Two baselines with different jobs
The Essential Eight and SMB1001 are routinely presented as competing answers to the same question. They are not. The Essential Eight is a technical hardening yardstick: eight mitigation strategies published by the Australian Cyber Security Centre, measured against maturity levels, with no certificate at the end. SMB1001 is a certifiable standard: a tiered, whole-of-business scheme that produces a dated certificate a buyer, insurer or head contractor can actually verify. One measures how hard your systems are to compromise. The other proves, in a form other parties will accept, that your business runs a credible security practice.
That distinction settles the ordering question for most smaller Australian businesses. Start with the four technical controls the two frameworks share, because they cut real risk from day one. Certify SMB1001 at a tier you can honestly meet, because certification converts that work into a claim the market can check. Treat Essential Eight Maturity Level One as the technical target you grow into, and commission a formal Essential Eight assessment when a contract or agency actually asks for one. Nothing in that sequence is wasted, because the overlap between the two frameworks does most of the compounding for you.
What the Essential Eight is, and what it is not
The Essential Eight is the ACSC's shortlist of the mitigation strategies that block the intrusion techniques it actually sees: application control, patching applications, configuring Microsoft Office macro settings, user application hardening, restricting administrative privileges, patching operating systems, multi-factor authentication, and regular backups. Progress is measured against maturity levels from zero to three, and the model is deliberately unforgiving: your maturity level is set by your weakest strategy, not your average. Seven strategies at Maturity Level Two and one at Level Zero means you are at Level Zero.
What the Essential Eight is not is a certification. There is no such thing as an Essential Eight certificate. The ACSC publishes an assessment process and an assessor can measure you against it, but the output is a maturity report, not a badge with an expiry date. A supplier who claims to be 'Essential Eight certified' is making a claim the scheme itself cannot support, which tells you something about the supplier. It is also worth remembering where the framework comes from: it was built for government, the Commonwealth mandates it for its own non-corporate entities under the Protective Security Policy Framework, and it quietly assumes a managed, largely Windows fleet. Application control and user application hardening are genuinely demanding engineering work for a fifteen-person business with no internal IT function, and pretending otherwise is how baseline projects stall.
What SMB1001 does that the Essential Eight cannot
SMB1001 is a multi-tier cyber security certification standard built for small and medium businesses, delivered through CyberCert, with five tiers running Bronze, Silver, Gold, Platinum and Diamond. Each tier is a defined set of requirements, certification is renewed annually, and the result is an artefact that exists in the world: a current, dated, tier-labelled certificate that a procurement officer or an insurer can verify without reading a technical report.
The scope is the other difference. SMB1001 reaches past the server room into the management layer: documented policies, staff training, incident response planning, and the governance conversations about insurance and supplier obligations that a purely technical framework never touches. Certification carries a sign-off from the business itself, which does something subtle and useful: it moves cyber security from an IT line item to a management attestation, with a renewal date that forces the business to re-earn the claim every year. Black Shard holds SMB1001 Gold, and that renewal discipline is a real part of the value rather than an administrative tax.
For the reader deciding what to show a buyer, this is the practical point. Supply-chain questionnaires and insurance proposals want something legible to a non-technical evaluator. A maturity report needs interpretation. A tiered certificate does not.
Where they overlap, and where each goes alone
The overlap between the two frameworks is the part that makes sequencing cheap. Half of the Essential Eight is, in substance, also SMB1001 territory, so hours spent there count twice. The rest splits cleanly by the job each framework is built for.
- Shared ground: multi-factor authentication, patching applications and operating systems, regular backups, and restricting administrative privileges appear in both frameworks. This is where the real risk reduction lives.
- Essential Eight only: application control, Microsoft Office macro settings, and user application hardening. These are deep fleet-engineering controls, and SMB1001 does not demand them at the tiers most smaller businesses target first.
- SMB1001 only: written policies, staff training, incident response planning, and the governance, insurance and supplier layer. The Essential Eight is silent on all of it.
The order that actually works
First, do the shared four properly: multi-factor authentication on everything that faces the internet, a patch cadence you actually keep, backups you have restored at least once, and local admin stripped from daily-driver accounts. These deliver the largest reduction in real-world compromise likelihood per hour spent, and every one of those hours counts toward both frameworks at once.
Second, certify SMB1001 at the tier you can honestly meet today, then step up a tier at renewal. The certificate has commercial value immediately, in tenders, supply-chain questionnaires and insurance conversations, and the tier structure hands you a sequenced work plan instead of a wall of controls. Starting at a modest tier and climbing is not a compromise; it is how the scheme is designed to be used, and it is far more credible than an ambitious tier you scraped past.
Third, treat Essential Eight Maturity Level One as the technical destination, and commission a formal assessment when something concrete demands it: a government-adjacent contract, a prime contractor flowing requirements down the chain, or a board that wants an independent measure. Sequenced this way, the assessment lands on hardened ground and produces a useful gap list, rather than a demoralising report that scores zero across the board because application control was never going to exist yet.
The framing to hold onto: SMB1001 is how a smaller business proves its practice, the Essential Eight is how it hardens its systems, and the overlap means the work compounds instead of forking. Run the sequence above and you never have to choose between looking secure and being secure. You get both, in the order a buyer and an attacker would each respect.
