Essential Eight and ISO 27001 · Sydney and NSW

Answer the security questionnaire without guessing.

Larger clients, insurers and government buyers now ask how you protect their data before they sign. Run Lighter works out where your business actually stands, lifts the controls that matter, and leaves you with evidence you can hand over.

ACSC Essential Eight upliftISO/IEC 27001 readinessSydney and NSW
Request a security position review
STRUCTURED · DOCUMENTED · EVIDENCED
Measured against published standards, not opinionBuilt around the systems you already runEvidence you can send to a client or insurer
Two ways in

Start with the Australian baseline: the Essential Eight.

Go further only if a contract asks you to. Most businesses do not need a certificate — they need to know which gaps are real, which are urgent, and what closing them costs. Both paths below start with the same honest assessment.

The Australian baseline

ACSC Essential Eight assessment and uplift

Eight mitigation strategies published by the Australian Signals Directorate, written as the Essential Eight and often shortened to Essential 8. They are the practical starting point for almost every Australian business, and the thing most client questionnaires are quietly derived from.

  • Patch applications
  • Patch operating systems
  • Multi-factor authentication
  • Restrict administrative privileges
  • Application control
  • Restrict Microsoft Office macros
  • User application hardening
  • Regular backups

Maturity is measured on a four-point scale. We assess where you sit today, agree the level that suits your risk and your contracts, then do the work to get there.

Level Zero
Gaps in the basics
Level One
Stops opportunistic attacks
Level Two
Stops attackers who are targeting you
Level Three
Stops adaptive, well-resourced attackers

Is the Essential Eight being retired?

In June 2026 the Australian Signals Directorate opened public consultation on evolving the Essential Eight into a broader Essentials series, beginning with a chapter called Essentials for enterprise IT. ASD's own consultation notice says organisations already using the Essential Eight can expect strong alignment with their existing controls and investments. Reporting at the time indicated a transition period of around two years, with both documents remaining live during it.

Two practical consequences. First, the Essential Eight is still the current published model, and it is still what client questionnaires, insurers and tenders are asking about today. Second, nothing you spend now on multi-factor authentication, patching, backups or restricting administrative privileges is wasted, because those controls are not going anywhere — only the way they are packaged and described is changing.

If you are being asked for Essential Eight evidence right now, the answer is the same as it was: get an honest maturity position and close the real gaps. We check this page against ASD's published guidance and update it as the new series appears. Last checked 25 August 2026.

The ASD does not require Essential Eight implementation to be certified by an independent party unless a regulator, directive or contract says otherwise. There is no certificate to buy here — only a maturity level you can evidence.
When a contract requires it

ISO/IEC 27001 readiness

ISO/IEC 27001:2022 sets the requirements for an information security management system: how your business manages information security risk as an ongoing discipline, rather than a one-off technical checklist.

  • Scope definition and gap analysis
  • Risk assessment and Statement of Applicability
  • Policies, controls and the records that prove them
  • Internal audit and management review
  • Evidence pack prepared for your certification audit
We do not issue certificates, and neither does any consultancy. In Australia an ISO/IEC 27001 certificate is issued by a certification body accredited by JAS-ANZ. Our job is to get you ready for that audit and support you through it. Anyone offering to certify you directly is not describing the process accurately.
CONTROLS · RECORDS · AUDIT TRAIL

Do we need ISO 27001, or is the Essential Eight enough?

For most Sydney businesses under fifty staff, the Essential Eight is enough and ISO/IEC 27001 is not. The Essential Eight is a set of technical controls with a maturity level you can evidence. ISO/IEC 27001 is a management system, which means ongoing governance, documented risk assessment, internal audit and an external certification audit that recurs. It is a genuine commitment of time and money.

The question that actually decides it is not how secure you want to be. It is what is written in the contract. If a client, a tender or a government buyer has specified ISO/IEC 27001 certification by name, you need the certificate and you should start the readiness work early. If they have sent you a questionnaire, asked about multi-factor authentication and backups, or referenced the Essential Eight, then an Essential Eight maturity position and a clean evidence pack will answer it.

