Essential Eight Assessment: an evidence-based assessment built for a defensible maturity position
It is not a checklist exercise. Inlight IT assesses how each control is actually implemented and whether it is operating effectively in the live environment, using ASD-aligned evidence methods that stand up to external scrutiny.
- Engineering-led evidence collection
- Not a self-attestation workshop
- Evidence that stands up to external scrutiny
- Aligned to the ASD assessment process guide
When the Essential Eight question moves from "are we aligned?" to "can we prove it?"
The Essential Eight has moved from a government framework to a commercial requirement. The buyers who land here are usually already facing one of these situations.
Essential Eight establishes the maturity position. Managed Cyber Security helps maintain it.
It produces a defensible position at a point in time: a maturity score per control, an evidence pack and a remediation roadmap.
Managed Cyber Security is the deeper operating layer for organisations that need that position maintained over time. It adds continuous monitoring across identity and endpoints, analyst-led alert triage, active Microsoft 365 security posture management, backup recoverability verification and evidence production as part of operations.
Some organisations use the assessment as a standalone deliverable and execute the roadmap internally. Others use the assessment as the starting point for Managed Cyber Security. The right path depends on what the organisation can sustain after the assessment is complete.
An Essential Eight assessment is not a checklist. Insurers, customers and procurement teams can tell the difference.
The ASD assessment process guide is explicit. Interviews, policy documents, reports and screenshots may contribute, but they are weaker forms of evidence than scripts, tools and simulated testing. Stronger evidence tests whether a control is actually implemented and operating as intended across the environment. That distinction matters when maturity claims may be tested by an insurer, an enterprise customer or a procurement team conducting due diligence. Self-attestation can still be useful for internal reporting. It is not the standard to rely on when the question is whether your Essential Eight position is defensible.
Configuration verified using scripts and tools across representative systems
Testing that confirms controls actually block, restrict or detect as intended
Population-level assessment, not a single device or isolated screenshot
Evidence quality documented clearly, including limitations where relevant
Exceptions and compensating controls formally recorded
Output suitable for insurers, customers and procurement due diligence
Policy documents and internal questionnaires reviewed and ticked off
Screenshots from a single device or tenant used as proof
Interviews relied on to confirm implementation
Tool reports assumed to confirm controls are effective
No active testing to confirm controls work under real conditions
Limited value under insurance, customer or procurement scrutiny
Source: ASD Essential Eight Assessment Process Guide
What you can take to leadership, an insurer or a procurement team.
The assessment is designed to support action, not just reporting. Each output has a clear operational, governance, insurance or procurement purpose. Each one is part of the deliverable.
What the organisation can claim and demonstrate, once the evidence exists.
The assessment shifts the organisation from estimated positions and ad-hoc evidence into a defensible, externally usable maturity record. Toggle to compare.
Maturity position is a self-reported estimate, not verified evidence
Maturity score per control, supported by cited technical evidence with limitations noted where relevant
Insurance questionnaire answers are based on the IT team's interpretation of control status
Evidence package structured specifically for underwriting review, with configuration and testing documentation organised for insurer use
Procurement and tender responses describe security posture in general terms
Procurement readiness summary providing a concise ML statement with material gaps and uplift priorities documented
Remediation priorities are unclear. The team knows there are gaps but cannot sequence them confidently
Risk-prioritised remediation roadmap with effort, sequencing and dependency clearly mapped
Board and leadership have no documented view of cybersecurity posture they can rely on externally
Executive summary translating technical findings into business risk, likely exposure and decisions leadership needs to make
Where full implementation is not currently practical, there is no formal record of the constraint or compensating control
Exceptions register formally documenting constraints, scope limitations, compensating controls and required risk acceptance
Every control is assessed with the same standard of rigour.
Inlight IT does not rely on a single-device review or a paper-based maturity claim. These are the eight control areas assessed, and the failure patterns Inlight IT sees most often in Australian environments. Hover a control to see where organisations consistently fall short.
New to the framework? What the Essential Eight actually is
The Essential Eight is the Australian Signals Directorate's baseline set of eight mitigation strategies for reducing common cyber risk. It is assessed through four maturity levels, not through a simple pass or fail certificate. For most Australian organisations, the practical question is not whether the framework exists. It is: what maturity level can you evidence today, where are the material gaps, and what needs to change to reach the target position? This assessment is built around that question. For a deeper explanation of the framework, the maturity model and common misconceptions, see the Essential Eight guide.
The ASD assessment process, run with engineering discipline.
Scope agreed up front. Timeline fixed. Evidence collection engineering-led throughout. The assessment follows the ASD assessment process, delivered in a format that is practical for real organisations.
Define the assessment boundary, confirm the target maturity level, identify constraints early, and document what is in scope and what is not. No surprises when evidence collection begins.
Verify control implementation using scripts, tools and selective testing across endpoints, servers, identity platforms and key SaaS environments. Coverage is population-level, not single-device.
Assess each control against the ASD maturity criteria, identify exceptions, evaluate compensating controls and determine where the organisation can and cannot credibly claim maturity.
Produce the full assessment pack, present the findings in both technical and leadership formats, and provide a roadmap built for execution, not just for filing.
