Choosing a Cyber Security Framework for Your SME
Why Frameworks Matter
A cyber security framework gives your business a structured, repeatable approach to managing risk. Without one, security efforts tend to be reactive — fixing problems after they happen rather than preventing them. For Australian SMEs, the challenge is not a lack of frameworks but choosing the right one from a crowded field.
This guide compares the five most relevant frameworks for Australian small and medium businesses, helping you decide which one (or which combination) fits your size, budget and risk profile.
The Five Frameworks
1. ASD Essential Eight
Developed by the Australian Signals Directorate (ASD), the Essential Eight is a set of eight baseline mitigation strategies designed to prevent the most common cyber attacks. It was originally created for Australian Government agencies but has become the de facto standard for all Australian organisations.
- Best for: Any Australian business looking for a practical, locally relevant starting point.
- Cost: Free. The strategies primarily involve configuring existing technology.
- Complexity: Low to moderate. Maturity Level 1 is achievable for most SMEs without external consultants.
- Certification: No formal certification body, but self-assessment and third-party assessments are common.
- Pros: Australian-specific, highly practical, well-documented, free guidance available.
- Cons: Focused on technical controls — does not address governance, people or process comprehensively.
For a detailed breakdown, see our Essential Eight guide for small business.
2. NIST Cybersecurity Framework (CSF)
Created by the U.S. National Institute of Standards and Technology, the NIST CSF is one of the most widely adopted frameworks globally. Version 2.0 (released February 2024) organises security into six functions: Govern, Identify, Protect, Detect, Respond and Recover.
- Best for: Businesses wanting a holistic, risk-based approach or those with U.S. clients/partners.
- Cost: Free to adopt. Implementation costs depend on scope.
- Complexity: Moderate. The framework is comprehensive but flexible — you choose which elements to implement.
- Certification: No formal certification. Used as a reference framework.
- Pros: Comprehensive, internationally recognised, vendor-neutral, risk-based.
- Cons: Not Australia-specific, can feel overwhelming for small teams, no clear “do this first” guidance.
3. ISO/IEC 27001
ISO 27001 is the international standard for information security management systems (ISMS). It provides a systematic approach to managing sensitive information, covering people, processes and technology. Certification is granted by accredited bodies after a formal audit.
- Best for: SMEs in regulated industries, those pursuing government contracts, or businesses wanting a globally recognised certification.
- Cost: High. Certification audits typically cost $10,000–$30,000+ for SMEs, plus ongoing annual surveillance audits.
- Complexity: High. Requires documented policies, risk assessments, internal audits and management reviews.
- Certification: Yes — formal third-party certification available and widely recognised.
- Pros: Internationally recognised gold standard, comprehensive, demonstrates serious commitment.
- Cons: Expensive, resource-intensive, can be overkill for businesses with fewer than 50 employees.
4. SMB1001 (CSCAU)
SMB1001 is a certification developed by the Cyber Security Certification Australia (CSCAU) specifically for Australian small and medium businesses. It features five tiers (Bronze through Diamond), allowing businesses to achieve progressively higher levels of cyber maturity at their own pace.
- Best for: Australian SMEs wanting a formal, affordable certification that is proportionate to their size.
- Cost: Low to moderate. Certification fees start from around $500–$2,000 per year depending on the tier.
- Complexity: Low to moderate. Bronze tier is achievable for most small businesses.
- Certification: Yes — formal certification with annual renewal.
- Pros: Australian-designed for SMEs, affordable, tiered approach, growing industry recognition.
- Cons: Relatively new (less internationally recognised), not yet a regulatory requirement.
Read our full SMB1001 certification guide for details on each tier.
5. CIS Controls
The Center for Internet Security (CIS) Controls (v8.1) is a prioritised set of 18 cyber defence actions. Each control is broken into Implementation Groups (IGs), with IG1 representing a minimum standard suitable for small organisations.
