Essential Eight:Australia's TechnicalSecurity Baseline
The Australian Signals Directorate's Essential Eight is eight specific mitigation strategies, each assessed from maturity level zero to three by the sophistication of the adversary it would withstand. There is no certificate — the assessment is technical, the evidence is configuration, and buyers ask for a level rather than a pass.
Book a call
[01] Why Companies Implement the Essential Eight
The Essential Eight opens Australian procurement, sits below ISO 27001 rather than beside it as a technical floor an ISMS does not guarantee, and is specific enough that a buyer can verify your answer.
// The Reality
The Essential Eight is published by the Australian Signals Directorate's Australian Cyber Security Centre, and non-corporate Commonwealth entities are required to implement it under the Protective Security Policy Framework. That obligation does not stop at the agency boundary.
// Business Impact
Vendors supplying Australian government, and the primes supplying them, are asked to demonstrate Essential Eight alignment at a stated maturity level. Without an answer you are filtered out before a technical evaluation begins.
// Who Asks
- Commonwealth entities and their procurement teams
- State and territory agencies adopting the same baseline
- Primes flowing requirements down to subcontractors
- Australian banks, insurers and critical infrastructure operators
- Any buyer whose own obligations make your posture their risk
// Strategic Advantage
The Essential Eight is specific enough to answer quickly and verifiably. A current self-assessment with evidence per strategy clears procurement far faster than a general security narrative.
[02] What the Essential Eight Actually Is
Eight strategies, three objectives, four maturity levels: the strategies say what to implement, the objectives say what each is for, and the maturity level says how deeply — judged by the adversary the implementation would withstand.
1
Application Control
Only approved executables, libraries, scripts and installers run. The hardest of the eight to deploy well and the one most often left at a partial implementation, because it requires knowing what your fleet legitimately runs.
2
Patch Applications
Patching internet-facing and productivity applications on defined timeframes, with the window tightening sharply when a working exploit exists. Also covers removing applications no longer supported by the vendor.
3
Configure Microsoft Office Macro Settings
Macros blocked for users with no business need, macros from the internet blocked, and macro execution restricted and logged. A narrowly scoped control that closes a disproportionately common delivery path.
4
User Application Hardening
Browsers configured to block or disable high-risk content and features, and hardening applied to the office suite and PDF readers. Aimed squarely at drive-by execution.
5
Restrict Administrative Privileges
Privileged access granted on validated need, reviewed on a cycle, and separated from general-purpose activity — privileged accounts kept away from email and web browsing.
6
Patch Operating Systems
The same discipline as patching applications, applied to operating systems on workstations, servers and network devices, including retiring versions no longer receiving support.
7
Multi-Factor Authentication
MFA for remote access, for privileged actions, and — at higher maturity — for users of important data repositories and third-party services holding your data. The phishing-resistance of the factors matters as maturity rises.
8
Regular Backups
Backups of important data, software and configuration, retained and tested for restoration, and protected so that an account compromise cannot destroy them. The only one of the eight aimed at recovery rather than prevention.
[03] Understanding Essential Eight Implementation
There is no Essential Eight certificate — there is a maturity rating per strategy, evidenced by configuration, and ASD's guidance is to reach the same level across all eight before advancing any of them.
[1/5] SELF-ASSESS THE CURRENT MATURITY (WEEK 1-2)
Establish where each of the eight actually sits today, per strategy, with evidence. Most organisations find they are at level zero on one or two strategies they assumed were handled.
// What Happens
An honest baseline per strategy, and a target maturity level chosen from what your buyers ask for rather than from ambition.
// Deliverables
- Current maturity rating for each of the eight, with evidence
- Target maturity level with the reason it was chosen
- Gap list ordered by distance from target
- Asset and fleet inventory the assessment was run against
// Effort
- Timeline: 1-2 weeks
- Your involvement: 10-16 hours
// activities
- Per-Strategy Rating: Assessed against the maturity model, not self-reported
- Evidence Capture: Configuration exports, not assertions
- Target Selection: Driven by buyer requirements and risk
- Fleet Inventory: You cannot rate what you have not enumerated
[05] A Smarter Security Investment
When platform, service, and execution are considered together, Konfirmity delivers security and compliance with fewer tradeoffs and clearer long-term costs.
DIY Manual
Platform
None
Service
