Nano Solutions

Essential Eight

Score your Essential Eight maturity

Twenty-four questions, three per mitigation strategy, one for each maturity level. Scored the way ASD scores: cumulative within a strategy, and capped at your weakest strategy overall.

Read this before you start

This is an indicative self-check. It is not an Essential Eight assessment, and it is not a substitute for one. It is arithmetic applied to your own answers about your own environment.

There is also no such thing as Essential Eight certification. ASD's maturity model states plainly: "there is no requirement for organisations to have their Essential Eight implementation certified by an independent party." ASD does not endorse or register assessors for the Essential Eight, and it publishes no list of approved products. Any vendor selling you “Essential Eight certification” is describing something that does not exist — the same misconception that surrounds IRAP, where ASD states plainly that it does not accredit, certify, endorse or register any system.

Questions are drawn from the Essential Eight Maturity Model (November 2023), which is the current release. There has been no revision since 27 November 2023.

Answer honestly rather than aspirationally. A self-assessment that flatters you is worse than none.

The WA Auditor General examined ten entities. Seven had overstated their own maturity. Five had not reached Maturity Level One in any control at all.

The ANAO has found the same pattern federally. Some entities "relied on documenting policies and procedures to achieve compliance" rather than implementing anything.

If you are unsure about a requirement, answer no. That is what an assessor would record. One of the seven assessment outcomes in ASD's Essential Eight assessment process guide is "no visibility".

Each question covers every requirement at that level for that strategy, so answer yes only if all of it is true. The detail behind each one is on the requirements matrix, and the individual strategy pages go deeper still.

The 24 questions

Three questions per strategy, one for each maturity level. Answer honestly — the requirements are cumulative, so answering yes to Level Three while Level One is not in place scores Level Zero for that strategy. Anything you leave blank counts as "no".

1. Patch applications

Level One. Do you scan online services for vulnerabilities daily and patch them within 48 hours when a vulnerability is critical or has a working exploit — and within two weeks otherwise?

Also requires weekly scanning of office suites, browsers and their extensions, email clients, PDF software and security products, patching those within two weeks, and removing any of them the vendor no longer supports.

Level Two. Do you also scan your remaining applications at least fortnightly and patch them within one month?

Maturity Level Two extends coverage beyond online services and the office/browser/email/PDF/security set to every other application.

Level Three. Do you patch office suites, browsers, email clients, PDF software and security products within 48 hours when critical or exploited, and remove every unsupported application of any kind?

Maturity Level Three extends the 48-hour timeframe from online services to critical or exploited vulnerabilities in everyday productivity software.

2. Patch operating systems

Level One. Do you patch internet-facing servers and network devices within 48 hours when critical or exploited (two weeks otherwise), and workstations and non-internet-facing systems within one month?

Requires daily scanning of internet-facing operating systems and fortnightly scanning elsewhere. Unsupported operating systems must be replaced. The November 2023 update relaxed workstation and non-internet-facing patching from two weeks to one month.

Level Two. Does that hold consistently across your entire fleet, with no unsupported operating system still in production anywhere?

Maturity Level Two adds no new operating-system requirements over Level One. What changes is that consistent, evidenced coverage is expected across the whole environment rather than a representative sample.

Level Three. Do you also scan and patch drivers and firmware (48 hours when critical, one month otherwise), and run only the latest or previous operating system release?

Drivers and firmware enter scope only at Maturity Level Three.

3. Multi-factor authentication

Level One. Is MFA enforced for users of your own and third-party online services that handle your organisation's sensitive data, and for customers of your online customer services handling sensitive customer data?

Factors must be something users have plus something they know, or something they have unlocked by something they know or are. SMS and voice calls count here but are not phishing-resistant. Security questions and "Trusted Signals" are not valid factors, and biometrics cannot be a primary factor.

Level Two. Is your MFA phishing-resistant, extended to all privileged and unprivileged users of your systems, with successful and unsuccessful MFA events centrally logged and protected?

Phishing-resistant means smart cards, security keys, Windows Hello for Business or passkeys — not SMS or voice. Customers must at least be offered a phishing-resistant option. MFA was the lowest-performing strategy across Commonwealth entities in 2024–25: 34% reached Level Two or above.

Level Three. Does MFA also cover users of data repositories, is it phishing-resistant for customers (not merely offered as an option), and are logs from workstations and non-internet-facing servers analysed?

Maturity Level Three removes the customer opt-out: phishing-resistant MFA becomes the only option.

4. Restrict administrative privileges

Level One. Are privileged access requests validated when first requested, privileged users given separate dedicated accounts, and privileged accounts blocked from the internet, email and web services?

Accounts explicitly authorised to administer online services are exempt from the internet block. That carve-out is what makes cloud administration workable under the Essential Eight, and it is widely misread as a blanket ban.

Level Two. Is privileged access to systems, applications and data repositories disabled after 12 months without revalidation; access to systems and applications disabled after 45 days of inactivity; administration performed via jump servers; and are break-glass, local administrator and service account credentials long, unique, unpredictable and managed?

ASD defines "long" as a minimum of 30 characters.

Level Three. Do you use Secure Admin Workstations and just-in-time administration, with Credential Guard, Remote Credential Guard, LSA protection and memory integrity enabled?

