Why Your IT Provider Is Quiet About Compliance

Most IT providers go quiet about compliance because a claim worth making has six parts, and saying all six is harder than saying nothing. Compliant with which framework, across what scope, to which maturity level, assessed by whom, on what date, and meaning what. The Australian Signals Directorate (ASD) publishes the Essential 8 as a baseline with four maturity levels and no certificate at the end. inSUPPORT has run more than 1,500 cyber audits for Australian businesses, and the silence is rarely a cover-up. It is usually a provider who knows the honest answer is longer than the question.

If a framework has landed on your desk with a board, a client or an insurer behind it, you know the uncomfortable part already. Alignment is not a certificate you buy, nobody in the building has time to run and prove it, and asking your provider if they are capable feels like an accusation. So the question sits in a drawer.

The reality is that this work never finishes, and the framework says so. ASD asks you to choose a target level, reach it across all eight mitigation strategies before you move up, and document any exception you keep. A provider promising a finished state has described something ASD does not issue.

What follows is the claim in six parts, the honest reasons the subject gets avoided even by good providers, and the questions that turn a vague "we handle that" into a document with a date on it.

TL;DR: What to remember

  • ✅ "Compliant" on its own is not a status ASD issues. A claim that means something names the framework, the scope, the maturity level, who assessed it, when, and what it does not cover.
  • ✅ The Essential 8 is a baseline with four maturity levels and no certificate. Same level across all eight strategies before you move up, exceptions documented and reviewed. It never finishes, which is exactly why nobody wants to promise it.
  • ✅ Ask for the evidence tier, not the adjective. ASD grades a policy document or a verbal statement of intent as Poor evidence and a tested control as Excellent. Which tier your provider's answer sits on is the whole conversation.
  • ✅ One ineffective control sinks the whole strategy in ASD's method, so your weakest area describes your position. A strong patching result cannot be averaged against a missing one.
  • ✅ If the fix is a separate project, raising compliance means raising a bill. Find out which commercial model you are on before you read anything into the silence.

Contents

What "we do compliance" has to say before it means anything

When a provider tells you that you are compliant, ask them "compliant with what". ASD does not issue that status. Its maturity model defines four levels, Maturity Level Zero through to Maturity Level Three, asks each organisation to identify a target suitable for its own environment, and states that no independent certification is required. A bare "compliant" is not a finding. It is a mood.

A claim that carries weight names six things, and you can hold a provider to all six without understanding a single control. The framework: Essential 8, ISO 27001, SMB1001, whichever one the person asking named. The scope: which systems, sites and users sit inside the assessment boundary, a stage of its own in ASD's guide. The level: which one was targeted, and whether it was met. The assessor: who looked, and whether they were independent of the team running the environment. The date, because last year's position is last year's position. And the meaning: what the claim does not cover, which is the part that gets left off. A checklist you fill in yourself is not an assessment.

Put those six on one page and the mystery leaves the room. "Assessed against Maturity Level One of the Essential 8, head office and the Microsoft 365 tenant, by our own engineers in March, with two documented exceptions open" is a sentence you can take to a board, an insurer or a client. It is not flattering, and it is something you can act on.

Why the conversation goes quiet, even with a decent provider

I do not think most providers are hiding something. The honest answer is awkward in three ways, and silence is cheaper than any of them. The first is that the work never finishes. ASD asks you to reach the same maturity level across all eight strategies before moving up, and to document and approve any exception, with none standing beyond a year. That is a standing obligation, not a project with an end date, and a provider selling helpdesk and patching cannot promise it without changing what they sell.

The second is evidence. ASD ranks what an assessor can rely on: testing a control is Excellent, reviewing the configuration through the system itself is Good, a report or a screenshot is Fair, and a policy document or a verbal statement of intent is Poor. That bottom tier is where "we do that" lives. A provider whose records are conversations knows the agency that wrote the framework would grade that Poor, and would rather it was not graded. The nine things a provider should show you at a review sit above that line.

The third is money, and the industry deserves its due. If the audit is one invoice and the fix is another, every gap found becomes a quote, and raising compliance means raising a bill nobody asked for. That is a legitimate way to sell IT. It is also why inSUPPORT priced remediation inside the support fee: when the fix is paid for, the finding is easier to mention.

