Compliance
Compliance

Security compliance in Australia: ISO 27001, Essential Eight and PCI DSS

The Short Answer

Three frameworks cover most Australian security compliance requirements. ISO 27001 is the international, certifiable standard for a whole security management system. The Essential Eight is the ASD’s technical baseline, mandated in federal government and passed into tenders. PCI DSS is contractual, and applies from the moment you touch cardholder data. The framework your buyer named is the one to start with.

ISO 27001, Essential Eight or PCI DSS: which one is being asked of you

Security compliance in Australia covers three separate questions. Which framework applies depends on which party is asking.

Framework What it is Who asks for it What you end up with
ISO 27001 The international, certifiable standard for an information security management system Enterprise customers, overseas buyers, boards, investors A certificate from an accredited certification body, on a three-year cycle
Essential Eight Eight technical mitigation strategies from the ASD, measured at Maturity Levels 0–3 Australian government — directly for federal entities, contractually for suppliers A maturity level, self-assessed or independently assessed
PCI DSS The card industry’s contractual security standard — 12 requirements Your acquiring bank and payment partners Validated compliance, reported annually

ISO 27001 is the framework procurement teams recognise. It certifies the system that runs your security: 93 Annex A controls assessed against your risks, a Statement of Applicability, then a Stage 1 and Stage 2 audit by an accredited certification body. A customer questionnaire asking whether you are certified is asking for this certificate. The ISO 27001 guide covers what it is, what it costs and how long it takes.

The Essential Eight is narrower and more technical: application control, patch applications, Microsoft Office macro settings, user application hardening, restricted administrative privileges, patched operating systems, multi-factor authentication and regular backups. Non-corporate Commonwealth entities must reach Maturity Level 2 under the PSPF. Every other organisation meets it through tenders and supplier clauses — the Essential Eight guide covers who is mandated and who inherits it contractually.

PCI DSS is a contract term rather than a market signal or a government baseline. It applies to any organisation that stores, processes or transmits cardholder data, with the scope set by how payments flow through your systems.

Where the three frameworks overlap

The same operational work appears under all three. ISO 27001’s A.8.15 (logging) and A.8.16 (monitoring) require the same running capability as PCI DSS Requirement 10. Vulnerability and patch management sits in ISO’s A.8.8, in PCI’s Requirement 11.3, and in two of the Essential Eight strategies. Multi-factor authentication and access control appear in all three.

That overlap is what makes a single build viable: run the security operations once, then evidence them per framework. The control library sets out ISO 27001 and PCI DSS side by side, control by control, showing where one piece of work satisfies two auditors.

Every guide in this section

Essential Eight

ISO 27001

ISO 27001 by jurisdiction

Log retention, residency and regulatory obligations

Controls

AI governance

The framework is chosen by the party asking for it

Teams select ISO 27001 because a competitor holds it, or the Essential Eight because it is Australian, and then find that the clause in front of them names the other one.

A federal tender naming Essential Eight Maturity Level 2 will not accept an ISO certificate in its place, and an enterprise security review asking for ISO 27001 will not be satisfied by an Essential Eight self-assessment. The clause or questionnaire determines the framework, which makes it the input to the budget decision rather than an output of it. Where nobody has asked yet, the market you intend to sell into next is the deciding factor — the decision ISO 27001 or Essential Eight works through.

How Secure60 handles this

Secure60 delivers the certification and operates the security behind it. Every framework on this page assumes someone is operating security day to day: collecting logs, watching for anomalies, patching what is exposed. That operating layer is what we bring, alongside the certification work itself — governance, controls and evidence kept current on one platform. Secure60 holds ISO 27001:2022 certification, so the system we build for you is the system we run. Choose your framework from the guides above, or book a readiness call and we will scope it with you.

Frequently Asked Questions

Which security compliance framework do Australian companies need?

The one named by the party blocking the deal. Enterprise and overseas customers ask for ISO 27001, Australian government work names the Essential Eight, and your acquiring bank enforces PCI DSS where you handle card data. Where nobody has asked yet and you sell B2B, ISO 27001 is usually the one to build toward.

Is the Essential Eight mandatory for private companies?

No. The mandate applies to non-corporate Commonwealth entities, which must reach Maturity Level 2 under the PSPF. Private companies meet it contractually, through tenders and supplier clauses that pass the obligation down.

Do we need both ISO 27001 and the Essential Eight?

Sometimes. They answer different questions: ISO 27001 certifies your management system for commercial buyers, and the Essential Eight is a technical baseline for the government market. The underlying work overlaps heavily. ISO 27001 or Essential Eight: which do we need? sets out the decision.

Where does SOC 2 fit?

SOC 2 is an AICPA attestation, dominant in the US market — a report rather than a certificate. Australian companies selling to US enterprises are sometimes asked for it. We focus on ISO 27001, the international certification; the comparison page explains when each applies.

Does PCI DSS apply if a payment provider handles our transactions?

Usually yes, with a smaller scope. PCI DSS applies to any organisation that stores, processes or transmits cardholder data. Outsourcing payments reduces what is in scope but rarely removes the obligation entirely. Your acquiring bank sets the validation level.

Does Secure60 certify us?

No. ISO 27001 certification audits are performed by an accredited certification body, independent of whoever prepared you — a provider claiming to both prepare and certify is describing something the accreditation rules do not permit. We do the preparation, the controls, and the security operations behind them, then get you through that audit.

Assess Current Compliance Position

A readiness call identifies which framework applies, what certification requires, and which controls Secure60 operates behind it.

30 days, every feature switched on. No credit card.