Home / Services / Essential Eight Assessment
Essential Eight Maturity Assessment

Know exactly where your
Essential Eight maturity and ACSC baseline sits.

An Essential Eight assessment reveals one number that matters: your weakest control. Guessing isn't a strategy.

The Essential Eight is the Australian Signals Directorate's shortlist of the mitigations that stop most intrusions before they start — and the benchmark that boards, insurers, and government contracts increasingly ask about by name. An Essential Eight assessment from Cyber Compliance Pro tests each of the eight strategies against the official maturity criteria, shows you the evidence behind every rating, and hands you a prioritised uplift plan your team can actually execute. Instead, no scare tactics, no product pitch — just an honest picture and a way forward.

Quick answer: An Essential Eight assessment measures an organisation against the ACSC's eight mitigation strategies (application control, patching, MFA, restricting admin privileges, and more) across four maturity levels, from Maturity Level 0 to Maturity Level 3.
Key facts: The Essential Eight covers eight mitigation strategies: application control, patching applications, Microsoft Office macro settings, user application hardening, restricting administrative privileges, patching operating systems, multi-factor authentication and regular backups. Each strategy is rated from Maturity Level 0 to Maturity Level 3, and an organisation's overall level is set by its weakest strategy.
Aligned frameworks
ACSC Essential Eight ISM Controls ML0–ML3 Model ISO/IEC 27001:2022 DEWR RFFR PSPF
ACSC ESSENTIAL 8
Engagement outcome
A verified maturity rating
and a roadmap to the
level you actually need.
8 Strategies Scored
EVIDENCE BEHIND EVERY RATING
ML0–ML3 Rating
PER OFFICIAL ACSC CRITERIA
Prioritised Roadmap
QUICK WINS FIRST
ML0 ML3 E8 MATURITY RATING
How scoring works
Eight strategies rated —
the lowest score becomes
your overall level.
What the Essential Eight actually is

What an Essential Eight assessment checks first.

Out of everything an organisation could do about cyber security, the ASD picked the eight mitigations that block the intrusion techniques attackers rely on most: application control, patching applications, patching operating systems, restricting Microsoft Office macros, user application hardening, restricting administrative privileges, multi-factor authentication, and regular backups. Each one gets rated from Maturity Level Zero to Three against published criteria — and your organisation's overall level is whichever strategy scores lowest. For example, seven strategies at Level Two and one at Level One makes you a Level One organisation. The model is deliberately unforgiving, because attackers only need one gap.

An Essential Eight assessment tells you, with evidence, where each strategy really sits — not where your last vendor report assumed it did. In short, Cyber Compliance Pro runs the assessment end to end: technical testing, honest scoring, a debrief your executive team will follow, and an implementation roadmap and mitigation controls roadmap sequenced by risk. Read more about our approach on the about us page or browse our guide to the ML0–ML3 maturity levels.

8
Mitigation Strategies
4
Maturity Levels (0–3)
2–4wk
Typical Assessment
12mo
Review Cadence
Analyst reviewing Essential Eight assessment results on a laptop dashboard
What's included

Six stages from unknown to uplifted

Some clients want a one-off Essential Eight assessment for the board or an insurer. Alternatively, others need the full arc — assessment, remediation, and a re-test that proves the uplift landed. The engagement is built in stages so you take exactly what you need.

Essential Eight assessment scorecard showing maturity ratings per strategy
01 · SCOPE

Scoping & Target Level

First, we map your environment, agree the systems in scope, and settle the maturity level your risk profile genuinely calls for — before any testing begins.

  • Asset and system discovery
  • Target maturity level agreed with leadership
  • Stakeholder interviews and access planning
02 · TEST

Technical Assessment

In practice, each of the eight strategies gets examined hands-on — configurations pulled, policies checked against reality, and gaps confirmed rather than assumed. As such, this is the core of every Essential Eight assessment we run.

  • Configuration and policy review per control
  • Vulnerability scanning across the fleet
  • Patch, privilege, and MFA coverage checks
03 · SCORE

Maturity Scoring

Specifically, every strategy is rated ML0 to ML3 strictly against the ACSC criteria, with the evidence recorded next to each rating so nothing rests on opinion.

