Somebody wants proof of your Essential 8 position, and they probably have not told you what that proof looks like. It might be a client's procurement team, your board, or the renewal questionnaire from your insurer. Whoever it is, the thing they are asking for has a defined shape: an Essential 8 assessment is a structured review of eight specific mitigation strategies published by the Australian Signals Directorate (ASD), measured against a target maturity level you choose in advance. It ends with a documented outcome for every control and a clear statement of whether that target was met. There is no certificate at the end and no pass mark you can buy.
Across more than 1,500 Cyber Strength Audits for Australian businesses, the pattern inSUPPORT sees most often is not a business failing an assessment. It is a business that was never told what the assessment was measuring, so the report lands and nobody can act on it. The confusion is fair enough, because two very different exercises get sold under the same name. One is a conversation and a folder of policies that produces a rating. The other tests whether the controls actually work. ASD has published guidance on which is which, and the difference decides whether the money was well spent.
TL;DR: What to remember
- ✅ An Essential 8 assessment measures eight ASD mitigation strategies against a target maturity level. There are four defined levels, Maturity Level Zero through Three, and only three of them are targets.
- ✅ ASD grades assessment evidence in four tiers. Interviews and policy documents sit in the lowest one, which ASD itself calls Poor. Testing the control is the top.
- ✅ Every control gets one of seven standardised outcomes. A single ineffective control and the maturity level cannot be claimed. No partial credit, no rounding.
- ✅ Certification does not exist. An independent assessment is required only when a directive, a regulator or a contract asks for one.
Contents
- The target level gets agreed before anyone looks at a system
- How the evidence gets gathered decides what the answer is worth
- Every control gets one of seven outcomes, and one bad one sinks the level
- What you are holding when the assessment finishes
- What businesses want to know before an assessment
The target level gets agreed before anyone looks at a system
An assessment without a target is just a look around. ASD's guidance is that organisations should identify and plan for a target maturity level suitable for their environment, then progressively implement each level until that target is achieved. The target is a decision, not a default. What drives it is how desirable your business is to an attacker and what a breach would actually cost you, in your data and in your operations.
There are four defined maturity levels, Maturity Level Zero through to Maturity Level Three, and only three of them are targets. Maturity Level Zero exists to capture the cases where the requirements of Maturity Level One are not met. So if a report hands you a Maturity Level Zero, it is describing a gap. It is not grading you out of three.
One rule at this stage catches people out. ASD's position is that organisations should plan to reach the same maturity level across all eight mitigation strategies before moving to a higher level. You do not get to be strong on patching, absent on multi-factor authentication and average the two. The eight are designed to complement each other, and the model treats them as a set.
Before the assessment starts, three things belong in writing. The target level, and why that level rather than another; if a client or insurer set the requirement, the document that says so is your input. The scope: which systems, which sites, which user groups, because an assessment of an unclear scope produces an unclear answer. And the approach, which ASD explicitly says should be risk-based, meaning it reflects your actual environment rather than a generic template.
How the evidence gets gathered decides what the answer is worth
This is the step that separates a useful assessment from an expensive one, and ASD is unusually direct about it. Its assessment process guide defines four levels of evidence quality, and ranks them.
Excellent evidence is testing a control with a simulated activity designed to confirm it is in place and effective, for example attempting to run a test application to check application control rulesets. Good evidence is reviewing the configuration of a system through the system's own interface. Fair evidence is reviewing a copy of that configuration, such as a report or a screenshot. Poor evidence, ASD's own term, is a policy or a verbal statement of intent, including controls being discussed during interviews with the people who administer the system.
Read that last one again, because it describes how a great many assessments are actually run. A questionnaire, a workshop and a folder of policies is Poor evidence by the standard of the agency that publishes the framework. It is not worthless, and ASD acknowledges as much: assessors should gather the highest quality evidence where reasonably practicable, because testing everything is not always possible. But if the whole assessment sits in the bottom tier, you have bought an opinion about your environment. A measurement costs more effort, and it is the thing your insurer or client thought they were getting.
