Cyber security · Essential Eight

Essential Eight assessment

Asked for your Essential Eight maturity level by an insurer, a customer contract or the board? An independent assessment that rates every control against evidence and ends with a costed plan to reach the level you have been asked for. Scoped in one call, with a fixed quote and a dated turnaround.

Book a scoping callRead the uplift guide
Fixed quote after one call Evidence based, not a questionnaire Maturity level per control Costed uplift plan included Uplift by us or your team

When an assessment is required

Where the requirement for an Essential Eight assessment comes from

The Essential Eight started as ASD guidance for Commonwealth entities, where Maturity Level 2 is mandated under the Protective Security Policy Framework. Over the past three years it has become the yardstick the private sector uses as well, because it is short, it is Australian, and it maps to the controls that stop the attacks that actually happen here. These are the situations that bring organisations to us.

Cyber insurance renewal or new cover

The proposal form asks for your maturity level

Australian cyber insurers now ask for Essential Eight maturity alongside MFA coverage, endpoint detection, backup testing and patching cadence, and price the policy on the answers. Some will not quote below a stated level. A self-declared level carries little weight with an underwriter; an independent, evidence-based rating does, and it is the document that gets pulled out if there is ever a claim. Our 2026 analysis of breach costs covers how underwriting has shifted.

Customer contracts and tenders

A security schedule names Maturity Level 2, with a date

Banks, insurers and large corporates write the Essential Eight into supplier security schedules, and APRA's CPS 230 has pushed regulated entities to verify their material service providers by 1 July 2026. Government tenders at Commonwealth and state level ask for a current maturity level, and Defence supply chain participants meet it through DISP. Winning or keeping the work depends on being able to state a level and show how it was reached.

Board, audit and risk committee

Directors want a number they can rely on and a cost to fix it

After a peer's breach makes the news, an internal audit finding, or a regulator's letter, the board asks where the organisation stands. The Essential Eight gives a defensible answer in a framework directors recognise, and a costed uplift plan turns the conversation from concern into a budget decision. For APRA-regulated entities it also feeds CPS 234 assurance over information security controls.

After an incident or a near miss

You need to know what let it in and what else is open

Once containment is done, an assessment against the Essential Eight establishes which controls failed, which are missing, and what the exposure looks like across the rest of the environment. It is also what insurers, customers and, in serious cases, the OAIC will ask to see when they ask what has changed since.

Verifying an MSP or internal self-assessment

The score came from the people who run the environment

Managed service providers routinely report an Essential Eight level to their clients. The rating is produced by the party whose work is being rated, often from the provider's own portal rather than from the tenant, and insurers and auditors discount it accordingly. We assess what exists in Microsoft 365, Intune, Defender and Entra directly, and the report goes to you.

Certification programmes and due diligence

ISO 27001, SOC 2, acquisition or investment

Organisations heading for ISO 27001 or SOC 2 use the Essential Eight as the technical control baseline underneath the management system, because an auditor will test the same things. Acquirers and investors increasingly ask for a maturity level during due diligence on Australian targets. An assessment done early sets the price of the uplift before someone else sets it for you.

What you receive

What an Essential Eight assessment from Coder Trove includes

  • A maturity level for each of the eight controls, rated against the current ASD Essential Eight Maturity Model on evidence gathered from your environment, not on questionnaire answers
  • An overall maturity level stated plainly, with the specific controls holding it down
  • The evidence register behind every rating, in a form an insurer, auditor or customer can inspect
  • A gap analysis for the target level you need, whether that is Maturity Level 1, 2 or 3
  • A sequenced uplift plan with effort and cost estimates against each step, in a form the board can approve as a budget
  • An executive briefing that explains the result in business terms, and a technical debrief for the people who will do the work
  • A quick-win list: items that lift the rating within weeks, usually inside Microsoft 365, Intune, Defender and Entra settings you already pay for
  • Re-rating of controls after uplift, so the level you report is the level you hold

How it runs

How the assessment runs

Scoping call

Thirty minutes. We confirm the size and shape of your environment, the level you have been asked for and the deadline behind it. You receive a fixed quote and a dated turnaround within one business day.

Evidence collection

Our team gathers configuration exports, policies, patch and backup records and tenant settings, with read-only access and a short list of requests for your IT lead. Your team's time is measured in hours across the engagement.

