Essential Eight Assessment · ASD-Aligned · Australia

Essential Eight Assessment: an evidence-based assessment built for a defensible maturity position

It is not a checklist exercise. Inlight IT assesses how each control is actually implemented and whether it is operating effectively in the live environment, using ASD-aligned evidence methods that stand up to external scrutiny.

  • Engineering-led evidence collection
  • Not a self-attestation workshop
  • Evidence that stands up to external scrutiny
  • Aligned to the ASD assessment process guide
What the Essential Eight covers
Applications and endpoints
Application control, hardening and third-party patch coverage
Identity and privileged access
MFA quality, admin restriction and privileged account hygiene
Patching and operating systems
OS and application patch cadence, legacy exposure windows
Macros and backups
Office macro control, backup immutability and restore testing
Why it comes up

When the Essential Eight question moves from "are we aligned?" to "can we prove it?"

The Essential Eight has moved from a government framework to a commercial requirement. The buyers who land here are usually already facing one of these situations.

01
Cyber insurance renewal is approaching and the insurer is asking for evidence
Insurers are increasingly asking for control-level evidence rather than relying only on self-attestation. Organisations without a defensible assessment are facing coverage gaps or premium increases.
02
A government tender or procurement questionnaire requires Essential Eight alignment
Government and enterprise procurement increasingly use Essential Eight alignment as part of supplier due diligence, especially where data handling, resilience or public-sector supply chains are involved. The requirement is moving through supply chains via procurement conditions and questionnaires.
03
A significant incident or breach in the sector has raised board-level attention
After a high-profile incident, boards and executives are asking the IT team to demonstrate current security posture. The answer has to be evidence-based, not a verbal assurance.
04
Internal IT has been asked to reach ML2 but has no clear baseline
The organisation knows it needs to improve. But without a current maturity score backed by technical evidence, there is no reliable starting point and no way to prioritise remediation spend.
05
An existing assessment produced a score but no usable evidence
A previous assessment was interview-based or questionnaire-driven. The score it produced has not been accepted by an insurer or procurement team. A properly evidenced assessment is now required.
06
A major enterprise customer has sent a security questionnaire referencing Essential Eight
Enterprise customers are increasingly including Essential Eight requirements in supplier onboarding and annual review questionnaires. The organisation needs a defensible position before responding.
Keeping the position

Essential Eight establishes the maturity position. Managed Cyber Security helps maintain it.

It produces a defensible position at a point in time: a maturity score per control, an evidence pack and a remediation roadmap.

Managed Cyber Security is the deeper operating layer for organisations that need that position maintained over time. It adds continuous monitoring across identity and endpoints, analyst-led alert triage, active Microsoft 365 security posture management, backup recoverability verification and evidence production as part of operations.

Some organisations use the assessment as a standalone deliverable and execute the roadmap internally. Others use the assessment as the starting point for Managed Cyber Security. The right path depends on what the organisation can sustain after the assessment is complete.

Which path fits depends on what the organisation can realistically sustain once the report is delivered.
Evidence, not attestation

An Essential Eight assessment is not a checklist. Insurers, customers and procurement teams can tell the difference.

The ASD assessment process guide is explicit. Interviews, policy documents, reports and screenshots may contribute, but they are weaker forms of evidence than scripts, tools and simulated testing. Stronger evidence tests whether a control is actually implemented and operating as intended across the environment. That distinction matters when maturity claims may be tested by an insurer, an enterprise customer or a procurement team conducting due diligence. Self-attestation can still be useful for internal reporting. It is not the standard to rely on when the question is whether your Essential Eight position is defensible.

Evidence-based assessmentwhat ASD considers stronger evidence

Configuration verified using scripts and tools across representative systems

Testing that confirms controls actually block, restrict or detect as intended

Population-level assessment, not a single device or isolated screenshot

Evidence quality documented clearly, including limitations where relevant

Exceptions and compensating controls formally recorded

Output suitable for insurers, customers and procurement due diligence

Self-attestationwhat ASD considers weaker evidence

Policy documents and internal questionnaires reviewed and ticked off

Screenshots from a single device or tenant used as proof

Interviews relied on to confirm implementation

Tool reports assumed to confirm controls are effective

No active testing to confirm controls work under real conditions

Limited value under insurance, customer or procurement scrutiny

Source: ASD Essential Eight Assessment Process Guide

What you come away with

What you can take to leadership, an insurer or a procurement team.

The assessment is designed to support action, not just reporting. Each output has a clear operational, governance, insurance or procurement purpose. Each one is part of the deliverable.

