Essential Eight Assessment and Maturity Services
Understand your actual Essential Eight maturity level through evidence-based assessment rather than self-reported compliance.
CCircle assesses implementation and effectiveness against ASD guidance, identifies gaps and provides practical recommendations to improve cyber security maturity. We test what is operating, not only what a policy says should be operating.
Essential Eight Maturity Assessments
Assessments use the ASD Essential Eight Assessment Process Guide with the Essential Eight Maturity Model. We define the boundary, gather credible evidence and technically validate controls before determining maturity.
This is materially different from a questionnaire. A control is not effective because it appears in a policy or because a platform is licensed; evidence must demonstrate implementation across the agreed scope.
What We Assess
1. Application control
Execution controls, rules, coverage, maintenance and bypass resistance.
2. Patch applications
Asset visibility, vulnerability identification, patch timeframes and exceptions.
3. Configure Microsoft Office macro settings
Macro sources, trust controls, user restrictions and logging.
4. User application hardening
Web browser, Office, PDF and other user application security settings.
5. Restrict administrative privileges
Privileged accounts, access paths, administration practices and reviews.
6. Patch operating systems
Operating system vulnerabilities, patch deployment and unsupported platforms.
7. Multi-factor authentication
Coverage, factor strength, administrative access and external services.
8. Regular backups
Backup scope, protection, retention, restoration testing and privileged access.
Essential Eight Maturity Levels
Maturity Level Zero records that the requirements of Maturity Level One are not met. Levels One, Two and Three are target states designed around increasing levels of adversary tradecraft and targeting. Requirements are cumulative when assessing higher target levels.
The highest level is not automatically the right target. The appropriate level depends on organisational risk, legal and contractual obligations, the system, information holdings and relevant government policy. We help define a defensible target before assessment effort begins.
Essential Eight Gap Assessment
A gap assessment establishes current state through evidence gathering and technical testing, then identifies where control implementation differs from the target. Findings explain the gap, affected scope, security consequence and recommended priority.
The output is a practical roadmap rather than a flattering score. It can be used to plan investment, define work packages and prepare for a later maturity assessment.
Essential Eight Uplift and Remediation
CCircle understands both assessment and implementation. We can help design and implement application control, patch management, Microsoft configuration, Active Directory and privileged access improvements, MFA, infrastructure hardening, endpoint configuration, backup controls, policies and technical validation.
Before recommending new products, we assess whether existing platforms and licences can deliver the required control. Uplift is scoped around the target environment, dependencies and the organisation's ability to operate the control after implementation.
Essential Eight for Government and Government Suppliers
The Essential Eight supports Australian Government security expectations and is referenced within broader ASD and government policy. Agencies, Defence environments and suppliers may need evidence that mitigations are implemented and effective.
Essential Eight maturity is not complete ISM compliance. Systems may require many additional controls based on classification, risk, architecture and obligations. Organisations preparing for government use should consider the Essential Eight alongside applicable ISM controls and, where required, IRAP assessment services.
Our Assessment Process
- Define the system boundary and target maturity.
- Collect documentation and credible control evidence.
- Conduct technical validation using agreed methods.
- Assess each mitigation strategy and its underlying controls.
- Determine maturity against ASD guidance.
- Identify gaps, scope and security consequences.
- Produce clear findings and a prioritised improvement roadmap.
Need a defensible maturity baseline?
Define scope and evidence expectations before relying on a self-assessed maturity result.
Essential Eight FAQs
What is an Essential Eight assessment?
It is an evidence-based assessment of the implementation and effectiveness of the controls underpinning ASD’s eight mitigation strategies, conducted against an agreed target maturity level and system scope.
What are Essential Eight maturity levels?
Maturity Level Zero records that Maturity Level One requirements are not met. Levels One, Two and Three are target maturity levels addressing increasing levels of adversary tradecraft and targeting.
What evidence is required for an Essential Eight assessment?
Evidence varies by control and environment. It may include configurations, policies, management-platform data, vulnerability and patch records, identity settings, backup results, logs, interviews and controlled technical testing.
What is the difference between an Essential Eight gap assessment and maturity assessment?
A maturity assessment determines achievement against a defined target using formal evidence. A gap assessment can be used earlier to identify what is missing and prioritise work before a formal maturity determination.
Can CCircle assess Maturity Level 1 and Maturity Level 2?
Yes. CCircle can assess Maturity Levels One, Two and Three, with the scope and target selected according to risk, obligations, environment and prior maturity.
Can CCircle implement the remediation work?
Yes. We can support technical and governance remediation, including application control, patching, Microsoft and endpoint configuration, privileged access, MFA, backups and policy updates.
How often should Essential Eight maturity be reassessed?
Reassessment frequency should reflect risk, obligations and the rate of environmental change. Material platform changes, control failures, audit findings or uplift completion are common triggers.
Is Essential Eight the same as ISM compliance?
No. The Essential Eight is a prioritised set of mitigation strategies within broader ASD guidance. An Essential Eight assessment does not demonstrate complete compliance with all applicable ISM controls.
Related Resources and Services
Know Your Actual Essential Eight Maturity
Get an evidence-based view of your current position and a practical roadmap for improvement.