Skip to content

Published 08 July 2026

Essential Eight self-assessment: a step-by-step guide

Consultant-led Essential Eight assessments run into the thousands of dollars. For a large enterprise with complex systems, that money is often well spent. For a typical Australian small business — a dozen laptops, Microsoft 365 or Google Workspace, a cloud accounting package — a structured self-assessment gets you most of the insight for none of the cost. Here's how to do one properly.

Update, 18 July 2026: the Essential Eight is transitioning to the new Essentials series over roughly two years. Self-assess against the current model as described below — it remains the published framework, and ASD says existing work carries across.

What a self-assessment is (and isn't)

A self-assessment means answering structured questions about your own environment, honestly, against the ASD's published criteria. Done well, it tells you your indicative maturity level per control and — more usefully — exactly which gaps are holding you down.

What it isn't: an audit or a certification. Nobody independently verifies your answers, so the result is only as honest as your inputs. That's fine for its actual purposes — knowing where you stand, prioritising fixes, and having documented answers ready for brokers and customers — as long as you resist the urge to grade yourself generously.

Before you start: three ground rules

  1. "Unsure" is a valid answer. If you don't know whether your browsers block internet ads, say so. Treating unknowns as "no" until confirmed is how the ACSC's own assessment guidance works — an unverified control is an unmet one.
  2. Answer for the whole business, not the best-configured laptop. One machine with admin rights for everyone drags the control down for the business.
  3. The person answering should be able to check. Whoever manages your IT — in-house or your MSP — should either answer the technical questions or verify your answers.

What to check, control by control

Work through the eight controls systematically. In brief:

  • Multi-factor authentication: Is a second sign-in step required for email and other services holding sensitive data? For admins? For everyone? Is it something the user physically has, not just security questions?
  • Regular backups: Do backups run to a schedule that matches how much data you can afford to lose? Are they protected from deletion by ordinary accounts? Have you ever done a test restore?
  • Patch applications: Do browsers, office suites, PDF readers and antivirus update within two weeks of a release — 48 hours for critical fixes to internet-facing services? Is anything end-of-life?
  • Patch operating systems: Same questions for Windows/macOS and your firewall or router firmware. Anything running an OS the vendor abandoned?
  • Restrict administrative privileges: Who has admin rights, and did anyone approve that? Do admins have separate everyday accounts? Would unused admin access ever get disabled?
  • Restrict Microsoft Office macros: Are macros blocked for staff without a business need, especially in files from the internet? (If you don't use Microsoft Office, this control may not apply to you.)
  • User application hardening: Do browsers block Java and ads from the internet? Is Internet Explorer 11 gone? Can staff change browser security settings?
  • Application control: Can staff computers run only approved programs? This is the hardest control for small businesses — many sit at Level 0 here, and knowing that honestly is the point.

How the scoring works

Each control lands at Level 0–3. Levels are cumulative — Level 2 requires everything at Level 1 — and a control's level is the highest one where all criteria are met. Your overall maturity is your lowest applicable control, because attackers use the weakest door. Most insurers and frameworks treat Level 2 as the sensible target for small businesses; Level 1 is the baseline; Level 3 adds advanced measures like phishing-resistant MFA.

What to do with the result

The result's value is in what you do next:

  1. Fix the weakest control first — it sets your overall score and is usually your most exploitable gap.
  2. Confirm your "unsure" answers — each one you verify may raise a level without any new spending.
  3. Write it down — dated results plus written policies are the documentation brokers and enterprise customers actually request.
  4. Diarise a re-assessment — annually at minimum, ideally before your insurance renewal.

Doing it the easy way

You can absolutely run this from the ACSC's published documents with a spreadsheet — the model is public and free. The trade-off is time: transcribing criteria, mapping questions, and deriving levels by hand.

The Veritas Cyber free self-assessment packages the same exercise into about 20 minutes: plain-English questions with the underlying ACSC criterion shown for each, conservative handling of "unsure", automatic level calculation, and an indicative snapshot across all eight controls at the end. No account needed, and your answers stay in your browser unless you choose to save them.

However you run it, the principle is the same: an honest look beats a hopeful guess. Every improvement starts with knowing where you actually stand.

This is a self-assessment based on your own answers. It is not a certification, audit, or guarantee of security or insurance outcomes, and is not legal or insurance advice. Results are indicative, reflect the information you provided, and are assessed against a representative subset of the ASD Essential Eight Maturity Model (November 2023).