ESSENTIAL EIGHT
Essential 8 Assessment — Know Your Maturity Level Before an Assessor Does
Run a guided Essential 8 assessment against the ACSC Maturity Model, get a prioritised uplift plan, and generate a board-ready posture report — without spinning up a four-week engagement. Includes a free 24-point self-assessment checklist.
WHY IT MANAGERS, CISOS AND SECURITY ANALYSTS IN AUSTRALIAN ORGANISATIONS CHOOSE FORTE/CYBERx
Decisions that hold up under scrutiny.
Maturity Level 0–3 in one mission
Score each of the eight strategies against the latest ACSC maturity model and see the realistic gap to your target.
Prioritised uplift plan
Get a sequence of mitigations ordered by risk reduction, effort and cost — not just a static checklist.
Board-ready posture report
BLUF, traffic-light heatmap and quarterly trend — formatted for the audit-and-risk committee.
TRY IT NOW
Bring one real decision. Get three defensible options.
The council returns a board-ready BLUF and three strategic options in under 60 seconds.
DECISIONS THE COUNCIL HANDLES
Sized for the conversation you're already having.
Pick a starting point or describe your decision in your own words. FORTE/CYBERx returns three strategic options with trade-offs, framework anchors and an execution-ready plan.
Where are we today vs ML1 / ML2 / ML3?
A defensible self-assessment that maps to the ASD ISM and Essential Eight Maturity Model.
What do we fix first?
Top five mitigations sorted by risk-reduction per dollar — not just patching first because it is easy.
How much will ML2 cost us?
A defensible budget shape for the uplift programme with optional managed-service comparison.
Are we eligible for federal contracts?
Map your maturity to the procurement requirements government and prime contractors increasingly enforce.
Quarterly board update on Essential Eight
Auto-generated trend and gap report ready to drop into the next board pack.
QUESTIONS
FAQ
What is the Essential Eight Maturity Model?
The ACSC Essential Eight Maturity Model scores your organisation from Maturity Level 0 (significant gaps) to Maturity Level 3 (adversaries with advanced tooling actively resisted) across eight mitigation strategies: application control, patch applications, Office macro restrictions, application hardening, restricted admin privileges, operating system patching, multi-factor authentication and regular backups. Most Australian boards and government tenders now expect ML2 as a baseline.
Is this a self-assessment or a third-party audit?
Self-assessment. It gives you a defensible, framework-anchored view of your Essential Eight posture you can take to the board and use to scope a formal assessment with an IRAP assessor when needed.
Do you cover all four mitigation strategy groupings?
Yes — application control, patch applications, configure MS Office macros, user application hardening, restrict admin privileges, patch operating systems, multi-factor authentication and regular backups.
How much does an Essential 8 assessment cost?
The guided platform assessment is free to start — two missions, no credit card — and the 24-point self-assessment checklist on this page is a free download. Formal third-party assessments (for example an IRAP-backed review) are scoped to your environment; we are happy to recommend an approach after seeing your self-assessment results.
Will the output map to ISO 27001:2022 controls?
Yes. Each Essential Eight strategy is cross-walked to the relevant Annex A 8.x controls so a single uplift plan satisfies both frameworks.
How often should we re-run the assessment?
Quarterly is the cadence most boards expect. The tool stores prior runs so trend lines show up automatically.
FREE RESOURCE
The Essential Eight Self-Assessment Checklist
Twenty-four checks across all eight ACSC mitigation strategies, ordered the way assessors actually review them — so you can walk into a formal assessment already knowing your gaps.
Stop the easy wins — application and macro control
The first four strategies block the most common intrusion paths. Assessors start here because attackers do too.
- Application control is enforced on all workstations and servers — not just deployed in audit mode
- Only approved, digitally signed scripts and installers can execute; users cannot self-approve new software
- Microsoft Office macros are blocked from the internet and only vetted macros run in trusted locations
+5 further checks in the download
Close the privilege and patch gaps
Privilege restriction and patching cadence are where most ML1 and ML2 assessments fail. Evidence matters more than intent here.
- Privileged accounts are separate from daily-use accounts and are never used for email or web browsing
- Admin rights are requested, time-bound and logged — standing admin access is the exception, not the rule
- Patches for internet-facing applications are applied within 48 hours; other applications within two weeks
+5 further checks in the download
Prove identity and recoverability
MFA and backups are the two strategies boards ask about first — and the two where untested assumptions hurt most.
- MFA is enforced for all remote access, all privileged access and all cloud services — no user-level opt-outs
- MFA uses phishing-resistant methods where supported (authenticator app or hardware key, not SMS)
- Backup schedules cover all critical data, systems and configuration — and coverage is reviewed quarterly
+5 further checks in the download
Get the checklist
PDF · No cost
Get the Essential Eight checklist
Free PDF · reply within one business day
Run your first mission free.
Two free missions. No credit card. Average mission resolves in under 60 seconds.