Essential Eight
Self-Assessment.
The ACSC's Essential Eight is a set of baseline mitigation strategies covering three key areas — prevention, limitation, and recovery — with each strategy scored against maturity levels M0 to M3. Answer 69 questions across all eight strategies and receive an indicative maturity result for your organisation.
Start the Essential Eight Self Assessment
Please read the note below before starting. Enter your email and confirm to begin — your indicative maturity result will be delivered to your inbox on completion.
Before you start
The Essential Eight is a highly technical set of strategies. If you are not directly involved in the operational aspects of your organisation's IT infrastructure, you may not be able to answer the questions accurately, which can produce a misleading result. If you feel you are unable to answer accurately, a professional Essential Eight assessment will give you a reliable review of your current posture.
Enter your details to begin
Your indicative maturity report will be sent to the email address you provide. We do not share this address with third parties.
I agree — start the assessment
I have read the note above and understand the result is indicative only.
I don't agree — take me back
I would prefer not to proceed with the self-assessment right now.
Great — you're all set.
The assessment link and your session details are on their way to . If you don't see the email within a few minutes, please check your junk folder or contact us directly.
Contact SupportNo problem — no assessment started.
If a professional review would suit you better, our team can run a full Essential Eight assessment with a defensible score and a prioritised uplift plan.
Talk to an ExpertDisclaimer
This self-assessment is based on the mitigation strategies published by the ACSC's Essential Eight and is intended to provide a broad indication of your organisation's overall cybersecurity maturity. Information is drawn from the ACSC Essential Eight webpage. Cyber Compliance Pro is not responsible for any errors, omissions, or results obtained from the use of this information. All content is provided "as is", with no guarantee of completeness, accuracy, or veracity of the results. This self-assessment is a guide only and should not replace professional advice in any capacity.
Six stages of your Essential Eight Self Assessment
Some clients want a one-off Essential Eight self assessment for the board or an insurer. Others, meanwhile, need the full arc — assessment, remediation, and, ultimately, a re-test that proves the uplift landed. The engagement is built in stages so you take exactly what you need.
Scoping & Target Level
First, we map your environment, agree the systems in scope, and settle the maturity level your risk profile genuinely calls for — all before any testing begins.
- Asset and system discovery
- Target maturity level agreed with leadership
- Stakeholder interviews and access planning
Essential Eight Technical Assessment
Each of the eight strategies gets examined hands-on — configurations pulled, policies checked against reality, and gaps confirmed rather than assumed. This is the core of every Essential Eight self assessment we run.
- Configuration and policy review per control
- Vulnerability scanning across the fleet
- Patch, privilege, and MFA coverage checks
Essential Eight Maturity Scoring
Every strategy is rated ML0 to ML3 strictly against the ACSC criteria; moreover, the evidence sits next to each rating, so nothing rests on opinion.
- Per-strategy ratings with supporting evidence
- Overall maturity level determination
- Gap register ranked by attack likelihood
Report & Executive Debrief
Findings from your Essential Eight assessment arrive as a written report and a walkthrough for both audiences: technical detail for IT, and a plain-language risk picture for the executive team.
- Full findings report with maturity scorecard
- Executive briefing session
- Q&A with the assessors who did the work
Remediation Support
From there, the roadmap sequences fixes by impact and effort — quick wins first, and then the structural changes planned properly. Your team can run it, or ours can work alongside them.
- Prioritised 12–18 month uplift roadmap
- Hands-on remediation where you want it
- Built on tools you already licence
Verification & Annual Review
Maturity drifts — patch cycles slip, exceptions accumulate, new systems arrive unhardened. As a result, a scheduled re-assessment keeps your rating real rather than historical.
- Post-remediation re-testing
- Annual maturity reviews
- Drift alerts after major IT changes
What your Essential Eight Self Assessment actually delivers
The Essential Eight earns its reputation by being narrow on purpose; that is, it targets the specific techniques behind ransomware, credential theft, and business email compromise, rather than trying to cover everything at once.
Real Attack Paths, Closed
In practice, the eight strategies interrupt the standard intrusion playbook — the malicious attachment that can't execute, the stolen password that hits MFA, the admin account that no longer exists.
The Benchmark Everyone Asks About
Mandatory for federal agencies under the Protective Security Policy Framework and increasingly a standing question in tenders and supplier reviews. A verified Essential Eight assessment answers it before it's asked.
A Stronger Insurance Position
Cyber insurers use Essential Eight alignment as shorthand for a well-run security program. Documented maturity, therefore, supports eligibility and gives you leverage at renewal.
Built On What You Already Own
Typically, most of the uplift that follows an Essential Eight self assessment comes from configuring platforms you already licence — application control, macro restrictions, MFA — not from buying another security product.
One Assessment, Many Frameworks
Often, Essential Eight work carries straight into ISM alignment, RFFR accreditation, and the technological controls of ISO 27001 — evidence gathered once, reused everywhere.
A Number The Board Understands
In short, security posture compressed into a rating leadership can track quarter over quarter — where you are, where you're heading, and what closing the gap will cost.
Eight Essential Eight Self Assessment strategies. One rating each.
Ultimately, every strategy below is scored independently during your Essential Eight self assessment against the ACSC's published maturity criteria — and your overall level is set by the lowest of the eight. Because of that, a serious assessment checks all of them with equal rigour: the control nobody's been watching is, after all, the one that decides your rating.
Request a Maturity SnapshotApplication Control
Only Approved Software RunsPatch Applications
Known Holes, Closed FastPatch Operating Systems
The Fleet Stays CurrentRestrict Office Macros
Internet Macros BlockedUser Application Hardening
Attack Surface TrimmedRestrict Admin Privileges
Least Privilege, EnforcedMulti-Factor Authentication
Passwords Aren't EnoughRegular Backups
Tested, Isolated, RestorableEssential Eight self-assessment questions
What is the Essential Eight self-assessment?
A 69-question self-assessment covering all eight ACSC Essential Eight strategies. It gives an indicative maturity result for your organisation.
How long does the Essential Eight self-assessment take?
About 15 minutes.
Is the self-assessment the same as a formal Essential Eight assessment?
No. The self-assessment gives an indicative result based on your own answers. A formal assessment tests the evidence behind each rating.