  • Per-strategy ratings with supporting evidence
  • Overall maturity level determination
  • Gap register ranked by attack likelihood
04 · REPORT

Report & Executive Debrief

As a result, findings from your Essential Eight assessment arrive as a written report and a walkthrough for both audiences: technical detail for IT, and a plain-language risk picture for the executive team.

  • Full findings report with maturity scorecard
  • Executive briefing session
  • Q&A with the assessors who did the work
05 · UPLIFT

Remediation Support

Consequently, the roadmap sequences fixes by impact and effort — quick wins first, structural changes planned properly. Your team can run it, or ours can work alongside them.

  • Prioritised 12–18 month uplift roadmap
  • Hands-on remediation where you want it
  • Built on tools you already licence
06 · RE-ASSESS

Verification & Annual Review

Overall, maturity drifts — patch cycles slip, exceptions accumulate, new systems arrive unhardened. A scheduled re-assessment keeps your rating real, not historical.

  • Post-remediation re-testing
  • Annual maturity reviews
  • Drift alerts after major IT changes
Why it matters

What a verified rating actually gets you

In short, the Essential Eight earns its reputation by being narrow on purpose — it targets the specific techniques behind ransomware, credential theft, and business email compromise, rather than trying to cover everything at once.

Defence

Real Attack Paths, Closed

Ransomware · BEC · Credential Theft

Specifically, the eight strategies interrupt the standard intrusion playbook — the malicious attachment that can't execute, the stolen password that hits MFA, the admin account that no longer exists.

Expectation

The Benchmark Everyone Asks About

Government · Tenders · Supply Chains

Mandatory for federal agencies under the Protective Security Policy Framework and increasingly a standing question in tenders and supplier reviews. A verified Essential Eight assessment answers it before it's asked.

Insurance

A Stronger Insurance Position

Eligibility & Premiums

Similarly, cyber insurers use Essential Eight alignment as shorthand for a well-run security program. Documented maturity supports eligibility and gives you leverage at renewal.

Efficiency

Built On What You Already Own

Microsoft 365 · Native OS Tooling

Generally, most of the uplift that follows an Essential Eight assessment comes from configuring platforms you already licence — application control, macro restrictions, MFA — not from buying another security product.

Leverage

One Assessment, Many Frameworks

ISM · RFFR · ISO 27001

Furthermore, Essential Eight work carries straight into ISM alignment, RFFR accreditation, and the technological controls of ISO 27001 — evidence gathered once, reused everywhere.

Clarity

A Number The Board Understands

ML0 → ML3

Ultimately, security posture compressed into a rating leadership can track quarter over quarter — where you are, where you're heading, and what closing the gap will cost.

What gets assessed

Eight strategies. One rating each. No averaging.

Every strategy below is scored independently during your Essential Eight assessment against the ACSC's published maturity criteria — and your overall level is set by the lowest of the eight. That's why a serious assessment checks all of them with equal rigour: the control nobody's been watching is the one that decides your rating.

Request a Maturity Snapshot

Application Control

Only Approved Software Runs

Patch Applications

Known Holes, Closed Fast

Patch Operating Systems

The Fleet Stays Current

Restrict Office Macros

Internet Macros Blocked

User Application Hardening

Attack Surface Trimmed

Restrict Admin Privileges

Least Privilege, Enforced

Multi-Factor Authentication

Passwords Aren't Enough

Regular Backups

Tested, Isolated, Restorable
Our methodology

Five stages from
first call to verified uplift

On average, a typical Essential Eight assessment wraps in two to four weeks depending on fleet size and site count — and it's designed to run without pulling your IT team off their day jobs.

01
Discover

Interviews & Scoping

First, we talk to the people who run your systems, map the environment, and agree the target maturity level — so the assessment measures against a goal, not a vacuum.

02
Assess

Technical Deep Dive

Next, configurations, policies, and systems get examined against each strategy's maturity criteria — with evidence collected as we go, not reconstructed afterwards.

03
Score

Ratings & Findings

Then, each strategy receives its ML0–ML3 rating with the reasoning documented. The lowest rating sets your overall level — and shows exactly where to focus first.

04
Plan

Debrief & Roadmap

After that, we present findings to your executive and IT teams together, then hand over a 12–18 month roadmap sequenced by risk, effort, and quick wins.

