Lesson 7 of 10 · Track B · · Updated
Running ISO 27001 and the Essential Eight together
Run one ISMS and put the Essential Eight inside it. ISO 27001 gives you the management loop (scope, risk, review, improvement) and a certificate. The Essential Eight gives you eight technical strategies and a maturity level to report. Much of the evidence overlaps, but the outcomes differ: a certificate for one, an assessed maturity level for the other.
Why do Australian customers ask for both?
ISO 27001 is the internationally recognised certificate for information security management, and many Australian organisations expect it from suppliers. The Essential Eight is the Australian Signals Directorate's baseline, so security teams in Australia often ask how a supplier measures up against it as well. A certificate answers the first question. It does not answer the second, because ISO 27001 does not require the Essential Eight.
Where does the evidence overlap?
Patching, multi-factor authentication, administrative privileges and backups all appear as controls most companies select in an ISO 27001 Statement of Applicability. The same reports can serve both. The difference is depth: the Essential Eight asks for a specific maturity level, so the evidence has to show coverage and settings, not just that a policy exists.
How should you structure the program?
Put the Essential Eight target in the ISMS as a security goal. Add its gaps to the risk treatment plan. Map each strategy to the ISO 27001 controls that carry its evidence, and note where the Essential Eight needs more. Review both in the same management review. One owner, one evidence store, two reports.
What should you ask a platform?
Ask whether the Essential Eight is a maintained framework or a custom one you build. Of the six vendors on this site, Vanta publishes an Essential Eight product page with templates pre-mapped across all eight strategies and also lists CPS 234; we did not find an Essential Eight page for Scytale, Drata, Sprinto, Scrut or Secureframe on the pages reviewed. Ask which maturity model version the mapping follows, how shared controls appear in both frameworks, and whether their auditors or partners also do Essential Eight assessments.
Which ranking should you use?
Our site has one ranking, on the ISO 27001 weights; the Essential Eight is not scored. If Australian customers ask about the Essential Eight, note that only Vanta publishes an Essential Eight product page among the six vendors, and ask each vendor directly how it maps the eight strategies.
What does a sensible first year look like?
Certify ISO 27001 first if a customer deadline depends on it, because the certificate is the harder, slower item and it builds the ISMS you need anyway. Run an Essential Eight gap review during the same period, using the evidence you are already collecting, and set a maturity target as a security goal. Close the gaps through the ISMS risk treatment plan, then assess. By the first surveillance audit, both reports should come from one evidence store.