# Essential Eight Assessment and Compliance

## What is the Essential Eight?

The Essential Eight, often written Essential 8, is a set of eight mitigation strategies that the Australian Signals Directorate (ASD) recommends organisations implement as a baseline. In ASD's words, this baseline "makes it much harder for adversaries to compromise systems".

The eight strategies are:

- Patch applications
- Patch operating systems
- Multi-factor authentication
- Restrict administrative privileges
- Application control
- Restrict Microsoft Office macros
- User application hardening
- Regular backups

ASD's [Essential Eight maturity model](https://www.cyber.gov.au/business-government/asds-cyber-security-frameworks/essential-eight/essential-eight-maturity-model), currently the November 2023 release, defines four maturity levels, from Maturity Level Zero to Maturity Level Three. Level One defends against attackers who use widely available tools and are "looking for any victim rather than a specific victim". Level Two defends against attackers who invest more time in a target, including phishing for passwords. Level Three defends against adaptive attackers who rely much less on public tools.

It is a floor, not a ceiling. ASD calls the Essential Eight "a minimum set of preventative measures" and says it "will not mitigate all cyber threats".

## Does the Essential Eight apply to my business?

For most private businesses it is recommended rather than required. ASD's [Small business cyber security guide](https://www.cyber.gov.au/business-government/small-business-cyber-security/small-business-hub/small-business-cyber-security-guide) says "we recommend small businesses implement Maturity Level One of the Essential Eight", and ASD's [FAQ](https://www.cyber.gov.au/business-government/asds-cyber-security-frameworks/essential-eight/essential-eight-maturity-model-faq) says Level One "may be suitable for small to medium enterprises".

In government it is mandatory. The [Protective Security Policy Framework](https://www.protectivesecurity.gov.au/system/files/2026-07/pspf-release-2026_6.pdf) (Release 2026) requires non-corporate Commonwealth entities to implement all eight strategies to Maturity Level Two. Queensland's [Information and cyber security policy (IS18)](https://www.forgov.qld.gov.au/information-technology/queensland-government-enterprise-architecture-qgea/qgea-directions-and-guidance/qgea-policies-standards-and-guidelines/information-security-policy-is18) requires Queensland Government departments to implement the Essential Eight and choose their own maturity targets.

Contracts can bring it to you. ASD notes that an Essential Eight implementation may need to be assessed by an independent party when a government directive, a regulator or a contract requires it.

The Essential Eight was designed for internet-connected IT networks. ASD says it "was not designed for" enterprise mobility or operational technology.

## Is there an Essential 8 compliance certificate?

No. ASD states that "there is no requirement for organisations to have their Essential Eight implementation certified by an independent party". Essential 8 compliance means every requirement of your target maturity level is met across all eight strategies, and you can show the evidence. The evidence matters as much as the control: ASD's [assessment process guide](https://www.cyber.gov.au/business-government/asds-cyber-security-frameworks/essential-eight/essential-eight-assessment-process-guide) rates a policy or a verbal statement of intent as poor evidence, and a review of how a system is actually configured as good evidence.

Two rules catch businesses out:

- **All eight, one level at a time.** ASD says the Essential Eight "is required to be implemented and assessed as a package". If one control for a strategy is assessed as ineffective, that maturity level is not met.
- **Insurance is not a control.** ASD's FAQ says that choosing cyber insurance or risk acceptance instead of implementing a whole strategy is assessed as Maturity Level Zero, for that strategy and for your Essential Eight overall.

## What does an Essential Eight assessment involve?

Our Essential Eight assessment is a review done with you and your IT provider. We help you identify the controls that meet each requirement and the evidence that can prove them. It is not a technical test of your systems.

1. **Choose the target.** We agree which systems are in scope and the maturity level you are aiming for. ASD advises reaching the same level across all eight strategies before aiming higher, and recommends Level One for small businesses.
2. **Map your controls.** For each strategy, we work through ASD's requirements for your target level and identify the tools, settings and processes that meet each one, including what your existing licences already provide.
3. **Identify the evidence.** For each control, we identify the evidence that can prove it, such as a configuration report from your management tools or a record of a backup being restored, and note where evidence is missing or is only a policy statement.
4. **Report the gaps.** We walk you and your IT provider through what is covered, what is not, and what to fix first.

If a customer or contract later requires an independent assessment, you go into it with your controls and evidence already identified and in one place.

## What you get

- For each of the eight strategies, the controls that meet ASD's requirements at your target level, and the ones that are missing.
- The evidence that can prove each control, and where it is missing or weak.
- The gaps in priority order, with the practical fix for each.
- A plain-English summary for owners, and the detail your IT provider needs.
- Optional help to close the gaps: we can do the work, or source and deliver the products, quoted separately.

## Is the Essential Eight changing?

Yes, but not yet. In June 2026 ASD consulted its partners on evolving the Essential Eight into a new "Essentials" series, starting with "Essentials for enterprise IT", and that consultation closed on 12 July 2026. At the time of writing, September 2026, the November 2023 maturity model is still the current one. ASD says organisations already using the Essential Eight "can expect strong alignment with their existing controls and investments". We will update this page when ASD publishes the new guidance.
