Know exactly where your
Essential Eight maturity and ACSC baseline sits.
An Essential Eight assessment reveals one number that matters: your weakest control. Guessing isn't a strategy.
The Essential Eight is the Australian Signals Directorate's shortlist of the mitigations that stop most intrusions before they start — and the benchmark that boards, insurers, and government contracts increasingly ask about by name. An Essential Eight assessment from Cyber Compliance Pro tests each of the eight strategies against the official maturity criteria, shows you the evidence behind every rating, and hands you a prioritised uplift plan your team can actually execute. Instead, no scare tactics, no product pitch — just an honest picture and a way forward.
and a roadmap to the
level you actually need.
the lowest score becomes
your overall level.
What an Essential Eight assessment checks first.
Out of everything an organisation could do about cyber security, the ASD picked the eight mitigations that block the intrusion techniques attackers rely on most: application control, patching applications, patching operating systems, restricting Microsoft Office macros, user application hardening, restricting administrative privileges, multi-factor authentication, and regular backups. Each one gets rated from Maturity Level Zero to Three against published criteria — and your organisation's overall level is whichever strategy scores lowest. For example, seven strategies at Level Two and one at Level One makes you a Level One organisation. The model is deliberately unforgiving, because attackers only need one gap.
An Essential Eight assessment tells you, with evidence, where each strategy really sits — not where your last vendor report assumed it did. In short, Cyber Compliance Pro runs the assessment end to end: technical testing, honest scoring, a debrief your executive team will follow, and an implementation roadmap and mitigation controls roadmap sequenced by risk. Read more about our approach on the about us page or browse our guide to the ML0–ML3 maturity levels.
Six stages from unknown to uplifted
Some clients want a one-off Essential Eight assessment for the board or an insurer. Alternatively, others need the full arc — assessment, remediation, and a re-test that proves the uplift landed. The engagement is built in stages so you take exactly what you need.
Scoping & Target Level
First, we map your environment, agree the systems in scope, and settle the maturity level your risk profile genuinely calls for — before any testing begins.
- Asset and system discovery
- Target maturity level agreed with leadership
- Stakeholder interviews and access planning
Technical Assessment
In practice, each of the eight strategies gets examined hands-on — configurations pulled, policies checked against reality, and gaps confirmed rather than assumed. As such, this is the core of every Essential Eight assessment we run.
- Configuration and policy review per control
- Vulnerability scanning across the fleet
- Patch, privilege, and MFA coverage checks
Maturity Scoring
Specifically, every strategy is rated ML0 to ML3 strictly against the ACSC criteria, with the evidence recorded next to each rating so nothing rests on opinion.
- Per-strategy ratings with supporting evidence
- Overall maturity level determination
- Gap register ranked by attack likelihood
Report & Executive Debrief
As a result, findings from your Essential Eight assessment arrive as a written report and a walkthrough for both audiences: technical detail for IT, and a plain-language risk picture for the executive team.
- Full findings report with maturity scorecard
- Executive briefing session
- Q&A with the assessors who did the work
Remediation Support
Consequently, the roadmap sequences fixes by impact and effort — quick wins first, structural changes planned properly. Your team can run it, or ours can work alongside them.
- Prioritised 12–18 month uplift roadmap
- Hands-on remediation where you want it
- Built on tools you already licence
Verification & Annual Review
Overall, maturity drifts — patch cycles slip, exceptions accumulate, new systems arrive unhardened. A scheduled re-assessment keeps your rating real, not historical.
- Post-remediation re-testing
- Annual maturity reviews
- Drift alerts after major IT changes
What a verified rating actually gets you
In short, the Essential Eight earns its reputation by being narrow on purpose — it targets the specific techniques behind ransomware, credential theft, and business email compromise, rather than trying to cover everything at once.
Real Attack Paths, Closed
Specifically, the eight strategies interrupt the standard intrusion playbook — the malicious attachment that can't execute, the stolen password that hits MFA, the admin account that no longer exists.
The Benchmark Everyone Asks About
Mandatory for federal agencies under the Protective Security Policy Framework and increasingly a standing question in tenders and supplier reviews. A verified Essential Eight assessment answers it before it's asked.
A Stronger Insurance Position
Similarly, cyber insurers use Essential Eight alignment as shorthand for a well-run security program. Documented maturity supports eligibility and gives you leverage at renewal.
Built On What You Already Own
Generally, most of the uplift that follows an Essential Eight assessment comes from configuring platforms you already licence — application control, macro restrictions, MFA — not from buying another security product.
One Assessment, Many Frameworks
Furthermore, Essential Eight work carries straight into ISM alignment, RFFR accreditation, and the technological controls of ISO 27001 — evidence gathered once, reused everywhere.
A Number The Board Understands
Ultimately, security posture compressed into a rating leadership can track quarter over quarter — where you are, where you're heading, and what closing the gap will cost.
Eight strategies. One rating each. No averaging.
Every strategy below is scored independently during your Essential Eight assessment against the ACSC's published maturity criteria — and your overall level is set by the lowest of the eight. That's why a serious assessment checks all of them with equal rigour: the control nobody's been watching is the one that decides your rating.
