Black Shard

One hardens the systems. The other proves the business.

The Essential Eight is the Australian Signals Directorate's technical hardening baseline, self-assessed and never certified; SMB1001 is a tiered certification standard with a public registry entry a buyer can check. Most businesses that ask which one they need eventually run both, in that order.

The Essential Eight, often written Essential 8, and SMB1001 come up in the same conversations and answer different questions. The Essential Eight answers: how hardened are these systems against the attacks that actually land. SMB1001 answers: can this business show a buyer, an insurer or a supply chain that its security fundamentals are certified and checkable.

The comparison below is plain: what each one is, who asks for it, how each is assessed, what the work involves, and the order that makes sense when the honest answer is both.

Our stake, declared up front: Black Shard holds SMB1001:2026 Gold, verifiable on the public CyberCert registry, and we assess and uplift clients against the Essential Eight. We prepare businesses for both; we certify neither.

Side by side.

Essential Eight compared with SMB1001
CriteriaEssential EightSMB1001
What it isEight mitigation strategies published by the Australian Signals Directorate: patching applications and operating systems, multi-factor authentication, restricting administrative privileges, application control, restricting Microsoft Office macros, user application hardening, and regular backups. Each is measured against maturity levels from zero to three.An Australian cybersecurity certification standard for small and medium businesses, tiered from Bronze upward so a business certifies at the level it can sustain. Revised annually, which is why a certificate carries its year.
Who asks for itAustralian government procurement, and the buyers and frameworks that follow its lead. When a tender asks about your Essential Eight maturity, it is asking for your self-assessed position, and it expects you to be able to defend the number.Australian buyers, insurers and supply chains that want an answer they can verify without auditing you themselves. The certificate sits on a public registry; due diligence can check it in a minute.
Assessment modelSelf-assessment against ASD's published maturity model. There is no certificate and no registry: nobody can be Essential Eight certified, and a vendor claiming to sell certification is telling you something about themselves.Certification through CyberCert. At Gold, the tier we hold, a company director formally attests to the standard's twenty-seven controls and the certificate is listed publicly.
ScopeTechnical controls on your systems: endpoints, servers, identities, backups. It says nothing about policies, training, insurance or governance. That narrowness is its strength; the maturity model is concrete enough to argue about.The business as a whole. Alongside technical fundamentals, the tiers bring in policy, training and process: the things a buyer means when they ask whether security is actually managed.
What the work looks likeHardening. Closing the gap between your current maturity and the target level: rolling out multi-factor authentication properly, getting patch cadences real, taking local admin away, making backups restorable. The evidence is technical state, not paperwork.Closing a fixed control set and evidencing it. Much of the technical work overlaps the Essential Eight directly, which is why the sensible sequence is rarely a choice between the two.
What you can show for itA defensible self-assessment: your maturity level per strategy and the evidence behind it. Strong inside a tender response; invisible outside one, because there is nothing a third party can look up.A registry listing anyone can check, and the evidence pack behind the attestation. It travels: insurers, supply-chain questionnaires and procurement teams can all verify it without your involvement.

When the Essential Eight is the right focus

  • A government tender or panel asks for your Essential Eight maturity. Answer the question asked.
  • You need to reduce actual breach likelihood before you need to prove anything to anyone.
  • Your systems are the gap: patching is ad hoc, admin rights are everywhere, MFA has holes. The maturity model is the sharpest available to-do list.
  • You already hold a certification and the next step is depth on the technical controls behind it.

When SMB1001 is the right focus

  • Buyers, insurers or supply chains keep asking what certification you hold, and you need an answer they can verify.
  • You want the policy, training and governance layer pulled up alongside the technical work, not left for later.
  • You need a credential on a realistic timeline: certify at a sustainable tier now, step up as the business matures.
  • The technical fundamentals are largely in place and unproven: the work is turning them into an attested, checkable position.

Why the two keep being confused

Both are Australian, both aim at the same class of real-world attacks, and both get named in the same due-diligence conversations, so they read as competitors. They are not. The Essential Eight is a measuring stick for technical hardening. SMB1001 is a certification that the fundamentals, technical and organisational, are in place and attested. One tells you how hardened you are; the other lets you prove to someone else that you are managed.

The overlap is real and useful. Multi-factor authentication, patching, backups and access control sit at the centre of both. Work done for one is not thrown away on the other, and a business that has genuinely closed its Essential Eight gaps walks into SMB1001 certification with most of the technical controls already evidenced.

