Konfirmity

Part of the Essential Eight compliance guide

The Essential Eight in a Government Tender: How to Answer It

Amit Gupta

Amit Gupta

2026-10-05

The Essential Eight in a Government Tender: How to Answer It

An Essential Eight requirement in an Australian government tender asks you to state a maturity level for each of the eight mitigation strategies, with evidence behind it. There is no certificate to attach and no body that issues one. What you hand over is a rating per strategy, the scope it covers, the date it was assessed, and who owns it.

The Essential Eight for government tenders therefore rewards a different skill than most security questions do. The work is not producing a document. It is reading the requirement precisely enough to answer the question that was asked, then answering in terms you can defend under a follow-up.

Vendors lose these responses two ways: by answering a different question than the one in the tender, and by claiming a level the evidence will not carry.

Essential Eight for Government Tenders Starts With Reading the Ask

Read the ask before you write anything, because the phrase "Essential Eight" in a tender can mean at least four materially different requirements.

  • A maturity level across all eight strategies. The most common shape, and the one needing the most evidence. An Essential Eight maturity level 2 requirement is the version most commonly named in Australian government supply chain requirements, which makes it a practical target rather than an aspirational one.
  • A level on specific strategies only. Some buyers care about multi-factor authentication, patching and backups for the service they are buying and say nothing about the rest.
  • An assessment by an independent party. A more expensive ask than the first two, with a lead time you need to know about on day one.
  • A description of your posture against the eight. A narrative answer, not a rating. Over-answering this one with a formal assessment wastes weeks you did not have.

These get conflated constantly. One vendor commissions an independent assessment nobody requested; another reads "describe your alignment with the Essential Eight" and sends a paragraph where a per-strategy rating was expected.

Write the requirement out in your own words before drafting, and if it is ambiguous, ask during the clarification window. Requirements vary by buyer, so the binding version is the one in front of you — not a rule you can look up.

There Is No Certificate and No Certification Body

There is no Essential Eight certificate and no certification body, so nothing exists for you to attach. The Essential Eight maturity model is published by the Australian Signals Directorate as a rating scale, not a certification scheme.

What a buyer receives is a stated maturity level per strategy with the evidence behind it. That evidence is technical configuration — enforcement state, coverage against an inventory, exception registers, a recorded restoration test — not policy documents and not a logo.

A vendor who writes "we are Essential Eight certified" in a bid is telling an experienced evaluator that this is their first time. The same goes for "Essential Eight compliant" used as a binary, because the model has no pass mark — it has four levels per strategy. An evaluator who knows the model reads either phrase as a reason to probe harder, and probing is where overstated claims come apart.

Some tenders do ask for an Essential Eight attestation. That is a signed statement of your own rating and its scope, signed by someone in your organisation who can stand behind it — not a credential anyone issues to you. Read the wording, because an attestation and an independent assessment carry very different lead times.

Self-Assessment or Independent Assessment

Both self-assessment and independent assessment are used, and the tender usually says which one the buyer expects. Where it does not, ask.

A self-assessment is legitimate. ASD publishes an assessment process guide describing how to perform one rigorously, and for many buyers a current self-assessment with evidence per strategy is exactly what they want.

An independent assessment carries more weight, and is more often expected when the contract involves systems the buyer treats as sensitive, when a prime is flowing a requirement down and needs something it can rely on without re-testing, or when the requirement names an external party. It also takes longer to arrange than vendors expect — the practical reason to read the requirement on day one rather than the week before submission.

The failure mode for self-assessment is not dishonesty. It is that the team owning a control rates its own control, and a two-year-old exception stops looking like a gap. Our Essential Eight assessment guide covers the evidence each strategy needs and the four places ratings get inflated.

Tender open and no current rating to put in it?

Share your work email and we'll map the requirement in your tender to a per-strategy answer you can evidence, and mark where a target and a dated plan is the honest response.

We check that your email domain is real and can receive mail before sending. If we can't verify it, we won't be able to follow up — so please use a work address rather than a forwarding or temporary one.

We'd like to know who we're talking to. By submitting this form you agree that we may contact you about Konfirmity — no more than six emails a year, and we won't ask again each time. You can unsubscribe from any of them, and we'll stop. See our Privacy Policy.

The Scoping Question That Trips Vendors

The scoping question decides how much work the requirement is, and vendors guess at it instead of asking: does it attach to the systems delivering the service, to your corporate environment, or to both?

