Everything your provider should show you at an Essential 8 review already exists, or it should. That is the whole test. A review is not a performance staged for the meeting; it is a walk through records the provider keeps anyway, because they run your environment every day. If the folder has to be built the week before you ask for it, what you are being shown is how the environment looked once somebody knew it would be inspected.
For an Australian business of 30 to 300 people, the review usually lands on the desk of whoever pays the invoices, and the temptation is to treat it as a technical document you are not qualified to judge. You are qualified. The Australian Signals Directorate (ASD) publishes a documented standard for what counts as evidence in an Essential 8 assessment, which means the meeting can be reduced to a short list of things to sight. Nine of them, in the order worth asking.
TL;DR: What to remember
- ✅ Nine things to sight. Eight of them map to ASD's own assessment material; the ninth, a costed path, is not an ASD requirement, which is exactly why you ask for it separately.
- ✅ Every item should exist before the meeting is booked. Evidence assembled for the review is a different product.
- ✅ Your weakest strategy describes your position. An average across the eight is a number that does not exist in the model.
- ✅ "Essential 8 compliant" is not a status ASD issues. A meaningful statement names the maturity level, the systems in scope, who assessed it and when.
Contents
- What the review claims about your environment
- The evidence sitting behind each finding
- What turns findings into a plan
- How to read what you are shown
- Questions owners ask about Essential 8 reviews
What the review claims about your environment
The first three items establish what the review is even saying. Skip them and the rest of the document floats free: findings with no target, no boundary and no shared language. Providers doing the work properly will have all three on hand, because the assessment cannot honestly be run without them.
1. The target maturity level, in writing, with the reason
ASD's model asks organisations to identify a target level suitable for their environment, so the first thing to sight is which level you are working to and why that one. The reason matters as much as the number. If a client contract or an insurer imposed the level, the document that imposed it is the answer, and it belongs in the file. A target nobody can explain is a target nobody chose.
2. The scope: which systems, sites and user groups are covered
Assessments are conducted against a system, so a review with no stated boundary produces a position you cannot honestly repeat to anyone else. When a client, a board or an insurer asks where you stand, the scope statement decides whether your answer is true. Ask for the boundary in writing before you read a single finding, because every finding inherits it.
3. An outcome for every control, in ASD's own seven terms
ASD's assessment process uses seven standardised outcomes: Not assessed, Effective, Alternate control, Ineffective, No visibility, Not implemented, and Not applicable. A report built on a home-made red, amber and green scheme is not wrong, but ask what each colour maps to, because those seven distinctions carry meaning that colours lose. No visibility is its own outcome for a reason: a control nobody can observe is a different problem from a control that failed, and the fix is different too.
The evidence sitting behind each finding
This is the group that separates a review from a meeting. Findings are claims; the next five items are what the claims stand on. None of them require you to understand the controls themselves. They only require you to ask what kind of proof is in the room.
4. The evidence tier behind each finding
ASD ranks assessment evidence in four levels. Testing a control with a simulated activity is Excellent. Reviewing configuration through a system's interface is Good. Reviewing a copy of that configuration, such as a screenshot, is Fair. A policy document or a verbal statement of intent is Poor. Ask which tier each significant finding rests on, and watch how quickly the answer comes back. The speed is itself evidence: an assessor who chose each tier deliberately can name it without looking anything up.
5. What was tested rather than sighted, and on what sample
ASD's guidance refers to testing across an accurate representative sample of workstations including laptops, servers and network devices. The sample decides what the finding is worth. A review of the head office desktop fleet that never touched the servers has answered part of the question, and it should say so. Ask what the sample was, and whether the machines that matter most were in it.
6. The exception register
Not everything can be implemented everywhere, and the framework knows it. Where a control could not be applied, there should be a documented exception with an assigned risk owner, the compensating controls in place, and evidence it went through an approval process. ASD's position is that a properly managed exception should not preclude an organisation from meeting the requirements. That cuts both ways. A gap with paperwork, an owner and a compensating control is being managed. An undocumented exception is just a gap.
7. The unsupported software list
Anything still running that no longer receives security updates belongs on a list you can read. The Essential Eight's patching requirements are specific rather than a blanket rule about all software, but ASD's own guidance is that legacy systems should be upgraded as a priority so the Essential Eight can be implemented in full, with compensating controls applied while that happens. In practice, this list is what most often caps what your position can be. It is also the item most likely to carry a cost nobody has raised yet, so sight it before renewal season, when the budget conversation is easier.
8. The date of the last restore test
Not the backup schedule. The date somebody last restored from a backup and confirmed it worked, and whether the backups are protected from an account with administrative privileges. That second half matters because an attacker who reaches an administrator account can reach the backups too. What is expected of backup protection differs by maturity level, so the useful question is what your target level requires and whether it is met. A dashboard of green backup jobs answers a different question from the one you asked.
What turns findings into a plan
9. The costed path
ASD does not require this one. Ask for it anyway. A list of findings with no sequence and no cost leaves the entire translation job with you: which gap first, what it costs, what can wait. A costed, sequenced plan is the artefact you can actually take to a board, and asking for it tells you something about the provider before a dollar is spent. A provider whose model funds the fixing will produce it readily. A provider whose model sells the fixing will produce a quote.
How to read what you are shown
Three rules make the output much easier to interpret, and all three come from the framework rather than from anyone's opinion.
