Essential Eight assessment and uplift

The maturity level you believe you hold, and the one your configuration demonstrates.

These are usually two different numbers. A control gets switched on once, an exception gets granted and never reviewed, a patch cadence slips — and the self-assessed ML2 on your tender response stops being true. CyberBakery tests what is actually enforced, closes the gaps that move your rating, and produces evidence an assessor can follow.

Sydney-based · ML0–ML3 · Assessment, uplift delivery and continuous monitoring

Where the Essential Eight actually stands

Verified against cyber.gov.au — [DATE TO CONFIRM BEFORE PUBLISH]

  • Current releaseEssential Eight Maturity Model, November 2023Still the live, assessable baseline. Every obligation and questionnaire that cites the Essential Eight still points at this document.
  • 15 June 2026ASD opens consultation on an Essentials seriesA proposed evolution grounded in the Information Security Manual. First chapter: Essentials for enterprise IT.
  • 12 July 2026Consultation closedFeedback from government, industry and regulators now feeds the drafting of the first chapter.
  • No published dateRetirement timeline remains unpublishedA twelve-month deprecation and twenty-four-month retirement has been widely reported from a named official's remarks. ASD has published no retirement date. We treat the two differently.

We re-verify this panel monthly. Ask us what changed this month.

Half of what you have read about the Essentials series is not ASD policy.

Several vendors are now telling Australian organisations the Essential Eight has been retired, and a few are using that to sell a pause, a pivot or a product. It is worth being precise, because the distinction between what ASD published and what a named official said in an interview is the difference between a defensible plan and an expensive guess.

Published by ASD

The Essential Eight Maturity Model of November 2023 is the current release and remains in force.

A proposed Essentials series exists, grounded in the Information Security Manual.

The first chapter is Essentials for enterprise IT.

Consultation ran through the Cyber Security Partnership Program portal and closed 12 July 2026.

Existing controls and investments are expected to align strongly with the new guidance.

Reported, not published

Deprecation beginning at roughly twelve months.

Full retirement at roughly twenty-four months.

The order in which subsequent chapters will be released.

Design intent around whether maturity levels survive in their current form.

Not known by anyone

The final control set for Essentials for enterprise IT. No draft has been published.

Whether the number eight survives at all.

Whether ML0–ML3 carries over, changes shape, or is replaced.

How the obligations and questionnaires that cite the Essential Eight will be reworded, and when.

What is actually changing, side by side.

Left is the document you are assessed against today. Right is what ASD has said about its successor — and, just as importantly, what it has not said. Every gap below is a real gap in the public record, not an omission on our part.

Essential Eight Maturity Model

November 2023 · current release · in force

Essentials series

Proposed · first chapter in drafting

Status

Published, current and assessable. The document your rating is measured against today.

A proposal consulted on between 15 June and 12 July 2026. No draft guidance has been released.

Foundation

A standalone set of eight mitigation strategies, first published in 2017 and revised since.

Grounded in the Information Security Manual, positioning it inside ASD's wider guidance rather than beside it.

Structure

One document covering one environment type.

A series of domain chapters, opening with Essentials for enterprise IT.

Scope

Written for enterprise IT networks. ASD notes other environments may need alternative strategies.

Intended to cover contemporary environments more directly — cloud, SaaS and operational technology among them.

Control set

Eight mitigation strategies, prescriptively specified.

Not published.

Whether eight survives as a number is unknown.

Approach

Prescriptive technical controls on a fixed ladder, calibrated to adversary tradecraft.

Described by ASD as prioritised and threat-informed, with greater flexibility in how organisations implement.

Maturity model

Four levels, ML0 to ML3, assessed per strategy. Your overall rating is your weakest strategy.

Not published.

Whether levels carry over, change shape or disappear is unknown.

Assessment method

A published assessment process guide, so results mean the same thing between assessors.

Not published.

Standing in obligations

Referenced directly across government policy, defence supply-chain requirements, critical-infrastructure reporting, tender questionnaires and insurance forms.

Not published.

Every one of those references will need rewording at some point, on a timetable nobody has announced.

What it means today

Assess against this. It is the only version anyone can hold you to.

Plan for it, do not wait for it. ASD has said existing investment is expected to carry across.

What we advise, plainly

Keep executing. Do not pause an active uplift, de-scope it, or move budget out of the current cycle on the strength of an announcement that has produced no draft control set. Every control you implement now carries across, and the parallel-running window is the right time to lock in a verified maturity rating as the baseline for whatever gap analysis the new guidance eventually requires. The one thing worth changing today is emphasis: frame your evidence around control outcomes and demonstrated risk reduction rather than solely around a level number. That is the direction ASD has signalled, and it reads better to a prime either way.

Eight strategies. Four that fail assessment most often.

Every control below is assessed against what your environment actually enforces, not against what the policy says it should.

Common gap

Application control

Only approved executables, libraries and scripts run. Consistently the hardest control to reach ML2 on.