The confusion only costs you when it becomes a substitution: treating a self-assessed maturity level as if it were a certificate, or treating a certificate as if it settled every question a government tender asks about maturity. Buyers notice both mistakes.

Essential Eight coverage by SMB1001 tier

The Essential Eight's eight strategies do not enter SMB1001 at the same point, and the gap between the two frameworks is not spread evenly across the tiers. Patching, multi-factor authentication, restricting administrative privileges and backups, the four controls that carry most of the real risk reduction in both instruments, are folded into SMB1001's earlier tiers. That is why Essential Eight uplift work keeps counting as a business climbs the SMB1001 tiers rather than being repeated.

Application control and Microsoft Office macro hardening are the exception. Neither is required at Bronze, Silver, Gold or Platinum; SMB1001 does not ask for them until Diamond, its top tier. Certification has already left director attestation behind by that point: the switch to external audit happens a tier earlier, at Platinum, and Diamond carries the same audit requirement plus these two controls. A business certified at Gold, the tier Black Shard holds, has been tested on the shared technical fundamentals and on the policy, training and governance layer SMB1001 adds beyond the Essential Eight. It has not been tested on the two Essential Eight strategies that demand the most fleet-management engineering, and a tender that names Essential Eight maturity will ask about both directly.

The order that usually makes sense

For most smaller Australian businesses the sequence is: use the Essential Eight to drive the hardening, then certify under SMB1001 to make the result visible. The Essential Eight tells you what to fix first because its maturity model is concrete about attacker tradecraft. SMB1001 then turns that work, plus the policy and training layer, into a credential a buyer can check.

If a government tender is in front of you naming Essential Eight maturity, that settles the priority the same way a contract clause naming ISO 27001 settles a different argument: answer what the buyer asked. If nothing names either, start with the hardening; it is the part that changes whether an attack lands.

The tier table above shows exactly where that overlap runs out. The SMB1001 explainer linked below covers the standard's full tier structure and governance layer, and our insights index carries a fuller sequencing note on running the two together.

Which one to start with

Three situations cover most businesses asking this question, and the tier table above decides two of them without much argument.

Questions, answered

Can you be certified against the Essential Eight?
No. The Essential Eight is a self-assessed maturity model published by the Australian Signals Directorate; there is no certificate and no public registry for it. Assessments of your maturity, including independent ones, are point-in-time opinions, not certifications. If a checkable credential is what you need, that is what SMB1001 is for.
Does SMB1001 cover the Essential Eight?
Not fully, and not until the top tier. Multi-factor authentication, patching, backups and restricting administrative privileges sit inside SMB1001 from Bronze and Silver, so most of the Essential Eight's early-maturity ground is covered well before Gold. Application control and Microsoft Office macro hardening are different: SMB1001 does not require either until Diamond, the top tier. Certification is already externally audited by then; the move away from director attestation happens a tier earlier, at Platinum. A business certified at Gold, our own tier, has not been tested against the two Essential Eight strategies that demand the most fleet-management engineering. User application hardening is not tested as a separate, named control at any SMB1001 tier.
Which one do insurers care about?
Insurers ask about controls, not standards: proposal forms want multi-factor authentication, backups, patching and administrative access answered specifically. A SMB1001 certificate is useful shorthand because it is verifiable; the Essential Eight work is what makes the answers on the form true. Our cyber insurance readiness tool walks the standard questions.
Which one does government actually require?
Follow the document in front of you rather than a general rule. The Commonwealth mandates the Essential Eight for its own non-corporate entities under the Protective Security Policy Framework, and a tender or panel that names an Essential Eight maturity level is asking for that self-assessed position specifically; no SMB1001 tier substitutes for it. Where a government-adjacent buyer or prime contractor asks for a certification instead, an SMB1001 tier is what they can verify without commissioning their own assessment. Read the actual clause before assuming which one is meant.
Can we do both, and does one save work on the other?
Yes, and doing one properly makes the other cheaper. Multi-factor authentication, patching, backups and restricting administrative privileges sit inside both instruments, so Essential Eight uplift work counts directly toward SMB1001's early tiers, and an SMB1001 gap review inherits evidence from Essential Eight work already done. What does not transfer is application control and macro hardening: genuine Essential Eight uplift that SMB1001 will not ask for below Diamond, and SMB1001's policy, training and governance layer, which the Essential Eight never asks for at all.

Tell us which buyer is asking. Get a straight answer.

Australia-wide, from our Brisbane head office. Someone will contact you as soon as possible.

Open a brief[email protected]