Essential Eight uplift · Maturity Level 1, 2 and 3

Essential Eight uplift to the maturity level you have been asked for

You already have an assessment, or a clear idea of where the gaps are. Our engineers close them in the platform you run, your team gets the processes to keep them closed, and we re-rate the controls at the end so the level you report has evidence behind it.

Book a 30-minute uplift call Thirty minutes with our cyber security practice manager. Bring your latest assessment, MSP report or insurer questionnaire.
  • Works from the assessment you already haveOurs, your MSP's, an auditor's or your own self-assessment
  • Fixed scope and quote against your gap listConfirmed in writing within one business day of the call
  • Delivered in the platform you runMicrosoft 365, Google Workspace, hybrid or on-premises
  • Re-rated on evidence when the work is doneAn evidence pack your insurer, auditor or customer can inspect
  • Evidence that carries into ISO 27001Built so it can be reused when you start an ISMS

Who this is for

Where most uplift engagements start

Report in hand

You have a gap list and a deadline

An assessment has told you where you sit and what is missing. The insurer renewal, tender or contract date has not moved, and your internal team is already at capacity. We take the gap list, sequence it and deliver it.

MSP score

Your provider gave you a number and a to-do list

A maturity level reported from a provider's portal is often discounted by insurers and auditors. We check the score against your tenant, agree the real gaps with you and your MSP, and close them alongside the people who run the environment day to day.

Next level

You are at Level 1 and need Level 2

Most contracts, insurer questionnaires and government supply chains ask for Maturity Level 2. The step from Level 1 is where application control, privileged access and patching cadence start to matter, and where tooling you already license usually does most of the work.

ISO 27001

You are getting ready for ISO 27001

The eight strategies map onto many of ISO 27001's technical controls. Lifting them first gives your ISMS a working technical baseline, with dated evidence an ISO auditor can sample, before the policy and governance work begins.

Book an uplift callTell us which of these applies and by when.

What we do

The uplift work, in the order it usually runs

Weeks

Configuration that moves the rating

  • MFA coverage across every sign-in path, including legacy and fallback routes
  • Office macro settings applied across the whole fleet
  • User application hardening on every device group, executive laptops included
  • Application control started in audit mode so the inventory builds early

Months

Processes your team keeps running

  • Privileged access cleaned up, with a named owner against every admin account
  • Patching set up as automated deployment with reporting in elapsed days
  • Backup restores tested on a schedule, timed and signed off by the process owner
  • Runbooks and handover so your IT team or MSP can operate it

Close out

Enforcement and evidence

  • Application control moved to enforcement by tranche, with an exceptions process
  • Controls re-rated against the current ASD maturity model
  • Evidence register updated and dated for your insurer, auditor or customer
  • A quarterly self-check so the level holds after we leave

For most Australian organisations the tools are already in the Microsoft 365 licence they hold: Intune, Defender and Entra. Google Workspace and mixed estates are uplifted the same way with the controls each platform provides. Our Essential Eight uplift guide covers the sequencing in more detail.

How it runs

How an uplift engagement runs

Uplift call

Thirty minutes. We go through your assessment or MSP report, the level you need and the date behind it, and who in your team or MSP will be involved.

Gap check and quote

We confirm the gap list against your environment with read-only access. You receive a fixed scope, a sequenced plan and a quote within one business day of the check.

Delivery

Our engineers work through the plan under your change control, with a weekly progress note that shows which controls have moved and what is next.

Re-rating and handover

We re-rate the changed controls on evidence, update the evidence register, and hand over runbooks so your team can keep the level from here.

Book the uplift call

Choose a time

Thirty minutes with Ben Jones, Cyber Security Practice Manager

Bring whatever you have: the assessment report, the MSP's maturity summary, the insurer's questionnaire or the contract clause. Ben will confirm what is in scope, whether your deadline is achievable, and what your own team will need to do.

If it turns out you need an independent assessment first, Ben will say so on the call and explain why.

Prefer email or phone? Use the contact page or call +61 2 7200 2554. A practitioner replies within one business day.

Common questions

Essential Eight uplift questions, answered

Can you work from another provider's assessment?
Yes. We start from whatever assessment you have, check the ratings that matter against your environment, and agree the gap list with you before any work is quoted. If a rating does not hold up against the evidence, we tell you before you spend money on it.
Do we need a new assessment before uplift starts?
Usually not. If your last assessment is recent and was done on evidence from your environment, the gap check is enough. If it is old, self-declared or came from a provider's portal, we may recommend a full Essential Eight assessment first so the plan is built on the real position.
How is uplift priced?
It depends on the number of gaps, the target level, the size of the environment and how much of the work your own team will do. We fix the scope and the price after the gap check, and the price only changes if the scope does.
How long does it take?
Configuration items such as MFA coverage, macro settings and hardening often move within weeks. Privileged access cleanup and patching cadence take a few months to settle. Application control takes longest because it needs a period in audit mode before enforcement, so it starts early. The timeline is written into the quote.
Will our MSP or IT team still run the environment?
Yes. We work under your change control alongside your MSP or internal team, and hand over runbooks at the end. If you would like help keeping the level afterwards, a managed arrangement with quarterly evidence packs and an annual re-assessment is available.
Does this help with ISO 27001?
Yes. The eight strategies cover many of the technical controls an ISO 27001 auditor will sample, and we date and store the evidence so it can feed your ISMS. Our ISO 27001 page covers the certification side.
ASD is replacing the Essential Eight. Is uplift still worth doing?
Yes. ASD opened consultation in June 2026 on an Essentials series that will succeed the Essential Eight over roughly the next two years, and the Essential Eight remains the standard insurers, auditors and contracts ask for today. The controls themselves (MFA, patching, application control, privileged access, backups) carry across, and we keep the evidence in a form that can be re-cut against the new guidance when it is published.

Related reading: Essential Eight uplift guide · How the maturity model is scored · Essential Eight compliance checklist · Essential Eight assessment

Start here

Tell us the level you need, and by when

Thirty minutes with Ben, then a gap check, a fixed scope and a dated plan in writing.