Essential Eight compliance, done properly.
The Australian Signals Directorate's Essential Eight is the baseline every organisation is measured against, whether by government tenders, insurers or clients. We assess where you actually stand across all eight controls, then remediate the gaps, with Australian engineers and plain-English reporting.
The Essential Eight usually stops being optional the day someone asks you about it
- A government or enterprise tender asks you to attest to an Essential Eight maturity level
- Your cyber-insurance renewal now asks about MFA, patching and backups
- A larger client's supply-chain security questionnaire landed on your desk
- You've been breached, or had a near miss, and need to know which doors are still open
Eight controls. Where most businesses fall short.
Each control below is what the ASD asks for, and the honest version of where small businesses usually fall down. Most SMBs sit between Maturity Level Zero and One on several of these and don't know it.
Application control
Only software you've approved runs; everything else is blocked by default, including the malicious attachment someone just double-clicked.
Where it falls short: Almost nobody implements it, so any executable a staff member is tricked into running runs with their permissions, no questions asked.
Patch applications
Keep everyday software current: browsers, Office, PDF readers, anything internet-facing. Critical vulnerabilities on exposed systems patched within 48 hours.
Where it falls short: The OS gets remembered; the long tail of apps does not. An outdated PDF reader or browser plugin is a common way in.
Restrict Office macros
Block macros in documents that came from the internet, and only allow them where there's a genuine, controlled business need.
Where it falls short: Left fully enabled because one old spreadsheet needs them, and that single exception holds the door open for every malicious document after it.
User application hardening
Turn off the risky features in daily-use software: block ads and untrusted code in browsers, disable legacy plugins, stop apps doing what they don't need to.
Where it falls short: Most browsers and Office installs run on factory defaults, which favour convenience over safety, exactly what malvertising and drive-by downloads rely on.
Restrict admin privileges
Admin rights go only to people who genuinely need them, are used only for admin work, and the list is reviewed regularly.
Where it falls short: Everyone ends up a local admin on their own machine because it was easier during setup, and IT runs everything from one all-powerful account.
Patch operating systems
Keep Windows, macOS and servers current, and retire anything the vendor no longer supports.
Where it falls short: The forgotten machine: the old server in the cupboard running the one app nobody wants to touch, on a version that stopped getting updates years ago.
Multi-factor authentication
A password alone shouldn't be enough. A second factor is required, especially for email, remote access, and anything holding customer or financial data.
Where it falls short: Switched on for the obvious things and skipped for the rest: an old mail protocol, a remote-access tool, or an admin account that quietly bypasses it.
Regular backups
Back up important data and configuration, keep copies somewhere an attacker can't reach or delete, and test that you can actually restore.
Where it falls short: Backups that have never been restored, so nobody knows they work. Or backups sitting online and writable, so the ransomware encrypts them too.
What "compliant" actually means.
The ASD grades each control from Level Zero to Level Three. You don't need to memorise the framework, but the levels are the language tenders and insurers use.
Level Zero
The control isn't really in place. More common than anyone admits.
Level One
Done well enough to stop opportunistic, spray-and-pray attacks that hit everyone.
Level Two
Done well enough to slow down an attacker putting in real, targeted effort.
Level Three
Done well enough to hold up against a capable, determined adversary.
For most Australian SMBs, honestly reaching Level One across all eight is a strong, achievable position, and a long way ahead of where most businesses sit.
Assess, remediate, maintain.
1. Assess
We rate every one of the eight controls against the ASD maturity levels: external signals via the Security Health Check, internal controls reviewed with you directly. You get a per-control maturity rating and a prioritised gap list. No 90-page PDF.
2. Remediate
We close the gaps that matter first: MFA rollout, patch management, admin-privilege cleanup, macro and browser hardening, application control, and a backup regime with tested restores. Fixed, not just flagged.
3. Maintain
Patching, backups and MFA decay the moment a project ends. Under Managed Services we keep the controls current, so the maturity level you paid to reach is the one you still have in twelve months.
The assessment is delivered through our Security Health Check (AUD $2,500), which maps every finding back to the Essential Eight. Ongoing control maintenance runs under Managed Services.
There is no Essential Eight "certificate" for SMBs
The ASD does not run an Essential Eight certification scheme for small business, so anyone selling you a certificate is selling you something that doesn't officially exist. What's real is an honest, evidence-based maturity assessment and the remediation to reach a target level, documented well enough to answer a tender or an insurer. That's what we provide.
Know which doors are open. Shut the ones that matter.
Start with a conversation about your obligations and where you stand today. Fixed-price assessment, with remediation quoted on the actual gaps. No surprises.
Australian businesses. Local engineers. No offshore subcontracting.
Want to self-assess first? Our plain-English Essential Eight checklist walks through all eight controls with a question you can answer yourself for each. The findings map to the official ASD Essential Eight guidance.
Frequently asked questions
- Is the Essential Eight mandatory for my business?
- For most private-sector Australian SMBs, no. It isn't a legal requirement. It is mandatory for non-corporate Commonwealth entities. But it's increasingly the yardstick that government tenders, cyber-insurance underwriters and larger clients measure you against, so in practice a growing number of businesses need to demonstrate it to win or keep work.
- Do I need the Essential Eight for a government tender?
- Often, yes. Many Australian government and enterprise tenders now ask suppliers to attest to a specific Essential Eight maturity level (commonly Maturity Level One or Two) as a condition of eligibility. We assess where you stand, tell you the gap to the level a tender requires, and remediate the controls that are short.
- What maturity level should we target?
- For most SMBs, honestly reaching Maturity Level One across all eight controls is a strong, achievable baseline, and well ahead of where most businesses sit today. Level Two or Three are worth pursuing when a specific contract, regulator or risk profile demands it. We'll recommend a target based on your actual obligations, not sell you the highest tier by default.
- How do you assess our Essential Eight maturity?
- We start with the externally observable controls (patching signals, MFA on public services, exposed systems) via our Security Health Check, then review the internal controls that can't be seen from outside (application control, macro settings, admin privilege, backup testing) with you directly. The output is a per-control maturity rating (Level Zero to Three) and a prioritised gap list.
- How much does it cost?
- An Essential Eight assessment starts with our fixed-price Security Health Check at AUD $2,500, which maps every finding back to the Essential Eight, NIST and OWASP. Remediation (closing the gaps) is quoted separately once we know the actual gaps. There's no point pricing a fix before we know what's broken. Ongoing maintenance of the controls can run under a Managed Services engagement.
- Can you fix the gaps, not just report them?
- Yes. That's the point. Reporting is the easy part. We remediate the controls that are short: MFA rollout, patch management, admin-privilege cleanup, macro and browser hardening, and backup regimes with tested restores. Several of these controls (patching, backups, MFA) are then kept current under Managed Services so your maturity doesn't quietly decay after the project ends.
- Is this an Essential Eight certification?
- No, and be wary of anyone selling one. The ASD does not run an Essential Eight certification scheme for SMBs. What you can have is an honest, evidence-based maturity assessment and the remediation to reach a target level. We give you the documented assessment; we don't hand out a badge that doesn't officially exist.