Essential Eight maturity, evidenced, not just implemented
The Australian Cyber Security Centre's Essential Eight defines 8 baseline mitigation strategies across 3 maturity levels. Certifyi builds and evidences controls for all eight — application control, patching, macro settings, hardening, admin restriction, MFA, and backups — mapped to the maturity level your customers or regulator require.
Eight strategies, three maturity levels, no shortcuts
Essential Eight looks simple on paper — in practice, evidencing maturity across every strategy is where teams stall.
Australian buyers require a stated maturity level
Government and enterprise customers in Australia increasingly ask which Essential Eight maturity level you've reached — not just whether you've "implemented" it.
Maturity is assessed per-strategy, not overall
You can be Maturity Level 3 on backups and Level 0 on application control — assessors score each of the 8 strategies independently.
Evidence requirements are specific
Configuration screenshots and policy documents alone aren't enough; assessors expect logs and evidence of consistent enforcement over time.
No single owner across the 8 strategies
Patching sits with IT, admin restriction with security, backups with infrastructure — without a coordinating framework, no one owns the full picture.
All 8 strategies, mapped to your target maturity level
Pre-built control sets for every strategy, with evidence automation so maturity is demonstrated, not asserted.
Full 8-strategy control library
Application control, patch applications, Office macro settings, user application hardening, restrict admin privileges, patch operating systems, MFA, and regular backups — all covered.
Maturity Level 1-3 mapping
Controls scoped and evidenced to the specific maturity level your customer or regulator requires — no over-building past what's needed.
Automated evidence collection
Continuous evidence capture for patching cadence, admin access reviews, and backup verification, instead of manual quarterly screenshots.
Weekly expert check-ins
A named compliance lead coordinates across IT, security, and infrastructure so each strategy has an accountable owner.
The path to your target maturity level
A proven 3-phase process — exactly what happens, week by week.
Week 0-1: Baseline Assessment
Score current maturity across all 8 strategies and confirm the target level your customers or regulator require.
Deliverable: Maturity Baseline ReportWeek 1-8: Control Deployment
Deploy and configure controls strategy by strategy, turning on evidence automation as each is completed.
Deliverable: 8-strategy control setWeek 8-10: Evidence Review & Sign-off
Validate evidence against target maturity level requirements and prepare documentation for customer or regulator review.
Deliverable: Maturity Assessment PackageWhat changes when maturity is evidenced
A defensible, per-strategy record instead of a general assertion of "we do security."
Strategies covered
Every Essential Eight mitigation strategy documented and evidenced, not just the ones that overlap with existing tooling.
Maturity levels supported
Controls scoped precisely to Level 1, 2, or 3 depending on what your customer or regulator actually requires.
To an evidenced maturity assessment
Structured, coordinated rollout instead of scattered ownership across IT, security, and infrastructure teams.
Essential Eight, answered
The Essential Eight is a set of 8 baseline cybersecurity mitigation strategies published by the Australian Cyber Security Centre (ACSC): application control, patch applications, configure Microsoft Office macro settings, user application hardening, restrict administrative privileges, patch operating systems, multi-factor authentication, and regular backups. Maturity is scored on a 0-3 scale per strategy.
It depends on your customer or regulatory requirement — Australian government contracts commonly specify Maturity Level 2 or 3, while commercial customers may accept Level 1. Certifyi confirms the target with you in week one before building controls.
No. While it's an ACSC framework, any company selling into the Australian market — government or enterprise — may be asked to demonstrate an Essential Eight maturity level as part of vendor risk review, regardless of where the company is headquartered.
8-10 weeks from baseline assessment to an evidenced maturity assessment package, covering all 8 strategies at your target level.
Get your Essential Eight scoping call
30 minutes to baseline your maturity and get a fixed-price quote.
Pay-at-signoff pricing · 50% upfront, 50% when your maturity is evidenced