None
Audit
$15K
Year 1 total
$15K
Annual
$5K
Generic Platform
Platform
$25K
Service
None
Audit
$15K
Year 1 total
$40K
Annual
$30K
Traditional Consultant
Platform
None
Service
$50K
Audit
$15K
Year 1 total
$65K
Annual
$25K
Konfirmity
Platform
Included
Service
Included
Audit
$15K
Year 1 total
$50K
Annual
$35K
[05] FAQ's
What the Essential Eight Actually Involves
No. There is no certification body and no certificate. The Essential Eight is assessed as a maturity rating per strategy — level zero through three — and the evidence is technical configuration rather than policy documents. Assessments are commonly performed as a self-assessment or by an independent assessor, and what a buyer receives is a stated maturity level with the evidence behind it, not a logo.
No, and this is the most common misconception. An ISMS asks whether you have a process for deciding on controls; the Essential Eight asks whether eight specific technical controls are deployed and how deeply. An organisation can hold a valid ISO 27001 certificate while application control is unimplemented and Office macro settings sit at their defaults. The two complement each other — the Essential Eight evidence feeds an ISMS directly — but neither substitutes for the other.
The one your buyers ask for, which for Australian government supply chains is usually stated explicitly in the requirement. ASD's guidance is to implement all eight to the same level before advancing any of them, so the target is a level across the set rather than a per-strategy ambition. Declaring a level you cannot evidence across all eight is worse than declaring a lower one honestly, because the assessment surfaces the weakest strategy.
Directly, only if you sell into Australian government supply chains or to Australian organisations that have adopted it as their baseline. Indirectly, the eight are a well-chosen technical floor that any security programme benefits from — patching, MFA, privilege restriction, hardening, application control and tested backups are not Australian in nature. Teams often implement the substance for risk reasons and declare a maturity level only when a buyer asks.
Application control, consistently. It requires knowing what your fleet legitimately runs before you can enforce anything, which means a learning period in audit mode and a ruleset that survives contact with real users. Teams frequently deploy it in audit mode, never move to enforcement, and remain at maturity level zero for that strategy while believing it is covered. Regular backups is the second, not because configuring them is hard but because restoration is rarely tested end to end.
No. The Information Security Manual is ASD's broad control catalogue; the Essential Eight is a small prioritised baseline drawn from ASD's wider strategies to mitigate cyber security incidents. The Essential Eight is where most organisations start because it is short and specific, while the ISM is the larger reference an assessment against Australian government requirements may draw on. Meeting the eight does not mean meeting the ISM.
[07] get started
Get started in the way that fits you best -- see the platform in action, speak directly with a security expert, or get real proof through a free external scan of your environment.
See the platform in action. We'll show you:
Adaptation to your specific stack
Integration with your existing tools
Custom evidence collection workflows
Dashboard views for stakeholders
Speak directly with one of our security experts:
Security program design for your industry
Compliance roadmap (SOC 2 → ISO)
Risk assessment and treatment planning
Vendor security review guidance
Want proof? We'll scan your surface for free:
Exposed assets and misconfigurations
SSL/TLS vulnerabilities
Vendor risk in your supply chain
Comparison to industry benchmarks
Guides
Essential Eight guides & articles

Security Controls & Practices
amit-gupta
2026-10-05
Essential Eight Application Control: Why It Stalls and How to Finish
Application control is the Essential Eight strategy most often left unfinished. What it covers, why deployments stall in audit mode, and how to reach enforcement.

Audit & Readiness
amit-gupta
2026-10-05
The Essential Eight Assessment: How to Rate Yourself Honestly
How an Essential Eight assessment works, the evidence each strategy needs, and the four places self-assessments overstate maturity before a buyer finds out.

Risk & Incidents
amit-gupta
2026-10-05
Essential Eight Backups: The Strategy That Decides a Ransomware Outcome
Regular backups is the only Essential Eight strategy aimed at recovery. What it requires beyond a successful job log, and why untested restores fail when it matters.

Security Controls & Practices
amit-gupta
2026-10-05
The Essential Eight Maturity Model: What Levels Zero to Three Mean
The Essential Eight maturity model rates each strategy zero to three by the adversary it withstands, not by effort. What each level means and why they move together.

Comparisons
amit-gupta
2026-10-05
Essential Eight vs ISO 27001: Why Certification Does Not Cover It
ISO 27001 certifies a management system; the Essential Eight rates eight technical controls. Where they overlap, where they do not, and how to run both once.