Delivered with engineering discipline, not a checklist run.
An engineering-led assessment, built around how Australian environments actually operate.
Essential Eight maturity depends on how controls operate across the environment, not how they are described in policy. That is why the assessment is performed by engineers with hands-on experience across identity, endpoint management, Microsoft 365, patching, backup, networking and operational support.
01Performed by engineers, not auditors
The assessment is conducted by engineers who understand how the controls actually run across identity, endpoint, Microsoft 365, patching, backup and operational support. Maturity claims are tested against operating reality.
02Tested against the way attackers actually move
The assessment is not a compliance-only exercise. It examines how the environment would hold under common attack paths: credential compromise, phishing, malicious documents, unpatched vulnerabilities, privileged access abuse and lateral movement.
03The roadmap is sequenced for execution
The roadmap considers dependencies, operating burden, supportability and sequencing, not only target maturity. It is built so an internal IT team, Inlight IT or another provider can pick it up and act on it.
04Designed for Australian insurance, procurement and governance
The assessment is shaped by Australian commercial reality: cyber insurance underwriting, government and enterprise procurement, board and audit-committee reporting, and the maturity expectations that travel through Australian supply chains.
05When to act
Cyber insurance renewal within three to six months with the insurer asking for control evidence; an active government tender or procurement questionnaire referencing Essential Eight; an enterprise customer security questionnaire that cannot be answered with confidence; a request to demonstrate ML2 without an independent baseline; a previous assessment whose evidence would not withstand scrutiny; or board leadership needing a documented baseline to act from.
06The Inlight IT view
Essential Eight maturity is not produced by a questionnaire workshop. It is produced by evidence collected from the live environment: configuration, control coverage, exceptions and what the environment actually shows. The difference between an assessment that supports an insurance claim and one that does not is whether the evidence behind it would stand up if someone tested it. Inlight IT runs the assessment the same way regardless of which path follows. The output has to stand on its own. What happens after the assessment is a separate decision.
The value of an Essential Eight assessment is not the score. It is the evidence behind the score and the quality of the roadmap that follows.
Essential Eight assessments delivered against real commercial drivers
Practical questions about scope, timing and what the assessment produces.
What is an Essential Eight maturity assessment?
An Essential Eight maturity assessment evaluates how effectively the organisation has implemented the eight ASD controls. A credible assessment does not stop at policy review or questionnaire responses. It uses technical verification to determine current maturity, identify gaps and establish what is required to improve. Evidence is collected from the live environment, not from self-reported intent.
How long does the assessment take?
For a typical mid-market environment, an evidence-based assessment takes two to four weeks from scope confirmation to final report, depending on user count, platform mix and the number of environments in scope. Scope and timeline are confirmed before work begins.
What maturity level should we target?
For most Australian organisations, ML2 is the practical commercial target. It is a meaningful baseline for environments facing phishing, credential compromise, cyber disruption risk and supply-chain due diligence. ML2 is where controls are not just present but consistently enforced, harder to bypass and defensible under external scrutiny. ML3 requires significantly more operational maturity and is typically justified by specific threat intelligence rather than general risk appetite.
What happens after the assessment?
The organisation receives a remediation roadmap that can be executed. Some organisations use it internally. Others engage Inlight IT to deliver the uplift program, close gaps and establish ongoing monitoring and evidence maintenance through Managed Cyber Security. The assessment can also be used as a standalone deliverable for governance, insurance or procurement purposes.
Is this the same as a self-attestation?
No. Self-attestation relies on interview responses and policy documents. This assessment uses technical verification: scripts, tools and selective testing across endpoints, identity platforms and key systems, to collect evidence of control implementation and effectiveness. The ASD assessment process guide explicitly identifies script and tool-based evidence as stronger than interview-based evidence. The output is designed to hold up under external review and due diligence.
Can the assessment be used for cyber insurance purposes?
Yes. One of the six outputs is a cyber insurance evidence package: configuration evidence, control verification records and testing documentation structured specifically for underwriting review, renewal discussions and premium negotiation. The assessment is designed to produce the kind of evidence insurers are asking for, not the kind that gets passed over in self-attestation reviews.
Is this required for Australian businesses?
Not automatically for every organisation. For Australian Commonwealth non-corporate entities, implementation to at least ML2 is required under formal governance. For private sector organisations, the practical question is whether customers, insurers or procurement teams expect a defensible baseline. Where they do, an evidence-based assessment is what supports that position.
Do we need to be at Maturity Level 2 before the assessment?
No. The assessment is designed to establish where the organisation currently stands. If the organisation is below ML2, the assessment identifies the control gaps, maturity blockers and remediation sequence required to move toward the target level.
What is the difference between this and Managed Cyber Security?
The Essential Eight Assessment is a discrete engagement that produces a defensible maturity position at a point in time: a maturity score, an evidence pack, a remediation roadmap. Managed Cyber Security is the ongoing operating layer that holds and improves that position continuously. Some organisations engage the assessment alone and execute the remediation with their internal team or existing provider. Others engage the assessment first and then move into Managed Cyber Security to operate the maturity continuously.