Essential Eight Compliance
Brisbane & Gold Coast
The Essential Eight is ASD’s security baseline for Australian businesses. We find your maturity level, put the eight strategies in place and keep them working.
- Maturity level assessed
- All eight strategies managed
- SMB1001 Gold achieved

The realistic target for most small businesses.
ASD mitigation strategies
Maturity levels
Typical SMB target
Achieved through CyberCert
What is the Essential Eight?
The Essential Eight is a set of eight mitigation strategies published by the Australian Signals Directorate (ASD). They block the ways most attacks start: malicious software, unpatched weaknesses, stolen passwords and misused admin accounts.
It isn’t a legal requirement for most private businesses, but it is the benchmark insurers, clients and tender panels use, and SMB1001 builds on many of the same controls.

- Eight strategies, each rated Maturity Level 0 to 3
- Not law for most, but widely asked about
- Assessed, not certified: you reach a maturity level
- Evolving into ASD’s broader Essentials series
The Essential Eight in plain English
What each one means, and what we do about it.
Application control
Only approved software can run, so malware can’t launch even if someone downloads it. We set the rules and approve new software requests in real time.
Patch applications
Browsers, PDF readers, Office and business apps get security fixes quickly. We patch on a schedule and scan for anything missed.
Configure Microsoft Office macro settings
Macros inside Office files are a common way to deliver malware. We block macros from the internet, allow them only where needed and lock the settings.
User application hardening
Browsers, Office and PDF software are set up so attackers can’t use them as a way in: web ads blocked, risky features off, settings locked.
Restrict administrative privileges
Admin access is limited to the few people who need it. Staff work on standard accounts, so a stolen login can’t install software or change settings.
Patch operating systems
Windows and macOS get security updates on a schedule, critical fixes first. Computers that no longer receive security updates are flagged for replacement.
Multi-factor authentication
A second check after the password. We turn it on for Microsoft 365 or Google Workspace, remote access and admin accounts, and block overseas sign-ins by default.
Regular backups
Data, apps and settings are backed up and kept separate from live systems. We monitor every backup and run test restores.
Where does your business sit today?
Our free cyber security assessment checks MFA, patching, admin access and backups: a quick view of your biggest gaps.
Maturity Levels 0 to 3, explained
ASD rates each strategy from Maturity Level 0 to 3. Each step up resists a more determined attacker.
Missing or only partly in place, leaving gaps common attacks can use.
In place at a basic level, stopping opportunistic attackers using freely available tools.
Tighter, faster and logged, to stop attackers who put in more time and effort.
Built to hold up against skilled, well-resourced attackers targeting a specific organisation.
ASD recommends reaching the same maturity level across all eight strategies before aiming higher.
The right target for your business
Most small businesses we meet start at Maturity Level 0 or 1. That’s normal, and fixable. We aim for Level 1 across all eight strategies first.
Then we aim for Level 2 where you hold sensitive client data, as healthcare practices and accounting firms do, or where a client or insurer asks for it.
We won’t promise Maturity Level 3. It is built for organisations facing skilled, targeted attackers, and rarely makes sense for a business of 5 to 100 staff.
- Level 1 across all eight strategies first
- The highest-impact fixes done in the first weeks
- Level 2 where your risk calls for it
- Regular reviews as your business changes
From the Essential Eight to the Essentials series
In June 2026, ASD announced that the Essential Eight will evolve into a broader “Essentials” series. The first chapter is Essentials for Enterprise IT, with later chapters for cloud and operational technology. The Essential Eight will be phased out over roughly the next two years.
ASD says organisations already implementing the Essential Eight can expect strong alignment with their existing controls. As new chapters are published, we’ll map your controls across and flag anything new.
Don’t pause your Essential Eight work. The controls carry across.

How we assess and implement it
Managed IT clients have most controls in place once onboarding is complete. Otherwise, four steps.
Maturity assessment
We check each strategy against ASD’s maturity criteria and record where you sit today.
Roadmap
A prioritised plan: which gaps to close first, the target level for each strategy and a fixed price.
Implementation
We put the controls in place and test them with your team, so nothing breaks on Monday morning. From scratch, allow four to eight weeks.
Evidence and upkeep
We document the controls for insurers, clients and SMB1001, then keep them managed.
Essential Eight, SMB1001 and cyber insurance
How it relates to SMB1001
An Australian certification standard for small and medium businesses. Its technical controls overlap heavily with the Essential Eight, and you get a certificate.
How it relates to cyber insurance
Insurers ask about MFA, patching, admin privileges and backups, all Essential Eight strategies. A documented maturity level helps you answer accurately. Approval and premiums stay the insurer’s call.
Very fast to help us with any issue we’ve had. Being in the building industry we don’t know computers, but they explain things in non geek speak. Very happy.
Southport, Gold Coast
We run these controls on our own systems
SEQ IT achieved SMB1001 Gold through CyberCert. We work under the controls we recommend.

SMB1001 Gold

Certification Partner

Partner and Cloud Solution Provider (CSP)

Google Cloud Partner
Essential Eight: common questions
Is the Essential Eight mandatory for small businesses?
Not for most private businesses, but insurers, clients and tender panels ask about it. The Privacy Act 1988 also expects businesses it covers to take reasonable steps to protect personal information, and these controls are a practical way to show you have.
What Essential Eight maturity level should a small business aim for?
Most small businesses begin at Maturity Level 0 or 1. We aim for Level 1 across all eight strategies first, then Level 2 where you hold sensitive data or a client or insurer asks for it. Level 3 suits organisations facing targeted attackers.
How long does Essential Eight implementation take?
It depends where you start. If MFA, patching and backups are already in place, the remaining controls can often be done within a few weeks. From scratch, allow four to eight weeks. For managed IT clients, most controls are in place once onboarding is complete.
Is the Essential Eight being replaced?
In June 2026 ASD announced it will evolve into a broader Essentials series, starting with Essentials for Enterprise IT, and be phased out over roughly the next two years. ASD expects strong alignment for organisations already implementing the Essential Eight.
What is the difference between the Essential Eight and SMB1001?
The Essential Eight is ASD’s set of eight technical strategies, measured by maturity level, with no certificate. SMB1001 is a certification standard for small and medium businesses, covering technical controls plus policies and processes, with tiers from Bronze upwards.
Do you do Essential Eight assessments?
Yes. We assess each strategy, record your maturity level and give you a prioritised plan to close the gaps. For clients on our managed plans the assessment is included. Standalone assessments are quoted at a fixed price before we start.
Build on your Essential Eight work
Cyber security services
The managed controls behind every strategy.
SMB1001 certification
Turn your controls into a recognised certificate.
Cyber insurance readiness
Answer insurer questions with evidence.
Governance and compliance
Policies and evidence for frameworks.
Data backup and recovery
Monitored backups, tested restores.
Find your Essential Eight maturity level
Tell us about your business. We’ll explain where you likely sit and what it takes to improve. No obligation.
- Your current maturity, strategy by strategy
- A realistic target and the order to work in
- A fixed price before any work starts
Prefer to talk? Call 1300 619 750, Monday to Friday.
Tell us what you need. We’ll get back to you within one business day.
