You can run an Essential 8 checklist on your own business in an afternoon, and you should. The Essential 8 is eight mitigation strategies published by the Australian Signals Directorate (ASD). The list is public, there is nothing proprietary about it, and working through it will tell you more about your environment than most owners ever get told. What it will not give you is evidence. Evidence is what the client, the board or the insurer asking about your security position is actually after, and knowing that difference before you send anyone a filled-in checklist will save you an awkward conversation.
The eight strategies are patch applications, patch operating systems, multi-factor authentication, restrict administrative privileges, application control, restrict Microsoft Office macros, user application hardening, and regular backups. That is the whole list. Below is each one as a set of questions you can answer this week, then the honest part: what your answers can and cannot prove, and the point where a checklist stops being enough.
TL;DR: What to remember
- ✅ The Essential 8 is eight mitigation strategies published by the ASD. The list is public, and you can review your own environment against it this week.
- ✅ Answer with facts, not intentions. "We should" and "there's a policy" both count as a no.
- ✅ Your weakest strategy is your position. ASD requires the same maturity level across all eight, and partial credit does not exist in this framework.
- ✅ A checklist you fill in yourself sits at or near ASD's lowest evidence tier. It will find your gaps; it will not prove your position to the client, board or insurer who asked.
Contents
- The checklist: eight strategies, one question set each
- How to read your own answers
- Where a checklist stops
- Common questions about the Essential 8 checklist
The checklist: eight strategies, one question set each
Take them in order and answer honestly. The useful answer is a fact, not an intention. If yours starts with "we should" or "there's a policy that", write it down as a no.
1. Patch applications
How long does it take you to patch a known vulnerability in an internet-facing application, measured from the day the fix was released rather than the day you noticed it? Can you produce that figure for the last three patches? A number you can pull from a record is an answer. A number somebody remembers is not.
2. Patch operating systems
Same question for your operating systems, plus a harder one: is anything still running that no longer receives security updates at all? An unsupported operating system limits what your position can be. ASD's guidance is to prioritise upgrading legacy systems so the Essential Eight can be implemented in full, with compensating controls in the meantime.
3. Multi-factor authentication
Which systems have multi-factor authentication (MFA) enforced, not merely available? Count remote access, email and any system holding customer data. Then check the exceptions. MFA that everybody can opt out of is not enforced.
4. Restrict administrative privileges
How many people have administrative access, and when was that list last reviewed? One more worth asking: do your administrators use separate accounts for administrative work, or do they read email and browse the web from a privileged account?
5. Application control
Can an ordinary user install and run software you did not approve? One question, one test, and if the answer is yes, application control is not in place in the sense the framework means.
6. Restrict Microsoft Office macros
Are macros blocked for the users who do not need them? Where they are allowed, is that allowance limited and reviewed? Restricting Office macros is one of the eight strategies in its own right, which is a reasonable signal of how ASD weighs it.
7. User application hardening
Are the features you do not use actually turned off, particularly in browsers and Office? This one is easy to assume and quick to verify. So verify.
8. Regular backups
Not whether you have backups. Two harder questions: when did you last restore from one and confirm the restore actually worked, and could an attacker with administrative access delete or encrypt your backups along with everything else?
How to read your own answers
Resist the urge to score yourself out of eight. The Essential 8 does not work that way, and reading your answers as a score is how a business ends up holding a number it cannot defend.
ASD's model defines four maturity levels, Maturity Level Zero through Three, and the requirement is to reach the same level across all eight strategies before moving to a higher one. The eight are designed to complement each other, so the weakest one describes your position more accurately than the average does. If seven answers are strong and one is a clear no, the honest reading is the one, not the seven.
There is a second rule that catches people who have done a genuine self-review and feel good about it. Under ASD's assessment guidance, every control within a mitigation strategy must be assessed as effective, or as an equivalent alternate control, for that strategy to count as implemented. One ineffective control and the requirements for that maturity level have not been met. Partial credit does not exist in this framework.
Where you genuinely cannot implement something, that is not automatically a failure. ASD's guidance provides for documented exceptions with compensating controls, approved through a proper process, and says an exception managed that way should not preclude an organisation from being assessed as meeting the requirements. What does not work is deciding not to implement a whole strategy and calling that a risk decision. Without adequate compensating controls, ASD treats that as not implemented.
Where a checklist stops
ASD's assessment process guide ranks evidence in four tiers, and the ranking is the point of this whole exercise. Testing a control with a simulated activity, for example attempting to run a test application to see whether application control actually blocks it, is Excellent evidence. Reviewing a system's configuration through its own interface is Good. Reviewing a copy of that configuration, such as a screenshot or a report, is Fair. A policy or a verbal statement of intent, including controls discussed in an interview with the people who administer them, is Poor evidence. That is ASD's own word for it.