05
Uplift

Remediation & Re-Test

Finally, your team implements — or ours does it with them — and a re-assessment verifies the new maturity level with evidence you can show a board, insurer, or assessor.

Why work with us

Honest ratings, practical uplift

An Essential Eight assessment is only useful if the scoring is straight and the recommendations fit the business paying for them. That's the whole pitch.

Cyber security consultant conducting an Essential Eight assessment with a client team

Independent By Design

Importantly, we don't resell hardware, licences, or managed services quotas — so a finding from your Essential Eight assessment is never a sales lead in disguise. You get the rating the evidence supports, nothing else.

Two Audiences, One Report

Engineers get the configuration detail they need to fix things. Meanwhile, executives get the risk picture in plain language. Nobody has to translate between the two.

Roadmaps That Respect Budgets

Instead, recommendations start with what your existing stack can do — Microsoft 365 settings, native OS controls, group policy — before anything that costs new money.

Still Around After The Report

Plenty of assessors deliver a PDF and disappear. By contrast, we stay available through remediation, answer the questions that surface mid-fix, and verify the uplift when it's done.

Who we help

Assessments across every kind of organisation

Naturally, the framework scales from a twenty-seat professional services firm to a multi-site enterprise — and so does our Essential Eight assessment approach for each one.

Finance, Legal
& Professional Services
Government &
Public Sector
Healthcare
& Aged Care
Education &
Not-For-Profits
SaaS, Cloud
& Growing SMBs
Frequently asked

Common questions,
clear answers

What organisations usually want to know before booking an Essential Eight assessment.

In short, it's mandated for non-corporate Commonwealth entities under the Protective Security Policy Framework and strongly recommended for everyone else. In practice, though, the pressure comes from other directions: tender questionnaires that ask for your maturity level, insurers that price against it, and head contractors that require it of their supply chain. Notably, for most private organisations "not legally required" and "not expected" are two very different things. An Essential Eight assessment settles the question either way.

Ultimately, it depends on who wants to attack you and how hard they'd try. Maturity Level One counters opportunistic attackers using widely available tooling. Level Two — the sensible target for most established businesses — withstands adversaries willing to invest real time in a specific victim. Meanwhile, Level Three is for organisations facing well-resourced, persistent threats. Instead, we settle this with you at scoping, based on your data, sector, and threat exposure rather than a default answer.

Because that's how attacks work. Specifically, the eight strategies are designed to reinforce each other — patching limits what an attacker can exploit, application control limits what they can run, MFA limits what a stolen password buys them. Leave one strategy behind and you've handed over the path of least resistance, no matter how strong the other seven are. As a result, every Essential Eight assessment we run makes that reality visible.

Typically, most assessments run two to four weeks end to end, scaling with the number of systems and sites in scope. Overall, disruption is minimal by design: a handful of interviews, read-only access to configurations, and scanning scheduled around your operations. Meanwhile, your team keeps working; we do the digging.

In fact, usually far less than people fear. Notably, the ASD deliberately keeps the framework vendor-neutral, and most requirements are met through capabilities already sitting in Microsoft 365, Windows, and your existing identity platform — application control policies, macro restrictions, MFA enforcement, backup configuration. Overall, our roadmaps exhaust what you already licence before recommending anything with a price tag.

In short, directly. The Essential Eight sits inside the Information Security Manual, which underpins RFFR accreditation — so maturity uplift here feeds your Statement of Applicability almost line for line. Additionally, it covers a meaningful slice of ISO 27001's technological controls. So if either of those programs is on your horizon, an Essential Eight assessment is the highest-leverage place to start, and we design the evidence so it's reusable across all three.

"

We assumed we were sitting at Level Two because our MSP said so. Instead, the Essential Eight assessment showed application control barely existed and half our servers were months behind on patches — Level Zero, with evidence we couldn't argue with. Eventually, six months into the roadmap we passed re-assessment at Level Two, and this time we can prove it.

JT
IT Manager Professional Services · Brisbane

Not sure where your
maturity really sits?

In short, book a readiness call and we'll scope your environment, agree the maturity level worth aiming for, and give you a fixed timeline and price for a full Essential Eight assessment.