Framework comparison
ISO 27001 vs Essential Eight: which do you need?
They get compared constantly, usually by someone who has been asked for one and has the other. They are not competing options. They cover different ground, and the overlap is smaller than most people expect.
One is international
ISO 27001 is recognised worldwide
One is Australian
Essential Eight comes from the ASD
Different scopes
Management system vs technical controls
Only one certifies
The Essential Eight has no certificate
ASD / ACSC
What is the Essential Eight?
Eight technical controls published by the Australian Signals Directorate, aimed at the attacks that actually happen: patching, application control, multi-factor authentication, restricting administrative privileges, backups, and hardening. You rate yourself against three maturity levels, ML1 to ML3, with ML2 the general expectation across most Australian industries.
It is free to self-assess and there is no certificate at the end, only a maturity level you work toward and hold. It is also on its way out. The ASD is replacing it with the Essentials series, though the Essential Eight stays current until at least 2028.
ISO / IEC
What is ISO 27001?
An international standard for running an information security management system. The current version is ISO/IEC 27001:2022. Rather than naming controls you must have, it requires you to define a scope, assess your risks, then select and justify controls against those risks. The technical controls are only one part of it. Governance, people, suppliers and physical security are all in there too.
It is certifiable by an accredited certification body, which is what makes it valuable commercially. A certificate is something you can hand to a client who asks how you manage security. IronSights holds ISO 27001 certification, so the process is one we have been through rather than one we have only read about.
How they compare
| Essential Eight | ISO 27001 | |
|---|---|---|
| Publisher | Australian Signals Directorate | ISO and IEC |
| Scope | Eight technical mitigation strategies | A full information security management system |
| Covers governance | No | Yes, it is the core of the standard |
| Covers people and HR | No | Yes |
| Covers physical security | No | Yes |
| Certification | No, a maturity level only | Yes, by an accredited certification body |
| Self-assessment | Yes, free | Possible internally, but not certification |
| Measured as | Maturity ML0 to ML3 | Conformance, pass or fail at audit |
| Risk-based | No, a fixed control set | Yes, controls follow your risk assessment |
| Ongoing obligation | Maintain the maturity level | Surveillance audits, then recertification |
| Recognised by | Australian government supply chains | International and enterprise clients |
| Future | Being replaced by the Essentials series | Current, revised as 27001:2022 |
Choosing
Which one your business needs
Start with the Essential Eight if
You sell to Australian government or sit in a regulated Australian sector. You are early in your security programme and want the controls that stop the most common attacks. You need something you can start on this month without a budget approval. An Essential Eight assessment gives you a maturity rating and an ordered list of gaps.
Go for ISO 27001 if
Enterprise or international clients are asking for evidence in their security questionnaires, and a self-assessed maturity level is not satisfying them. You need a certificate rather than a position. Your security problem is as much about process and accountability as it is about technology.
Run both if
Your client base is mixed, which is common for Australian businesses that sell across government and private sector. Sequencing helps here. Do the Essential Eight first, then build the management system around it, because the technical controls count toward both.
Comparing against SMB1001 instead? Read our SMB1001 vs Essential Eight framework selector.
Common questions
Asked by businesses like yours.
Not answered here? Get in touch and we will point you in the right direction.
Is ISO 27001 better than the Essential Eight?
Neither is better, because they answer different questions. The Essential Eight asks whether eight specific technical controls are in place and how well. ISO 27001 asks whether your organisation has a working system for managing security risk, of which technical controls are one part. A business can hit Essential Eight maturity level two and still fail an ISO 27001 audit, because the standard also wants governance, documented risk assessment, internal audit and management review.
Do we need both?
Plenty of Australian businesses end up with both, and they overlap more than they look like they do. If you sell to government or sit in a regulated Australian sector, the Essential Eight is what gets asked about. If you sell to enterprise or international clients, their security questionnaires will ask for ISO 27001. Running them together is practical: the Essential Eight controls map into the ISO 27001 Annex A control set, so the technical work counts twice.
Which one should we start with?
Start with the Essential Eight if you are early in your security programme. It is free to self-assess, it is prescriptive enough to act on immediately, and it fixes the controls that stop the most common attacks. ISO 27001 is a larger commitment involving scope definition, a risk assessment, a statement of applicability, internal audit and an external certification audit. Doing the Essential Eight first means you arrive at ISO 27001 with the technical groundwork already done.
Does the Essential Eight retirement change this?
It changes the Australian half of the picture, not the ISO half. The ASD is replacing the Essential Eight with the Essentials series, and the Essential Eight remains current until at least 2028. ISO 27001 is unaffected. If anything the replacement moves the Australian framework closer to ISO 27001 in style, because the Essentials series is outcomes-based rather than a prescriptive checklist.
How long does ISO 27001 certification take?
For a small or medium business starting from a reasonable technical baseline, plan on several months to build and run the management system before an audit is worth booking. The certification body needs evidence that the system has been operating, not just documented, so there is a minimum period where you run internal audits and management reviews before the external audit. We scope this properly rather than quote a number that suits nobody.
Can our Essential Eight work count toward ISO 27001?
Yes, and that is the practical argument for sequencing them. Patching, application control, multi-factor authentication, backups and administrative privilege restriction all appear in the ISO 27001 Annex A control set. What the Essential Eight does not give you is the management system around them: the scope, the risk assessment, the statement of applicability, the internal audit programme. That part is new work.
Work out where you stand
Not sure which one
you are being asked for?
Send us the questionnaire or tender clause and we will tell you what it actually requires. Our audit and assurance work covers both frameworks, and we will say plainly if you do not need the bigger one yet.