A checklist you complete about your own environment sits at or near that bottom tier, depending on whether each answer is backed by configuration evidence or only by recollection. That does not make it worthless, and ASD is realistic that testing everything is not always reasonably practicable. It makes it a starting point. "We have MFA" is a belief. "MFA is enforced on every system that matters, with no standing exceptions, and here is the configuration proving it" is a finding. The person who asked for your position is trying to close the gap between those two sentences.
Self-assessment has been tested at national scale, and the result is on the record. When the Australian Securities and Investments Commission (ASIC) surveyed corporate Australia on cyber resilience and reported the results in November 2023, the survey was a voluntary self-assessment, and ASIC still concluded the results exposed deficiencies in critical cyber capabilities. Its chair, Joe Longo, singled out one finding as alarming: 44% of participants were not managing third-party or supply chain risks. Organisations assessing themselves are not usually being dishonest. They cannot see what they cannot see.
So the practical rule is straightforward. Use the checklist to find your obvious gaps, and to stop paying anyone to tell you things you could have worked out yourself. When somebody external has asked you to demonstrate a position, whether that is a client's procurement team, a board or an insurer, a self-completed checklist is not the artefact they need, and sending one usually costs you a round trip. inSUPPORT aligns clients to the compliance frameworks their industry actually uses and tests the controls rather than sighting the policy, because the tested answer is the only one that survives being asked twice.
Common questions about the Essential 8 checklist
Is there an official ASD checklist we can download?
ASD publishes the maturity model, an assessment process guide, an assessment report template and an assessment toolkit, and it also provides verification tools including the Essential Eight Maturity Verification Tool through its Partner Portal. Those are assessor-grade materials rather than a one-page tick sheet. The list above is a plain-language starting point for a business owner, and ASD's own publications are the authority once you get to the detail.
Does completing a checklist mean we are Essential 8 compliant?
No, and it is worth being careful with that phrase generally. The Essential 8 is a maturity model rather than a certification, and there is no compliant or non-compliant status to hold. What exists is a target maturity level, an assessed position against it, and the evidence supporting that position. Any statement about where you stand should name the level, the scope of systems it covers, who assessed it and when.
Which strategy should we fix first?
ASD's guidance is to plan for the same maturity level across all eight rather than perfecting them one at a time, because they are designed to work together. In practice the sequencing question is usually settled by what your self-review turned up: an unsupported operating system or an unenforced MFA policy will outrank a macro setting. If a provider recommends a sequence, ask them to explain why in terms of your environment rather than a generic order.
How often should we redo this?
Treat it as a standing review rather than a project. Environments drift, staff change, exceptions get granted and forgotten, and a control that was effective in March can be ineffective by September without anybody deciding anything. ASD also updates the maturity model periodically and opened a consultation on evolving the Essential Eight in June 2026, so the requirements themselves are not fixed.
Run the checklist first. It costs nothing and the findings are yours. If it turned up something you cannot resolve internally, or somebody external is waiting on proof, the useful next step is a scoped look at those specific gaps rather than a general conversation about security. inSUPPORT works with Australian businesses of roughly 30 to 300 users and has run more than 1,500 cyber audits. A Cyber Strength Audit tests the controls, records an outcome for each one, and returns a costed list of what it takes to close the gaps. We don't take your money and run.
Book a Cyber Strength Audit →Citations
- "Essential Eight explained", Australian Signals Directorate. The authoritative list of the eight mitigation strategies. cyber.gov.au
- "Essential Eight assessment process guide", Australian Signals Directorate. The source of the four evidence-quality tiers used above, the requirement that every control in a strategy be effective for that strategy to count, and the treatment of exceptions and compensating controls. cyber.gov.au
- "ASIC calls for greater organisational vigilance to combat cyber threats" (23-300MR, November 2023). Reports the cyber pulse survey, a voluntary self-assessment, including the finding that 44% of participants were not managing third-party or supply chain risks. asic.gov.au
Framework guidance changes. This reflects ASD's published Essential Eight material as at August 2026, and ASD opened a consultation on evolving the Essential Eight in June 2026. Check current ASD guidance before relying on a specific requirement.
Related Reading
- How the Essential 8 Maturity Model Benchmarks Cybersecurity
- What is Maturity Level 3
- The 6 Step Cyber Strength System
- What inSUPPORT actually runs for Australian businesses
About the author: Kane Nawrocki is the founder and CEO of inSUPPORT. He has spent more than 25 years in IT and built inSUPPORT to give Australian businesses managed IT, security and compliance as one model, with the remediation an audit finds included in the support fee rather than billed back as a surprise project.
Content reviewed by Probably Genius for accuracy and relevance.
inSUPPORT provides managed IT and cyber security services. It is not an insurer, insurance broker or underwriter and does not hold an Australian Financial Services Licence. Where cyber insurance forms part of a plan, it is arranged through licensed insurance partners and underwritten by the insurer. Cover is subject to the insurer's assessment, the policy terms and the Product Disclosure Statement and Target Market Determination. This article is general information about IT and security practice, not financial product advice, and it does not take account of your objectives, financial situation or needs.
CLICK HERE


