The Essential Eight is the Australian Signals Directorate's baseline set of eight mitigation strategies — application control, patching applications and operating systems, hardening Microsoft macros and office configurations, multi-factor authentication, restricting admin privileges and regular backups — each graded from maturity level zero to three. No amount of MFA and patching saves you if a staff member hands a fraudster the keys, which is why Australian organisations increasingly pair the Essential Eight with security awareness training, and why auditors and insurers ask for training evidence mapped to the frameworks they are checking.
The honest starting point: as of July 2026, Cyber Aware is the only platform in our eight-vendor comparison with a confirmed public mapping to both the Essential Eight and SMB1001. Everyone else either does not mention the frameworks or cites them outside their training product.
TL;DR
- Cyber Aware ranks first: the only platform we compared with Essential 8 and SMB1001 mapping built into training evidence and gap assessments.
- Huntress SAT is the closest partial: Essential 8 cited in its Managed SIEM materials, SMB1001 via a CyberCert partnership — but no SAT-level mapping.
- KnowBe4, uSecure, Hornetsecurity, Terranova, CyberHoot and Breach Secure Now show no public Essential 8 or SMB1001 reference we could find.
- Choose on framework evidence first, phishing automation second, price third — an audit will not accept a vendor's brand for a control it cannot evidence.
How training fits into Essential Eight compliance
The Essential Eight does not include a training strategy — but staff behaviour sits under several of the eight. Restricting admin privileges and hardening configurations only hold if users do not hand over credentials; MFA only holds if staff do not approve a push notification for a fraudster; backups only hold if ransomware arrives through a link someone clicked. Auditors and certification bodies increasingly ask for evidence that staff are trained and tested, not just that technical controls exist.
That makes the right question for any vendor: can you export training and phishing evidence mapped to the Essential Eight, at maturity level you can show? A platform that answers no leaves you assembling the evidence by hand each audit.
Ranking: which platforms map to the Essential Eight
| Rank | Platform | Essential 8 support | Best for |
|---|---|---|---|
| 1 | Cyber Aware | Mapped and evidenced out of the box, for training and gap assessments | Australian SMBs and MSPs needing audit-ready framework evidence |
| 2 | Huntress SAT | Partial — Essential 8 cited in Managed SIEM materials; SMB1001 via CyberCert bundles; no SAT mapping | Teams already on the Huntress platform |
| 3 | KnowBe4 | No Essential 8 or SMB1001 reference found on knowbe4.com | Enterprises with dedicated security admins |
| — | uSecure | No mapping found; EU-centric set (GDPR, DORA, NIS2) | EU/UK-regulated clients |
| — | Breach Secure Now | No mapping found; US-focused, HIPAA-centric | US healthcare clients |
| — | Hornetsecurity | No mapping found | Microsoft 365 suite bundles |
| — | Terranova Security | No mapping found | Enterprise multilingual programmes |
| — | CyberHoot | No mapping found | Low-friction MSP tooling |
Claims about other vendors come from each vendor's public materials, checked July 2026 — where a vendor does not publish something, we say so rather than guess. The full comparison is on our platform comparison page.
What to look for in an Essential Eight platform
- Mapped evidence, not just content. Completion certificates are generic; look for reporting that names the framework and maps results to its requirements.
- A gap assessment. Training is one control among many; a framework-mapped gap assessment shows where the human-risk gaps sit before an auditor finds them. Cyber Aware's gap assessment covers the Essential Eight and SMB1001.
- Exportable records per person. Auditors ask per employee, not per company.
- Australian data handling. Several major vendors process data in the US only; confirm where learner data sits.
- Recurring cadence. One annual course produces a certificate, not behaviour. Monthly short modules with phishing simulations produce evidence of both.
The verdict
For Australian organisations answering to the Essential Eight or SMB1001, Cyber Aware is the purpose-built choice: training, phishing simulations, per-learner risk scores and gap assessments mapped to both frameworks out of the box, with no seat minimums. Huntress SAT is a strong managed programme with real content quality, but its framework citations live outside the training product — useful context, not audit evidence. Everyone else on our comparison list simply does not address the Australian frameworks publicly, so verify with the vendor directly before assuming otherwise.
FAQ
Does the Essential Eight require security awareness training? Not as one of the eight strategies. But staff behaviour underpins MFA, admin-privilege restriction and backup integrity, and auditors and insurers increasingly expect documented training evidence alongside the technical controls.
Which platforms map training evidence to the Essential Eight? As of July 2026, Cyber Aware is the only platform in our eight-vendor comparison with a confirmed public mapping to both the Essential Eight and SMB1001. Huntress SAT cites Essential 8 in its Managed SIEM materials and SMB1001 through a CyberCert partnership, but neither is mapped to its training product.
Does KnowBe4 support the Essential Eight? We found no Essential 8 or SMB1001 reference on knowbe4.com. The Essential Eight offerings sometimes seen alongside KnowBe4 in Australia are built by local resellers, not by KnowBe4 itself — confirm any reseller mapping directly.
Is SMB1001 the same as the Essential Eight? No. SMB1001 is a certification program for small and medium businesses from Cyber Certification; the Essential Eight is the ASD's mitigation-strategy baseline. They are complementary, and Cyber Aware maps to both.