First, your weakest strategy describes your position. ASD's guidance is to reach the same maturity level across all eight strategies before moving higher, because the eight are designed to complement each other. A review presenting an average across the eight is presenting a number that does not exist in the model, and averages are kind to gaps.
Second, one ineffective control is decisive. Under ASD's assessment guidance, every control within a strategy must be assessed as effective or as an equivalent alternate control for that strategy to be claimed as implemented, and if one or more strategies is not implemented, the target maturity level cannot be claimed for that system. The consequence is scoped to the system being assessed rather than to your whole business, which is one more reason the scope statement in item two matters.
Third, a decision not to do something is not automatically a risk decision. ASD is explicit that assessors should not allow risk acceptance as a justification for skipping an entire mitigation strategy, and that without adequate compensating controls the strategy is treated as not implemented. If a review hands you a strategy marked as risk accepted with nothing else in place, read it as a finding, because that is what it is.
One further thing worth knowing sits behind the review rather than inside it: the commercial structure. Where the review is the product, it is complete when the document lands, and the remediation arrives as a second quote. Where remediation sits inside the ongoing support fee, as it does in inSUPPORT's model, the review is scoping work that is already covered rather than opening a new sale. Plenty of good providers run the first model, and there is nothing dishonest about it. It is simply worth knowing which one you are in before you read the findings, because the model explains the shape of what you are handed.
Questions owners ask about Essential 8 reviews
Our provider says we are Essential 8 compliant. Is that a real status?
Not as stated. The Essential 8 is a maturity model rather than a certification scheme, and ASD does not issue a compliant status. A meaningful statement names the maturity level, the systems in scope, who assessed it and when. If the phrase arrives without those four things attached, ask for them. A provider doing the work properly will have them, and producing them costs nothing.
Should we get an independent assessment or is our provider's review enough?
ASD does not require independent certification. It does note that an implementation may need to be assessed by an independent party where a government directive or policy, a regulator, or a contractual arrangement requires it, which is the situation most businesses are in when the question comes up. There is also a practical point worth naming openly rather than treating as a scandal: a provider assessing the environment they themselves configured is grading their own work. The nine items above are how you read that homework either way, because evidence tiers and test dates do not care who produced them.
What if our provider cannot produce most of this?
It usually means the review has not been done to the framework's standard, which is a different finding from your environment being unsafe. The proportionate response is to ask for the specific gaps to be closed and re-presented, with a date, and then hold the date. If the answer is that this level of evidence sits outside the service you bought, that is useful information in itself, and it is a fair conversation to have at renewal rather than an accusation to make today.
How often should a review like this happen?
Environments drift continuously. Staff change, exceptions get granted, software ages, and a position established once decays without anybody deciding anything. Treat the review as a maintained state rather than an annual event. The standard you are measured against moves as well: ASD updates the maturity model periodically and opened a consultation on evolving the Essential Eight in June 2026.
Put the nine to whoever runs your environment today, before you change anything. If most of it comes back quickly, you are in better hands than many businesses your size. If it does not, a Cyber Strength Audit produces exactly the artefacts above: an outcome per control, the evidence behind each one, and a costed path. We support more than 5,500 desktops and users for Australian businesses, we have run over 1,500 Cyber Strength Audits, and the security remediation an audit finds is included in the monthly support fee rather than quoted back as a separate project. We don't take your money, hand you the problem and walk away.
Book a Cyber Strength Audit →Citations
- "Essential Eight assessment process guide", Australian Signals Directorate. The seven standardised assessment outcomes, the four evidence-quality tiers, representative sampling across workstations, servers and network devices, the all-controls-effective rule, and the treatment of exceptions and risk acceptance. cyber.gov.au
- "Essential Eight maturity model", Australian Signals Directorate. Target levels, the same-level-across-all-eight requirement, and the position that no independent certification is required unless mandated by directive, regulator or contract. cyber.gov.au
- "ASIC calls for greater organisational vigilance to combat cyber threats" (23-300MR, November 2023). Reports that smaller organisations lagged larger ones in adopting industry standards and in third-party risk management. asic.gov.au
Framework guidance changes. This reflects ASD's published Essential Eight material as at August 2026, and ASD opened a consultation on evolving the Essential Eight in June 2026.
Related Reading
- The Risks of Not Using Managed Services
- How the Essential 8 Maturity Model Benchmarks Cybersecurity
- The 6 Step Cyber Strength System
- What inSUPPORT support includes, and what is quoted separately
About the author: Kane Nawrocki is the founder and CEO of inSUPPORT. He has spent more than 25 years in IT and built inSUPPORT to give Australian businesses managed IT, security and compliance as one model, with the remediation an audit finds included in the support fee rather than billed back as a surprise project.
Content reviewed by Probably Genius for accuracy and relevance.
inSUPPORT provides managed IT and cyber security services. It is not an insurer, insurance broker or underwriter and does not hold an Australian Financial Services Licence. Where cyber insurance forms part of a plan, it is arranged through licensed insurance partners and underwritten by the insurer. Cover is subject to the insurer's assessment, the policy terms and the Product Disclosure Statement and Target Market Determination. This article is general information about IT and security practice, not financial product advice, and it does not take account of your objectives, financial situation or needs.
CLICK HERE


