ESSENTIAL EIGHT

Essential 8 Assessment — Know Your Maturity Level Before an Assessor Does

Run a guided Essential 8 assessment against the ACSC Maturity Model, get a prioritised uplift plan, and generate a board-ready posture report — without spinning up a four-week engagement. Includes a free 24-point self-assessment checklist.

Run your first mission freeTalk to usTwo free missions · No credit card
Aligned to the ACSC Essential Eight Maturity Model (latest update)Cross-walked to ISO 27001:2022 and NIST CSF 2.0Includes the eligibility-for-government-tender lensOutputs an editable maturity report and uplift roadmap

WHY IT MANAGERS, CISOS AND SECURITY ANALYSTS IN AUSTRALIAN ORGANISATIONS CHOOSE FORTE/CYBERx

Decisions that hold up under scrutiny.

Maturity Level 0–3 in one mission

Score each of the eight strategies against the latest ACSC maturity model and see the realistic gap to your target.

Prioritised uplift plan

Get a sequence of mitigations ordered by risk reduction, effort and cost — not just a static checklist.

Board-ready posture report

BLUF, traffic-light heatmap and quarterly trend — formatted for the audit-and-risk committee.

TRY IT NOW

Bring one real decision. Get three defensible options.

The council returns a board-ready BLUF and three strategic options in under 60 seconds.

Run your first mission free

DECISIONS THE COUNCIL HANDLES

Sized for the conversation you're already having.

Pick a starting point or describe your decision in your own words. FORTE/CYBERx returns three strategic options with trade-offs, framework anchors and an execution-ready plan.

Where are we today vs ML1 / ML2 / ML3?

A defensible self-assessment that maps to the ASD ISM and Essential Eight Maturity Model.

What do we fix first?

Top five mitigations sorted by risk-reduction per dollar — not just patching first because it is easy.

How much will ML2 cost us?

A defensible budget shape for the uplift programme with optional managed-service comparison.

Are we eligible for federal contracts?

Map your maturity to the procurement requirements government and prime contractors increasingly enforce.

Quarterly board update on Essential Eight

Auto-generated trend and gap report ready to drop into the next board pack.

QUESTIONS

FAQ

What is the Essential Eight Maturity Model?

The ACSC Essential Eight Maturity Model scores your organisation from Maturity Level 0 (significant gaps) to Maturity Level 3 (adversaries with advanced tooling actively resisted) across eight mitigation strategies: application control, patch applications, Office macro restrictions, application hardening, restricted admin privileges, operating system patching, multi-factor authentication and regular backups. Most Australian boards and government tenders now expect ML2 as a baseline.

Is this a self-assessment or a third-party audit?

Self-assessment. It gives you a defensible, framework-anchored view of your Essential Eight posture you can take to the board and use to scope a formal assessment with an IRAP assessor when needed.

Do you cover all four mitigation strategy groupings?

Yes — application control, patch applications, configure MS Office macros, user application hardening, restrict admin privileges, patch operating systems, multi-factor authentication and regular backups.

How much does an Essential 8 assessment cost?

The guided platform assessment is free to start — two missions, no credit card — and the 24-point self-assessment checklist on this page is a free download. Formal third-party assessments (for example an IRAP-backed review) are scoped to your environment; we are happy to recommend an approach after seeing your self-assessment results.

Will the output map to ISO 27001:2022 controls?

Yes. Each Essential Eight strategy is cross-walked to the relevant Annex A 8.x controls so a single uplift plan satisfies both frameworks.

How often should we re-run the assessment?

Quarterly is the cadence most boards expect. The tool stores prior runs so trend lines show up automatically.

FREE RESOURCE

The Essential Eight Self-Assessment Checklist

Twenty-four checks across all eight ACSC mitigation strategies, ordered the way assessors actually review them — so you can walk into a formal assessment already knowing your gaps.

01

Stop the easy wins — application and macro control

The first four strategies block the most common intrusion paths. Assessors start here because attackers do too.

  • Application control is enforced on all workstations and servers — not just deployed in audit mode
  • Only approved, digitally signed scripts and installers can execute; users cannot self-approve new software
  • Microsoft Office macros are blocked from the internet and only vetted macros run in trusted locations

+5 further checks in the download

02

Close the privilege and patch gaps

Privilege restriction and patching cadence are where most ML1 and ML2 assessments fail. Evidence matters more than intent here.

  • Privileged accounts are separate from daily-use accounts and are never used for email or web browsing
  • Admin rights are requested, time-bound and logged — standing admin access is the exception, not the rule
  • Patches for internet-facing applications are applied within 48 hours; other applications within two weeks

+5 further checks in the download

03

Prove identity and recoverability

MFA and backups are the two strategies boards ask about first — and the two where untested assumptions hurt most.

  • MFA is enforced for all remote access, all privileged access and all cloud services — no user-level opt-outs
  • MFA uses phishing-resistant methods where supported (authenticator app or hardware key, not SMS)
  • Backup schedules cover all critical data, systems and configuration — and coverage is reviewed quarterly

+5 further checks in the download

Get the checklist

PDF · No cost

Native secure submission. Your details are never sold or shared.

A senior advisor responds within one business day — no sales sequence.

Get the Essential Eight checklist

Free PDF · reply within one business day

Get it

Run your first mission free.

Two free missions. No credit card. Average mission resolves in under 60 seconds.