Skip to content

Published 08 July 2026

Essential 8 compliance for Australian small business

If you run a small business in Australia, the phrase Essential Eight — often written Essential 8 — has probably reached you through one of three doors: your insurance broker asked about it, a big customer's procurement questionnaire mentioned it, or your IT provider suggested it. This guide explains what it is and how to approach it — in plain English, without assuming you have an IT department.

Update, 18 July 2026: ASD has announced the Essential Eight will evolve into a new Essentials series over roughly two years. The current maturity model — and everything in this guide — remains in force during the transition, and ASD says existing controls carry across.

What the Essential Eight actually is

The Essential Eight is a set of eight baseline security strategies published by the Australian Signals Directorate (ASD), the government agency responsible for cyber security. It is not a law and not a certification scheme — it is a prioritised list of the eight things — explained control by control — that block the most common attacks:

  1. Application control — only approved software runs on your computers
  2. Patch applications — everyday software gets security updates promptly
  3. Restrict Microsoft Office macros — document-borne malware is blocked
  4. User application hardening — risky software features are switched off
  5. Restrict administrative privileges — admin rights are limited and controlled
  6. Patch operating systems — Windows, macOS and network devices stay updated
  7. Multi-factor authentication — a stolen password alone is not enough to sign in
  8. Regular backups — your data survives ransomware, and restores are tested

The order is not random. The ASD ranks these because together they address the attack paths — phishing, malicious attachments, unpatched software, stolen passwords — behind most incidents Australian businesses actually experience.

What the maturity levels mean

Each control is assessed at a maturity level from 0 to 3 — see our Essential Eight maturity levels explained for a full breakdown of what changes at each level:

LevelWhat it means in practice
0The baseline isn't met — there are gaps attackers commonly exploit
1Partly aligned — basic protections exist against commodity attacks
2Mostly aligned — controls are systematically applied. The common target for SMBs
3Fully aligned — advanced measures like phishing-resistant MFA

Two things trip people up. First, levels are cumulative: reaching Level 2 means meeting everything at Level 1 as well. Second, your overall maturity equals your weakest control. A business with excellent backups and MFA but no macro restrictions is, overall, only as mature as its macro settings. That sounds harsh, but it reflects how attacks work — intruders find the weakest door, not the strongest.

Is Essential 8 compliance mandatory?

For most private small businesses, no law forces Essential Eight compliance. But three practical forces push in the same direction:

  • Cyber insurance. Australian insurers commonly ask about MFA, backups and patching at application and renewal, and the Essential Eight is a widely used reference point for those questions.
  • Privacy Act obligations. Businesses handling personal information are expected to take reasonable steps to protect it, and the Essential Eight is frequently cited as a sensible baseline for what "reasonable" looks like.
  • Customers and supply chains. Larger organisations increasingly ask their suppliers — including small ones — to demonstrate security maturity before doing business.

None of these require a certificate. What they generally require is that you know your posture and can document it.

How a small business can approach it

You don't need to start with a consultant engagement. A sensible sequence:

  1. Assess where you stand. Answer honest questions about each of the eight controls. Our free self-assessment does this in about 20 minutes, in plain English, and gives you an indicative Level 0–3 per control.
  2. Find your weakest control. Because overall maturity equals the lowest control, the fastest improvement is usually closing one specific gap — often macro settings, admin-account separation, or untested backups.
  3. Fix in priority order. MFA and backups typically deliver the most protection per hour of effort for a small business.
  4. Document it. Written policies and an evidence summary are what brokers and customers actually ask to see.
  5. Re-check periodically. Controls drift — staff change, software changes, exceptions accumulate. An annual re-assessment aligned to your insurance renewal keeps documentation current.

The honest caveats

A self-assessment reflects what you know about your own environment — it is not an audit, and it can't catch things you're unaware of. If you handle unusually sensitive data or face specific threats, professional advice is worth the money. And no maturity level guarantees you won't have an incident; the Essential Eight reduces risk, it doesn't eliminate it.

But for the vast majority of Australian small businesses, the gap between "we've never looked" and "we know our level and are closing the gaps" is enormous — in real security, in insurability conversations, and in the confidence you can offer customers.

Start with the 20-minute check: the free Essential Eight self-assessment gives you an indicative maturity snapshot across all eight controls, no account required.

This is a self-assessment based on your own answers. It is not a certification, audit, or guarantee of security or insurance outcomes, and is not legal or insurance advice. Results are indicative, reflect the information you provided, and are assessed against a representative subset of the ASD Essential Eight Maturity Model (November 2023).