust cybersecurity and professional assurance”. No accounting body has gone that far yet, but a professional body naming a tier is the direction questionnaires follow.
Insurers ask more questions at every renewal, and a current certificate answers the framework question directly.
Larger clients increasingly want suppliers to show their security posture before signing. A certificate is an answer that doesn't require a meeting.

Accounting firms sit under every one of those pressures. Worth being straight about the limits too: at the attested tiers, the certificate is your director's word. That isn't a weakness of the standard, it's the design that makes certification reachable for a twelve-person firm. But it is your director's name on the attestation, and people rely on it, so treat that signature the way you'd treat signing off accounts: on evidence, not on reassurance.

If the questionnaire is due before any of this

A client's questionnaire or a renewal sitting on your desk now won't wait for either framework. What goes in the box this week is the truthful current state: which of the eight controls are in place today, which your IT provider can answer in writing, and what the firm is working toward, with a date on it. “We operate against the Essential Eight and are working toward SMB1001 certification” is a strong answer when it's true and a fatal one when it isn't, because these answers get relied on and sometimes checked. If the controls genuinely are in place, an attested tier can follow quickly, because at those tiers the signature is the last step, not the first.

Why the versus framing falls apart

Line the two up and the versus dissolves.

The Essential Eight is the work. SMB1001 is the recognised statement of the work. One hardens your systems, the other gives you something to show for it. You want both, and for related reasons.

Picture the two firms that pick a side.

Strong and silent
The first has quietly worked its way up the Essential Eight maturity levels. Its systems are genuinely hard to breach. But when a client's questionnaire asks for evidence of a recognised framework, the partner has nothing formal to send back. The work is invisible.
Certified and hollow
The second has a Bronze certificate on the website. It looks reassuring. Underneath, the technical hardening is thin, because a director-attested baseline got treated as the finish line instead of the starting point.

Neither firm is where it thinks it is. One did the work and can't show it; the other can show a bar it barely cleared.

Neither gap stays hidden. It reveals itself at the worst possible moment, which is when someone important is asking.

Put the two together and the gap closes. The higher SMB1001 tiers ask for many of the same technical controls the Essential Eight already covers: multi-factor authentication, managed patching, controlled admin access, and a backup regime that Platinum and Diamond require to be restore-tested at least once a year. At Diamond, the standard also names application control and restricting untrusted Office macros outright, two Essential Eight controls by name. Harden your systems against the Essential Eight and you've built the foundation the certification sits on and speaks for. Work you do for one counts toward the other. They were never opponents. They were always two halves of the same answer.

Wondering if any of this is compulsory?
Is the Essential Eight mandatory for accounting firms?
Read →

The order matters

Both belong in your firm, but they don't arrive at the same time. The technical hardening comes first, because a certificate is only worth what sits underneath it, and at the attested tiers the certificate is your director's signature on exactly that question. Get the sequence backwards and you've bought a receipt for a lock you never fitted.

One more thing before you anchor a plan to the Essential Eight name: the ASD began consulting in June 2026 on replacing it with a new Essentials series, and has said it expects to retire the Essential Eight in about two years. That doesn't make the work disposable. ASD's own line is that organisations already using the Essential Eight “can expect strong alignment with their existing controls and investments”. But a plan written this year should know the name is changing.

The detail
Is the Essential Eight being replaced?
Read →

What it costs

The certificate is the cheap part. CyberCert's published pricing at the time of writing is A$95 a year at Bronze, A$195 at Silver and A$395 at Gold, plus tax if applicable. Platinum is A$595 and Diamond A$995, each plus a required audit fee, A$3,000 and A$5,000 respectively.

The real cost is closing whatever gap sits between your current setup and the tier you want to sign for, and that number is different for every firm. For a practice already on business-grade Microsoft licensing, closing it is typically a project measured in weeks, not months. In our experience the early tiers are also a gentler climb than a full Essential Eight maturity uplift, with less disruption to daily work along the way, which is what makes them the right on-ramp rather than a substitute.

Which raises the practical question: does your firm know where it stands on either one today?

Common questions

What is SMB1001?
SMB1001 is a cyber security standard built for small and medium businesses, developed by Dynamic Standards International and certified through CyberCert. It runs across five tiers: Bronze, Silver and Gold, which are director-attested, and Platinum and Diamond, which add an independent external audit on top of the attestation. A firm certifies at the tier matching its current maturity and climbs from there.
What is the Essential Eight?
The Essential Eight is the Australian Signals Directorate's set of eight baseline technical controls for stopping common cyber attacks: application control, patching applications, patching operating systems, restricting Microsoft Office macros, user application hardening, restricted administrative privileges, multi-factor authentication and regular backups. Progress is measured against a maturity model, but there is no certificate for reaching a level.
Is SMB1001 the same as the Essential Eight?
No. The Essential Eight is a set of technical controls that hardens your systems but produces no certificate. SMB1001 is a certification standard that produces a recognised credential. The higher SMB1001 tiers require many of the same controls the Essential Eight covers, so the work you do for one counts toward the other.
Do you need the Essential Eight to get SMB1001 certified?
Not formally, but in practice the overlap is large. The higher SMB1001 tiers ask for controls the Essential Eight already covers, such as multi-factor authentication, patching and backups. A firm that has done Essential Eight hardening will find certification straightforward; a firm that has not will find the certificate is promising things its systems don't yet do.
Is SMB1001 independently audited?
At Platinum and Diamond an external audit is added on top of the director's attestation. At Bronze, Silver and Gold the certification is director-attested only, meaning a company director signs that the controls are in place and the certificate is issued on that signature. That makes entry-level certification accessible, and it also means the signature should follow the work, not replace it.
Is SMB1001 the same as ISO 27001?
No. ISO/IEC 27001 is the international standard for a full information security management system. It applies to organisations of any size, but the cost and ongoing effort of running one put it out of practical reach for most small practices. SMB1001 is deliberately scoped for small and medium businesses, with tiered requirements and a much lower cost of entry. For most accounting practices, SMB1001 is the realistic starting point and ISO/IEC 27001 a later consideration, if ever.
Nathan James
Founder, Worktopia
Nathan started Worktopia after years inside a Brisbane accounting firm, moving it off legacy systems and into the cloud. He writes about the practical side of security and IT for practices that would rather be doing the work.
Kip, the Worktopia mascot, holding a shield
See where you stand

Start with what you can actually measure

This is work we already do. Every Worktopia client baseline is built and measured against the Essential Eight, and that groundwork is what makes SMB1001 certification a formality rather than a scramble. Our free Cyber Compliance Health Check shows you where your firm stands against both. Read-only. Nothing in your systems changes. You approve access, and revoke it any time.

Start a Health Check or call 1300 856 912