What Order Should Businesses Implement the Essential Eight, Further Five, and SMB1001?

FAQ’s, tips and insights > Cyber Security

Which Comes First: Essential Eight, Further Five or SMB1001?

When building cyber resilience, many Australian businesses ask:

Should we start with the Essential Eight, the Further Five or SMB1001?

The short answer:

Start with the Essential Eight, then work towards SMB1001, and finish with the Further Five.

Here’s why:

1. Start with SMB1001

SMB1001 is designed specifically for Australian SMBs and provides a practical, risk-based starting point.

– Covers foundational IT security, backups, continuity, and governance

– Maps to the Essential Eight but adds real-world, operationally relevant controls

– Highly actionable for businesses without large IT teams

Explore our SMB1001 Cybersecurity Framework

2. Layer in the Essential Eight

Once the groundwork is laid with SMB1001, the Essential Eight becomes your next step.

3. Strengthen with the Further Five

With both SMB1001 and the Essential Eight in place, you’re ready to implement the Further Five.