Cyber security framework comparison questions land on the desk of almost every NZ owner and GM eventually, usually triggered by an insurance renewal, a tender or a customer questionnaire. The three names that keep coming up are the Essential Eight, SMB1001 and ISO 27001. They solve different problems, cost wildly different amounts and are asked for by different people.
This guide compares all three for New Zealand businesses, then maps them to the Privacy Act 2020. OxygenIT holds ISO 27001 and ISO 42001 certification ourselves and takes clients through SMB1001, so the comparison below comes from running these frameworks, not just reading them.
Which cyber framework does a NZ small business need?
Most NZ small and medium businesses need SMB1001. Choose the Essential Eight where Australian government work or an Australian corporate supply chain requires it, and ISO 27001 where enterprise or regulated contracts demand independent audit. The right question is not which framework is best, it is which evidence your customers, insurer and board actually ask for.
As a quick decision guide:
- Under 200 staff and you want a certificate insurers and tenders accept: SMB1001, usually straight to Gold.
- Supplying Australian government or large Australian corporates with Essential Eight clauses in contracts: target an Essential Eight maturity level, often alongside SMB1001.
- Enterprise customers, regulated data or government contracts here in NZ: ISO 27001, typically from around 50 staff or when a contract makes it unavoidable.
- No budget yet: implement the Essential Eight basics first, then certify once the controls are real.
Whichever route you take, cyber compliance in NZ is converging on the same core controls: multi-factor authentication, endpoint detection and response, patching, tested backups and an incident response plan. The frameworks differ in how they package, verify and badge that work, which makes the decision commercial as much as technical. Starting with any of them beats waiting for the perfect choice.
What is the Essential Eight?
The Essential Eight is a set of eight technical mitigation strategies published by the Australian Cyber Security Centre (ACSC), part of the Australian Signals Directorate (ASD). It is not a certification. Businesses self assess against four maturity levels, from Maturity Level Zero to Maturity Level Three, and harden their systems accordingly.
The eight strategies are application control, patching applications, configuring Microsoft Office macro settings, user application hardening, restricting administrative privileges, patching operating systems, multi-factor authentication and regular backups. Each is assessed at a maturity level: ML1 counters commodity attacks, ML2 counters more capable adversaries and ML3 targets advanced tradecraft.
For a typical NZ SMB, Maturity Level One is the sensible first target and is achievable on a modern Microsoft 365 stack. In practice ML1 means patches applied within defined timeframes, Office macros from the internet blocked, admin accounts separated from daily accounts, MFA in place and backups that have been restored at least once, not just scheduled.
The honest news is that the bar is high even for well resourced organisations. ASD reported in its Commonwealth Cyber Security Posture in 2025 that 22 percent of Australian government entities reached Maturity Level Two once compensating controls were counted, up from 15 percent in 2024. If fewer than a quarter of Commonwealth entities clear ML2, a 30 person Kiwi firm should treat the Essential Eight as a technical roadmap, not a weekend project.
For NZ businesses the Essential Eight matters in two situations: an Australian customer or parent company writes it into contracts, or you simply want a proven hardening sequence. The full documentation is free on the ACSC website. What it will never give you is a certificate to show anyone, because no such thing exists.
What is SMB1001?
SMB1001 is a five tier cyber security certification standard developed by Dynamic Standards International (DSI) and certified through the CyberCert platform. The tiers are Bronze, Silver, Gold, Platinum and Diamond. Bronze, Silver and Gold are certified by director attestation, while Platinum and Diamond require an external audit, and certificates renew annually.
SMB1001 exists because frameworks like ISO 27001 assume resources most small businesses do not have. The standard is updated every year, the current edition is SMB1001:2026, and the tiers give a business a realistic ladder: start where you are, certify, climb. Gold is the tier that matters commercially, with 27 controls including endpoint detection and response, enforced SPF, DKIM and DMARC email authentication, multi-factor authentication, offline backups, mandatory cyber insurance, a responsible AI policy and an incident response plan.
Cost is the other differentiator. The CyberCert certificate fee runs from AUD $195 for Silver to AUD $395 for Gold and AUD $3,595 for Platinum, plus whatever remediation your environment needs. Most of our clients reach Gold in one to six months, and we run a structured 90 day programme. Our complete guide to SMB1001 Gold certification in NZ covers the controls, costs and process in detail.
What is ISO 27001?
ISO 27001 is the international standard for an information security management system (ISMS). Rather than prescribing specific technical controls, it requires a documented, risk driven management system covering people, processes and technology, verified by an accredited external auditor on a three year cycle with annual surveillance audits.
It is the most recognised security credential in the world and the most demanding of the three. A realistic NZ budget starts around NZD $20,000 in the first year across consulting, certification body fees and internal time, and the journey typically takes 6 to 18 months. The ongoing commitment is real too: internal audits, management reviews, risk registers and evidence maintenance every year.
That effort buys you access. Enterprise procurement, government work and regulated industries frequently make ISO 27001 a hard requirement, and it ends security questionnaires faster than anything else. We hold ISO 27001 alongside ISO 42001 for AI management at OxygenIT, and our view for clients is consistent: pursue it when a contract, regulator or growth plan demands it, not as a first step. For most SMBs, SMB1001 delivers the commercial value sooner, and we compare the two directly in our SMB1001 vs ISO 27001 guide.