How to open the conversation, and what a straight answer sounds like

Start with the provider's own house, because ASD hands you the questions. Its guidance for organisations engaging a managed service provider asks five: are you implementing better practice cyber security, are you securely administering your systems and services, are you monitoring activity on them, are you regularly assessing them, and are you prepared for and able to respond to a cyber security incident. A provider who cannot answer those about their own environment is not going to run Essential 8 compliance across yours.

Then ask for the six parts in writing. Which framework, and who chose it. What is in scope, what was left out, and why. Which maturity level, and whether it was met across all eight strategies or only the strong ones. That distinction is ASD's own: every control in a strategy must be effective or an alternate control, and one ineffective control means the level cannot be claimed. Then who assessed it, on which evidence tier, when it is next due, and what it does not cover.

A straight answer is a document with a date on it, an exception register with an owner against every gap, and a costed list of what is still open in the order it should be closed. That is what a Cyber Strength Audit produces. A nervous answer is an adjective, a promise to send something through, and a change of subject. I would take the awkward document over the comfortable adjective every time, and so should you.

  • Write down who is asking, whether that is the board, a client or an insurer, and the exact words they used. Their document sets the target.
  • Put ASD's five questions to your provider about their own environment first.
  • Request the six-part claim in writing, with the evidence tier behind each finding and the exception register.
  • Ask which commercial model you are on: remediation inside the fee, or quoted separately.
  • Ask for the record ASD expects an organisation to keep about a managed service: the provider and service named, the data involved, the due date for the next security control assessment, the contractual arrangements and 24/7 contact details. Those controls are written for government systems, so they do not bind your business. They are a good shape for the question.
  • If nothing dated comes back, get an independent read before you decide anything about contracts.

Questions owners ask when compliance finally comes up

Does my managed IT provider handle Essential 8 compliance?

Ask, and ask for the six parts. Plenty of providers will say Essential 8 compliance is included, and in practice that can mean anything from a documented assessment against a target maturity level to a patching schedule and multi-factor authentication switched on for most users. Neither is wrong, but only one of them is a position you can repeat to the person who asked you. If the answer names the framework, the scope, the level, the assessor and the date, they handle it. If it names none of those, they may be doing good work and still be unable to prove it, which to a board, a client or an insurer is the same thing as not doing it.

Do I need a separate compliance assessor, or should my IT provider do it?

ASD's own position is that there is no requirement for an Essential Eight implementation to be certified by an independent party, but that an implementation may need to be assessed by an independent party where a government directive or policy, a regulatory authority, or a contract requires it. So read who is asking. If it is your own board, a well-documented assessment by the provider who runs the environment, or by your own people where you have them, can be exactly right, provided the evidence tier is named honestly. If it is a client contract or a regulator, read what it demands before you commission anything. The trap is paying one firm for a report and another for a quote, and ending up with two documents and no closed gaps.

How long does it take to get aligned to the Essential 8?

Longer than a project and shorter than forever, and the honest answer depends on the size and complexity of the environment, which is ASD's own position on assessment. The model is sequential: you reach one maturity level across all eight mitigation strategies before you start on the next, and one ineffective control stops you claiming that level. What can be pinned down early is the order of work, the owner of each gap and what it costs to close, which is why inSUPPORT builds the remediation plan after the audit rather than before it. One caution on dates. The two Essential 8 pages behind this article were last updated in November 2023 and October 2024, and ASD has since consulted on evolving the Essential 8 into a broader Essentials series, in a consultation that closed on 12 July 2026. Nothing about what is required today has changed, and ASD says organisations already using the Essential Eight can expect strong alignment with their existing controls and investments. All three of those pages were read on 18 September 2026, and it is worth checking the current release before you rely on a level.

Where do I start if my provider has never raised compliance?

Start by not treating the silence as a verdict. Send them the six parts and ASD's five questions and give them a fair chance to answer, because a provider who comes back with a dated document has just told you something good. If what comes back is an adjective and a promise to send something later, get an independent picture of where the environment actually stands before you make any decision about contracts. An assessment turns a suspicion into a list, and a list is something you can put in front of the provider you have or the one you are considering.

