Security you can prove.
Essential Eight assessments and ISO 27001 compliance services, Melbourne and Sydney.
Being secure and being able to prove it are two different jobs. We run the controls, keep the evidence current, and hand you something an auditor, an insurer or a tender panel will actually accept. AWD services are ISO 27001 certified, so we are documenting a process we already live with.
Where you stand
Essential Eight maturity.
The eight controls, each scored from Maturity Level 0 to 3. This is where a real assessment starts.
Application control
ML0Patch applications
ML1Office macros
ML2User application hardening
ML3Restrict admin privileges
ML0Patch operating systems
ML1Multi-factor authentication
ML2Regular backups
ML3What is the Essential Eight?
Eight mitigation strategies published by the Australian Signals Directorate, each scored from Maturity Level Zero to Maturity Level Three. It is the Australian baseline for practical cyber security uplift.
Is the Essential Eight mandatory?
For non-corporate Commonwealth entities, yes, under the Protective Security Policy Framework. NSW government agencies must implement it to at least Maturity Level 1 under the NSW Cyber Security Policy. Defence Industry Security Program members must meet or exceed Maturity Level 2 on systems used to correspond with Defence. For private business generally it is not law, but it is increasingly a contractual requirement flowed down by customers.
Is the Essential Eight being replaced?
ASD announced in June 2026 that it will replace the Essential Eight with a new “Essentials” series over roughly two years, with separate guidance for enterprise IT, operational technology and cloud. The Essential Eight remains current and both will run side by side during the transition. Work done now is not wasted, and we took part in the consultation.
What is the difference between ISO 27001 aligned and ISO 27001 certified?
Alignment means your controls match the standard and the evidence exists. Certification means an accredited certification body has audited you and issued a certificate. AWD prepares, governs and supports the process. Only an accredited certification body can certify you, and in Australia those bodies are accredited by JAS-ANZ or another IAF Multilateral Recognition Arrangement signatory.
How long does ISO 27001 certification take?
Typically nine to eighteen months from gap analysis to Stage 2 audit, depending on scope and how much is already documented.
Do we need ISO 27001 or the Essential Eight?
Essential Eight if you want measurable security uplift and your customers ask about ACSC alignment. ISO 27001 if you need a certificate to satisfy enterprise customers, insurers or offshore partners. Many businesses do the Essential Eight first and use it as the foundation.
The journey
ISO 27001 certification timeline.
Six milestones from first look to certified. A clear path, with no surprises at the audit.
-
01Gap analysis
-
02ISMS build
-
03Internal audit
-
04Stage 1 audit
-
05Stage 2 audit
-
06Certified
Which framework
ISO 27001 vs Essential Eight vs SMB1001.
Three routes to demonstrable security. This is how to work out which one fits where you are.
| Consideration | ISO 27001 | Essential Eight | SMB1001 |
|---|---|---|---|
| Best for | Larger & regulated orgs | Any Australian business | Small business, fast start |
| Audit / certification | Included | Self or assessed | Tiered certification |
| Government alignment | International standard | ACSC / federal | SMB supply chain |
| Effort | High | Medium | Low |
Cost of inaction
The cost of doing nothing.
Skipping certification does not remove the risk, it just moves it onto the balance sheet. These are the Australian figures, self-reported to the ASD.
The cost of doing nothing
ASD Annual Cyber Threat Report 2024-25; OAIC Notifiable Data Breaches, calendar year 2025.
Proof
We hold the badge ourselves
AWD services are ISO 27001 certified and independently audited, so the process we run you through is the same one we passed. Here is one certified client, anonymised.
A national charity reached Essential Eight Maturity Level 2 in six months.
“They turned a daunting framework into a clear plan, and we passed without the last-minute panic we expected.”
Anonymised • sector label only.
Start here
Not sure where to start?
A no-obligation conversation about your infrastructure, security posture and operational risk. No lock-in, and a response within one business day.