- Best for: Technically-oriented SMEs wanting a detailed, prioritised action list.
- Cost: Free to adopt. CIS provides free benchmarks and hardening guides.
- Complexity: Moderate. IG1 is manageable; IG2 and IG3 require more resources.
- Certification: No formal certification, but CIS offers self-assessment tools.
- Pros: Highly actionable, prioritised by effectiveness, free resources, maps to other frameworks.
- Cons: U.S.-centric, less recognised in Australia, 18 controls can feel like a lot to manage.
Comparison at a Glance
| Framework | Origin | Cost to Adopt | Formal Certification | Best SME Entry Point |
|---|---|---|---|---|
| Essential Eight | Australia (ASD) | Free | No | Maturity Level 1 |
| NIST CSF 2.0 | USA (NIST) | Free | No | Core Functions assessment |
| ISO 27001 | International (ISO) | $10k–$30k+ | Yes | Gap analysis first |
| SMB1001 | Australia (CSCAU) | $500–$2k/yr | Yes | Bronze tier |
| CIS Controls | USA (CIS) | Free | No | Implementation Group 1 |
The Problem: Framework Lock-In
One challenge SMEs face is choosing a framework only to discover later that a client, insurer or regulator expects a different one. This is where a framework-independent operating model becomes valuable.
The IDIA framework takes a different approach to the standards listed above. Instead of prescribing a specific set of controls, IDIA organises every cybersecurity control into four pillars:
- Identity — access control, authentication, MFA, user management.
- Data — data classification, encryption, backups, data loss prevention.
- Infrastructure — endpoints, networks, patching, email security, cloud configuration.
- Assurance — governance, risk management, compliance, continuous improvement, incident response.
Because IDIA is framework-independent, it maps cleanly to ISO 27001, NIST CSF, CIS Controls, Essential Eight, PCI DSS, SOC 2 and SMB1001 — without locking you into any single standard. You implement controls once, organised by pillar, and then demonstrate compliance against whichever framework your stakeholders require. For growing businesses that may need Essential Eight today and ISO 27001 tomorrow, IDIA eliminates the need to start over.
Where Should You Start?
For the majority of Australian SMEs, we recommend this approach:
- Start with the Essential Eight. It is free, practical and locally relevant. Achieving Maturity Level 1 across all eight strategies gives you a strong baseline that prevents most common attacks.
- Consider SMB1001 Bronze certification when you want to demonstrate your security posture to clients, partners or insurers. It builds on many of the same principles as the Essential Eight but adds governance elements and provides a formal certificate.
- Use NIST CSF as a strategic lens if you need to think about governance, detection and recovery — areas the Essential Eight does not cover in depth.
- Adopt IDIA as your operating model to organise all of the above into a single, coherent structure. IDIA does not replace these frameworks — it gives you one place to manage them all.
- Progress to ISO 27001 only when your business size, regulatory obligations or client requirements justify the investment. Many SMEs find that Essential Eight plus SMB1001, organised through IDIA, provides more than adequate coverage.
“The best framework is the one you actually implement. Start small, be consistent, and build from there.”
As your business grows, your security approach should grow with it. Our guide to cyber security strategy for growing businesses covers how to build a 12-month security roadmap and scale your investment appropriately.
Measure Your Current Posture
Whichever framework you choose, the first step is understanding where you stand today. Platforms like How’s My Cyber use the IDIA framework (Identity, Data, Infrastructure, Assurance) to organise every control into a clear operating model that maps across the Essential Eight, SMB1001, NIST CSF, ISO 27001 and more — so you are never locked into a single standard. Start with the free CYBER9 assessment to benchmark your business across nine critical security domains in under 10 minutes. You will receive a maturity score, an IDIA pillar breakdown and a prioritised action plan so you know exactly where to focus first.
How secure is your business?
Take the free CYBER9 assessment and get your security score in under 10 minutes. No credit card required.
Try CYBER9 Free