ACSC Essential Eight Maturity Model
Essential Eight readiness assessment
Prove the Essential Eight maturity you can actually substantiate.
The eight ACSC mitigation strategies as a curated, maturity-aware control library.
8 mitigation strategy entries · versioned & change-controlled
Who it’s for
Australian organisations (and their MSPs) using the ACSC Essential Eight to baseline and evidence cyber maturity.
What readiness means for Essential Eight
For the Essential Eight, readiness means each of the eight mitigation strategies is evidenced at the maturity level you target — application control, patching, macro settings, MFA, backups and more.
How Netallion handles it
Your Essential Eight readiness journey
- 1
Set the target maturity
Fix the maturity level you are targeting (One to Three) so each of the eight strategies is assessed against the expectations for that level, not a generic pass/fail.
- 2
Map evidence to strategies
Attach configuration exports, patch reports and MFA and backup records to the mitigation strategy they support, with ownership and review dates.
- 3
Assess achieved posture
Each strategy is assessed for whether the evidence demonstrates the targeted maturity in operation across the fleet — coverage and configuration, not just that a tool is present.
- 4
Surface blockers
Strategies where evidence falls short of the targeted level — a control deployed but not consistently configured — become explicit blockers per strategy.
- 5
Review & finalise
An authorised assessor reviews the determinations and pins the achieved posture; Essential Eight maturity is determined by an assessor against the ACSC model — there is no Netallion-issued certification.
The control library
What the Essential Eight library gives you
The eight ACSC mitigation strategies as a curated, maturity-aware control library.
A curated, versioned catalogue of this framework’s 8 mitigation strategy entries — with provenance — to collect, own, organise and track the currency of your evidence against.
From the field
Common Essential Eight blockers we find
Where evidence most often falls short — surfaced explicitly, not averaged away.
- Application control is deployed but macro settings are unmanaged, so one strategy passes while an adjacent one is wide open.
- MFA covers the corporate SSO but not remote access or privileged accounts, so coverage is partial against the targeted level.
- Backups run nightly but there is no restoration-test evidence, so recoverability is asserted rather than demonstrated.
- OS patching is timely but application patching lags well beyond the window the targeted maturity requires.
Evidence
The evidence you'll bring
You upload and own your evidence; Netallion organises it and tracks ownership and expiry. For this framework it typically spans:
Application control & patching
- application-control configuration & allowlists
- patch-management reports for applications
- operating-system patch cadence
- vulnerability-scan results
Macro & hardening
- Office macro settings & source restrictions
- user-application-hardening configuration (browsers, PDF, Java)
- web-content controls
Admin & MFA
- restrict-admin-privileges reviews
- privileged-access management records
- MFA coverage evidence across users and remote access
Backups
- backup schedules & scope
- restoration-test evidence
- backup access controls
- offline/immutable-copy arrangements
Start now — free
Prepare your Essential Eight evidence
Assess your Essential Eight evidence with Netallion
There’s no self-serve kit for Essential Eight yet. On an assessed engagement, Netallion scopes the requirements, organises your evidence, and determines readiness with explicit blockers.
From evidence to a conclusion
How readiness is reached
The kit helps you prepare. Netallion organises the evidence, assesses whether it's sufficient, and reaches a traceable readiness conclusion.
- 1Scope
The applicable requirement set for your framework and scope.
- 2Applicable requirements
A fixed denominator — every in-scope requirement counts.
- 3Evidence
You attach and own evidence; ownership and expiry are tracked.
- 4Evidence assessment
The evidence is read against each requirement for sufficiency.
- 5Determination
A requirement-level verdict with byte-verified citations.
- 6Blocker
Negative findings surface as explicit blockers, not averages.
- 7Remediation
Track the fix; reassessment — not a checkbox — resolves it.
- 8Review (R0–R3)
Controlled human review with recorded provenance.
- 9Finalisation
A signed, scope-pinned readiness conclusion.
- 10Report / export
Readiness report, evidence index, SoA, audit ZIP + SHA-256.
- 11Lifecycle & reassessment
Evidence expires/changes → affected requirements reopen.
Schematic of the assurance workflow. Evidence collection and management are available today; the assessment, determination, review and finalisation stages are the System-B assurance engine.
What you get out
- Maturity-aware readiness across all eight mitigation strategies
- per-strategy achieved-posture view against your target level
- explicit blocker list with reasons
- evidence index + audit ZIP with SHA-256 manifest
FAQ
Essential Eight readiness — common questions
Does Netallion certify Essential Eight maturity?
No. Essential Eight maturity is determined by an assessor against the ACSC maturity model. Netallion assesses your evidence against each mitigation strategy to show the posture you can substantiate.
Which maturity level does Netallion assess against?
The eight strategies are maturity-aware; an engagement is scoped to the maturity level you are targeting.
Is the Essential Eight enough on its own?
It is a strong baseline; many organisations pair it with ISO 27001 or CPS 234. Related libraries are linked on the hub.
Related
Cross-framework leverage
Evidence you assemble for one framework often supports another. Commonly paired with:
Readiness, not certification. Netallion provides evidence assurance and readiness assessment; it does not issue or guarantee any formal outcome. Where a framework has a formal certification, attestation, authorisation or conformity-assessment scheme, that outcome remains with the appropriately authorised third party or authority. Essential Eight maturity is determined by an assessor against the ACSC maturity model; there is no Netallion-issued certification. Where the boundary sits.
See what your Essential Eight evidence proves
See how Netallion assesses whether your evidence is sufficient — with explicit blockers and a traceable readiness conclusion.