Cybersecurity

Essential Eight compliance for Australian organisations

The Essential Eight is a maturity model, not a certification, and the Australian Signals Directorate has begun replacing it. This page covers what each maturity level requires, what the move to the Essentials series means for work you are doing now, and what to do when the requirement in front of you needs a certificate the Essential Eight does not produce.

How it works

Four things about the Essential Eight worth knowing before you start

The framework itself is published by the Australian Signals Directorate and is free to read. The difficulty is never understanding the eight strategies. It is evidencing them, and knowing which maturity level you are being asked for.

01

Eight strategies, four maturity levels

Application control, patching applications, configuring Office macros, user application hardening, restricting administrative privileges, patching operating systems, multi-factor authentication and regular backups. Each is assessed at Maturity Level Zero through Three. The level is what the requirement usually specifies, and it is what most conversations skip.

02

Level One is achievable, Level Two is a programme

Most organisations reach Level One with configuration and discipline. Level Two introduces application control and stricter privilege management, which changes how people work day to day. That step is where Essential Eight projects stall, and it is worth planning for rather than discovering.

03

It produces no certificate

The Essential Eight is self-assessed. There is no certificate and no third party issuing one. If a client or an insurer wants evidence rather than an assertion, you need either an independent assessment against the model, or a standard that certifies, such as SMB1001 or ISO 27001.

04

Most of it is already in your licences

Multi-factor authentication, patching, macro settings, application hardening and backups are largely configuration inside Microsoft 365 or Google Workspace. Organisations regularly buy products to satisfy controls they already own and have not enabled.

05

It is being replaced, and the work still counts

On 15 June 2026 the Australian Signals Directorate opened consultation on retiring the Essential Eight and replacing it with the Essentials series, a multi-chapter body of guidance covering enterprise IT, cloud and operational technology. The Essential Eight stays supported, begins deprecation in around twelve months and retires in around twenty four. The reason is that a fixed maturity ladder built for on-premises IT does not map onto cloud and shared responsibility models. Controls you implement now carry across, so this is a reason to plan the sequence rather than a reason to wait.

What you actually need

Maturity level or certificate

This is the fork that decides the whole programme, and it is settled by reading the request rather than by choosing a framework.

Essential Eight is right when

You work with government, bid for public sector contracts, or handle government data. It is the language used in that market, and IRAP assessment builds on the same foundations. It is also a sound risk reduction model on its own merits, whether or not anybody is asking.

Government and public sector

You need something else when

A client questionnaire, insurer or tender wants proof. The Essential Eight cannot produce that on its own because it is self-assessed. SMB1001 certifies at five tiers for businesses under two hundred people. ISO 27001 is the answer for enterprise procurement. The work overlaps heavily, so nothing is wasted.

When evidence is the requirement

How we help

Getting to a maturity level you can defend

We are vendor funded, so the service costs your business nothing.

01

Establish the target level, from the requirement

Level One, Two or Three. Ask the party requesting it rather than assuming Level Three is safer. Aiming too high is the most common reason these programmes never finish.

02

Assess against what you have

A gap assessment across all eight strategies, scored honestly at each maturity level. This usually shows more coverage than expected on some controls and none at all on others.

03

Turn on what you already own

Most Level One gaps close inside existing Microsoft or Google licensing. We do this before anything is purchased, because it changes what actually needs buying.

04

Close the remaining gaps in commercial order

Application control and privileged access are the expensive ones. We sequence them by risk reduction per dollar rather than by the order of the list.

05

Evidence it continuously

Point in time assessments go stale within a quarter. We put platform tooling in place that collects evidence continuously, so answering the next questionnaire is a report rather than a project.

Due diligence

What to check on an Essential Eight programme

These are the items that decide whether the work produces something defensible.

Which maturity level is required

Level One, Two and Three are materially different amounts of work. Get the number from the requesting party in writing before scoping anything.

Whether self-assessment is acceptable

Some requirements accept a self-assessment. Others want independent assessment. Ask, because the difference is a cost and a timeline, not a formality.

What is already licensed

Audit your Microsoft or Google entitlements before buying security products. Duplicate spend on already-owned controls is the most common waste in these programmes.

How application control will affect users

Level Two application control changes what people can install and run. Plan the exceptions process before rollout, or the control gets disabled within a month.

Who maintains the evidence

A maturity level is a claim about a point in time. Without continuous evidence collection it is out of date by the next quarter. Establish ownership before you start.

Whether the goal is really a certificate

If the actual driver is a client questionnaire or insurance renewal, the Essential Eight alone will not satisfy it. Check this at the outset rather than at the end.

How the Essentials series affects your timeline

If your programme runs past the next eighteen months, ask how the work maps to the Essentials series chapters. Contracts written today that name the Essential Eight will outlive it, so the wording is worth checking before signature.

Common questions

Questions about the Essential Eight

What Australian organisations ask us

What are the Essential Eight controls?

Application control, patch applications, configure Microsoft Office macro settings, user application hardening, restrict administrative privileges, patch operating systems, multi-factor authentication and regular backups. Each is assessed against four maturity levels, Zero through Three, published by the Australian Signals Directorate.

Is there an Essential Eight certification?

No. The Essential Eight is a maturity model that organisations self-assess against, and no certificate is issued. If you need third party evidence for a client, insurer or tender, SMB1001 certifies at five tiers for businesses under two hundred people, and ISO 27001 is the enterprise answer. An independent assessment against the Essential Eight is the middle option.

What maturity level do we need?

Whatever the party asking for it specifies. Level One is achievable for most organisations with configuration and discipline. Level Two introduces application control and stricter privilege management and is a genuine programme. Level Three is aimed at organisations facing targeted attackers. Aiming higher than required is the main reason these efforts stall.

How much does Essential Eight compliance cost?

Less than most quotes suggest, because much of Level One is configuration of licences you already hold. The real costs appear at Level Two, in application control and privileged access management, and in the internal time to evidence everything. We assess what you already own before anything gets priced.

How do we prove Essential Eight compliance to a client?

Either an independent assessment against the model, or continuous evidence from platform tooling that shows the controls operating rather than existing. A self-assessment spreadsheet satisfies some requesters and not others, so confirm what will be accepted before producing it.

Is the Essential Eight being retired?

Yes, over time. The Australian Signals Directorate opened public consultation on 15 June 2026 on replacing it with the Essentials series, which covers enterprise IT, cloud and operational technology as separate chapters rather than one fixed maturity ladder. The Essential Eight remains supported and in use, starts being deprecated in roughly twelve months and retires in roughly twenty four. Work done against it is not wasted, because the underlying controls carry across, and government tenders still reference it today.

Can you help with the Essential Eight?

Yes. We run the gap assessment, tell you what your existing licences already cover, sequence the remaining work by risk reduction, and provide the tooling that evidences it continuously. We are vendor funded, so the service costs your business nothing.

We are vendor funded and completely free to your business. Always focused on the right outcome.

Find out what your licences already cover.

Most organisations are further along the Essential Eight than they think and are being quoted for controls they already own. Answer six questions and we will tell you where you actually stand, which maturity level you need, and what the move to the Essentials series changes.

Book a Call

Independent guidance at no cost to your business.

Read further on this

The pages and articles that answer the next question a buyer usually asks.