Compliance
Compliance

Security compliance in Australia: ISO 27001, Essential Eight and PCI DSS

The short answer

Three frameworks cover most Australian security compliance asks. ISO 27001 is the international, certifiable standard for your whole security management system. The Essential Eight is the ASD’s technical baseline, mandated in federal government and pulled into tenders. PCI DSS is contractual — it applies the moment you touch cardholder data. Start with the one your buyer named.

ISO 27001, Essential Eight or PCI DSS: which one is being asked of you

Security compliance in Australia is really three different questions wearing one name. Which framework you need depends on who’s asking — not on which one looks cheapest or most familiar.

Framework What it is Who asks for it What you end up with
ISO 27001 The international, certifiable standard for an information security management system Enterprise customers, overseas buyers, boards, investors A certificate from an accredited certification body, on a three-year cycle
Essential Eight Eight technical mitigation strategies from the ASD, measured at Maturity Levels 0–3 Australian government — directly for federal entities, contractually for suppliers A maturity level, self-assessed or independently assessed
PCI DSS The card industry’s contractual security standard — 12 requirements Your acquiring bank and payment partners Validated compliance, reported annually

ISO 27001 is the one procurement teams recognise. It certifies the system that runs your security: 93 Annex A controls assessed against your risks, a Statement of Applicability, then a Stage 1 and Stage 2 audit by an accredited certification body. When a customer questionnaire asks “are you certified?”, this is the certificate it means. The ISO 27001 guide covers what it is, what it costs and how long it takes.

The Essential Eight is narrower and more technical: application control, patch applications, Microsoft Office macro settings, user application hardening, restricted administrative privileges, patched operating systems, multi-factor authentication and regular backups. Non-corporate Commonwealth entities must reach Maturity Level 2 under the PSPF. Everyone else meets it through tenders and supplier clauses — the Essential Eight guide covers who’s mandated and who’s dragged in.

PCI DSS is neither a market signal nor a government baseline. It’s a contract term. Store, process or transmit cardholder data and it applies, with the scope set by how payments actually flow through your systems.

Where the three frameworks overlap

Underneath the acronyms, the same operational work keeps reappearing. ISO 27001’s A.8.15 (logging) and A.8.16 (monitoring) ask for the same running capability as PCI DSS Requirement 10. Vulnerability and patch management sits in ISO’s A.8.8, in PCI’s Requirement 11.3, and in two of the Essential Eight strategies. Multi-factor authentication and access control appear in all three.

That overlap is the practical point of this whole section: build the security operations once, then evidence them per framework. The control library lays out ISO 27001 and PCI DSS side by side, control by control, so you can see exactly where one piece of work satisfies two auditors.

Every guide in this section

Essential Eight

ISO 27001

Log retention and regulatory obligations

Controls

AI governance

What most people get wrong

Choosing a framework by familiarity instead of by asker. Teams pick ISO 27001 because a competitor has it, or the Essential Eight because it’s Australian, then discover the clause in front of them names the other one.

The asker decides. A federal tender that names Essential Eight Maturity Level 2 won’t accept an ISO certificate in its place, and an enterprise security review that asks for ISO 27001 won’t be satisfied by an Essential Eight self-assessment. Read the clause or the questionnaire before you commit budget to either. If nobody has asked yet, start from the market you want next — that’s the decision ISO 27001 or Essential Eight works through.

How Secure60 handles this

Tools hand you a to-do list. We do the list — and run the security behind it. Every framework on this page quietly assumes someone is operating security day to day: collecting logs, watching for anomalies, patching what’s exposed. That operating layer is what we bring, alongside the certification work itself — governance, controls and evidence kept current on one platform. We hold ISO 27001:2022 certification ourselves, so the system we build for you is the one we run. Pick your framework from the guides above, or book a readiness call and we’ll pick it with you.

Frequently asked questions

Which security compliance framework do Australian companies actually need?

Whichever one the person blocking your deal has named. Enterprise and overseas customers ask for ISO 27001, Australian government work names the Essential Eight, and your acquiring bank enforces PCI DSS if you handle card data. If nobody has asked yet and you sell B2B, ISO 27001 is usually the one to build toward.

Is the Essential Eight mandatory for private companies?

No. The mandate applies to non-corporate Commonwealth entities, which must reach Maturity Level 2 under the PSPF. Private companies meet it contractually — through tenders and supplier clauses that pass the obligation down.

Do we need both ISO 27001 and the Essential Eight?

Sometimes — they answer different questions. ISO 27001 certifies your management system for commercial buyers; the Essential Eight is a technical baseline for the government market. The good news is the underlying work overlaps heavily. ISO 27001 or Essential Eight: which do we need? walks the decision.

Where does SOC 2 fit?

SOC 2 is an AICPA attestation, dominant in the US market — a report, not a certificate. Australian companies selling to US enterprises sometimes get asked for it. We focus on ISO 27001, the international certification; the comparison page explains when each applies.

Does PCI DSS apply if a payment provider handles our transactions?

Usually yes, with a smaller scope. PCI DSS applies to any organisation that stores, processes or transmits cardholder data; outsourcing payments reduces what’s in scope but rarely removes the obligation entirely. Your acquiring bank sets the validation level.

Does Secure60 certify us?

No — and be wary of anyone who says they can. ISO 27001 certification audits are performed by an accredited certification body, independent of whoever prepared you. We do the preparation, the controls, and the security operations behind them, then get you through that audit.

Start with the framework your deal needs.

Book a readiness call — we'll tell you which framework fits, what it takes, and what we'd run behind it.

Book a readiness call Run a pilot