Cybersecurity
Essential Eight compliance for Australian organisations
The Essential Eight is a maturity model, not a certification, and the Australian Signals Directorate has begun replacing it. This page covers what each maturity level requires, what the move to the Essentials series means for work you are doing now, and what to do when the requirement in front of you needs a certificate the Essential Eight does not produce.
How it works
Four things about the Essential Eight worth knowing before you start
The framework itself is published by the Australian Signals Directorate and is free to read. The difficulty is never understanding the eight strategies. It is evidencing them, and knowing which maturity level you are being asked for.
What you actually need
Maturity level or certificate
This is the fork that decides the whole programme, and it is settled by reading the request rather than by choosing a framework.
Essential Eight is right when
You work with government, bid for public sector contracts, or handle government data. It is the language used in that market, and IRAP assessment builds on the same foundations. It is also a sound risk reduction model on its own merits, whether or not anybody is asking.
Government and public sector
You need something else when
A client questionnaire, insurer or tender wants proof. The Essential Eight cannot produce that on its own because it is self-assessed. SMB1001 certifies at five tiers for businesses under two hundred people. ISO 27001 is the answer for enterprise procurement. The work overlaps heavily, so nothing is wasted.
When evidence is the requirement
How we help
Getting to a maturity level you can defend
We are vendor funded, so the service costs your business nothing.
Establish the target level, from the requirement
Level One, Two or Three. Ask the party requesting it rather than assuming Level Three is safer. Aiming too high is the most common reason these programmes never finish.
Assess against what you have
A gap assessment across all eight strategies, scored honestly at each maturity level. This usually shows more coverage than expected on some controls and none at all on others.
Turn on what you already own
Most Level One gaps close inside existing Microsoft or Google licensing. We do this before anything is purchased, because it changes what actually needs buying.
Close the remaining gaps in commercial order
Application control and privileged access are the expensive ones. We sequence them by risk reduction per dollar rather than by the order of the list.
Evidence it continuously
Point in time assessments go stale within a quarter. We put platform tooling in place that collects evidence continuously, so answering the next questionnaire is a report rather than a project.
Due diligence
What to check on an Essential Eight programme
These are the items that decide whether the work produces something defensible.
Which maturity level is required
Level One, Two and Three are materially different amounts of work. Get the number from the requesting party in writing before scoping anything.
Whether self-assessment is acceptable
Some requirements accept a self-assessment. Others want independent assessment. Ask, because the difference is a cost and a timeline, not a formality.
What is already licensed
Audit your Microsoft or Google entitlements before buying security products. Duplicate spend on already-owned controls is the most common waste in these programmes.
How application control will affect users
Level Two application control changes what people can install and run. Plan the exceptions process before rollout, or the control gets disabled within a month.
Who maintains the evidence
A maturity level is a claim about a point in time. Without continuous evidence collection it is out of date by the next quarter. Establish ownership before you start.
Whether the goal is really a certificate
If the actual driver is a client questionnaire or insurance renewal, the Essential Eight alone will not satisfy it. Check this at the outset rather than at the end.
How the Essentials series affects your timeline
If your programme runs past the next eighteen months, ask how the work maps to the Essentials series chapters. Contracts written today that name the Essential Eight will outlive it, so the wording is worth checking before signature.
Common questions
Questions about the Essential Eight
What Australian organisations ask us
What are the Essential Eight controls?
Application control, patch applications, configure Microsoft Office macro settings, user application hardening, restrict administrative privileges, patch operating systems, multi-factor authentication and regular backups. Each is assessed against four maturity levels, Zero through Three, published by the Australian Signals Directorate.
Is there an Essential Eight certification?
No. The Essential Eight is a maturity model that organisations self-assess against, and no certificate is issued. If you need third party evidence for a client, insurer or tender, SMB1001 certifies at five tiers for businesses under two hundred people, and ISO 27001 is the enterprise answer. An independent assessment against the Essential Eight is the middle option.
What maturity level do we need?
Whatever the party asking for it specifies. Level One is achievable for most organisations with configuration and discipline. Level Two introduces application control and stricter privilege management and is a genuine programme. Level Three is aimed at organisations facing targeted attackers. Aiming higher than required is the main reason these efforts stall.
How much does Essential Eight compliance cost?
Less than most quotes suggest, because much of Level One is configuration of licences you already hold. The real costs appear at Level Two, in application control and privileged access management, and in the internal time to evidence everything. We assess what you already own before anything gets priced.
How do we prove Essential Eight compliance to a client?
Either an independent assessment against the model, or continuous evidence from platform tooling that shows the controls operating rather than existing. A self-assessment spreadsheet satisfies some requesters and not others, so confirm what will be accepted before producing it.
Is the Essential Eight being retired?
Yes, over time. The Australian Signals Directorate opened public consultation on 15 June 2026 on replacing it with the Essentials series, which covers enterprise IT, cloud and operational technology as separate chapters rather than one fixed maturity ladder. The Essential Eight remains supported and in use, starts being deprecated in roughly twelve months and retires in roughly twenty four. Work done against it is not wasted, because the underlying controls carry across, and government tenders still reference it today.
Can you help with the Essential Eight?
Yes. We run the gap assessment, tell you what your existing licences already cover, sequence the remaining work by risk reduction, and provide the tooling that evidences it continuously. We are vendor funded, so the service costs your business nothing.
We are vendor funded and completely free to your business. Always focused on the right outcome.
Find out what your licences already cover.
Most organisations are further along the Essential Eight than they think and are being quoted for controls they already own. Answer six questions and we will tell you where you actually stand, which maturity level you need, and what the move to the Essentials series changes.
Book a Call
Independent guidance at no cost to your business.
Read further on this
The pages and articles that answer the next question a buyer usually asks.
- Our advice on cybersecurity advisory
- Check where you stand
- Cyber security services Brisbane
- Cyber security services Melbourne
- Cyber security services Sydney
- iso-27001
- mdr
- penetration-testing
- security-services-explained
- security-standards-compared
- smb1001-certification
- virtual-ciso
- the incident response pack, free download
- the IT continuity pack, free download
- connectivity and SD-WAN
- advice for IT leaders
- advice for finance leaders
- ACMA’s 2026-27 priorities, and the SMS deadline

