ACSC Essential Eight assessment and uplift
Eight mitigation strategies published by the Australian Signals Directorate, written as the Essential Eight and often shortened to Essential 8. They are the practical starting point for almost every Australian business, and the thing most client questionnaires are quietly derived from.
- Patch applications
- Patch operating systems
- Multi-factor authentication
- Restrict administrative privileges
- Application control
- Restrict Microsoft Office macros
- User application hardening
- Regular backups
Maturity is measured on a four-point scale. We assess where you sit today, agree the level that suits your risk and your contracts, then do the work to get there.
Is the Essential Eight being retired?
In June 2026 the Australian Signals Directorate opened public consultation on evolving the Essential Eight into a broader Essentials series, beginning with a chapter called Essentials for enterprise IT. ASD's own consultation notice says organisations already using the Essential Eight can expect strong alignment with their existing controls and investments. Reporting at the time indicated a transition period of around two years, with both documents remaining live during it.
Two practical consequences. First, the Essential Eight is still the current published model, and it is still what client questionnaires, insurers and tenders are asking about today. Second, nothing you spend now on multi-factor authentication, patching, backups or restricting administrative privileges is wasted, because those controls are not going anywhere — only the way they are packaged and described is changing.
If you are being asked for Essential Eight evidence right now, the answer is the same as it was: get an honest maturity position and close the real gaps. We check this page against ASD's published guidance and update it as the new series appears. Last checked 25 August 2026.