SMB1001 vs Essential 8: one certifies the business, the other hardens its systems.
The Essential Eight is ASD's self-assessed technical hardening baseline; SMB1001 is a tiered certification with a public registry entry a buyer can check.
SMB1001 and the Essential Eight, often written Essential 8, come up in the same conversations and answer different questions. The Essential Eight answers: how hardened are these systems against common attacks.
What SMB1001 answers
SMB1001 answers: can this business show a buyer, an insurer or a supply chain that its security fundamentals are certified and checkable.
Black Shard prepares businesses for both and certifies neither.
Side by side.
| Criteria | Essential Eight | SMB1001 |
|---|---|---|
| What it is | Essential EightEight mitigation strategies published by the Australian Signals Directorate: patching applications and operating systems, multi-factor authentication, restricting administrative privileges, application control, restricting Microsoft Office macros, user application hardening, and regular backups. Each is measured against maturity levels from zero to three. | SMB1001An Australian cybersecurity certification standard for small and medium businesses, tiered from Bronze upward so a business certifies at the level it can sustain. Revised annually, which is why a certificate carries its year. |
| Who asks for it | Essential EightAustralian government procurement, and the buyers and frameworks that follow its lead. When a tender asks about your Essential Eight maturity, it is asking for your self-assessed position, and it expects you to be able to defend the number. | SMB1001Australian buyers, insurers and supply chains that want an answer they can verify without auditing you themselves. The certificate sits on a public registry; due diligence can check it in a minute. |
| Assessment model | Essential EightSelf-assessment against ASD's published maturity model. There is no certificate and no registry: nobody can be Essential Eight certified. | SMB1001Certification through CyberCert. At Gold, a company director formally attests to the standard's twenty-seven controls and the certificate is listed publicly. |
| Scope | Essential EightTechnical controls on your systems: endpoints, servers, identities, backups. It says nothing about policies, training, insurance or governance; the maturity model covers technical controls only. | SMB1001The business as a whole. Alongside technical fundamentals, the tiers bring in policy, training and process: the things a buyer means when they ask whether security is managed. |
| What the work looks like | Essential EightHardening. Closing the gap between your current maturity and the target level: rolling out multi-factor authentication properly, getting patch cadences running, taking local admin away, making backups restorable. The evidence is technical state. | SMB1001Closing a fixed control set and evidencing it. Much of the technical work overlaps the Essential Eight directly, which is why the sensible sequence is rarely a choice between the two. |
| What you can show for it | Essential EightA defensible self-assessment: your maturity level per strategy and the evidence behind it. Strong inside a tender response; invisible outside one, because there is nothing a third party can look up. | SMB1001A registry listing anyone can check, and the evidence pack behind the attestation. It travels: insurers, supply-chain questionnaires and procurement teams can all verify it without your involvement. |
When the Essential Eight is the right focus
- A government tender or panel asks for your Essential Eight maturity. Answer the question asked.
- You need to reduce breach likelihood before you need to prove anything to anyone.
- Your systems are the gap: patching is ad hoc, admin rights are everywhere, MFA has holes.
- You already hold a certification and the next step is depth on the technical controls behind it.
When the Essential Eight is the right focus, in full
- Your systems are the gap: patching is ad hoc, admin rights are everywhere, MFA has holes. The maturity model is the sharpest available to-do list.
When SMB1001 is the right focus
- Buyers, insurers or supply chains keep asking what certification you hold, and you need an answer they can verify.
- You want the policy, training and governance layer pulled up alongside the technical work.
- You need a credential on a realistic timeline: certify at a sustainable tier now, step up as the business matures.
- The technical fundamentals are largely in place and unproven: the work is turning them into an attested, checkable position.
Why the two keep being confused
Both are Australian, both aim at the same class of attacks, and both get named in the same due-diligence conversations, so they read as alternatives. They are different instruments. The Essential Eight is a measuring stick for technical hardening. SMB1001 is a certification that the fundamentals, technical and organisational, are in place and attested.
Where the two overlap
One tells you how hardened you are; the other lets you prove to someone else that you are managed.
The overlap is substantial. Multi-factor authentication, patching, backups and access control sit at the centre of both. Work done for one is not thrown away on the other, and a business that has closed its Essential Eight gaps walks into SMB1001 certification with most of the technical controls already evidenced.
The confusion only costs you when it becomes a substitution: treating a self-assessed maturity level as if it were a certificate, or treating a certificate as if it settled every question a government tender asks about maturity. Buyers notice both mistakes.
Essential Eight coverage by SMB1001 tier
The Essential Eight's eight strategies do not enter SMB1001 at the same point, and the gap between the two frameworks is not spread evenly across the tiers. Patching, multi-factor authentication, restricting administrative privileges and backups, the four controls that carry most of the risk reduction in both instruments, are folded into SMB1001's earlier tiers.
Strategy by strategy, Bronze to Diamond
That is why Essential Eight uplift work keeps counting as a business climbs the SMB1001 tiers rather than being repeated.
Patching applications and patching operating systems sit at Bronze, the entry tier, alongside regular backups. Multi-factor authentication and restricting administrative privileges are added at Silver, where individual accounts replace shared logins; Platinum raises the multi-factor requirement to phishing-resistant methods. User application hardening is not tested as a separate, named control at any SMB1001 tier.
Application control and Microsoft Office macro hardening are the exception. Neither is required at Bronze, Silver, Gold or Platinum; SMB1001 does not ask for them until Diamond, its top tier. Certification has already left director attestation behind by that point: the switch to external audit happens a tier earlier, at Platinum, and Diamond carries the same audit requirement plus these two controls. A business certified at Gold has been tested on the shared technical fundamentals and on the policy, training and governance layer SMB1001 adds beyond the Essential Eight. It has not been tested on the two Essential Eight strategies that demand the most fleet-management engineering, and a tender that names Essential Eight maturity will ask about both directly.