This is not a hypothetical gap. The Australian Securities and Investments Commission (ASIC) ran a cyber pulse survey of corporate Australia, reported in November 2023, as a voluntary self-assessment, and said the results exposed deficiencies in the management of critical cyber capabilities. Its chair, Joe Longo, described one finding as alarming: 44% of participants were not managing third-party or supply chain risks. Self-declaration is where most organisations start. An assessment should finish somewhere better.
So before you commission the work, ask which evidence tier each finding will rest on; a credible assessor answers without hesitating. Ask what will be tested rather than sighted, and on what sample of workstations, servers and network devices. And if an assessor cannot get visibility of a control, that has its own recorded outcome, covered below. It should never quietly become a pass.
Every control gets one of seven outcomes, and one bad one sinks the level
ASD publishes seven standardised assessment outcomes, and a good report uses them by name rather than inventing a traffic-light scheme. A control is recorded as Effective when the organisation is meeting the control's objective; Alternate control when it is meeting that objective another way; Ineffective when it is not adequately meeting it; No visibility when the assessor could not obtain adequate visibility of the implementation; Not implemented when the organisation has decided not to implement it; Not applicable when it does not apply to the environment; and Not assessed when it has not yet been looked at.
Then comes the rule that surprises most people. To claim a mitigation strategy is implemented, every control within it must be assessed as effective or as an alternate control. One ineffective control means the requirements for that maturity level have not been met, and that carries all the way up: if one or more of the eight strategies is not implemented, the target maturity level for the system cannot be claimed. No partial credit, no rounding.
Two things soften that, and both are worth knowing before you assume the worst. Exceptions are permitted: where a control cannot be implemented, a documented exception with genuine compensating controls, approved through a proper process, should not stop an organisation being assessed as meeting the requirements. What you cannot do is use risk acceptance on its own to skip an entire strategy. ASD's wording is that assessors should not allow risk acceptance as a justification for not implementing a whole mitigation strategy, and that in those cases, without adequate compensating controls, the strategy is considered not implemented. The qualifier does the work here. Compensating controls are the difference between a managed exception and a gap with paperwork attached.
What you are holding when the assessment finishes
A finished assessment gives you three things the framework accounts for: a recorded outcome for every control across the eight strategies, a statement of whether the target maturity level has been met, and the evidence each conclusion rests on. There is a fourth thing, and the framework does not require it, which is exactly why quotes differ: turning the gap between where you are and where you were asked to be into a costed, sequenced plan. That is the part with commercial value, because it converts an obligation somebody else set into a scoped piece of work you can price, schedule and argue about internally. If a quote does not include it, you will pay for the answer and then pay again for the plan.
What you do not hold is a certificate. ASD is clear that there is no requirement for organisations to have their Essential 8 implementation certified by an independent party, though an independent assessment may be required by a government directive or policy, by a regulatory authority, or as part of contractual arrangements. If a client or insurer is asking, that contractual route is usually why. Anyone selling you Essential 8 certification is selling something the framework does not issue.
The ceiling deserves the same honesty. ASD states that while the Essential 8 can help mitigate the majority of cyber threats, it will not mitigate all of them, and that Maturity Level Three will not stop an attacker willing to invest enough time, money and effort. The Essential 8 is a floor that clears the common cases well, and a floor is not the whole of a security programme, which is why inSUPPORT aligns clients to the compliance frameworks their industry actually uses rather than treating one model as the destination. The framework itself also moves: ASD opened a consultation on evolving the Essential Eight in June 2026, and this article reflects the maturity model and assessment process guide as published at August 2026, so check the current ASD guidance before relying on a specific requirement.
One last practical difference shows up at this point. Where the assessment is the product, the engagement finishes when the document lands. Where remediation is included in the ongoing support fee, as it is in inSUPPORT's model, the assessment is the start of the work, and it gets scoped accordingly. That is a commercial structure worth asking about, whoever you engage.