Assessment

Each control is tested against the maturity model's requirements using the evidence collected, with verification where the evidence and the configuration disagree. Controls that exist on paper but not in practice are rated as they operate.

Report and plan

You receive the maturity rating, the evidence register, the gap analysis and the costed uplift plan, and we walk your executive team and your engineers through it separately. Then you choose who delivers the uplift.

After the assessment

Essential Eight uplift and ongoing compliance after the assessment

Uplift

Close the gaps

Application control, patching, macro and hardening settings, privilege restriction, MFA and backups, delivered by our engineers largely within the Microsoft 365, Intune, Defender and Entra tooling you already hold. Fixed scope against the plan, or handed to your own team with our support.

Managed Essential Eight

Stay at the level

Maturity decays every time an app is added or an admin account is created. A managed arrangement monitors configuration drift and patch compliance, produces a quarterly evidence pack for insurers and customers, and re-assesses annually so the level you report stays true.

Beyond the Eight

When contracts escalate

The same team runs vCISO retainers, ISO 27001 readiness and penetration testing for organisations whose obligations grow past the Essential Eight. The assessment evidence carries forward, so nothing is collected twice.

Executive briefing · 27 October 2026

Online · Tuesday 27 October · 12:00pm to 1:00pm AEDT

How North Korean operatives are getting through legitimate hiring processes and into Australian software teams

Ben Jones, our Cyber Security Practice Manager, joins Dan Elliott, Field CISO at Recorded Future, to examine how fabricated candidates pass AI-assisted interviews, the warning signs engineering and security teams miss, and how fake recruiters target existing developers with malicious coding tests. Attendees receive the Human Verification Checklist: twelve interview questions built on Recorded Future's research.

Register for the briefing
For leaders in engineering, security, risk, legal and talent at Australian organisations with in-house software teams.

Moderated by Steve Young, Head of Strategy, Lead Express.

Presented with Recorded Future.

Common questions

Essential Eight assessment questions, answered

What does an Essential Eight assessment cost?
It depends on the number of users and devices, how many environments and business units are in scope, and how much evidence already exists. A flat published rate would be padded for a small organisation and wrong for a large one, so we fix the price after a scoping call instead. You will have a fixed quote within one business day of the call, and it will not change unless the scope does. Our uplift guide explains what drives the cost.
How long does it take?
The turnaround is set at scoping and written into the quote, so you can plan around an insurance renewal or a contract date. Smaller environments with good records run in a couple of weeks; larger or multi-entity environments take longer, mostly in evidence collection. Tell us the deadline and we will tell you whether it is achievable before you commit.
Which maturity level do we need?
Whatever the party asking for it requires. Maturity Level 2 is the most common target in contracts, insurer questionnaires and government supply chains, and is realistic for most organisations running Microsoft 365. Level 3 is usually reserved for organisations handling sensitive data or facing capable, targeted adversaries. If nobody has named a level yet, we recommend one based on your data and your customers, and explain why. Ben's post on how the maturity model is scored covers the detail.
Is the assessment independent of our IT provider?
Yes. We do not run your environment, so we have no reason to rate it kindly. We work alongside your MSP or internal IT team for access and evidence, and the report goes to you. If your provider then delivers the uplift, the re-rating still comes from us.
What do you need from our team?
A point of contact in IT for read-only access and a short list of evidence requests, a few hours of that person's time across the engagement, and one conversation with whoever owns risk. We collect and organise the evidence; your team is not asked to fill in spreadsheets.
Is this the same as an IRAP assessment?
No. An Essential Eight assessment rates your controls against the ASD Essential Eight Maturity Model and is what insurers, customers and most contracts ask for. An IRAP assessment is a broader government security assessment against the Information Security Manual, performed by an IRAP-endorsed assessor, and is required for specific Commonwealth work. If what you have been asked for is IRAP, we will tell you at the scoping call and point you to the right assessor.
Can you deliver the uplift as well, or do we need another provider?
We can deliver it, and most clients ask us to, because the people who found the gaps already know the environment. You are equally free to hand the costed plan to your own team or your MSP. Either way, we re-rate the controls once the work is done so the level you report is evidenced.

Start here

Tell us what you have been asked for, and by when.

A thirty minute scoping call, a fixed quote and a dated turnaround within one business day. No tooling to buy and no managed service attached unless you want one.