01
Maturity scorecard, evidence-graded
A maturity score for each of the eight controls, supported by cited technical evidence collected from the live environment. Where evidence is weaker, limitations are documented. The assessment reflects actual control effectiveness, not stated intent.
02
Executive summary
A non-technical summary that translates findings into business risk, likely exposure and the decisions leadership needs to make. Suitable for board packs and senior stakeholder review.
03
Risk-prioritised remediation roadmap
A sequenced remediation backlog grouped by risk impact, control dependency, effort and timing. Quick wins are separated from larger platform or policy changes, with leadership decisions surfaced clearly.
04
Exceptions and compensating controls register
Formal documentation of constraints, scope limitations, compensating controls and required risk acceptance where full implementation is not currently practical.
05
Cyber insurance evidence package
Configuration evidence and testing documentation structured for underwriting review, renewal discussions and premium negotiation.
06
Tender and procurement readiness summary
A concise summary of Essential Eight maturity, material gaps and uplift priorities for customer due diligence, government tender responses and supply chain assurance.
What it lets you claim

What the organisation can claim and demonstrate, once the evidence exists.

The assessment shifts the organisation from estimated positions and ad-hoc evidence into a defensible, externally usable maturity record. Toggle to compare.

Maturity position is a self-reported estimate, not verified evidence

Maturity score per control, supported by cited technical evidence with limitations noted where relevant

Insurance questionnaire answers are based on the IT team's interpretation of control status

Evidence package structured specifically for underwriting review, with configuration and testing documentation organised for insurer use

Procurement and tender responses describe security posture in general terms

Procurement readiness summary providing a concise ML statement with material gaps and uplift priorities documented

Remediation priorities are unclear. The team knows there are gaps but cannot sequence them confidently

Risk-prioritised remediation roadmap with effort, sequencing and dependency clearly mapped

Board and leadership have no documented view of cybersecurity posture they can rely on externally

Executive summary translating technical findings into business risk, likely exposure and decisions leadership needs to make

Where full implementation is not currently practical, there is no formal record of the constraint or compensating control

Exceptions register formally documenting constraints, scope limitations, compensating controls and required risk acceptance

How we assess it

Every control is assessed with the same standard of rigour.

Inlight IT does not rely on a single-device review or a paper-based maturity claim. These are the eight control areas assessed, and the failure patterns Inlight IT sees most often in Australian environments. Hover a control to see where organisations consistently fall short.

New to the framework? What the Essential Eight actually is

The Essential Eight is the Australian Signals Directorate's baseline set of eight mitigation strategies for reducing common cyber risk. It is assessed through four maturity levels, not through a simple pass or fail certificate. For most Australian organisations, the practical question is not whether the framework exists. It is: what maturity level can you evidence today, where are the material gaps, and what needs to change to reach the target position? This assessment is built around that question. For a deeper explanation of the framework, the maturity model and common misconceptions, see the Essential Eight guide.

How we work

The ASD assessment process, run with engineering discipline.

Scope agreed up front. Timeline fixed. Evidence collection engineering-led throughout. The assessment follows the ASD assessment process, delivered in a format that is practical for real organisations.

1
Scope and target maturity

Define the assessment boundary, confirm the target maturity level, identify constraints early, and document what is in scope and what is not. No surprises when evidence collection begins.

2
Technical verification across all controls

Verify control implementation using scripts, tools and selective testing across endpoints, servers, identity platforms and key SaaS environments. Coverage is population-level, not single-device.

3
Gap analysis and maturity determination

Assess each control against the ASD maturity criteria, identify exceptions, evaluate compensating controls and determine where the organisation can and cannot credibly claim maturity.

4
Evidence-based outputs and remediation roadmap

Produce the full assessment pack, present the findings in both technical and leadership formats, and provide a roadmap built for execution, not just for filing.

Track record

Delivered with engineering discipline, not a checklist run.

8
Controls assessed with the same standard of rigour, evidence-graded to the ASD process guide
2–4 weeks
From scope confirmation to final report for a typical mid-market environment
ML2
The practical commercial target for most Australian organisations
6
Outputs in the deliverable pack, each with a governance, insurance or procurement purpose
Industrial
Recent assessments delivered across industrial and materials-handling environments.
Why Inlight IT

An engineering-led assessment, built around how Australian environments actually operate.

Essential Eight maturity depends on how controls operate across the environment, not how they are described in policy. That is why the assessment is performed by engineers with hands-on experience across identity, endpoint management, Microsoft 365, patching, backup, networking and operational support.

01

Performed by engineers, not auditors

The assessment is conducted by engineers who understand how the controls actually run across identity, endpoint, Microsoft 365, patching, backup and operational support. Maturity claims are tested against operating reality.

