Essential Eight (E8) Compliance — Certifyi | ACSC Maturity Levels
ACSC Essential Eight

Essential Eight maturity, evidenced, not just implemented

The Australian Cyber Security Centre's Essential Eight defines 8 baseline mitigation strategies across 3 maturity levels. Certifyi builds and evidences controls for all eight — application control, patching, macro settings, hardening, admin restriction, MFA, and backups — mapped to the maturity level your customers or regulator require.

Why E8 trips teams up

Eight strategies, three maturity levels, no shortcuts

Essential Eight looks simple on paper — in practice, evidencing maturity across every strategy is where teams stall.

01

Australian buyers require a stated maturity level

Government and enterprise customers in Australia increasingly ask which Essential Eight maturity level you've reached — not just whether you've "implemented" it.

02

Maturity is assessed per-strategy, not overall

You can be Maturity Level 3 on backups and Level 0 on application control — assessors score each of the 8 strategies independently.

03

Evidence requirements are specific

Configuration screenshots and policy documents alone aren't enough; assessors expect logs and evidence of consistent enforcement over time.

04

No single owner across the 8 strategies

Patching sits with IT, admin restriction with security, backups with infrastructure — without a coordinating framework, no one owns the full picture.

How Certifyi is different

All 8 strategies, mapped to your target maturity level

Pre-built control sets for every strategy, with evidence automation so maturity is demonstrated, not asserted.

Full 8-strategy control library

Application control, patch applications, Office macro settings, user application hardening, restrict admin privileges, patch operating systems, MFA, and regular backups — all covered.

Maturity Level 1-3 mapping

Controls scoped and evidenced to the specific maturity level your customer or regulator requires — no over-building past what's needed.

Automated evidence collection

Continuous evidence capture for patching cadence, admin access reviews, and backup verification, instead of manual quarterly screenshots.

Weekly expert check-ins

A named compliance lead coordinates across IT, security, and infrastructure so each strategy has an accountable owner.

Your roadmap

The path to your target maturity level

A proven 3-phase process — exactly what happens, week by week.

Week 0-1: Baseline Assessment

Score current maturity across all 8 strategies and confirm the target level your customers or regulator require.

Deliverable: Maturity Baseline Report

Week 1-8: Control Deployment

Deploy and configure controls strategy by strategy, turning on evidence automation as each is completed.

Deliverable: 8-strategy control set

Week 8-10: Evidence Review & Sign-off

Validate evidence against target maturity level requirements and prepare documentation for customer or regulator review.

Deliverable: Maturity Assessment Package
The business impact

What changes when maturity is evidenced

A defensible, per-strategy record instead of a general assertion of "we do security."

8/8

Strategies covered

Every Essential Eight mitigation strategy documented and evidenced, not just the ones that overlap with existing tooling.

3

Maturity levels supported

Controls scoped precisely to Level 1, 2, or 3 depending on what your customer or regulator actually requires.

8-10 wks

To an evidenced maturity assessment

Structured, coordinated rollout instead of scattered ownership across IT, security, and infrastructure teams.

Common questions

Essential Eight, answered

The Essential Eight is a set of 8 baseline cybersecurity mitigation strategies published by the Australian Cyber Security Centre (ACSC): application control, patch applications, configure Microsoft Office macro settings, user application hardening, restrict administrative privileges, patch operating systems, multi-factor authentication, and regular backups. Maturity is scored on a 0-3 scale per strategy.

It depends on your customer or regulatory requirement — Australian government contracts commonly specify Maturity Level 2 or 3, while commercial customers may accept Level 1. Certifyi confirms the target with you in week one before building controls.

No. While it's an ACSC framework, any company selling into the Australian market — government or enterprise — may be asked to demonstrate an Essential Eight maturity level as part of vendor risk review, regardless of where the company is headquartered.

8-10 weeks from baseline assessment to an evidenced maturity assessment package, covering all 8 strategies at your target level.

Ready when you are

Get your Essential Eight scoping call

30 minutes to baseline your maturity and get a fixed-price quote.

Pay-at-signoff pricing · 50% upfront, 50% when your maturity is evidenced

Scroll to Top