Common gap

Application control

Only approved executables, libraries and scripts run. Consistently the hardest control to reach ML2 on.

Common gap

Patch applications

Vulnerability scanning and patch windows for internet-facing and productivity software.

Common gap

Patch applications

Vulnerability scanning and patch windows for internet-facing and productivity software.

Strategy

Configure Office macros

Macro execution blocked or restricted to vetted, signed and sandboxed cases.

Strategy

Configure Office macros

Macro execution blocked or restricted to vetted, signed and sandboxed cases.

Strategy

User application hardening

Browsers, PDF readers and Office locked down against the delivery techniques that actually get used.

Strategy

User application hardening

Browsers, PDF readers and Office locked down against the delivery techniques that actually get used.

Common gap

Restrict admin privileges

Privileged access validated, time-bound, separated from day-to-day accounts and reviewed.

Common gap

Restrict admin privileges

Privileged access validated, time-bound, separated from day-to-day accounts and reviewed.

Strategy

Patch operating systems

Cadence and coverage across servers, endpoints and network devices, including the ones nobody owns.

Strategy

Patch operating systems

Cadence and coverage across servers, endpoints and network devices, including the ones nobody owns.

Common gap

Multi-factor authentication

Phishing-resistant where the level requires it, and applied to the systems people forget about.

Common gap

Multi-factor authentication

Phishing-resistant where the level requires it, and applied to the systems people forget about.

Strategy

Regular backups

Tested restoration, not just successful jobs. Retention and access restrictions that survive an incident.

Strategy

Regular backups

Tested restoration, not just successful jobs. Retention and access restrictions that survive an incident.

Maturity is assessed per strategy, and your rating is the lowest one.

This is the detail most self-assessments get wrong. Seven strategies at ML2 and one at ML1 is an ML1 organisation.

ML0

Not yet aligned

Weaknesses that leave the organisation exposed to the tradecraft ML1 is designed to stop. A real and common finding, not a failure to report honestly.

ML0

Not yet aligned

Weaknesses that leave the organisation exposed to the tradecraft ML1 is designed to stop. A real and common finding, not a failure to report honestly.

ML1

Baseline

Resistant to widely available, opportunistic tradecraft. The right first target for smaller environments starting from scratch.

ML1

Baseline

Resistant to widely available, opportunistic tradecraft. The right first target for smaller environments starting from scratch.

ML2

Contract-ready

The level most buyers, insurers and assurance teams expect to see evidenced. Where the majority of our engagements are aimed.

ML2

Contract-ready

The level most buyers, insurers and assurance teams expect to see evidenced. Where the majority of our engagements are aimed.

ML3

Adaptive adversary

Resistant to attackers who invest time and effort in a specific target. Appropriate where the consequence of compromise is severe.

ML3

Adaptive adversary

Resistant to attackers who invest time and effort in a specific target. Appropriate where the consequence of compromise is severe.

Assessed against enforcement, then actually fixed.

Our assessment method follows the ASD Essential Eight Assessment Process Guide, so the result means the same thing to an auditor as it does to you. We then do the remediation work, not just describe it.

01

Scope and baseline

Establish which systems are in scope, which target level your obligations actually require, and what your current rating is per strategy.

Assessment

01

Scope and baseline

Establish which systems are in scope, which target level your obligations actually require, and what your current rating is per strategy.

Assessment

02

Test enforcement

Verify each control against configuration and behaviour rather than documentation. Where a control is claimed but not enforced, we say so and show why.

Assessment

02

Test enforcement

Verify each control against configuration and behaviour rather than documentation. Where a control is claimed but not enforced, we say so and show why.

Assessment

03

Remediate and evidence

We implement the fixes, in priority order, working with your team or your MSP where one exists. Evidence is captured as each control lands rather than reconstructed months later.

Uplift delivery

03

Remediate and evidence

We implement the fixes, in priority order, working with your team or your MSP where one exists. Evidence is captured as each control lands rather than reconstructed months later.

Uplift delivery

04

Verify and sustain

Retest, issue the evidence pack, then monitor continuously — because maturity decays quietly and exceptions outlive the reason they were granted.

Ongoing

04

Verify and sustain

Retest, issue the evidence pack, then monitor continuously — because maturity decays quietly and exceptions outlive the reason they were granted.

Ongoing

A rating verified eleven months ago is a claim, not evidence.

Between assessments, environments move. A new server misses the patch group, an exception is granted for a project and never revoked, an admin account gets created outside the process. Our posture management platform watches the eight strategies continuously and tells you when your assessed rating stops being true.

What it watches

Control state against your assessed baseline, per strategy

Control state against your assessed baseline, per strategy

Configuration drift, with the change that caused it

Configuration drift, with the change that caused it

Patch cadence and coverage gaps as they open

Patch cadence and coverage gaps as they open

Exception register ageing and expiry

Exception register ageing and expiry

What you get from it

A current maturity position, not an annual snapshot

A current maturity position, not an annual snapshot

Evidence that regenerates rather than being rebuilt for each questionnaire

Evidence that regenerates rather than being rebuilt for each questionnaire

Early warning before a rating slips ahead of a tender or renewal

Early warning before a rating slips ahead of a tender or renewal

Quarterly reporting, with a Fractional CISO option to present it

Quarterly reporting, with a Fractional CISO option to present it

What you can hand to an assessor without rewriting it first.

