Konfirmity

Essential Eight:Australia's TechnicalSecurity Baseline

The Australian Signals Directorate's Essential Eight is eight specific mitigation strategies, each assessed from maturity level zero to three by the sophistication of the adversary it would withstand. There is no certificate — the assessment is technical, the evidence is configuration, and buyers ask for a level rather than a pass.

Book a call
Essential Eight compliance

[01] Why Companies Implement the Essential Eight

The Essential Eight opens Australian procurement, sits below ISO 27001 rather than beside it as a technical floor an ISMS does not guarantee, and is specific enough that a buyer can verify your answer.

// The Reality

The Essential Eight is published by the Australian Signals Directorate's Australian Cyber Security Centre, and non-corporate Commonwealth entities are required to implement it under the Protective Security Policy Framework. That obligation does not stop at the agency boundary.

// Business Impact

Vendors supplying Australian government, and the primes supplying them, are asked to demonstrate Essential Eight alignment at a stated maturity level. Without an answer you are filtered out before a technical evaluation begins.

// Who Asks

  • Commonwealth entities and their procurement teams
  • State and territory agencies adopting the same baseline
  • Primes flowing requirements down to subcontractors
  • Australian banks, insurers and critical infrastructure operators
  • Any buyer whose own obligations make your posture their risk

// Strategic Advantage

The Essential Eight is specific enough to answer quickly and verifiably. A current self-assessment with evidence per strategy clears procurement far faster than a general security narrative.

[02] What the Essential Eight Actually Is

Eight strategies, three objectives, four maturity levels: the strategies say what to implement, the objectives say what each is for, and the maturity level says how deeply — judged by the adversary the implementation would withstand.

1

Application Control

Only approved executables, libraries, scripts and installers run. The hardest of the eight to deploy well and the one most often left at a partial implementation, because it requires knowing what your fleet legitimately runs.

2

Patch Applications

Patching internet-facing and productivity applications on defined timeframes, with the window tightening sharply when a working exploit exists. Also covers removing applications no longer supported by the vendor.

3

Configure Microsoft Office Macro Settings

Macros blocked for users with no business need, macros from the internet blocked, and macro execution restricted and logged. A narrowly scoped control that closes a disproportionately common delivery path.

4

User Application Hardening

Browsers configured to block or disable high-risk content and features, and hardening applied to the office suite and PDF readers. Aimed squarely at drive-by execution.

5

Restrict Administrative Privileges

Privileged access granted on validated need, reviewed on a cycle, and separated from general-purpose activity — privileged accounts kept away from email and web browsing.

6

Patch Operating Systems

The same discipline as patching applications, applied to operating systems on workstations, servers and network devices, including retiring versions no longer receiving support.

7

Multi-Factor Authentication

MFA for remote access, for privileged actions, and — at higher maturity — for users of important data repositories and third-party services holding your data. The phishing-resistance of the factors matters as maturity rises.

8

Regular Backups

Backups of important data, software and configuration, retained and tested for restoration, and protected so that an account compromise cannot destroy them. The only one of the eight aimed at recovery rather than prevention.

[03] Understanding Essential Eight Implementation

There is no Essential Eight certificate — there is a maturity rating per strategy, evidenced by configuration, and ASD's guidance is to reach the same level across all eight before advancing any of them.

[1/5] SELF-ASSESS THE CURRENT MATURITY (WEEK 1-2)

Establish where each of the eight actually sits today, per strategy, with evidence. Most organisations find they are at level zero on one or two strategies they assumed were handled.

// What Happens

An honest baseline per strategy, and a target maturity level chosen from what your buyers ask for rather than from ambition.

// Deliverables

  • Current maturity rating for each of the eight, with evidence
  • Target maturity level with the reason it was chosen
  • Gap list ordered by distance from target
  • Asset and fleet inventory the assessment was run against

// Effort

  • Timeline: 1-2 weeks
  • Your involvement: 10-16 hours

// activities

  • Per-Strategy Rating: Assessed against the maturity model, not self-reported
  • Evidence Capture: Configuration exports, not assertions
  • Target Selection: Driven by buyer requirements and risk
  • Fleet Inventory: You cannot rate what you have not enumerated

[05] A Smarter Security Investment

When platform, service, and execution are considered together, Konfirmity delivers security and compliance with fewer tradeoffs and clearer long-term costs.

DIY Manual

Platform

None

Service

None

Audit

$15K

Year 1 total

$15K

Annual

$5K

Generic Platform

Platform

$25K

Service

None

Audit

$15K

Year 1 total

$40K

Annual

$30K

Traditional Consultant

Platform

None

Service

$50K

Audit

$15K

Year 1 total

$65K

Annual

$25K

Konfirmity

Platform

Included

Service

Included

Audit

$15K

Year 1 total

$50K

Annual

$35K

[05] FAQ's

What the Essential Eight Actually Involves

No. There is no certification body and no certificate. The Essential Eight is assessed as a maturity rating per strategy — level zero through three — and the evidence is technical configuration rather than policy documents. Assessments are commonly performed as a self-assessment or by an independent assessor, and what a buyer receives is a stated maturity level with the evidence behind it, not a logo.

No, and this is the most common misconception. An ISMS asks whether you have a process for deciding on controls; the Essential Eight asks whether eight specific technical controls are deployed and how deeply. An organisation can hold a valid ISO 27001 certificate while application control is unimplemented and Office macro settings sit at their defaults. The two complement each other — the Essential Eight evidence feeds an ISMS directly — but neither substitutes for the other.

The one your buyers ask for, which for Australian government supply chains is usually stated explicitly in the requirement. ASD's guidance is to implement all eight to the same level before advancing any of them, so the target is a level across the set rather than a per-strategy ambition. Declaring a level you cannot evidence across all eight is worse than declaring a lower one honestly, because the assessment surfaces the weakest strategy.

Directly, only if you sell into Australian government supply chains or to Australian organisations that have adopted it as their baseline. Indirectly, the eight are a well-chosen technical floor that any security programme benefits from — patching, MFA, privilege restriction, hardening, application control and tested backups are not Australian in nature. Teams often implement the substance for risk reasons and declare a maturity level only when a buyer asks.

Application control, consistently. It requires knowing what your fleet legitimately runs before you can enforce anything, which means a learning period in audit mode and a ruleset that survives contact with real users. Teams frequently deploy it in audit mode, never move to enforcement, and remain at maturity level zero for that strategy while believing it is covered. Regular backups is the second, not because configuring them is hard but because restoration is rarely tested end to end.

No. The Information Security Manual is ASD's broad control catalogue; the Essential Eight is a small prioritised baseline drawn from ASD's wider strategies to mitigate cyber security incidents. The Essential Eight is where most organisations start because it is short and specific, while the ISM is the larger reference an assessment against Australian government requirements may draw on. Meeting the eight does not mean meeting the ISM.

[07] get started

Get started in the way that fits you best -- see the platform in action, speak directly with a security expert, or get real proof through a free external scan of your environment.

See the platform in action. We'll show you:

Adaptation to your specific stack

Integration with your existing tools

Custom evidence collection workflows

Dashboard views for stakeholders

Speak directly with one of our security experts:

Security program design for your industry

Compliance roadmap (SOC 2 → ISO)

Risk assessment and treatment planning

Vendor security review guidance

BOOK A CALL

Want proof? We'll scan your surface for free:

Exposed assets and misconfigurations

SSL/TLS vulnerabilities

Vendor risk in your supply chain

Comparison to industry benchmarks