Send us the clause or the questionnaire and we will tell you which of the two you are actually being asked for, before you spend anything.

Why people call

What usually prompts the call.

Five situations prompt most security enquiries, and all five arrive at the same first question.

A client questionnaire arrives, often from a larger customer tightening its own supply chain. A tender or NSW government panel application asks how you protect information before it will accept your submission. An insurer asks about multi-factor authentication and backups at renewal, and the premium depends on the answer. A near miss — an invoice fraud attempt, a compromised mailbox — makes the risk concrete. Or an accounting practice, engineering consultancy, law firm or allied health clinic simply decides it holds enough client data that guessing is no longer acceptable.

All five arrive at the same first question: where do we actually stand? That is what the position review answers, and it is deliberately the smallest and cheapest thing we do.

How it runs

Know where you stand before you spend anything.

The first engagement is deliberately small. You should be able to decide whether the rest is worth doing on the strength of what it finds. It runs the same way as an on-site review.

02

Uplift plan

A prioritised plan with a target maturity level, what each step costs, what it protects against, and what you can safely leave alone for now.

03

Implementation and evidence

We do the work, document it as we go, and hand you the evidence pack — so the next questionnaire takes an afternoon instead of a fortnight.

Straight answers

Essential Eight and ISO 27001 questions we get asked.

The questions that come up on nearly every first call, answered without a sales pitch.

What does an Essential Eight assessment cost?

There is no standard price and we will not quote one before we have seen your environment. What moves the number is the count of staff and devices, how many systems hold client data, whether your devices are centrally managed, and how much usable documentation already exists. The position review is the step that produces a real figure, and you get that figure in writing before any uplift work starts.

How long does Essential Eight uplift take?

It depends on where you are starting from and how your devices are managed. A business with centrally managed laptops and one main platform moves quickly. A business with mixed personal devices, several disconnected systems and no patching routine takes longer. We give you a sequenced plan with the order of work rather than a fixed date we cannot honour.

What maturity level does my business actually need?

That is decided by what you are being asked for and what you are protecting, not by an ambition. Read the contract, the tender clause or the questionnaire first, because they usually name a level or describe controls that map to one. If nothing names a level, we work from what a compromise would actually cost your business. We will tell you when a higher level is not worth the money for you.

Can Run Lighter certify us to ISO 27001?

No. In Australia an ISO/IEC 27001 certificate is issued by a certification body accredited by JAS-ANZ or another IAF signatory, and the consultancy that prepares you cannot also certify you. Run Lighter does the readiness work — scope, gap analysis, risk assessment, Statement of Applicability, policies and evidence — and supports you through the external audit. Anyone offering to certify you directly is not describing the process accurately.

Do we need to buy new security software?

Usually not much, and often nothing. Most of the Essential Eight is configuration of licences you already pay for: multi-factor authentication, patching, backup settings and administrative access. We start by finding out what your existing subscriptions already entitle you to, and we will say plainly if there is a genuine gap that needs a purchase.

What evidence do we get at the end?

A maturity position against each of the eight mitigation strategies, a written record of what was changed and when, the configuration and policy documents behind it, and a plain-English summary you can attach to a client questionnaire, an insurance renewal or a tender response. The point is that the next time someone asks, you answer from a file instead of from memory.

Security position review

Find out where you actually stand.

Tell us what has prompted this — a client questionnaire, a tender, an insurer, or getting ahead of it. We will reply within one business day.

For businesses in Sydney and NSW. No obligation. Your details are used only to respond to this request. Privacy.

Essential Eight controls and maturity levels as published by the Australian Signals Directorate in the Essential Eight Maturity Model (November 2023), which remains the current published model. In June 2026 ASD opened public consultation on evolving the Essential Eight into a broader Essentials series; this page was last reviewed against ASD guidance on 25 August 2026. ISO/IEC 27001:2022 certification is issued by a certification body accredited by JAS-ANZ or another IAF signatory — Run Lighter provides readiness, implementation and audit-preparation services only, and does not issue certification. Run Lighter is not an ASD-endorsed IRAP assessor.