Skip to content

Published 08 July 2026

Essential 8 compliance for Australian small business

If you run a small business in Australia, the phrase Essential Eight (often written Essential 8) has probably reached you through one of three doors. Your insurance broker asked about it. A big customer's procurement questionnaire mentioned it. Or your IT provider suggested it. This guide covers what it is and how to approach it, in plain English, without assuming you have an IT department.

Update, 18 July 2026: ASD has announced the Essential Eight will evolve into a new Essentials series over roughly two years. The current maturity model, and everything in this guide, remains in force during the transition, and ASD says existing controls carry across.

What the Essential Eight actually is

The Essential Eight is a set of eight baseline security strategies published by the Australian Signals Directorate (ASD), the government agency responsible for cyber security. It isn't a law. It isn't a certification scheme either. It's a prioritised list of the eight things that block the most common attacks, and we've explained them control by control:

  1. Application control: only approved software runs on your computers
  2. Patch applications: everyday software gets security updates promptly
  3. Restrict Microsoft Office macros: document-borne malware is blocked
  4. User application hardening: risky software features are switched off
  5. Restrict administrative privileges: admin rights are limited and controlled
  6. Patch operating systems: Windows, macOS and network devices stay updated
  7. Multi-factor authentication: a stolen password alone isn't enough to sign in
  8. Regular backups: your data survives ransomware, and restores are tested

The order isn't random. ASD ranks these because together they deal with the attack paths behind most incidents Australian businesses actually run into: phishing, malicious attachments, unpatched software and stolen passwords.

What the maturity levels mean

Each control is assessed at a maturity level from 0 to 3. Our Essential Eight maturity levels explained guide breaks down what changes at each level. The short version:

LevelWhat it means in practice
0The baseline isn't met. There are gaps attackers commonly exploit
1Partly aligned. Basic protections exist against commodity attacks
2Mostly aligned. Controls are applied systematically. The common target for SMBs
3Fully aligned. Advanced measures such as phishing-resistant MFA

Two things catch people out. First, levels are cumulative: reaching Level 2 means meeting everything at Level 1 as well. Second, your overall maturity equals your weakest control. A business with excellent backups and MFA but no macro restrictions is, overall, only as mature as its macro settings. Sounds harsh. It's also how attacks work. Intruders look for the weakest door, not the strongest.

Is Essential 8 compliance mandatory?

For most private small businesses, no law forces Essential Eight compliance. Three practical pressures push the same way anyway:

  • Cyber insurance. Australian insurers commonly ask about MFA, backups and patching at application and renewal, and the Essential Eight is a widely used reference point for those questions.
  • Privacy Act obligations. Businesses handling personal information are expected to take reasonable steps to protect it, and the Essential Eight is often cited as a sensible baseline for what "reasonable" looks like.
  • Customers and supply chains. Larger organisations increasingly ask their suppliers, small ones included, to show their security maturity before doing business. Some industries feel this earlier than others, such as accountants and bookkeepers holding concentrated client financial data.

None of these calls for a certificate. What they generally want is for you to know your posture and be able to document it.

How a small business can approach it

You don't need to kick off with a consultant engagement. Here's a sensible order:

  1. Assess where you stand. Answer honest questions about each of the eight controls. Our free self-assessment does this in about 20 minutes, in plain English, and gives you an indicative Level 0–3 per control.
  2. Find your weakest control. Overall maturity equals the lowest control, so the quickest improvement usually comes from closing one specific gap. Often that's macro settings, separate admin accounts or backups nobody has test-restored.
  3. Fix in priority order. For a small business, MFA and backups typically give the most protection per hour of effort.
  4. Document it. Written policies and an evidence summary are what brokers and customers actually ask to see.
  5. Re-check periodically. Controls drift. Staff change, software changes, exceptions pile up. An annual re-assessment lined up with your insurance renewal keeps the documentation current.

The honest caveats

A self-assessment reflects what you know about your own environment. It isn't an audit, and it can't catch things you don't know about. If you handle unusually sensitive data or face specific threats, professional advice is worth paying for. And no maturity level rules out an incident. The Essential Eight reduces risk. It doesn't remove it.

Still, for the vast majority of Australian small businesses, the distance between "we've never looked" and "we know our level and we're closing the gaps" is huge. You feel it in real security, in insurance conversations, and in the confidence you can give customers.

FAQ

What is Essential 8 (Essential Eight) compliance? The Essential Eight, often written Essential 8, is a set of eight baseline cyber security strategies published by the Australian Signals Directorate. It isn't a law, and it isn't a certification scheme. It's a prioritised list of controls, each assessed at a maturity level from 0 to 3, that block the most common ways small businesses are attacked.

Is Essential 8 compliance mandatory for small businesses in Australia? For most private small businesses, no law mandates it directly. Three practical pressures push the same way instead: cyber insurers commonly ask about Essential 8 controls like MFA, backups and patching at application and renewal; the Privacy Act's expectation of "reasonable steps" is often measured against it; and larger customers increasingly ask suppliers to show their security maturity.

What are the Essential 8 maturity levels? Each control is scored from Level 0 (baseline not met) to Level 3 (fully aligned, advanced measures). Levels are cumulative, so reaching Level 2 means also meeting Level 1. Your overall maturity equals your weakest control, not an average.

Is Essential 8 the same as Essential Eight? Yes, it's the same ASD framework. "Essential Eight" is the official name. "Essential 8" is the numeral shorthand most people search for and write day to day. This guide uses both interchangeably.

How can a small business check where it stands against the Essential 8? Our free self-assessment asks plain-English questions about each of the eight controls, takes about 20 minutes and gives an indicative Level 0–3 per control. No account needed. It's a self-assessment based on your own answers, not a certification or an audit.

Start with the 20-minute check: the free Essential Eight self-assessment gives you an indicative maturity snapshot across all eight controls, no account required.

This is a self-assessment based on your own answers. It is not a certification, audit, or guarantee of security or insurance outcomes, and is not legal or insurance advice. Results are indicative, reflect the information you provided, and are assessed against a representative subset of the ASD Essential Eight Maturity Model (November 2023).