The output of an assessment is only useful if someone else can follow it. Every finding traces to the configuration that produced it, and every remediation traces back to the finding it closed.

Assessment output

Written to be read by a technical assessor and summarised for a board in the same document.

Maturity rating per strategy, with the overall rating explained

Maturity rating per strategy, with the overall rating explained

Finding-level detail with the configuration evidence behind it

Finding-level detail with the configuration evidence behind it

Risk-ranked gap register with effort estimates and named owners

Risk-ranked gap register with effort estimates and named owners

Executive summary written in plain language

Executive summary written in plain language

Evidence pack

Structured for reuse across the obligations and questionnaires that cite the Essential Eight, rather than rebuilt for each one.

Configuration exports and screenshots mapped to each control

Configuration exports and screenshots mapped to each control

Policy extracts, change records and the exception register

Policy extracts, change records and the exception register

Retest results with a traceability chain from finding to fix to proof

Retest results with a traceability chain from finding to fix to proof

Roadmap to the next maturity level with dependencies mapped

Roadmap to the next maturity level with dependencies mapped

Start with a rating you can actually defend.

Essential Eight assessment

A rating per strategy, tested against enforcement, following the ASD assessment process guide.

Current maturity per strategy

Current maturity per strategy

Risk-ranked gap register

Risk-ranked gap register

Executive and technical reporting

Executive and technical reporting

Uplift delivery

We implement the remediation to your target level, alongside your team or your existing MSP.

Prioritised implementation with named owners

Prioritised implementation with named owners

Evidence captured as controls land

Evidence captured as controls land

Verification retest and evidence pack

Verification retest and evidence pack

Transition readiness review

Lock in a verified baseline now, so the eventual gap analysis against the Essentials series starts from evidence rather than assumption.

Verified baseline rating and evidence set

Verified baseline rating and evidence set

Register of every contract, policy and questionnaire that cites the Essential Eight

Register of every contract, policy and questionnaire that cites the Essential Eight

Watch brief covering published ASD guidance only

Watch brief covering published ASD guidance only

Posture management

Continuous monitoring so your rating stays true between assessments instead of quietly decaying.

Drift detection against assessed baseline

Drift detection against assessed baseline

Exception register review

Exception register review

Quarterly reporting and Fractional CISO option

Quarterly reporting and Fractional CISO option

We assess for a living, so we know what evidence survives scrutiny.

Controls-assessment heritage

Our core practice is testing whether a stated control is actually operating and actually evidenced. That discipline is what separates an assessment from a questionnaire.

Controls-assessment heritage

Our core practice is testing whether a stated control is actually operating and actually evidenced. That discipline is what separates an assessment from a questionnaire.

We will tell you the number is wrong

If your self-assessed ML2 does not hold up, you hear it from us before you hear it from someone else's assurance team. That is the whole value of an independent assessment.

We will tell you the number is wrong

If your self-assessed ML2 does not hold up, you hear it from us before you hear it from someone else's assurance team. That is the whole value of an independent assessment.

Assessment and delivery in one team

We find the gaps and we close them, then verify our own work with a retest you can hand to a third party. No handover, no translation loss between the report and the fix.

Assessment and delivery in one team

We find the gaps and we close them, then verify our own work with a retest you can hand to a third party. No handover, no translation loss between the report and the fix.

Essential Eight, answered plainly.

Is the Essential Eight being retired?

ASD has proposed replacing it with an Essentials series and consulted on the first chapter, which closed on 12 July 2026. ASD has not published a retirement date. A twelve-month deprecation and twenty-four-month retirement timeline has been widely repeated, but that traces to a named official's public remarks rather than to published policy. The November 2023 Maturity Model remains the current, assessable release.

Should we pause our uplift until the new framework lands?

Why is our self-assessed rating usually higher than yours?

How is the overall maturity level calculated?

Do you do the remediation, or just the report?

Does an Essential Eight rating help with our other obligations?

Gradient

When you need method to the chaos

Find out whether your maturity rating would survive an assessment.

A short scoping conversation establishes which target level your obligations actually require, what is in scope, and where the gaps usually sit in an environment like yours.

Gradient

When you need method to the chaos

Your safety is our mission. Your trust is our commitment.

Click below to schedule your free risk assessment and learn how we can help protect your world.

Gradient

When you need method to the chaos

Your safety is our mission. Your trust is our commitment.

Click below to schedule your free risk assessment and learn how we can help protect your world.

Gradient

When you need method to the chaos

Your safety is our mission. Your trust is our commitment.

Click below to schedule your free risk assessment and learn how we can help protect your world.