Cyber security · Essential Eight
Essential Eight assessment
Asked for your Essential Eight maturity level by an insurer, a customer contract or the board? An independent assessment that rates every control against evidence and ends with a costed plan to reach the level you have been asked for. Scoped in one call, with a fixed quote and a dated turnaround.
When an assessment is required
Where the requirement for an Essential Eight assessment comes from
The Essential Eight started as ASD guidance for Commonwealth entities, where Maturity Level 2 is mandated under the Protective Security Policy Framework. Over the past three years it has become the yardstick the private sector uses as well, because it is short, it is Australian, and it maps to the controls that stop the attacks that actually happen here. These are the situations that bring organisations to us.
Cyber insurance renewal or new cover
The proposal form asks for your maturity level
Australian cyber insurers now ask for Essential Eight maturity alongside MFA coverage, endpoint detection, backup testing and patching cadence, and price the policy on the answers. Some will not quote below a stated level. A self-declared level carries little weight with an underwriter; an independent, evidence-based rating does, and it is the document that gets pulled out if there is ever a claim. Our 2026 analysis of breach costs covers how underwriting has shifted.
Customer contracts and tenders
A security schedule names Maturity Level 2, with a date
Banks, insurers and large corporates write the Essential Eight into supplier security schedules, and APRA's CPS 230 has pushed regulated entities to verify their material service providers by 1 July 2026. Government tenders at Commonwealth and state level ask for a current maturity level, and Defence supply chain participants meet it through DISP. Winning or keeping the work depends on being able to state a level and show how it was reached.
Board, audit and risk committee
Directors want a number they can rely on and a cost to fix it
After a peer's breach makes the news, an internal audit finding, or a regulator's letter, the board asks where the organisation stands. The Essential Eight gives a defensible answer in a framework directors recognise, and a costed uplift plan turns the conversation from concern into a budget decision. For APRA-regulated entities it also feeds CPS 234 assurance over information security controls.
After an incident or a near miss
You need to know what let it in and what else is open
Once containment is done, an assessment against the Essential Eight establishes which controls failed, which are missing, and what the exposure looks like across the rest of the environment. It is also what insurers, customers and, in serious cases, the OAIC will ask to see when they ask what has changed since.
Verifying an MSP or internal self-assessment
The score came from the people who run the environment
Managed service providers routinely report an Essential Eight level to their clients. The rating is produced by the party whose work is being rated, often from the provider's own portal rather than from the tenant, and insurers and auditors discount it accordingly. We assess what exists in Microsoft 365, Intune, Defender and Entra directly, and the report goes to you.
Certification programmes and due diligence
ISO 27001, SOC 2, acquisition or investment
Organisations heading for ISO 27001 or SOC 2 use the Essential Eight as the technical control baseline underneath the management system, because an auditor will test the same things. Acquirers and investors increasingly ask for a maturity level during due diligence on Australian targets. An assessment done early sets the price of the uplift before someone else sets it for you.
What you receive
What an Essential Eight assessment from Coder Trove includes
- A maturity level for each of the eight controls, rated against the current ASD Essential Eight Maturity Model on evidence gathered from your environment, not on questionnaire answers
- An overall maturity level stated plainly, with the specific controls holding it down
- The evidence register behind every rating, in a form an insurer, auditor or customer can inspect
- A gap analysis for the target level you need, whether that is Maturity Level 1, 2 or 3
- A sequenced uplift plan with effort and cost estimates against each step, in a form the board can approve as a budget
- An executive briefing that explains the result in business terms, and a technical debrief for the people who will do the work
- A quick-win list: items that lift the rating within weeks, usually inside Microsoft 365, Intune, Defender and Entra settings you already pay for
- Re-rating of controls after uplift, so the level you report is the level you hold
How it runs
How the assessment runs
Scoping call
Thirty minutes. We confirm the size and shape of your environment, the level you have been asked for and the deadline behind it. You receive a fixed quote and a dated turnaround within one business day.
Evidence collection
Our team gathers configuration exports, policies, patch and backup records and tenant settings, with read-only access and a short list of requests for your IT lead. Your team's time is measured in hours across the engagement.
Assessment
Each control is tested against the maturity model's requirements using the evidence collected, with verification where the evidence and the configuration disagree. Controls that exist on paper but not in practice are rated as they operate.
Report and plan
You receive the maturity rating, the evidence register, the gap analysis and the costed uplift plan, and we walk your executive team and your engineers through it separately. Then you choose who delivers the uplift.
After the assessment
Essential Eight uplift and ongoing compliance after the assessment
Uplift
Close the gaps
Application control, patching, macro and hardening settings, privilege restriction, MFA and backups, delivered by our engineers largely within the Microsoft 365, Intune, Defender and Entra tooling you already hold. Fixed scope against the plan, or handed to your own team with our support.
Managed Essential Eight
Stay at the level
Maturity decays every time an app is added or an admin account is created. A managed arrangement monitors configuration drift and patch compliance, produces a quarterly evidence pack for insurers and customers, and re-assesses annually so the level you report stays true.
Beyond the Eight
When contracts escalate
The same team runs vCISO retainers, ISO 27001 readiness and penetration testing for organisations whose obligations grow past the Essential Eight. The assessment evidence carries forward, so nothing is collected twice.
Executive briefing · 27 October 2026
How North Korean operatives are getting through legitimate hiring processes and into Australian software teams
Ben Jones, our Cyber Security Practice Manager, joins Dan Elliott, Field CISO at Recorded Future, to examine how fabricated candidates pass AI-assisted interviews, the warning signs engineering and security teams miss, and how fake recruiters target existing developers with malicious coding tests. Attendees receive the Human Verification Checklist: twelve interview questions built on Recorded Future's research.
Register for the briefingCommon questions
Essential Eight assessment questions, answered
What does an Essential Eight assessment cost?
How long does it take?
Which maturity level do we need?
Is the assessment independent of our IT provider?
What do you need from our team?
Is this the same as an IRAP assessment?
Can you deliver the uplift as well, or do we need another provider?
Start here
Tell us what you have been asked for, and by when.
A thirty minute scoping call, a fixed quote and a dated turnaround within one business day. No tooling to buy and no managed service attached unless you want one.