These are not close to equivalent. A requirement scoped to the production environment may be answerable from infrastructure you already control tightly. One scoped to your corporate fleet brings in every laptop, every contractor machine, every system inherited through acquisition, and the strategies that live on endpoints — Office macro settings, user application hardening, application control. Both is the sum of the two, and the endpoint half is the harder half.

Scope too narrowly and your answer collapses when the buyer clarifies that corporate devices are included. Scope too broadly and you have committed to an uplift programme the contract never required.

Ask in writing during clarifications, and state the scope in the answer you give. "Maturity level two across all eight for the corporately managed fleet and the production environment delivering this service; contractor-owned devices are excluded and have no access to either" survives the follow-up. "Level two" does not.

Why an Honest Level Beats an Overstated One

An honest level beats an overstated one for a reason that has nothing to do with ethics: a claimed level an assessment would not support surfaces during procurement or during an incident, and both are the most expensive moments available.

During procurement it surfaces as a question: what enforcement state is application control in, and when was the backup last restored? What follows is either the claim unravelling in front of the buyer or a vendor discovering live that they do not know. During an incident it surfaces worse — a contractual problem on top of a security one, because you stated a level, the buyer relied on it, and the control that failed is one you said was implemented.

Overstating is also the most common failure, not a rare one. The four patterns behind nearly every inflated rating are familiar: application control left in audit mode and counted as enforcement, coverage measured against the managed fleet while contractors and acquisitions are quietly excluded, exceptions with no expiry that have become the configuration, and backups never actually restored. Each is findable in an afternoon by anyone who looks deliberately — including the buyer's assessor. A lower honest level has none of that exposure.

How to Answer When You Are Below the Level Asked

When you are below the level asked, answer with four things rather than a claim: the current rating per strategy, the target, a dated plan to reach it, and the evidence behind the rating you already hold.

In practice: state the level you can evidence today for each of the eight, naming the strategies that sit lower and why. State the target the requirement asks for. Give the uplift plan with dates and a named owner per strategy, sequenced honestly — patching and multi-factor authentication move fastest, application control sets the pace. Then offer the evidence for what you already hold.

Buyers accept this more often than vendors expect. Procurement teams deal with gaps constantly; what they handle badly is a gap they discover themselves after relying on a claim. A dated plan is a known risk they can price and monitor.

The one version that fails is the undated one. "We are working toward level two" with no rating, no dates and no owner reads as nothing at all.

What to Have Ready Before the Tender Appears

Have the answer assembled before the tender appears, because the response window is never long enough to produce a first assessment from scratch. If selling to Australian government is part of your pipeline, security questions arrive as a request for a maturity rating rather than a certificate check. Four things make the difference:

  • A current rating per strategy, with the evidence behind it. Eight ratings, each traceable to configuration rather than recollection.
  • The scope stated explicitly. Which fleet, which systems, what is excluded and why — written down in advance so you are not inventing the boundary under deadline.
  • The date of the assessment. A rating more than a year old describes a configuration that has since changed, and stating it as current is a claim you may not be able to support.
  • A named owner per strategy, so a buyer's follow-up reaches someone who can answer it the same day.

Reassess annually and ahead of any procurement cycle you expect to enter. If the same buyers also ask for ISO 27001, how the two frameworks differ is worth settling early, because an ISMS certificate does not evidence the eight. ASD publishes the maturity model and its supporting guidance at cyber.gov.au, which is the reference to work from rather than a vendor summary.

Why All Eight Move Together in a Bid

All eight move together, so a strong rating on three strategies and level zero on one reads badly to anyone who understands the model. ASD's guidance is to implement all eight to the same maturity level before advancing any of them, and an assessment reports the weakest strategy because that is what determines the outcome.

An evaluator who knows this reads your eight ratings as a set and looks straight at the lowest one. Level three for multi-factor authentication beside level zero for application control does not read as partial progress. It reads as a team that spent its budget where the tooling was easy, which is exactly what happened.

Uneven maturity has a predictable shape. Patching and MFA have mature tooling and obvious owners, so they move. Application control and restricting administrative privileges cut across how people work, so they lag. Plan the uplift around the laggards.

Essential Eight Tender Questions Vendors Ask

These are the Essential Eight tender questions vendors ask most often in the days after finding the requirement in a bid document.

