Essential Eight Compliance: A Guide for Business Owners

14 min read

If you run a business with 15 to 80 staff, chances are Essential Eight compliance has already come up in conversation. An insurer asked about it at renewal. A larger client sent through a security questionnaire. Your IT provider mentioned it and you nodded along. And you probably walked away no clearer on what it actually requires of you.

The framework itself is sound. The way it usually gets explained is the problem. Most of what is written about it falls into one of two camps: government documentation written for compliance officers, or vendor marketing designed to sell you a product.

This guide is neither. It covers what the Essential Eight is, whether it applies to a business like yours, which maturity level to aim for, and what the work genuinely looks like once you start. It also covers a significant development from June 2026 that changes how you should think about the framework, though probably not what you should do next.

Why Essential Eight Compliance Matters, Even Though It Is Voluntary

The Essential Eight is a set of eight security controls published by the Australian Signals Directorate (ASD). It was built from real incident data: ASD looked at how Australian organisations were actually being compromised, and prioritised the controls that stopped the most attacks.

Legally, it is mandatory only for non-corporate Commonwealth entities, which must reach Maturity Level Two under the Protective Security Policy Framework. For a private Australian business, there is no legal mandate.

That is where most explanations stop, and it is why a lot of owners file it under “not my problem”. In practice, the commercial pressure has caught up:

  • Cyber insurers are asking far more specific questions at renewal. Whether you enforce multi-factor authentication, how quickly you patch, whether you test your backups. Vague answers now affect premiums and, increasingly, eligibility.
  • Enterprise and government clients run vendor risk programs. If you sell into either, the Essential Eight is often the yardstick in the supplier questionnaire.
  • Privacy obligations apply to most businesses turning over more than $3 million, and to any business handling health information regardless of turnover. Regulators expect “reasonable steps” to protect personal information, and the Essential Eight is a widely accepted view of what reasonable looks like.

There is also the plain cost of getting it wrong. In its Annual Cyber Threat Report for 2024-25, ASD recorded more than 84,700 cybercrime reports, roughly one every six minutes, with the average self-reported cost per report reaching $56,600 for small businesses and around $97,200 for medium-sized ones. Those are not headline breach figures from a major bank. They are the cost of an incident at a business roughly your size, with your team and your budget absorbing the recovery.

What the Essential Eight Actually Asks You to Do

Eight controls, grouped around three objectives: make it harder to get in, limit the damage if someone does, and make sure you can recover. Here they are without the acronyms.

Preventing attacks

  1. Application control: only approved software is allowed to run. If a staff member downloads something malicious, it does not execute, because it is not on the approved list.
  2. Patch applications: keep software updated, prioritising anything that touches the internet. Browsers, email clients, PDF readers, Office. Critical vulnerabilities in internet-facing systems need to be dealt with fast.
  3. Configure Microsoft Office macro settings: block macros from the internet by default and only allow them where there is a demonstrated business need. Macros remain a common delivery method for malware.
  4. User application hardening: turn off the features that attackers exploit and most staff never use. Web browser plugins, legacy scripting, unnecessary functionality in Office.

Limiting the extent of an incident

  1. Restrict administrative privileges: admin rights go only to people who genuinely need them, and only for the systems they need. Admin accounts should not be used for daily email and browsing.
  2. Patch operating systems: the same discipline as patching applications, applied to Windows, macOS and anything running on your network. Unsupported operating systems get replaced.
  3. Multi-factor authentication: a second proof of identity beyond the password. This is the single highest-value control on the list and, for most businesses already on Microsoft 365, it is a configuration change rather than a purchase.

Recovering your data

  1. Regular backups: back up your important data, keep copies where an attacker cannot reach or encrypt them, and test that you can actually restore. An untested backup is an assumption, not a control.

Read through that list and most owners have the same reaction: none of it sounds unreasonable. That is the point. The Essential Eight is not exotic security engineering. It is the basics, done consistently and provably.

How the Maturity Levels Work

Each control is measured against four maturity levels, which is where a lot of the confusion comes from. You are not compliant or non-compliant. You sit somewhere on a ladder.

  • Maturity Level Zero: meaningful weaknesses in your overall posture.
  • Maturity Level One: enough to frustrate opportunistic attackers using widely available tools and known vulnerabilities. This is the practical target for most Australian SMBs.
  • Maturity Level Two: holds up against attackers willing to invest more time and effort in a specific target. This is the mandated level for federal government agencies and what many insurers and enterprise clients now look for.
  • Maturity Level Three: built for well-resourced, adaptive adversaries. Relevant to defence, critical infrastructure and organisations holding highly sensitive data.

