Essential Eight & ASD Essentials
Know where you really stand against ASD's baseline, and be ready for what comes next.
The Essential Eight is the Australian Signals Directorate's baseline set of mitigation strategies. It's increasingly what boards, insurers, government customers and enterprise buyers ask about. We assess your maturity honestly, show you what it takes to reach your target level, and help you prepare for ASD's transition to the new Essentials series.
The Essential Eight is changing
ASD has announced that the Essential Eight will be gradually retired over the next two years. It will be replaced by the Essentials series, a broader, outcomes-based framework covering enterprise IT, then operational technology and cloud.
That doesn't make your Essential Eight work wasted. ASD has said investment in the Essential Eight carries forward into the Essentials. The current maturity model is still the one you'll be assessed against today. We assess you against the current model while mapping your controls to where ASD is heading, so you don't build anything you'll need to redo.
What we assess
We assess your maturity across all eight strategies:
Patching applications
Patching operating systems
Multi-factor authentication
Restricting administrative privileges
Application control
Restricting Microsoft Office macros
User application hardening
Regular backups
Your overall maturity is set by your weakest strategy. So we focus on what moves your rating, not just what's easiest to fix.
How it works
1. Scoping
We agree your target maturity level and which systems are in scope.
2. Assessment
We review configurations, policies and evidence with your IT team or managed service provider, testing that controls actually work rather than just checking they exist.
3. Report and roadmap
You get your current maturity level for each strategy, the specific gaps between you and your target, and a prioritised plan to close them.
4. Uplift support (optional)
We work alongside your IT team or managed service provider to guide implementation and re-assess as you progress.
Who this is for
Organisations asked for an Essential Eight maturity level by a government customer, insurer or enterprise buyer
Boards and executives who want an honest, independent view of cyber maturity
IT teams and managed service providers who want a clear, prioritised roadmap rather than a long list of findings
Why Cyber Systems HQ
Governance, not just technology. We connect Essential Eight results to your broader risk, ISO 27001 and regulatory obligations, so it's part of a coherent security program, not an isolated technical checklist.
Ready for the transition. We track ASD's move to the Essentials series closely and build your roadmap to carry across.
Recognised expertise. Gavin Oh holds ISACA's CISM and CRISC certifications. Dan Goldberg has three decades of experience leading security and technology transformation programs.
Start with an Essential Eight assessment
Find out your real maturity level in 2–3 weeks, with a clear roadmap to your target.
Frequently asked questions
Is the Essential Eight still worth doing if it's being retired?
Yes. It remains the current ASD guidance and the standard many customers and insurers ask for. ASD has said Essential Eight investment carries forward into the new Essentials series.
What maturity level should we aim for?
It depends on your risk and who's asking. Many organisations target Maturity Level Two as a practical baseline. We'll help you choose a level that matches your threat environment and any contractual requirements.
Do you implement the controls?
We assess and guide. Hands-on implementation is usually done by your IT team or managed service provider, with us providing direction and verifying the results.