Often both, because they answer different questions. ISO 27001 is the international, certifiable standard for a security management system, and it wins enterprise and international deals. The Essential Eight is the Australian Signals Directorate’s baseline of eight technical mitigations, and it wins Australian government work. The eight mitigations sit inside an ISO 27001 ISMS as technical controls.
ISO 27001 answers whether you run a management system for security: risk assessment, controls, audits, improvement. The Essential Eight answers whether you have implemented eight specific technical mitigations, and to what depth. A buyer can ask either question, or both.
| ISO 27001 | Essential Eight | |
|---|---|---|
| Published by | ISO/IEC — an international standard | The Australian Cyber Security Centre / Australian Signals Directorate (cyber.gov.au) |
| What it is | A certifiable standard for an information security management system (ISMS) | Eight prioritised mitigation strategies: application control, patch applications, configure Microsoft Office macro settings, user application hardening, restrict administrative privileges, patch operating systems, multi-factor authentication, regular backups |
| Breadth | The whole system: risk assessment, 93 Annex A controls across organisational, people, physical and technological themes, internal audit, management review | Deliberately narrow: technical mitigations, assessed in depth against maturity levels 0–3 |
| What you can claim | Certification — Stage 1 (documentation review) and Stage 2 (interviews and evidence) by an accredited certification body, with annual surveillance and recertification every three years | A maturity level — self-assessed, assessed by a consultancy, or by an ASD-endorsed IRAP assessor where formal independent assurance is required |
| Who asks for it | Enterprise customers, international buyers, security questionnaires | Australian government buyers and tenders; non-corporate Commonwealth entities are themselves mandated to Maturity Level 2 under the PSPF |
| Recognition | International | Australian |
The two are also structured differently. ISO 27001 is broad and risk-based: you assess all 93 controls, document which apply in your Statement of Applicability, and justify exclusions. The Essential Eight is narrow and prescriptive: eight mitigations, defined maturity levels, assessed against the ASD’s published wording. ISO 27001 certifies how security is managed; the Essential Eight measures whether specific defences are in place.
Each framework answers a specific buyer, so the party asking determines the requirement.
A government tender names the Essential Eight. The Essential Eight is the requirement, at the maturity level the tender specifies, and an ISO certificate does not substitute — the assessor’s questions cover application control and patching cadence rather than the ISMS. What to do when a tender requires Essential Eight compliance covers the response.
An enterprise or international customer sends a security questionnaire. ISO 27001 is the credential they recognise. It is the international standard, it produces a certificate from an accredited body, and it answers the questionnaire’s management questions — risk, policy, incident response, supplier security — that the Essential Eight does not address.
You sell to both. This is common for Australian companies, and the two compose rather than duplicating each other. The Essential Eight’s mitigations — patching applications and operating systems, MFA, restricting administrative privileges, backups — sit within Annex A’s technological controls. Implemented once inside the ISMS, the same operating evidence serves the IRAP assessor and the certification auditor. The ISMS adds what the maturity model alone does not carry: an owner, a review cycle, and a record that the mitigations kept running after the assessment.
Sequence by revenue. Where the government deal closes this quarter and the enterprise deal next year, run the Essential Eight now and build the ISMS around it afterwards. Where the order is reversed, build the ISMS and use the eight mitigations as your technological control set from the start.
There is no Essential Eight certificate. It is a maturity model, and assurance comes from self-assessment, consultancies, or IRAP assessors where formal assurance is required, so certifying to the Essential Eight in place of ISO 27001 is not an available option.
The reverse assumption fails too: an ISO 27001 certificate does not establish that the eight mitigations are in place. ISO 27001 is risk-based, the Statement of Applicability records which controls apply and how, and certification does not fix you at any Essential Eight maturity level. A buyer asking for both is asking one question about management and one about defences, and each framework answers only its own.
We build one system that carries both. The governance capability runs your ISMS — risk assessment, Statement of Applicability, policies, evidence — and the security operations underneath it are the same controls the Essential Eight measures: patching visibility, privileged-access monitoring, MFA coverage, backup verification. One set of operating evidence serves a certification auditor or an Essential Eight assessor. Certification audits stay with an accredited certification body, and Essential Eight assurance stays with the assessor your contract requires. We get you ready for either without doing the work twice.
Is there an Essential Eight certificate?
No. The Essential Eight is a maturity model with levels 0–3 and no certification scheme. Assurance is a mix of self-assessment, private consultancies, and ASD-endorsed IRAP assessors where formal independent assurance is required. A certificate offered for the Essential Eight carries no accreditation behind it.
Is the Essential Eight mandatory for private companies?
Not directly. The mandate applies to non-corporate Commonwealth entities, which must reach Maturity Level 2 under the PSPF. Private companies inherit it contractually — government tenders and supplier requirements name it, and it becomes mandatory for that deal.
Does ISO 27001 certification cover the Essential Eight automatically?
No. ISO 27001 is risk-based: you assess all 93 Annex A controls and document applicability, and the standard does not prescribe the eight mitigations at any maturity level. A buyer asking for both is asking two different questions.
Can Essential Eight work count toward ISO 27001?
Yes, directly. The eight mitigations — patching, MFA, restricting admin privileges, backups and the rest — sit within Annex A’s technological controls. Implemented inside an ISMS, the same operating evidence serves both.
Which should we do first?
The one your nearest revenue requires. A tender naming Essential Eight maturity puts the Essential Eight first; an enterprise security questionnaire puts ISO 27001 first. Where both are live, build the ISMS and put the eight mitigations inside it, so neither effort is wasted.