Skip to content

Essential Eight

Know your Essential Eight maturity, then reach the level you need.

Contracts, insurers and boards now ask for a maturity level. We measure each of the eight strategies against evidence, agree a realistic target with you, and deliver the uplift as code so it stays in place.

Locked steel server cabinet door, with blue light through the perforated mesh.

Who it is for

Organisations that need to show an Essential Eight maturity level: government suppliers with a contract clause, APRA-regulated entities, critical infrastructure operators, and anyone whose insurer or board has started asking. It suits Microsoft-centred, hybrid environments with an internal IT team.

A checklist of six security findings, four ticked as closed and two still open, connected to three areas of work: identity, endpoint and detection.

The assessment

We test all eight strategies against the ACSC Essential Eight Maturity Model, following the ACSC's assessment process guidance. Controls are tested, sampled and evidenced, so the result shows what happens rather than what is intended.

  • Duration: three to four weeks from access to readout
  • Your time: about three hours across a kick-off, interviews and the readout, plus an application owner for the application control conversation
  • Access: read-only administrative access to Entra ID, Intune, Defender, Microsoft 365, Active Directory, and your patch and backup tooling

What you receive

  • A maturity level for each of the eight strategies, with the evidence behind it
  • The specific gaps to the next level, written so an engineer can act on them
  • A recommended target level, with the reasoning
  • An uplift plan with effort, dependencies, sequencing and the business impact of each change
  • A one-page summary for your leadership and board

The uplift

Most organisations need work on application control, administrative privileges and macro settings, because those change how people work. We plan them with the business, pilot them and roll them out in rings, with a fast route for legitimate exceptions.

Controls are built as code, such as Intune policies, Conditional Access and App Control for Business rules in your repository, so the configuration can be reviewed, reapplied and evidenced. When the uplift is done we reassess and give you an updated evidence pack.

Keeping the level

Maturity slips when nobody owns it. New applications bypass application control, admin rights creep back and patch timeframes stretch. Under Managed Engineering, North Ark keeps the controls in place, reports on them monthly and reassesses before each attestation.

How it runs

  1. Scoping: we agree the systems in scope, the target you are working towards and the version of the maturity model your contract or auditor refers to.
  2. Assessment: evidence collection, testing and sampling across the environment.
  3. Readout: results and the uplift plan, walked through with your leadership and technical team.
  4. Uplift: controls delivered in planned phases, piloted and rolled out in rings.
  5. Reassessment: evidence refreshed against your target level.

Questions buyers ask

Is this an IRAP assessment?

No. IRAP assessments are carried out by assessors registered under the ACSC's Infosec Registered Assessors Program. If your contract requires IRAP, tell us and we will help you prepare for it. For most organisations, an evidence-based assessment and uplift is what the contract, insurer or board is asking for.

Which maturity level should we aim for?

It depends on your obligations and the threats you face. Maturity Level One is the usual first target, and Level Two is common for government suppliers and regulated entities. The ACSC advises reaching the same level across all eight strategies before going higher.

Will application control break our applications?

Not if it is rolled out properly. Policies run in audit mode first, rules are built from what your people use, and enforcement is rolled out in rings with a quick exception process.

How long does the uplift take?

It depends on the gaps and your change windows. The assessment gives you a dated plan, and most uplifts run over a few months so changes can be piloted.

Can we use the results with another provider?

Yes. The findings and plan are yours to use with anyone.

Do you certify us as Essential Eight compliant?

There is no Essential Eight certification. We measure maturity against evidence and give you an evidence pack you can show to a contracting agency, insurer or auditor.

Start a conversation

Find out where you stand before someone else asks.

Tell us what is driving the question and the level you need to reach.

Talk to an Engineer