What changes between Essential Eight Maturity Levels One, Two and Three
The eight strategies stay the same at every level. What changes is how far each one has to reach, and the reach that matters most for a business weighing this framework against SMB1001 sits in four places: patch windows, multi-factor authentication, application control and logging.
Patching, MFA, application control and logging by level
Patch timing for online services does not move between levels: 48 hours for critical vulnerabilities, two weeks for non-critical ones, at every level. What changes is the window for less-exposed systems. Workstations and non-internet-facing servers get a month at Levels One and Two, tightening to 48 hours for critical vulnerabilities at Level Three; office productivity suites, browsers, email clients and PDF software move the same way, from two weeks to 48 hours. Level Three also brings drivers and firmware into the same split, and pins operating systems to the current release or the one before it.
Multi-factor authentication starts at Level One for accessing sensitive data. Level Two extends it to every privileged and unprivileged user of a system, requires it to be phishing-resistant for online services, and starts centrally logging every successful and failed attempt. Level Three carries the phishing-resistant requirement further, to customers of online customer services and to anyone authenticating to a data repository, and is the first level to require multi-factor authentication for data repositories at all.
Application control at Level One covers workstations, restricting the standard set of executables, scripts and installers to an approved list. Level Two adds internet-facing servers, extends the restriction to every location, layers in Microsoft's recommended application blocklist, and requires the ruleset revalidated at least annually. Level Three adds non-internet-facing servers, restricts which drivers can load, and adds Microsoft's separate vulnerable driver blocklist.
Logging and incident response are not required at Level One at all; they appear at Level Two. Event logs must then be centrally collected and protected from tampering, logs from internet-facing servers reviewed for security events, and a confirmed incident reported to the chief information security officer and to ASD under an enacted response plan. Level Three widens the same obligation to non-internet-facing servers and workstations.
Which to start on, for three buyer situations
A government tender or panel names an Essential Eight maturity level. Answer what was asked: complete the self-assessment against that level and hold the evidence behind it. No SMB1001 tier hands over a certificate that stands in for a named maturity level, because nothing in the standard maps one-to-one onto ASD's four levels.
The other two situations
An insurer's proposal form or a supply-chain questionnaire usually names specific controls: multi-factor authentication, patching, backups and administrative access. A SMB1001 certificate answers the form in one verifiable line, because Bronze and Silver already require those same four controls; use the Essential Eight maturity model to decide how far to harden each one.
A buyer or partner asks only whether you hold a certification, with no maturity level or control list named. Go straight to SMB1001. The Essential Eight has no certificate to hand over at any maturity level, so it cannot answer this question on its own.
Where nothing external names either framework, start with the hardening. It is the part that changes whether an attack lands, and its controls carry straight into SMB1001 certification evidence.
Questions, answered
Is SMB1001 the same as Essential Eight?
No. The Essential Eight is a self-assessed technical maturity model with no certificate; SMB1001 is a certification standard with a public registry entry. Neither substitutes for the other: a tender naming an Essential Eight maturity level is not answered by an SMB1001 certificate, and a buyer asking for a certification is not answered by a maturity self-assessment.
Can you be certified against the Essential Eight?
No. The Essential Eight is a self-assessed maturity model published by the Australian Signals Directorate; there is no certificate and no public registry for it. Assessments of your maturity, including independent ones, are point-in-time opinions and carry no certificate. If a checkable credential is what you need, that is what SMB1001 is for.
Does SMB1001 cover the Essential Eight?
Not fully. Multi-factor authentication, patching, backups and restricting administrative privileges sit inside SMB1001 from Bronze and Silver. Application control and Microsoft Office macro hardening sit inside Platinum and Diamond, the two tiers that move certification from director attestation to external audit. User application hardening is not tested as a separate, named control at any SMB1001 tier.
Does SMB1001 Gold cover the Essential Eight?
Only part of it. Gold carries forward Silver's requirements for multi-factor authentication, patching, backups and restricted administrative access, covering most of Essential Eight Maturity Level One on those four strategies. It does not reach Maturity Level Two: application control and Microsoft Office macro restriction sit inside Platinum and Diamond, and neither is tested at Gold.
Which one do insurers care about?
Insurers ask about controls, and they do not ask about standards: proposal forms want multi-factor authentication, backups, patching and administrative access answered specifically. A SMB1001 certificate is useful shorthand because it is verifiable; the Essential Eight work is what makes the answers on the form true. Our cyber insurance readiness tool walks the standard questions.
Which one does government require?
Follow the document in front of you. The Commonwealth mandates the Essential Eight for its own non-corporate entities under the Protective Security Policy Framework, and a tender naming an Essential Eight maturity level wants that position; no SMB1001 tier substitutes for it. Where a buyer or prime contractor asks for a certification, an SMB1001 tier is what they can verify.
Which is cheaper to maintain, Essential Eight or SMB1001?
The maturity level drives the cost more than the framework's name. SMB1001 renews annually against that year's edition, a fixed event. The Essential Eight has no certificate or renewal fee, but its cost tracks the level: Level One is periodic hardening, while Levels Two and Three add a logging and incident-response function that runs all year.
Can we do both, and does one save work on the other?
Yes. Multi-factor authentication, patching, backups and restricting administrative privileges sit inside both, so Essential Eight uplift counts toward SMB1001's early tiers and an SMB1001 gap review inherits that evidence. Application control and macro hardening, which SMB1001 does not ask for below Diamond, do not transfer; nor does SMB1001's policy, training and governance layer.

