Services · Framework assessment
Essential Eight Assessment and Compliance
An Essential Eight assessment shows how well your business has put the Australian Signals Directorate's eight mitigation strategies in place. We help you identify the controls that meet each strategy and the evidence that can prove them, show you the gaps to the maturity level you need, and give you a prioritised plan in plain English.
What is the Essential Eight?
The Essential Eight, often written Essential 8, is a set of eight mitigation strategies that the Australian Signals Directorate (ASD) recommends organisations implement as a baseline. In ASD's words, this baseline "makes it much harder for adversaries to compromise systems".
The eight strategies are:
- Patch applications
- Patch operating systems
- Multi-factor authentication
- Restrict administrative privileges
- Application control
- Restrict Microsoft Office macros
- User application hardening
- Regular backups
ASD's Essential Eight maturity model, currently the November 2023 release, defines four maturity levels, from Maturity Level Zero to Maturity Level Three. Level One defends against attackers who use widely available tools and are "looking for any victim rather than a specific victim". Level Two defends against attackers who invest more time in a target, including phishing for passwords. Level Three defends against adaptive attackers who rely much less on public tools.
It is a floor, not a ceiling. ASD calls the Essential Eight "a minimum set of preventative measures" and says it "will not mitigate all cyber threats".
Does the Essential Eight apply to my business?
For most private businesses it is recommended rather than required. ASD's Small business cyber security guide says "we recommend small businesses implement Maturity Level One of the Essential Eight", and ASD's FAQ says Level One "may be suitable for small to medium enterprises".
In government it is mandatory. The Protective Security Policy Framework (Release 2026) requires non-corporate Commonwealth entities to implement all eight strategies to Maturity Level Two. Queensland's Information and cyber security policy (IS18) requires Queensland Government departments to implement the Essential Eight and choose their own maturity targets.
Contracts can bring it to you. ASD notes that an Essential Eight implementation may need to be assessed by an independent party when a government directive, a regulator or a contract requires it.
The Essential Eight was designed for internet-connected IT networks. ASD says it "was not designed for" enterprise mobility or operational technology.
Is there an Essential 8 compliance certificate?
No. ASD states that "there is no requirement for organisations to have their Essential Eight implementation certified by an independent party". Essential 8 compliance means every requirement of your target maturity level is met across all eight strategies, and you can show the evidence. The evidence matters as much as the control: ASD's assessment process guide rates a policy or a verbal statement of intent as poor evidence, and a review of how a system is actually configured as good evidence.
Two rules catch businesses out:
- All eight, one level at a time. ASD says the Essential Eight "is required to be implemented and assessed as a package". If one control for a strategy is assessed as ineffective, that maturity level is not met.
- Insurance is not a control. ASD's FAQ says that choosing cyber insurance or risk acceptance instead of implementing a whole strategy is assessed as Maturity Level Zero, for that strategy and for your Essential Eight overall.
What does an Essential Eight assessment involve?
Our Essential Eight assessment is a review done with you and your IT provider. We help you identify the controls that meet each requirement and the evidence that can prove them. It is not a technical test of your systems.
- Choose the target. We agree which systems are in scope and the maturity level you are aiming for. ASD advises reaching the same level across all eight strategies before aiming higher, and recommends Level One for small businesses.
- Map your controls. For each strategy, we work through ASD's requirements for your target level and identify the tools, settings and processes that meet each one, including what your existing licences already provide.
- Identify the evidence. For each control, we identify the evidence that can prove it, such as a configuration report from your management tools or a record of a backup being restored, and note where evidence is missing or is only a policy statement.
- Report the gaps. We walk you and your IT provider through what is covered, what is not, and what to fix first.
If a customer or contract later requires an independent assessment, you go into it with your controls and evidence already identified and in one place.
What you get
- For each of the eight strategies, the controls that meet ASD's requirements at your target level, and the ones that are missing.
- The evidence that can prove each control, and where it is missing or weak.
- The gaps in priority order, with the practical fix for each.
- A plain-English summary for owners, and the detail your IT provider needs.
- Optional help to close the gaps: we can do the work, or source and deliver the products, quoted separately.
Is the Essential Eight changing?
Yes, but not yet. In June 2026 ASD consulted its partners on evolving the Essential Eight into a new "Essentials" series, starting with "Essentials for enterprise IT", and that consultation closed on 12 July 2026. At the time of writing, September 2026, the November 2023 maturity model is still the current one. ASD says organisations already using the Essential Eight "can expect strong alignment with their existing controls and investments". We will update this page when ASD publishes the new guidance.
How much does an Essential Eight assessment cost?
Each assessment is priced by individual quote, because the effort depends on how many systems and sites are in scope and what the assessment is for: a maturity target, a certification or a customer's requirement.
If you are not sure where you stand, start with the fixed-price IT Security Review ($399 inc GST). It gives you a prioritised action plan and tells you whether a full assessment is worth doing yet.
Ask for a quoteRelated
- Free coverage check →
See how far your existing licences take you towards each Essential Eight maturity level, in about three minutes.
- Sample coverage report →
Every ISM control with its Essential Eight maturity levels. This link opens at multi-factor authentication.
- Free Cyber Security Self-Check for Small Business →
Does Microsoft 365 Business Premium cover the Essential Eight, and which level should a small business aim for?
- ISM September 2026: What Changed and What to Check →
This quarter's changes to the ISM, including the Essential Eight markings.
Other frameworks we assess against
- ISM →
The ASD Information Security Manual (ISM) explained: who must follow it, how it is built, what changed this quarter, and what an ISM assessment involves.
Sources
- ASD, Essential Eight - the baseline wording
- ASD, Essential Eight maturity model (November 2023) - the maturity levels, the same-level-across-all-eight advice, the minimum-set wording and independent assessment
- ASD, Essential Eight maturity model FAQ - Maturity Level One for small to medium enterprises, and cyber insurance as Maturity Level Zero
- ASD, Essential Eight assessment process guide (October 2024) - assessing as a package, and evidence quality
- ASD, Small business cyber security guide - the Maturity Level One recommendation
- Department of Home Affairs, Protective Security Policy Framework Release 2026 - Requirements 0099 to 0106, Maturity Level Two
- Queensland Government, Information and cyber security policy (IS18) - Requirement 3
- ASD, Consultation on evolution of Essential Eight - the Essentials series
Quoted ASD material © Commonwealth of Australia, CC BY 4.0, via cyber.gov.au.