Framework National Cyber & Cloud Schemes
Essential 8
The Essential Eight is the Australian Signals Directorate's set of eight prioritized mitigation strategies for internet-connected Windows-based enterprise networks: patch applications, patch operating systems, multifactor authentication, restrict administrative privileges, application control, restrict Microsoft Office macros, user application hardening, and regular backups.
The Essential Eight Maturity Model rates each strategy at Maturity Level Zero through Three, and an organization's overall level is the lowest level it reaches across all eight.
The model was substantially updated in November 2023 to use the same wording as the Information Security Manual (ISM) controls, to require patching of critical vulnerabilities within 48 hours, and to tighten MFA and logging expectations.
Under the Protective Security Policy Framework, non-corporate Commonwealth entities must reach Maturity Level Two, and many state governments, regulated sectors, and large buyers push the same expectation onto suppliers by contract.
The Essential Eight is not a certification. Entities self-assess using ASD's Essential Eight Assessment Process Guide, and independent assessments are commonly performed by IRAP assessors or specialist firms following that guide.
In writing, an organization needs a scope definition, the assessment against each strategy's requirements at the target level, configuration evidence and technical test results (for example application control bypass testing, patch age reports, MFA configuration exports, privileged account inventories), backup and restoration test records, and a remediation plan for gaps.
help
Who has to comply
Mandatory at Maturity Level Two for non-corporate Commonwealth entities under PSPF Policy 10; adopted as policy by several Australian state governments for their agencies; voluntary for everyone else but widely written into contracts, insurance questionnaires, and sector regulator expectations (for example APRA-regulated entities and critical infrastructure operators under the SOCI Act).
What the assessor asks to see
Scope and asset inventory; patch management reports showing age of application and operating system patches against the 48-hour, two-week, and one-month timelines; MFA configuration and coverage for users, privileged accounts, and remote access; privileged account inventory, separation, and just-in-time controls; application control policy and bypass test results; Office macro settings; browser and application hardening configuration; backup schedules, restoration tests, and access restrictions on backups; centralized logging evidence; the assessment report against each strategy at the target level; remediation plan.
Maturity levels
Level Zero indicates weaknesses in the organization's posture; Level One targets adversaries using commodity tradecraft; Level Two targets adversaries willing to invest more effort; Level Three targets more adaptive adversaries. The organization's level is the lowest achieved across all eight strategies.
Assessors
Who assesses Essential 8
Self-assessment by the entity following ASD's assessment guide; independent assessment by IRAP assessors (for Commonwealth reporting) or by specialist assessment firms. ASD does not certify Essential Eight compliance. Accredited by ASD endorses IRAP assessors; no accreditor exists for other Essential Eight assessors.
Public register of assessors: https://www.cyber.gov.au/business-government/protecting-devices-systems/assessment-evaluation-programs/irap/irap-assessors
No firm has claimed a Essential 8 assessor listing yet. Claim yours →
Consultants
Who helps with Essential 8
Australian managed service providers and cybersecurity consultancies offer Essential Eight uplift and assessment services; ASD publishes free implementation and assessment guides. Uplift to Level Two typically takes three to twelve months depending on the environment.
Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.
No firm has claimed a Essential 8 consultant listing yet. Claim yours →
Software
Tools for Essential 8
Tools that name this framework in their own material.
No firm has claimed a Essential 8 tool listing yet. Claim yours →
Related reading
- Australian security and compliance: Essential Eight maturityPlaces the Essential Eight inside the wider ISM and PSPF obligations, and explains which entities the maturity levels bind.Amazon Web Services
- ACSC Essential Eight overviewWalks the eight mitigation strategies and the maturity model, showing what evidence each level expects.Microsoft
Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.
Need a hand implementing it?
Find a Consultant for Essential 8
Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.
Not sure where to start?
Get Help with Essential 8
Tell us what you are trying to put in place. We will point you to the right tool, a consultant who can implement it, or both.