Essential Eight vs SMB1001 vs ISO 27001: the full comparison
The table below compares the three frameworks on the factors NZ businesses actually decide on: cost, audit type, effort, best fit size and what insurers and tenders recognise. Use it to shortlist, then let your customer and insurer requirements make the final call.
| Factor | Essential Eight | SMB1001 | ISO 27001 |
|---|---|---|---|
| Published by | ACSC, part of the ASD | Dynamic Standards International, certified via CyberCert | ISO and IEC, audited by accredited certification bodies |
| Certificate issued | No, self assessed maturity levels only | Yes, renewed annually | Yes, three year cycle with surveillance audits |
| Audit type | Self assessment against ML0 to ML3 | Director attestation for Bronze, Silver and Gold; external audit for Platinum and Diamond | Independent external audit |
| Typical cost | Free framework, implementation only | AUD $195 to $3,595 per year plus implementation | NZD $20,000 plus in the first year |
| Effort | Ongoing technical programme | 1 to 6 months to certify | 6 to 18 months to certify |
| Best fit | Technical hardening, AU government supply chains | NZ businesses of 5 to 200 staff | Enterprise, regulated industries, government contracts |
| Insurer and tender recognition | Controls valued, but nothing to show | Growing quickly across ANZ insurers and tenders | Universally recognised |
Note the overlap: the Essential Eight strategies appear inside SMB1001 Gold as controls, and both sit comfortably inside an ISO 27001 ISMS. Work done on any of them carries forward rather than being thrown away.
How do the frameworks map to the NZ Privacy Act 2020?
None of the three frameworks is required by New Zealand law, but the Privacy Act 2020 requires reasonable security safeguards for personal information and notification of serious breaches to the Privacy Commissioner. Each framework is a way of evidencing that your safeguards were, in fact, reasonable when something goes wrong.
Information Privacy Principle 5 obliges every agency, which includes almost every business, to protect personal information against loss, misuse and unauthorised access. The Act does not define reasonable safeguards, which is exactly where frameworks earn their keep. If a breach lands in front of the Office of the Privacy Commissioner, a current SMB1001 certificate or ISO 27001 registration is strong evidence you took the obligation seriously; an empty folder is strong evidence you did not.
The mapping is practical. The Essential Eight delivers the technical safeguards: patching, MFA, backups and restricted privileges. SMB1001 Gold adds the response side the Act cares about, a tested incident response plan, staff training and cyber insurance, which together determine how fast you can identify, contain and notify a notifiable breach, and NZ law expects notification as soon as practicable. ISO 27001 wraps the whole obligation in a management system, with personal information handled as a formally assessed risk. Our IT compliance service runs this mapping for clients so privacy, security and certification stop being three separate projects.
Cyber security framework comparison NZ: frequently asked questions
Is the Essential Eight mandatory in New Zealand?
No. The Essential Eight is mandated for Australian non corporate Commonwealth entities, not NZ businesses. It becomes relevant here when an Australian government agency or corporate writes it into supplier contracts. NZ organisations otherwise follow guidance from the National Cyber Security Centre, which points in a very similar technical direction.
Can we do both SMB1001 and the Essential Eight?
Yes, and the combination works well. The overlap is large, since MFA, patching, backups and restricted admin privileges appear in both. Treat the Essential Eight as your technical depth target and SMB1001 as the certification layer that turns the work into something you can show customers and insurers.
Which framework do cyber insurers recognise?
Underwriters ask about controls rather than framework names: MFA, EDR, tested backups and an incident response plan. SMB1001 Gold packages exactly those controls into an annual certificate, which simplifies the proposal form. ISO 27001 is respected everywhere but is more than most insurers require from a firm under 200 staff.
How much does each framework cost?
The Essential Eight framework is free, so you pay only for implementation. SMB1001 certificates run from AUD $195 to AUD $3,595 per year depending on tier, with Gold at AUD $395, plus remediation. ISO 27001 typically starts around NZD $20,000 in the first year once consulting, audit fees and internal time are counted.
Does ISO 27001 cover the Essential Eight?
Not automatically. ISO 27001 lets each organisation choose controls through risk assessment, so a certified company can still miss specific Essential Eight mitigations like application control. If a contract names both, map the Essential Eight strategies into your ISMS deliberately rather than assuming the certificate covers them.
Where should a 20 person NZ firm start?
Start with SMB1001, at Gold if insurers or customers are already asking questions, and use the Essential Eight strategies as the technical hardening sequence underneath it. Escalate to ISO 27001 only when a contract demands it. Our virtual chief security office service runs this as a managed programme with a fixed monthly cost.
Not sure which framework fits? Talk to OxygenIT
OxygenIT has secured New Zealand businesses since 2005. We hold ISO 27001 and ISO 42001 certification ourselves, run SMB1001 Gold programmes that finish in 90 days, and build Essential Eight aligned hardening into our managed services. Based in Christchurch with coverage in Wellington, we will tell you plainly which framework your customers, insurer and growth plans actually justify, including when the answer is the cheaper one.
Book a discovery call and bring your last insurance proposal or tender questionnaire. Or call us on 0800 101 095.