Often both, because they answer different questions. ISO 27001 is the international, certifiable standard for a security management system — it wins enterprise and international deals. The Essential Eight is the Australian Signals Directorate’s baseline of eight technical mitigations — it wins Australian government work. The eight mitigations slot into an ISO 27001 ISMS as technical controls.
The reason this comparison confuses people is that it isn’t really a comparison. ISO 27001 answers “do you run a management system for security — risk assessment, controls, audits, improvement?” The Essential Eight answers “have you implemented these eight specific technical mitigations, and how deeply?” A buyer can reasonably ask you either question, or both.
| ISO 27001 | Essential Eight | |
|---|---|---|
| Published by | ISO/IEC — an international standard | The Australian Cyber Security Centre / Australian Signals Directorate (cyber.gov.au) |
| What it is | A certifiable standard for an information security management system (ISMS) | Eight prioritised mitigation strategies: application control, patch applications, configure Microsoft Office macro settings, user application hardening, restrict administrative privileges, patch operating systems, multi-factor authentication, regular backups |
| Breadth | The whole system: risk assessment, 93 Annex A controls across organisational, people, physical and technological themes, internal audit, management review | Deliberately narrow: technical mitigations, assessed in depth against maturity levels 0–3 |
| What you can claim | Certification — Stage 1 (documentation review) and Stage 2 (interviews and evidence) by an accredited certification body, with annual surveillance and recertification every three years | A maturity level — self-assessed, assessed by a consultancy, or by an ASD-endorsed IRAP assessor where formal independent assurance is required |
| Who asks for it | Enterprise customers, international buyers, security questionnaires | Australian government buyers and tenders; non-corporate Commonwealth entities are themselves mandated to Maturity Level 2 under the PSPF |
| Recognition | International | Australian |
The shapes are different, too. ISO 27001 is broad and risk-based: you assess all 93 controls, document which apply in your Statement of Applicability, and can justify exclusions. The Essential Eight is narrow and prescriptive: eight mitigations, defined maturity levels, mirror the ASD wording or you’re not doing it. One certifies how you manage security; the other measures whether specific defences are in place.
Work backwards from who’s asking, because each framework is the answer to a specific buyer.
A government tender names the Essential Eight. Then the Essential Eight is your requirement, at the maturity level the tender specifies, and an ISO certificate won’t substitute — the assessor questions are about application control and patching cadence, not your ISMS. Start with what to do when a tender requires Essential Eight compliance.
An enterprise or international customer sends a security questionnaire. Then ISO 27001 is the credential they recognise. It’s the international standard, it comes with a certificate from an accredited body, and it answers the questionnaire’s management questions — risk, policy, incident response, supplier security — that the Essential Eight never touches.
You sell to both. Common for Australian companies, and the reason “which one” is usually the wrong question. The good news is the two compose cleanly rather than doubling your work. The Essential Eight’s mitigations — patching applications and operating systems, MFA, restricting administrative privileges, backups — sit squarely inside Annex A’s technological controls. Implement them once, inside the ISMS, and the same operating evidence serves the IRAP assessor and the certification auditor. The ISMS also gives the eight mitigations what the maturity model alone doesn’t: an owner, a review cycle, and a record that they kept running after the assessment.
Sequence by revenue, not by preference. If the government deal closes this quarter and the enterprise deal next year, do the Essential Eight now and build the ISMS around it after. If it’s the reverse, build the ISMS and slot the eight in as your technological control set from day one.
Treating them as competing certifications. There is no Essential Eight certificate — it’s a maturity model, and assurance comes from self-assessment, consultancies, or IRAP assessors where formal assurance is required. So “we’ll get Essential Eight certified instead of ISO” isn’t a decision anyone can actually execute.
The reverse error is just as common: assuming an ISO 27001 certificate proves the eight mitigations are in place. It doesn’t. ISO 27001 is risk-based — the Statement of Applicability records which controls apply and how, and certification doesn’t pin you to any Essential Eight maturity level. When a buyer asks for both, they’re not being bureaucratic. They’re asking one question about management and one about defences, and each framework only answers its own.
We build one system that carries both. The governance capability runs your ISMS — risk assessment, Statement of Applicability, policies, evidence — and the security operations underneath it are the same controls the Essential Eight measures: patching visibility, privileged-access monitoring, MFA coverage, backup verification. One set of operating evidence, presentable to a certification auditor or an Essential Eight assessor, depending on who’s across the table. Certification audits stay with an accredited certification body; Essential Eight assurance stays with the assessor your contract requires. We get you ready for either, without doing the work twice.
Is there an Essential Eight certificate?
No. The Essential Eight is a maturity model (levels 0–3), not a certification scheme. Assurance is a mix of self-assessment, private consultancies, and ASD-endorsed IRAP assessors where formal independent assurance is required. Anyone selling you an ‘Essential Eight certificate’ is selling their own letterhead.
Is the Essential Eight mandatory for private companies?
Not directly. The mandate applies to non-corporate Commonwealth entities, which must reach Maturity Level 2 under the PSPF. Private companies inherit it contractually — government tenders and supplier requirements name it, and then it’s mandatory for that deal.
Does ISO 27001 certification cover the Essential Eight automatically?
No. ISO 27001 is risk-based — you assess all 93 Annex A controls and document applicability, but the standard doesn’t prescribe the eight mitigations at any maturity level. A buyer asking for both isn’t double-asking; they’re asking two different questions.
Can Essential Eight work count toward ISO 27001?
Yes, directly. The eight mitigations — patching, MFA, restricting admin privileges, backups and the rest — land squarely in Annex A’s technological controls. Implement them inside an ISMS and the same operating evidence serves both.
Which should we do first?
The one your nearest revenue asks for. A tender naming Essential Eight maturity means Essential Eight first; an enterprise security questionnaire means ISO 27001 first. If both are live, build the ISMS and put the eight mitigations inside it, so neither effort is wasted.