Home / Resources / Essential Eight Self-Assessment
Free tool · ACSC Aligned

Essential Eight
Self-Assessment.

The ACSC's Essential Eight is a set of baseline mitigation strategies covering three key areas — prevention, limitation, and recovery — with each strategy scored against maturity levels M0 to M3. Answer 69 questions across all eight strategies and receive an indicative maturity result for your organisation.

Quick answer: An Essential Eight self-assessment scores your organisation against the ACSC's eight mitigation strategies, from Maturity Level 0 to Maturity Level 3. Answering 69 questions gives an indicative maturity rating per strategy and a baseline before a formal assessment.
Key facts: The Essential Eight Maturity Model rates each of the eight strategies from Maturity Level 0 to Maturity Level 3. This self-assessment asks 69 questions across all eight strategies and takes about 15 minutes. The result is indicative and does not replace a formal assessment.
69 Questions ~15 Minutes All 8 Strategies M0–M3 Levels
M0 M1 M2 M3 MATURITY

Start the Essential Eight Self Assessment

Please read the note below before starting. Enter your email and confirm to begin — your indicative maturity result will be delivered to your inbox on completion.

Before you start

The Essential Eight is a highly technical set of strategies. If you are not directly involved in the operational aspects of your organisation's IT infrastructure, you may not be able to answer the questions accurately, which can produce a misleading result. If you feel you are unable to answer accurately, a professional Essential Eight assessment will give you a reliable review of your current posture.

69
Questions Total
15min
Estimated Time
M0–M3
Result Scale

Enter your details to begin

Your indicative maturity report will be sent to the email address you provide. We do not share this address with third parties.

Consent to proceed
I agree — start the assessment

I have read the note above and understand the result is indicative only.

I don't agree — take me back

I would prefer not to proceed with the self-assessment right now.

Source: ACSC Essential Eight

Great — you're all set.

The assessment link and your session details are on their way to . If you don't see the email within a few minutes, please check your junk folder or contact us directly.

Contact Support

No problem — no assessment started.

If a professional review would suit you better, our team can run a full Essential Eight assessment with a defensible score and a prioritised uplift plan.

Talk to an Expert
Disclaimer

This self-assessment is based on the mitigation strategies published by the ACSC's Essential Eight and is intended to provide a broad indication of your organisation's overall cybersecurity maturity. Information is drawn from the ACSC Essential Eight webpage. Cyber Compliance Pro is not responsible for any errors, omissions, or results obtained from the use of this information. All content is provided "as is", with no guarantee of completeness, accuracy, or veracity of the results. This self-assessment is a guide only and should not replace professional advice in any capacity.

What's included

Six stages of your Essential Eight Self Assessment

Some clients want a one-off Essential Eight self assessment for the board or an insurer. Others, meanwhile, need the full arc — assessment, remediation, and, ultimately, a re-test that proves the uplift landed. The engagement is built in stages so you take exactly what you need.

Essential Eight self assessment scorecard showing maturity ratings per strategy
01 · SCOPE

Scoping & Target Level

First, we map your environment, agree the systems in scope, and settle the maturity level your risk profile genuinely calls for — all before any testing begins.

  • Asset and system discovery
  • Target maturity level agreed with leadership
  • Stakeholder interviews and access planning
02 · TEST

Essential Eight Technical Assessment

Each of the eight strategies gets examined hands-on — configurations pulled, policies checked against reality, and gaps confirmed rather than assumed. This is the core of every Essential Eight self assessment we run.

  • Configuration and policy review per control
  • Vulnerability scanning across the fleet
  • Patch, privilege, and MFA coverage checks
03 · SCORE

Essential Eight Maturity Scoring

Every strategy is rated ML0 to ML3 strictly against the ACSC criteria; moreover, the evidence sits next to each rating, so nothing rests on opinion.

  • Per-strategy ratings with supporting evidence
  • Overall maturity level determination
  • Gap register ranked by attack likelihood
04 · REPORT

Report & Executive Debrief

Findings from your Essential Eight assessment arrive as a written report and a walkthrough for both audiences: technical detail for IT, and a plain-language risk picture for the executive team.

  • Full findings report with maturity scorecard
  • Executive briefing session
  • Q&A with the assessors who did the work
05 · UPLIFT

Remediation Support

From there, the roadmap sequences fixes by impact and effort — quick wins first, and then the structural changes planned properly. Your team can run it, or ours can work alongside them.

  • Prioritised 12–18 month uplift roadmap
  • Hands-on remediation where you want it
  • Built on tools you already licence
06 · RE-ASSESS

Verification & Annual Review

Maturity drifts — patch cycles slip, exceptions accumulate, new systems arrive unhardened. As a result, a scheduled re-assessment keeps your rating real rather than historical.

  • Post-remediation re-testing
  • Annual maturity reviews
  • Drift alerts after major IT changes
Why it matters

What your Essential Eight Self Assessment actually delivers

The Essential Eight earns its reputation by being narrow on purpose; that is, it targets the specific techniques behind ransomware, credential theft, and business email compromise, rather than trying to cover everything at once.

Defence

Real Attack Paths, Closed

Ransomware · BEC · Credential Theft

In practice, the eight strategies interrupt the standard intrusion playbook — the malicious attachment that can't execute, the stolen password that hits MFA, the admin account that no longer exists.

Expectation

The Benchmark Everyone Asks About

Government · Tenders · Supply Chains

Mandatory for federal agencies under the Protective Security Policy Framework and increasingly a standing question in tenders and supplier reviews. A verified Essential Eight assessment answers it before it's asked.

Insurance

A Stronger Insurance Position

Eligibility & Premiums

Cyber insurers use Essential Eight alignment as shorthand for a well-run security program. Documented maturity, therefore, supports eligibility and gives you leverage at renewal.

Efficiency

Built On What You Already Own

Microsoft 365 · Native OS Tooling

Typically, most of the uplift that follows an Essential Eight self assessment comes from configuring platforms you already licence — application control, macro restrictions, MFA — not from buying another security product.

Leverage

One Assessment, Many Frameworks

ISM · RFFR · ISO 27001

Often, Essential Eight work carries straight into ISM alignment, RFFR accreditation, and the technological controls of ISO 27001 — evidence gathered once, reused everywhere.

Clarity

A Number The Board Understands

ML0 → ML3

In short, security posture compressed into a rating leadership can track quarter over quarter — where you are, where you're heading, and what closing the gap will cost.

What gets assessed

Eight Essential Eight Self Assessment strategies. One rating each.

Ultimately, every strategy below is scored independently during your Essential Eight self assessment against the ACSC's published maturity criteria — and your overall level is set by the lowest of the eight. Because of that, a serious assessment checks all of them with equal rigour: the control nobody's been watching is, after all, the one that decides your rating.

Request a Maturity Snapshot

Application Control

Only Approved Software Runs

Patch Applications

Known Holes, Closed Fast

Patch Operating Systems

The Fleet Stays Current

Restrict Office Macros

Internet Macros Blocked

User Application Hardening

Attack Surface Trimmed

Restrict Admin Privileges

Least Privilege, Enforced

Multi-Factor Authentication

Passwords Aren't Enough

Regular Backups

Tested, Isolated, Restorable
FAQ

Essential Eight self-assessment questions

What is the Essential Eight self-assessment?

A 69-question self-assessment covering all eight ACSC Essential Eight strategies. It gives an indicative maturity result for your organisation.

How long does the Essential Eight self-assessment take?

About 15 minutes.

Is the self-assessment the same as a formal Essential Eight assessment?

No. The self-assessment gives an indicative result based on your own answers. A formal assessment tests the evidence behind each rating.