Essential Eight
Score your Essential Eight maturity
Twenty-four questions, three per mitigation strategy, one for each maturity level. Scored the way ASD scores: cumulative within a strategy, and capped at your weakest strategy overall.
Read this before you start
This is an indicative self-check. It is not an Essential Eight assessment, and it is not a substitute for one. It is arithmetic applied to your own answers about your own environment.
There is also no such thing as Essential Eight certification. ASD's maturity model states plainly: "there is no requirement for organisations to have their Essential Eight implementation certified by an independent party." ASD does not endorse or register assessors for the Essential Eight, and it publishes no list of approved products. Any vendor selling you “Essential Eight certification” is describing something that does not exist — the same misconception that surrounds IRAP, where ASD states plainly that it does not accredit, certify, endorse or register any system.
Questions are drawn from the Essential Eight Maturity Model (November 2023), which is the current release. There has been no revision since 27 November 2023.
Answer honestly rather than aspirationally. A self-assessment that flatters you is worse than none.
The WA Auditor General examined ten entities. Seven had overstated their own maturity. Five had not reached Maturity Level One in any control at all.
The ANAO has found the same pattern federally. Some entities "relied on documenting policies and procedures to achieve compliance" rather than implementing anything.
If you are unsure about a requirement, answer no. That is what an assessor would record. One of the seven assessment outcomes in ASD's Essential Eight assessment process guide is "no visibility".
Each question covers every requirement at that level for that strategy, so answer yes only if all of it is true. The detail behind each one is on the requirements matrix, and the individual strategy pages go deeper still.
Common questions
How is the score calculated?
Two rules, both ASD's. Within a strategy, levels are cumulative and all-or-nothing: you sit at the highest level where that level and every level beneath it are met, so answering yes to Level Three while Level One is not in place scores Level Zero. Across strategies, your overall maturity is the lowest level of any single strategy — not an average, not a count. That is why one weak strategy caps the entire result.
Is this an Essential Eight assessment?
No. It is arithmetic applied to your own answers about your own environment. ASD ranks evidence in four tiers and places "a policy or verbal statement of intent" in the weakest. A self-assessment sits below even that, because nothing has been examined at all. A real assessment tests controls — ASD says assessments using interviews, reports and screenshots "will always be inferior to conducting assessments using scripts and tools".
Will this make us Essential Eight certified?
Nothing will, because Essential Eight certification does not exist. ASD's maturity model states there is no requirement for organisations to have their implementation certified by an independent party, ASD does not endorse or register Essential Eight assessors, and graduates of ASD's own assessment course are told they must not state or imply ASD endorsement. An independent assessment may still be required of you by a contract, a regulator or a government directive — that is a procurement obligation, not a certificate.
What do you do with our answers?
We store your contact details and the eight resulting level numbers, and nothing else. The individual answers are scored and discarded — we do not keep a record of which specific controls you told us were missing. Security weaknesses tied to a named organisation are not something we want sitting in a CRM.
Why does the tool say we are at Level Zero when most things are in place?
Almost certainly the weakest-link rule. Overall maturity equals your lowest-scoring strategy, so seven strategies at Level Two and one at Level Zero is an organisation at Level Zero. This is deliberate on ASD's part — the eight strategies are designed to complement each other, and ASD's guidance is to reach the same level across all eight before moving up. The result page names the strategies holding the score down.
Read next
-
The Essential Eight, explained
The Essential Eight is ASD's baseline set of eight cyber security mitigation strategies for internet-connected corporate IT. This hub explains what each strategy requires, who must implement it, and what ASD has announced about the proposed Essentials series.
-
Essential Eight requirements matrix
What each Essential Eight strategy requires at Maturity Levels One, Two and Three: timeframes, scanning intervals and controls introduced at higher levels. Sourced line by line from the November 2023 maturity model.
-
Essential Eight glossary
A sourced guide to terms used in ASD's Essential Eight publications and in the separate instruments that make the framework mandatory for some organisations.
Essential Eight
Need this assessed rather than self-scored?
We assess your maturity across all eight strategies against evidence rather than answers, show you where you actually stand, and do the remediation.