No, because no such certification exists. There is no certification body and no certificate, so the phrase signals inexperience to any evaluator who knows the model. State a maturity level per strategy instead, with the scope it covers, the date of assessment and whether it was self-assessed or performed by an independent party. That answer sounds less impressive and is considerably stronger, because it survives the first follow-up question.

Maturity level two is commonly named in Australian government supply chain requirements, but requirements vary by buyer and the binding version is the one written in your tender. Some name a level across all eight, some name specific strategies, some ask only for a description of your posture, and some require an independent assessment. Each is a different piece of work, and answering the wrong one is the most common failure in these responses.

Ask the buyer, because the answer changes the work enormously and the tender often does not say. A requirement scoped to the production environment delivering the service is answerable from infrastructure you already control. One covering your corporate fleet brings in laptops, contractor machines and acquired systems, plus the endpoint-heavy strategies that are hardest to evidence. Ask during the clarification window and state the scope explicitly in your answer.

A self-assessment against the maturity model, with the scope and date stated, plus a dated uplift plan for anything below the level asked. ASD publishes guidance on performing a self-assessment rigorously. A focused assessment against a defined scope is achievable inside a typical response window if your asset inventory is current; if it is not, that reconstruction is the work, and it is worth doing regardless because coverage is what the rating depends on.

Less often than vendors fear, and far less often than a claim that fails under questioning. Evaluators price a stated gap with a dated remediation plan as a manageable risk, while a claimed level that unravels costs you the section and the credibility of everything around it.

Have the Essential Eight answer ready before the next tender

Book a demo and we'll show how Konfirmity tracks coverage, enforcement state and exceptions per strategy so a tender response is an export rather than a scramble.

Book a demo

Answer the Question That Was Actually Asked

Most of the value in an Essential Eight tender response comes from two unglamorous habits: read the requirement closely enough to know which of the four asks it is, and ask what the scope attaches to instead of guessing. Those two steps prevent most of the wasted effort in these responses.

The rest is a current rating per strategy with evidence, a stated scope, an assessment date and a named owner — assembled before the tender appears rather than during it. Where you are short of the level asked, say so with a target and dates. That answer survives the questions an evaluator is paid to ask; a claim does not.

If you have no current rating, start there this week. Work through the assessment process against a defined scope and rate all eight before deciding what you can put in a bid.

Tools

Put your Essential Eight plan into numbers

More Essential Eight guides

Related Articles

Essential Eight Application Control: Why It Stalls and How to Finish

Security Controls & Practices

amit-gupta

2026-10-05

Essential Eight Application Control: Why It Stalls and How to Finish

arrow

Application control is the Essential Eight strategy most often left unfinished. What it covers, why deployments stall in audit mode, and how to reach enforcement.

The Essential Eight Assessment: How to Rate Yourself Honestly

Audit & Readiness

amit-gupta

2026-10-05

The Essential Eight Assessment: How to Rate Yourself Honestly

arrow

How an Essential Eight assessment works, the evidence each strategy needs, and the four places self-assessments overstate maturity before a buyer finds out.

Essential Eight Backups: The Strategy That Decides a Ransomware Outcome

Risk & Incidents

amit-gupta

2026-10-05

Essential Eight Backups: The Strategy That Decides a Ransomware Outcome

arrow

Regular backups is the only Essential Eight strategy aimed at recovery. What it requires beyond a successful job log, and why untested restores fail when it matters.

The Essential Eight Maturity Model: What Levels Zero to Three Mean

Security Controls & Practices

amit-gupta

2026-10-05

The Essential Eight Maturity Model: What Levels Zero to Three Mean

arrow

The Essential Eight maturity model rates each strategy zero to three by the adversary it withstands, not by effort. What each level means and why they move together.

Essential Eight Multi-Factor Authentication: The Strategy Teams Overrate

Security Controls & Practices

amit-gupta

2026-10-05

Essential Eight Multi-Factor Authentication: The Strategy Teams Overrate

arrow

The Essential Eight multi-factor authentication strategy is rated lower than teams expect. What coverage and phishing-resistant MFA actually require.

Essential Eight Macro Settings and User Application Hardening

Security Controls & Practices

amit-gupta

2026-10-05

Essential Eight Macro Settings and User Application Hardening

arrow

Essential Eight macro settings and user application hardening are rated lower than teams expect. What the two strategies cover and how to evidence them.

How Real Security Becomes Compliance

Built by the CTO who scaled NIUM to $2 billion. 10 years building security and compliance for regulated fintechs. 4.5 years running Konfirmity profitably.

Book a call