What businesses want to know before an assessment
How long does an Essential 8 assessment take?
It depends on the size and complexity of the environment, which is ASD's own position: the approach to conducting an assessment varies, though the foundational principles are common to each. What moves the timeline most is how many systems are in scope, how much can be tested directly rather than sighted, and how quickly the assessor gets administrative visibility of the environment. Agreeing scope and access up front is the single biggest thing you can do to shorten it.
Can we assess ourselves, or do we need someone independent?
You can assess yourself, and many organisations do as a first pass. ASD does not require certification by an independent party. Independent assessment becomes necessary when a government directive or policy, a regulator, or a contract requires it, which is the situation most businesses are in when somebody hands them a deadline. The practical limit on self-assessment is evidence quality. Testing your own controls with the detachment the top evidence tier calls for is genuinely hard.
What maturity level should we be aiming for?
That is your decision, based on how attractive you are as a target and what a breach would cost you in confidentiality, availability and integrity. Where a client, insurer or regulator has named a level, they have made the decision for you, and the document that names it is your scope. Be wary of any provider who quotes a target level before understanding your environment or reading the requirement you have been given.
What is the first step if we have never done this?
Find the requirement in writing, whether that is a procurement clause, an insurer's question set or a board minute, and establish what is actually being asked. Then get a scoped assessment that tells you your position against each of the eight, with the evidence tier for each finding stated. From there the work is a costed list rather than an open question.
If a framework requirement has landed on your desk with a deadline attached, the useful first conversation is about what you have been asked to prove, not about products. inSUPPORT runs managed IT, security and compliance work for Australian businesses of roughly 30 to 300 users, with more than 1,500 Cyber Strength Audits behind the current approach and remediation included in the monthly support fee rather than billed back as a separate project. A Cyber Strength Audit documents your environment against the frameworks your industry uses and returns a costed list of what it takes to close the gaps, so you know which controls are effective, which are not, and what the work is worth before you commit to any of it. We don't take your money and run.
Book a Cyber Strength Audit →Citations
- "Essential Eight maturity model", Australian Signals Directorate. Confirms the four defined maturity levels, the requirement to reach the same level across all eight strategies before progressing, the risk-based approach, and that no certification is required unless mandated by directive, regulator or contract. cyber.gov.au
- "Essential Eight assessment process guide", Australian Signals Directorate. The source of the four evidence quality tiers and the seven standardised assessment outcomes, and of the rule that one ineffective control prevents a maturity level being claimed. cyber.gov.au
- "ASIC calls for greater organisational vigilance to combat cyber threats" (23-300MR, November 2023), Australian Securities and Investments Commission. Reports the cyber pulse survey findings, including that 44% of participants were not managing third-party or supply chain risks, and that smaller organisations lagged in adoption of industry standards. asic.gov.au
Related Reading
- How the Essential 8 Maturity Model Benchmarks Cybersecurity
- What is Maturity Level 3
- The 6 Step Cyber Strength System
- Managed IT, compliance and cyber insurance as one operating model
About the author: Kane Nawrocki is the founder and CEO of inSUPPORT. He has spent more than 25 years in IT and built inSUPPORT to give Australian businesses managed IT, security and compliance as one model, with the remediation an audit finds included in the support fee rather than billed back as a surprise project.
Content reviewed by Probably Genius for accuracy and relevance.
inSUPPORT provides managed IT and cyber security services. It is not an insurer, insurance broker or underwriter and does not hold an Australian Financial Services Licence. Where cyber insurance forms part of a plan, it is arranged through licensed insurance partners and underwritten by the insurer. Cover is subject to the insurer's assessment, the policy terms and the Product Disclosure Statement and Target Market Determination. This article is general information about IT and security practice, not financial product advice, and it does not take account of your objectives, financial situation or needs.
CLICK HERE