One detail worth understanding, because it catches people out: ASD’s guidance is to reach the same maturity level across all eight controls before moving up. The controls are designed to complement each other, so being excellent at backups and weak on administrative privileges does not average out to a middling result. It leaves an open door. ASD’s full Essential Eight maturity model sets out the specific requirements at each level, and it also makes clear that implementation should follow a risk-based approach rather than a box-ticking one.

Before You Start: ASD Is Replacing the Essential Eight

This matters, and it is the part most guides published before mid-2026 do not mention.

In June 2026, ASD opened consultation on evolving the Essential Eight into a broader body of guidance called the Essentials series, starting with a chapter titled Essentials for enterprise IT. Shortly afterwards, ACSC’s head of cyber security resilience Chris Horlyck told iTnews that both frameworks would run as live documents through a transition period, with ASD expecting to begin deprecating the Essential Eight at around 12 months and retire it entirely at around 24 months.

The reasoning is structural rather than a criticism of the controls. The Essential Eight was written in 2017 for an on-premises, Windows-centred, perimeter-based environment. Most businesses no longer operate that way. Cloud platforms, software as a service and mobile endpoints do not map cleanly onto controls designed before the shared responsibility model existed. The Essentials series is expected to be domain-based, with separate chapters covering enterprise IT, cloud, operational technology and potentially agentic AI.

So should you wait? No. Three reasons:

  • Nothing has changed today. The Essential Eight is still the live, supported framework, and it is still what tenders, insurance questionnaires and supplier assessments reference.
  • ASD has been explicit that existing work carries across. Organisations already implementing the Essential Eight can expect strong alignment with their existing controls and investments.
  • The controls themselves are not going anywhere. Multi-factor authentication, patching, restricting admin rights and tested backups will be foundational under any framework, whatever it ends up being called.

Pausing your security program because the framework is being restructured is a bit like skipping seatbelts while crash-testing standards get updated.

Step 1: Work Out Whether Essential Eight Compliance Applies to You

Before you spend a dollar, establish why you are doing this. The answer shapes everything that follows, particularly your target maturity level.

Work through three questions:

  1. Is anyone contractually asking for it? Check your current contracts and any tenders you plan to bid on. Government, defence-adjacent and large enterprise clients are the usual sources.
  2. Is your insurer asking for it? Pull out your last renewal questionnaire. If you answered “yes” to questions you are not certain you could evidence, that is a gap worth closing before you need to claim.
  3. What are your regulatory obligations? Turnover, the type of information you hold and your industry all matter here. Worth confirming rather than assuming.

If the answer to all three is no, you may still want to align with the Essential Eight, but you get to do it on your own timeline and to your own standard rather than someone else’s. That is a much more comfortable position, and it is worth knowing which one you are in.

Step 2: Choose a Target Maturity Level

For most owner-led businesses in the 15 to 80 staff range, Maturity Level One is the right first target. It addresses the bulk of what actually happens to businesses your size: opportunistic phishing, credential stuffing, commodity ransomware. It also satisfies the baseline expectations of most insurers.

Aim for Maturity Level Two if you sell into government or defence, operate in a regulated industry, or hold data whose exposure would be genuinely damaging to clients. Treat it as a 12 to 24 month program rather than a sprint.

Maturity Level Three is almost certainly not your problem. If someone is quoting you for Level Three and you are a 40-person professional services firm, ask them to justify it against your actual risk profile.

Step 3: Run a Gap Assessment Across All Eight Controls

You cannot plan the work until you know where you stand, and the honest answer is usually lower than expected. Most businesses assume they are close to Level One and land at Level Zero on two or three controls.

Two things make an assessment useful rather than decorative.

First, start with an asset inventory. You cannot patch software you do not know is installed, or restrict admin rights on a laptop nobody has looked at since 2023. Asset visibility is the foundation of half these controls.

Second, insist on evidence rather than assertion. “We have MFA” is not the same as “MFA is enforced on all users across email, remote access and administrative accounts, and here is the configuration report showing it.” The gap between those two sentences is where breaches happen.

Record the results somewhere durable, with owners and dates attached. If you already maintain an IT risk register, this is exactly the kind of thing it exists for: known gaps, accepted risks, and a documented decision about each one.

Step 4: Sequence the Work by Effort and Impact

This is where the cost question usually gets answered better than owners expect. A meaningful share of Maturity Level One is configuration of tools you are already paying for.

