HomeFrameworksNational Cyber & Cloud SchemesEssential 8

Framework  National Cyber & Cloud Schemes

Essential 8

The Essential Eight is the Australian Signals Directorate's set of eight prioritized mitigation strategies for internet-connected Windows-based enterprise networks: patch applications, patch operating systems, multifactor authentication, restrict administrative privileges, application control, restrict Microsoft Office macros, user application hardening, and regular backups.

The Essential Eight Maturity Model rates each strategy at Maturity Level Zero through Three, and an organization's overall level is the lowest level it reaches across all eight.

The model was substantially updated in November 2023 to use the same wording as the Information Security Manual (ISM) controls, to require patching of critical vulnerabilities within 48 hours, and to tighten MFA and logging expectations.

Under the Protective Security Policy Framework, non-corporate Commonwealth entities must reach Maturity Level Two, and many state governments, regulated sectors, and large buyers push the same expectation onto suppliers by contract.

The Essential Eight is not a certification. Entities self-assess using ASD's Essential Eight Assessment Process Guide, and independent assessments are commonly performed by IRAP assessors or specialist firms following that guide.

In writing, an organization needs a scope definition, the assessment against each strategy's requirements at the target level, configuration evidence and technical test results (for example application control bypass testing, patch age reports, MFA configuration exports, privileged account inventories), backup and restoration test records, and a remediation plan for gaps.

AI-compiled
Share
Sponsored
Essential
help
Consultants  Assessors  Quotes
Matched3 quotesread by a human
The Shortlist is Yoursfrom this directory
Comply the Modern WayFind help with Essential 8
01
Verified listings first
Unverified ones follow, labeled
02
Published prices where they exist
“Quote only” where we confirmed it, “Not published” where we have not
03
Up to three quotes, one form
Firms don’t see you until you choose
House ad. This slot is open to firms listed for this page. Get help Advertise here

Who has to comply

Mandatory at Maturity Level Two for non-corporate Commonwealth entities under PSPF Policy 10; adopted as policy by several Australian state governments for their agencies; voluntary for everyone else but widely written into contracts, insurance questionnaires, and sector regulator expectations (for example APRA-regulated entities and critical infrastructure operators under the SOCI Act).

What the assessor asks to see

Scope and asset inventory; patch management reports showing age of application and operating system patches against the 48-hour, two-week, and one-month timelines; MFA configuration and coverage for users, privileged accounts, and remote access; privileged account inventory, separation, and just-in-time controls; application control policy and bypass test results; Office macro settings; browser and application hardening configuration; backup schedules, restoration tests, and access restrictions on backups; centralized logging evidence; the assessment report against each strategy at the target level; remediation plan.

Maturity levels

Level Zero indicates weaknesses in the organization's posture; Level One targets adversaries using commodity tradecraft; Level Two targets adversaries willing to invest more effort; Level Three targets more adaptive adversaries. The organization's level is the lowest achieved across all eight strategies.

Assessors

Who assesses Essential 8

Self-assessment by the entity following ASD's assessment guide; independent assessment by IRAP assessors (for Commonwealth reporting) or by specialist assessment firms. ASD does not certify Essential Eight compliance. Accredited by ASD endorses IRAP assessors; no accreditor exists for other Essential Eight assessors.

Public register of assessors: https://www.cyber.gov.au/business-government/protecting-devices-systems/assessment-evaluation-programs/irap/irap-assessors

No firm has claimed a Essential 8 assessor listing yet. Claim yours →

Consultants

Who helps with Essential 8

Australian managed service providers and cybersecurity consultancies offer Essential Eight uplift and assessment services; ASD publishes free implementation and assessment guides. Uplift to Level Two typically takes three to twelve months depending on the environment.

Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.

No firm has claimed a Essential 8 consultant listing yet. Claim yours →

Software

Tools for Essential 8

Tools that name this framework in their own material.

No firm has claimed a Essential 8 tool listing yet. Claim yours →

Related reading

  1. Australian security and compliance: Essential Eight maturityPlaces the Essential Eight inside the wider ISM and PSPF obligations, and explains which entities the maturity levels bind.Amazon Web Services
  2. ACSC Essential Eight overviewWalks the eight mitigation strategies and the maturity model, showing what evidence each level expects.Microsoft

Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.

Need a hand implementing it?

Find a Consultant for Essential 8

Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.

Not sure where to start?

Get Help with Essential 8

Tell us what you are trying to put in place. We will point you to the right tool, a consultant who can implement it, or both.

About this data

Pages on this site are compiled with AI from two or more linked sources, rewritten in our words, and reviewed by people in stages. Each record shows its stage and date. Nothing here is legal, audit or tax advice, and policyandcompliance.com accepts no responsibility for errors or for decisions made on it. Read the source, then decide.
How we compile and verify →

Think something is wrong?

[email protected]
Tell us the page and what you found. We check it against the source and fix it.
Corrections log →

Want to advertise here?

[email protected]
A primary ad and a secondary placement, flat fee. Buying one changes nothing else on the page.