See what your compliance claim would actually say

If you cannot fill in the six parts for your own business today, that is the gap, and it is a fixable one. A Cyber Strength Audit assesses your environment against the compliance frameworks that apply to your industry, including the relevant Essential 8 controls, and hands you a plain-English risk picture ranked by what would actually hurt you, a documented audit trail you can give to a board, an insurer or a client who asks, and a costed path to closing each gap. inSUPPORT has run more than 1,500 of them for Australian businesses of roughly 30 to 300 users, and if you go on to managed support with us, the remediation it finds is included in the fee rather than billed back as a separate project. We will say the uncomfortable part out loud, and put a date on it.

Book a Cyber Strength Audit →

Citations

  • "Essential Eight maturity model, Australian Signals Directorate", ASD's own model, read 18 September 2026 and last updated 27 November 2023: four maturity levels, Maturity Level Zero through to Maturity Level Three; a target level identified per environment; the same maturity level across all eight mitigation strategies before moving onto higher ones; exceptions minimised, documented, approved and reviewed regularly; the Essential Eight as a minimum set of preventative measures; and the statement that there is no requirement for an implementation to be certified by an independent party unless a government directive or policy, a regulatory authority or a contract requires it. cyber.gov.au
  • "Essential Eight assessment process guide, Australian Signals Directorate", Read 18 September 2026 and last updated 2 October 2024. The four levels of evidence quality (Excellent, Good, Fair, Poor) and what sits in each; the seven standardised assessment outcomes; the rule that all controls within a mitigation strategy must be assessed as effective or alternate control, so one ineffective control means the maturity level cannot be claimed; the assessor's determination of the assessment scope, or boundary, as a stage of its own; the requirement that exceptions carry their detail, scope and justification and not be approved beyond one year; and the position that the approach to an assessment depends on the size and complexity of a system. cyber.gov.au
  • "Guidelines for procurement and outsourcing, Information Security Manual, Australian Signals Directorate", Read 18 September 2026 and last updated 3 September 2026. Controls ISM-1736 and ISM-1737: a managed service register is developed, implemented, maintained and regularly verified, and for each managed service it records the provider's name, the service name, the purpose for using it, the sensitivity or classification of the data involved, the due date for the next security control assessment, the contractual arrangements, the organisational point of contact and 24/7 contact details. The same section expects managed service providers to undergo regular security control assessments against the ISM. These controls apply to government systems at the classifications listed against them, not to Australian businesses generally, which is why the article offers the register as a shape for the question rather than an obligation. cyber.gov.au
  • "Consultation on evolution of Essential Eight, Australian Signals Directorate", Read 18 September 2026; first published and last updated 15 June 2026. ASD's news item announcing consultation with its Cyber Security Network partners on evolving the Essential Eight into a new Essentials series grounded in the Information Security Manual, with the current guidance forming the first chapter, Essentials for enterprise IT. The consultation ran via the ASD Cyber Security Partnership Program portal until 12 July 2026 and is closed. The page states that organisations already using the Essential Eight can expect strong alignment with their existing controls and investments. Cited for the review-date sentence; no requirement has changed and the current maturity model still governs. cyber.gov.au
  • "Questions to ask managed service providers, Australian Signals Directorate", Read 18 September 2026 and last updated 6 October 2021. The five questions ASD suggests putting to a managed service provider about its own practice: are you implementing better practice cyber security, are you securely administering your systems and services, are you monitoring activity on your systems and services, are you regularly assessing your systems and services, and are you prepared for and able to respond to cyber security incidents. cyber.gov.au
Kane Nawrocki, Founder and CEO of inSUPPORT

About the author: Kane Nawrocki is the founder and CEO of inSUPPORT. He has spent more than 25 years in IT and built inSUPPORT to give Australian businesses managed IT, security and compliance as one model, with the remediation an audit finds included in the support fee rather than billed back as a surprise project.

Content reviewed by Probably Genius for accuracy and relevance.

Want to discuss this topic more?
CLICK HERE