Request a Maturity SnapshotApplication Control
Only Approved Software RunsPatch Applications
Known Holes, Closed FastPatch Operating Systems
The Fleet Stays CurrentRestrict Office Macros
Internet Macros BlockedUser Application Hardening
Attack Surface TrimmedRestrict Admin Privileges
Least Privilege, EnforcedMulti-Factor Authentication
Passwords Aren't EnoughRegular Backups
Tested, Isolated, RestorableFive stages from
first call to verified uplift
On average, a typical Essential Eight assessment wraps in two to four weeks depending on fleet size and site count — and it's designed to run without pulling your IT team off their day jobs.
Interviews & Scoping
First, we talk to the people who run your systems, map the environment, and agree the target maturity level — so the assessment measures against a goal, not a vacuum.
Technical Deep Dive
Next, configurations, policies, and systems get examined against each strategy's maturity criteria — with evidence collected as we go, not reconstructed afterwards.
Ratings & Findings
Then, each strategy receives its ML0–ML3 rating with the reasoning documented. The lowest rating sets your overall level — and shows exactly where to focus first.
Debrief & Roadmap
After that, we present findings to your executive and IT teams together, then hand over a 12–18 month roadmap sequenced by risk, effort, and quick wins.
Remediation & Re-Test
Finally, your team implements — or ours does it with them — and a re-assessment verifies the new maturity level with evidence you can show a board, insurer, or assessor.
Honest ratings, practical uplift
An Essential Eight assessment is only useful if the scoring is straight and the recommendations fit the business paying for them. That's the whole pitch.
Independent By Design
Importantly, we don't resell hardware, licences, or managed services quotas — so a finding from your Essential Eight assessment is never a sales lead in disguise. You get the rating the evidence supports, nothing else.
Two Audiences, One Report
Engineers get the configuration detail they need to fix things. Meanwhile, executives get the risk picture in plain language. Nobody has to translate between the two.
Roadmaps That Respect Budgets
Instead, recommendations start with what your existing stack can do — Microsoft 365 settings, native OS controls, group policy — before anything that costs new money.
Still Around After The Report
Plenty of assessors deliver a PDF and disappear. By contrast, we stay available through remediation, answer the questions that surface mid-fix, and verify the uplift when it's done.
Assessments across every kind of organisation
Naturally, the framework scales from a twenty-seat professional services firm to a multi-site enterprise — and so does our Essential Eight assessment approach for each one.
& Professional Services
Public Sector
& Aged Care
Not-For-Profits
& Growing SMBs
Common questions,
clear answers
What organisations usually want to know before booking an Essential Eight assessment.
In short, it's mandated for non-corporate Commonwealth entities under the Protective Security Policy Framework and strongly recommended for everyone else. In practice, though, the pressure comes from other directions: tender questionnaires that ask for your maturity level, insurers that price against it, and head contractors that require it of their supply chain. Notably, for most private organisations "not legally required" and "not expected" are two very different things. An Essential Eight assessment settles the question either way.
Ultimately, it depends on who wants to attack you and how hard they'd try. Maturity Level One counters opportunistic attackers using widely available tooling. Level Two — the sensible target for most established businesses — withstands adversaries willing to invest real time in a specific victim. Meanwhile, Level Three is for organisations facing well-resourced, persistent threats. Instead, we settle this with you at scoping, based on your data, sector, and threat exposure rather than a default answer.
Because that's how attacks work. Specifically, the eight strategies are designed to reinforce each other — patching limits what an attacker can exploit, application control limits what they can run, MFA limits what a stolen password buys them. Leave one strategy behind and you've handed over the path of least resistance, no matter how strong the other seven are. As a result, every Essential Eight assessment we run makes that reality visible.
Typically, most assessments run two to four weeks end to end, scaling with the number of systems and sites in scope. Overall, disruption is minimal by design: a handful of interviews, read-only access to configurations, and scanning scheduled around your operations. Meanwhile, your team keeps working; we do the digging.
In fact, usually far less than people fear. Notably, the ASD deliberately keeps the framework vendor-neutral, and most requirements are met through capabilities already sitting in Microsoft 365, Windows, and your existing identity platform — application control policies, macro restrictions, MFA enforcement, backup configuration. Overall, our roadmaps exhaust what you already licence before recommending anything with a price tag.
In short, directly. The Essential Eight sits inside the Information Security Manual, which underpins RFFR accreditation — so maturity uplift here feeds your Statement of Applicability almost line for line. Additionally, it covers a meaningful slice of ISO 27001's technological controls. So if either of those programs is on your horizon, an Essential Eight assessment is the highest-leverage place to start, and we design the evidence so it's reusable across all three.
We assumed we were sitting at Level Two because our MSP said so. Instead, the Essential Eight assessment showed application control barely existed and half our servers were months behind on patches — Level Zero, with evidence we couldn't argue with. Eventually, six months into the roadmap we passed re-assessment at Level Two, and this time we can prove it.
Not sure where your
maturity really sits?
In short, book a readiness call and we'll scope your environment, agree the maturity level worth aiming for, and give you a fixed timeline and price for a full Essential Eight assessment.