Essential Eight

Assess Your Essential Eight Maturity

Understand where you stand against ASD's Essential Eight. Get a clear roadmap to ML2 compliance with actionable priorities.

AGSVA Cleared Team Canberra-Based ACSC-Aligned Assessment

E8 ML2 Assessment

Essential Eight Maturity

Application Control ML2 achieved
Patch Applications ML2 achieved
Configure Macros ML2 achieved
User App Hardening ML1 — In Progress
Restrict Admin ML2 achieved
Patch OS ML1 — In Progress
Multi-Factor Auth ML2 achieved
Regular Backups ML2 achieved

ML2 Status

6/8 AT ML2

Assessment Cost

From $15k

Scales with environment complexity

Sound familiar?

The challenges you're facing

Pressure to demonstrate progress

Reporting cycles, audits, or delivery timelines require evidence of security maturity within defined timeframes.

Unclear where to focus your investment

There are many possible security activities, but limited clarity on which actions will reduce risk or improve maturity.

Conflicting or incomplete guidance

Different stakeholders provide advice on what to implement, but there is limited clarity on scope, applicability, and how requirements are actually assessed.

Too much to do, no clear prioritisation

Security, projects, and operational demands compete for attention, making it difficult to decide what should be addressed first.

What you get

What's included in the assessment

Defensible maturity position

Clear view of current maturity based on evidence, with alignment to how assessments are conducted and interpreted in practice.

Assessment aligned to ACSC expectations

Assessment of all Essential Eight strategies using ACSC guidance and tools, supported by practitioner-led validation of control implementation.

Prioritised uplift plan

Sequenced actions based on risk, effort, and impact — so you know what to address first and why.

Indicative investment view

Practical guidance on effort and cost to close gaps, supporting planning and decision-making.

Executive-level reporting

Clear summary translating technical findings into decisions and priorities for leadership.

Baseline for ongoing assurance

Documented view of control implementation to support future reviews, reporting, and continuous improvement.

Why Strategic Cyber

Independent view, focused on what matters

Your internal teams and providers focus on operating and supporting your environment. We provide an independent view of your Essential Eight maturity, clarify what matters, and support you to prioritise and address gaps.

Is this right for you?

Who this service is for

Demonstrating maturity

Organisations required to demonstrate Essential Eight maturity

You need to evidence your current posture and identify gaps aligned to formal assessment expectations.

Review & audit cycles

Organisations preparing for review, audit, or reporting cycles

You need a clear, defensible view of maturity and a structured plan to address gaps within defined timeframes.

Validating next steps

Organisations with existing assessments but limited clarity on next steps

You've been assessed before, but need to validate results, prioritise actions, and plan uplift effectively.

Investment

Transparent, scalable pricing

Start here

Free Health Check

No cost Free

Indicative posture review — delivery format (in-person or remote) agreed based on location and engagement scope.

  • High-level posture review
  • Initial gap identification
  • Recommended next steps
Book Free Health Check
Aligned to recognised E8 assessment standards Understand where you stand and what to prioritise to reach ML2.

E8 ML2 Assessment

Starting from $15,000

Clear view of effort and next steps.

  • All 8 mitigation strategies assessed
  • Prioritised remediation roadmap
  • Executive & board-ready reporting
  • DISP readiness indicator
Get a Quote
Close priority gaps and progress toward ML2.

Assessment & Uplift

Starting from $40,000

Assessment plus implementation — closing gaps, building documentation, and preparing your organisation for compliance milestones. Delivery format (in-person / remote) agreed based on location and engagement scope.

  • Implement and validate controls
  • Close gaps for ML2
  • Support delivery of uplift activities
Get a Quote

We don't just assess — we help you close gaps and demonstrate progress toward ML2.

Pricing note: Assessment pricing scales with environment complexity. Small environments (under 50 users, M365-centric) start from $15,000. Larger or hybrid environments are scoped individually. All pricing is indicative and depends on environment size and complexity.

Talk to us on the spot

Book an intro call

Pick a time that works for you — we'll confirm scope and send a pre-read before the call.

Proof

Real engagements, real outcomes

Anonymised

Federal department

Essential Eight maturity maintained between formal assessments

Delivered an Essential Eight maturity review across a multi-system environment using ACSC verification methodology. Followed with continuous assurance aligned to PSPF reporting and ASD survey cycles, maintaining visibility of control effectiveness between formal assessments.

Anonymised

Federal agency

Essential Eight compliance sustained beyond project delivery

Evaluated a multi-year Essential Eight uplift program and assessed its sustainability. Delivered a transition-to-business-as-usual plan with defined ownership, cadence, and evidence requirements, enabling compliance to be maintained beyond project delivery.

Anonymised

Federal agency

E8 uplift focused on priority gaps

Refined assessment outputs to identify the most critical gaps requiring action, enabling leadership to prioritise effort and focus investment on reducing risk and improving maturity.

Common questions

Frequently asked questions

How long does an E8 assessment take?

Typically 2–4 weeks depending on environment size. Small environments can be assessed in under 2 weeks. The timeline depends on how quickly your team can provide access to key systems, documentation, and key stakeholders for workshops.

What do we need to prepare?

Access to your environment documentation, IT architecture diagrams, and key stakeholders for workshops. We'll provide a detailed preparation checklist during scoping so you know exactly what you need to have ready.

Do you also implement the fixes?

Yes — our Uplift tier covers assessment plus implementation. We can assess first and then scope uplift separately, or combine both from the start. We'll discuss the best approach for your situation during scoping.

How is this different from what our MSP tells us?

MSP reporting is operationally focused — uptime, tickets, patching status. Our assessment maps controls specifically to ASD's Essential Eight maturity model with evidence-based verification against each mitigation strategy. It's a formal, compliance-grade assessment rather than operational reporting — and every consultant on the engagement is senior, AGSVA-cleared, and from a government delivery background, so you work directly with experienced practitioners throughout.

Can this help with our DISP submission?

Absolutely. Essential Eight ML2 is a core DISP cyber security requirement. The assessment report directly supports your DISP submission and CSQ completion. Many of our clients use the E8 assessment as a stepping stone to full DISP readiness.

How long from first conversation to compliance-ready evidence?

For a small, M365-centric environment we typically go from scoping to a full ML2 assessment report in 4-6 weeks. Uplift timelines depend on the size of the gap but most defence suppliers reach ML2 within 3-6 months of starting.

How do we budget for this?

Assessment starts from $15,000 and scales with environment complexity. Uplift starts from $40,000. We scope and price every engagement individually after a free health check so you know the range before committing.

Get started

Ready to understand your Essential Eight maturity?

Book a call with our team to scope your assessment.

Canberra-based • AGSVA cleared • Government-experienced