The Essential Eight is a set of eight cyber security strategies that the Australian Signals Directorate (ASD) recommends as a baseline for Australian organisations. It covers patching, multi-factor authentication, admin privileges, application control, Office macros, application hardening and backups, with maturity levels from zero to three. It is required for non-corporate Commonwealth entities and voluntary for private businesses.
Reviewed by Ben Webster
ASD publishes a longer list of ways to reduce cyber risk. The Essential Eight are the eight it considers most effective, and it recommends organisations implement them as a baseline. In plain terms:
The strategies are designed to work together. ASD recommends reaching the same maturity level across all eight before moving any one of them higher.
ASD's maturity model sets out four levels, from Maturity Level Zero to Maturity Level Three:
ASD's FAQ says that, generally, Maturity Level One may be suitable for small to medium enterprises, Maturity Level Two for large enterprises, and Maturity Level Three for critical infrastructure providers and others in high-threat environments. It also asks organisations to choose a target level that suits their own environment.
For federal government, yes. The Protective Security Policy Framework (PSPF) requires non-corporate Commonwealth entities to implement the Essential Eight, and ASD describes Maturity Level Two as their mandatory baseline.
For private businesses, no. There is no general law requiring an Australian business to adopt it, and ASD says there is no requirement to have an implementation certified. A contract, a tender or a regulator can still ask you to meet a particular level, so check what you have agreed to.
Cyber insurers do not usually ask whether you are "Essential Eight compliant". What we see instead is proposal forms asking about individual controls, and the ones that come up most often are Essential Eight strategies: multi-factor authentication, backups, patching and admin access. Insurers also tend to ask about things outside the Eight, such as email authentication (DMARC) and whether remote desktop is exposed to the internet.
So the Essential Eight is a useful checklist even if nobody requires it of you. The same controls that reduce the chance of an incident are the ones an insurer is likely to ask about.
A formal Essential Eight assessment is done by a qualified assessor using ASD's assessment process. For most small businesses, a sensible first step is lighter: find out which controls you already have and where the obvious gaps are.
A free scan and self-assessment will do that. The scan checks what anyone can see of your business from the internet, and the self-assessment asks short yes-or-no questions mapped to the Essential Eight. It is not a formal assessment, but it shows you where to start. Run a free scan.
The Essential Eight is a short list of technical controls published by the Australian Signals Directorate, with a maturity model for each. ISO/IEC 27001 is an international standard for running an information security management system, covering governance, risk assessment and policy as well as controls, and it is usually certified by an external auditor. Many organisations use the Essential Eight as part of the controls inside a broader framework.
It depends on how many devices and systems you run and what is already in place. A small business on modern cloud services that already uses multi-factor authentication and automatic updates is often most of the way there. A business with older servers, shared admin accounts or no tested backups has more to do. Work through one strategy at a time and aim for the same level across all eight.
The Australian Signals Directorate (ASD), through its Australian Cyber Security Centre. The strategies, the maturity model and an FAQ are published free on cyber.gov.au and are updated from time to time.
No. ASD says there is no requirement to have an Essential Eight implementation certified by an independent party. An independent assessment may still be needed if a government policy, a regulator or a contract requires one.
General information only, not financial or insurance advice. Talk to a licensed broker about your situation.
Enter your website and CertIQ scores your cyber health out of 100 in under 10 seconds, with a short Essential Eight self-assessment. Free, no account needed.
More answers: Do I need cyber insurance? · How much does cyber insurance cost in Australia? · A customer sent me a cyber security questionnaire. Where do I start? · Can someone send email pretending to be my business?