Sensible sequencing looks roughly like this:

  • Do first, low cost, high impact: enforce multi-factor authentication everywhere, block internet-sourced Office macros, strip unnecessary admin rights, disable unused browser and Office features, and separate admin accounts from daily-use accounts.
  • Do next, moderate effort: establish a patching cadence with defined timeframes and reporting, retire unsupported operating systems and applications, and verify your backups by running actual test restores.
  • Plan properly: application control. This is the heaviest lift by a distance and the one most likely to disrupt staff if rushed. It needs a documented approved-software list, a request process, and a pilot group before it goes anywhere near the whole business.

Doing it in this order means you reduce real risk in the first few weeks rather than waiting for a six-month project to finish. It also means the invoice arrives in a sensible order.

Step 5: Document the Evidence as You Go

Holding ISO 27001 accreditation ourselves has taught us something worth passing on: implementing a control is only half the job. Being able to demonstrate it, on request, months later, is the other half.

Capture as you go rather than reconstructing later:

  • Configuration reports and screenshots, dated
  • Short written policies for patching, access and backups
  • Test restore results, with the date and what was restored
  • An exception register: what is not compliant, why, who approved it, and when it will be revisited

That last one is more important than it sounds. Documented, approved exceptions are a sign of a mature program. Undocumented gaps you have quietly stopped noticing are the opposite.

Step 6: Build a Review Cycle

Maturity drifts. New staff arrive, new software gets installed, a laptop is set up in a hurry, someone gets admin rights for a project and keeps them for two years. A business that assessed at Level One in March can be well short of it by December without a single deliberate decision.

Set a review rhythm and put it in the calendar. Quarterly is realistic for most businesses, with a fuller reassessment annually and after any material change: an acquisition, an office move, a cloud migration, significant headcount growth. Tying this into your broader IT strategy and roadmap keeps it from becoming a standalone compliance chore disconnected from how the business is actually growing.

Common Mistakes to Avoid

  • Treating it as a project with an end date. It is a maturity model. The expectation is continuous improvement, not a finish line.
  • Buying tools before assessing. Plenty of vendors will sell you a product mapped to the Essential Eight. Know your gaps first, or you will pay to solve problems you did not have.
  • Uneven maturity. Level Two on backups and Level Zero on admin privileges is not “mostly there”. Attackers find the lowest control, not the average.
  • Answering questionnaires optimistically. Overstating your position on an insurance form is a problem you inherit at exactly the worst moment.
  • Stopping because of the Essentials transition. The controls carry over. Momentum does not.

Frequently Asked Questions

Is Essential Eight compliance mandatory for private businesses in Australia?

No. It is mandatory for non-corporate Commonwealth entities, which must reach Maturity Level Two under the Protective Security Policy Framework. Private businesses face no direct legal mandate. That said, cyber insurers, enterprise clients and government supply chains increasingly treat it as the expected baseline, so for many businesses it is a commercial requirement even without being a legal one.

Which maturity level should a small or medium business target?

Maturity Level One for most businesses in the 15 to 80 staff range. It addresses the majority of attacks that actually affect businesses of that size and meets most insurers’ baseline expectations. Move toward Level Two if you sell into government or defence, operate in a regulated industry, or hold particularly sensitive client data.

How long does it take to reach Maturity Level One?

For a business running Microsoft 365 or Google Workspace with reasonably current hardware, several months of focused work is a realistic expectation. The quick wins land in the first few weeks. Application control and patching discipline take longer because they change how people work, and rushing those creates more problems than it solves.

Is the Essential Eight being replaced?

Yes, over roughly two years. ASD opened consultation in June 2026 on a new Essentials series, and ACSC has indicated the Essential Eight will begin to be deprecated at around 12 months and be retired at around 24 months. It remains the current supported framework today, and ASD has confirmed that work done under the Essential Eight aligns with what comes next.

Do we get certified, and who signs it off?

There is no certificate for the Essential Eight in the way there is for ISO 27001. Compliance is established through assessment against the maturity model, either internally or by a third party, using ASD’s assessment process guidance. For most private businesses, a documented independent assessment with supporting evidence is what satisfies an insurer or a client questionnaire.

Where to Start

If you take one thing from this guide, make it this: the Essential Eight is not a technology problem, it is a discipline problem. The controls are well understood and largely unglamorous. What separates businesses that hold their maturity level from businesses that drift is whether someone owns the work, evidences it, and reviews it on a schedule.

That is a hard thing to sustain internally when IT is one of several things you are responsible for and none of them are your actual job. It is a reasonable thing to expect from a partner.

Our cyber security services include assessing where your business currently sits against the Essential Eight, building a prioritised plan to close the gaps that matter most, and maintaining the evidence trail so that the next insurance renewal or client questionnaire is a straightforward conversation rather than a scramble.

If you would like a clear read on where you stand, get in touch and we will walk you through it.

Want to learn more?

Stay ahead with the latest IT insights delivered straight to your inbox.