02

Tested against the way attackers actually move

The assessment is not a compliance-only exercise. It examines how the environment would hold under common attack paths: credential compromise, phishing, malicious documents, unpatched vulnerabilities, privileged access abuse and lateral movement.

03

The roadmap is sequenced for execution

The roadmap considers dependencies, operating burden, supportability and sequencing, not only target maturity. It is built so an internal IT team, Inlight IT or another provider can pick it up and act on it.

04

Designed for Australian insurance, procurement and governance

The assessment is shaped by Australian commercial reality: cyber insurance underwriting, government and enterprise procurement, board and audit-committee reporting, and the maturity expectations that travel through Australian supply chains.

05

When to act

Cyber insurance renewal within three to six months with the insurer asking for control evidence; an active government tender or procurement questionnaire referencing Essential Eight; an enterprise customer security questionnaire that cannot be answered with confidence; a request to demonstrate ML2 without an independent baseline; a previous assessment whose evidence would not withstand scrutiny; or board leadership needing a documented baseline to act from.

06

The Inlight IT view

Essential Eight maturity is not produced by a questionnaire workshop. It is produced by evidence collected from the live environment: configuration, control coverage, exceptions and what the environment actually shows. The difference between an assessment that supports an insurance claim and one that does not is whether the evidence behind it would stand up if someone tested it. Inlight IT runs the assessment the same way regardless of which path follows. The output has to stand on its own. What happens after the assessment is a separate decision.

The value of an Essential Eight assessment is not the score. It is the evidence behind the score and the quality of the roadmap that follows.

Common questions

Practical questions about scope, timing and what the assessment produces.

What is an Essential Eight maturity assessment?

An Essential Eight maturity assessment evaluates how effectively the organisation has implemented the eight ASD controls. A credible assessment does not stop at policy review or questionnaire responses. It uses technical verification to determine current maturity, identify gaps and establish what is required to improve. Evidence is collected from the live environment, not from self-reported intent.

How long does the assessment take?

For a typical mid-market environment, an evidence-based assessment takes two to four weeks from scope confirmation to final report, depending on user count, platform mix and the number of environments in scope. Scope and timeline are confirmed before work begins.

What maturity level should we target?

For most Australian organisations, ML2 is the practical commercial target. It is a meaningful baseline for environments facing phishing, credential compromise, cyber disruption risk and supply-chain due diligence. ML2 is where controls are not just present but consistently enforced, harder to bypass and defensible under external scrutiny. ML3 requires significantly more operational maturity and is typically justified by specific threat intelligence rather than general risk appetite.

What happens after the assessment?

The organisation receives a remediation roadmap that can be executed. Some organisations use it internally. Others engage Inlight IT to deliver the uplift program, close gaps and establish ongoing monitoring and evidence maintenance through Managed Cyber Security. The assessment can also be used as a standalone deliverable for governance, insurance or procurement purposes.

Is this the same as a self-attestation?

No. Self-attestation relies on interview responses and policy documents. This assessment uses technical verification: scripts, tools and selective testing across endpoints, identity platforms and key systems, to collect evidence of control implementation and effectiveness. The ASD assessment process guide explicitly identifies script and tool-based evidence as stronger than interview-based evidence. The output is designed to hold up under external review and due diligence.

Can the assessment be used for cyber insurance purposes?

Yes. One of the six outputs is a cyber insurance evidence package: configuration evidence, control verification records and testing documentation structured specifically for underwriting review, renewal discussions and premium negotiation. The assessment is designed to produce the kind of evidence insurers are asking for, not the kind that gets passed over in self-attestation reviews.

Is this required for Australian businesses?

Not automatically for every organisation. For Australian Commonwealth non-corporate entities, implementation to at least ML2 is required under formal governance. For private sector organisations, the practical question is whether customers, insurers or procurement teams expect a defensible baseline. Where they do, an evidence-based assessment is what supports that position.

Do we need to be at Maturity Level 2 before the assessment?

No. The assessment is designed to establish where the organisation currently stands. If the organisation is below ML2, the assessment identifies the control gaps, maturity blockers and remediation sequence required to move toward the target level.

What is the difference between this and Managed Cyber Security?

The Essential Eight Assessment is a discrete engagement that produces a defensible maturity position at a point in time: a maturity score, an evidence pack, a remediation roadmap. Managed Cyber Security is the ongoing operating layer that holds and improves that position continuously. Some organisations engage the assessment alone and execute the remediation with their internal team or existing provider. Others engage the assessment first and then move into Managed Cyber Security to operate the maturity continuously.

Practical next step

A clear maturity position. The gaps prioritised. Evidence that stands up.

Book an Essential Eight Assessment