Secure Admin Workstations and Privileged Access Workstations are two names for the same concept, and ASD confirms dedicated physical hardware is not strictly required.

5. Application control

Level One. Does application control run on workstations, restricting executables, software libraries, scripts, installers, compiled HTML, HTML applications and control panel applets to an approved set — across user profiles and the temp folders used by the operating system, browsers and email clients?

ASD is explicit that application control is NOT a portal for installing approved software, NOT web or email content filtering, NOT cloud reputation checking, and NOT next-generation firewall application identification.

Level Two. Does it also cover internet-facing servers and all other locations, use Microsoft's recommended application blocklist, with rulesets validated at least annually and both allowed and blocked events centrally logged?

Blocked events alone are not enough — allowed executions must be logged too.

Level Three. Does it also cover non-internet-facing servers and drivers, using Microsoft's vulnerable driver blocklist?

Driver control is a Maturity Level Three requirement only.

6. Restrict Microsoft Office macros

Level One. Are macros disabled for users without a demonstrated business requirement, blocked in files originating from the internet, scanned by antivirus, and are macro security settings unchangeable by users?

ASD calls this strategy "restrict Microsoft Office macros" in the maturity model but "configure Microsoft Office macro settings" in the 2017 Strategies document. Both are current ASD wording for the same thing.

Level Two. Are macros also blocked from making Win32 API calls?

The November 2023 update REMOVED the macro execution event logging requirement. ASD cited a lack of native support in Windows and advice from incident responders that the events gave limited benefit. Pages still listing it are quoting a superseded model.

Level Three. Do only macros from a sandboxed environment, a Trusted Location, or signed by a trusted publisher execute — with V3 signatures enforced, macros checked for malicious code before signing, and the trusted publisher list validated at least annually?

V3 signatures are required because an earlier flaw let macro code be tampered with without invalidating the file's signature.

7. User application hardening

Level One. Are web browsers blocked from processing Java and web advertisements from the internet, is Internet Explorer 11 disabled or removed, and are browser security settings unchangeable by users?

Blocking Java from the internet does NOT mean blocking JavaScript — ASD answers this explicitly. This strategy is about browsers, Office, PDF software and PowerShell; it is not about hardening software you ship.

Level Two. Are browsers, Office suites and PDF software hardened to ASD and vendor guidance, Office blocked from creating child processes, creating executable content, injecting code into other processes and activating OLE packages — with PowerShell and command-line process creation events centrally logged?

Where ASD and vendor hardening guidance conflict, the most restrictive takes precedence.

Level Three. Are .NET Framework 3.5 and Windows PowerShell 2.0 disabled or removed, and is PowerShell configured to use Constrained Language Mode?

Disabling .NET 3.5 also covers .NET 2.0 and 3.0.

8. Regular backups

Level One. Are backups performed and retained in line with business criticality and continuity requirements, synchronised to a common point in time, retained securely and resiliently, restoration tested as part of disaster recovery exercises, and unprivileged accounts prevented from accessing other users' backups or modifying or deleting any backup?

There is no numeric retention period anywhere in the maturity model — not three months, not thirty days. The "three months" figure comes from the 2017 Strategies document, which the maturity model superseded on this point.

Level Two. Are privileged accounts other than backup administrators also prevented from accessing other users' backups, and from modifying or deleting any backup?

Level Two closes the gap for privileged accounts; the backup administrator is still trusted at this level.

Level Three. Are unprivileged and privileged accounts prevented from accessing even their own backups, and are backup administrator accounts themselves prevented from modifying or deleting backups during the retention period?

Level Three is what stops an attacker who has compromised the backup administrator from destroying the last line of recovery.

Where should we send your scorecard?

Your result appears on this page as soon as you submit.

We store your contact details and the eight resulting level numbers so we can talk you through the result. We do not store your individual answers or any description of specific gaps in your environment. See our privacy policy.

Common questions

How is the score calculated?

Two rules, both ASD's. Within a strategy, levels are cumulative and all-or-nothing: you sit at the highest level where that level and every level beneath it are met, so answering yes to Level Three while Level One is not in place scores Level Zero. Across strategies, your overall maturity is the lowest level of any single strategy — not an average, not a count. That is why one weak strategy caps the entire result.

Is this an Essential Eight assessment?

No. It is arithmetic applied to your own answers about your own environment. ASD ranks evidence in four tiers and places "a policy or verbal statement of intent" in the weakest. A self-assessment sits below even that, because nothing has been examined at all. A real assessment tests controls — ASD says assessments using interviews, reports and screenshots "will always be inferior to conducting assessments using scripts and tools".

Will this make us Essential Eight certified?

Nothing will, because Essential Eight certification does not exist. ASD's maturity model states there is no requirement for organisations to have their implementation certified by an independent party, ASD does not endorse or register Essential Eight assessors, and graduates of ASD's own assessment course are told they must not state or imply ASD endorsement. An independent assessment may still be required of you by a contract, a regulator or a government directive — that is a procurement obligation, not a certificate.

What do you do with our answers?

We store your contact details and the eight resulting level numbers, and nothing else. The individual answers are scored and discarded — we do not keep a record of which specific controls you told us were missing. Security weaknesses tied to a named organisation are not something we want sitting in a CRM.

Why does the tool say we are at Level Zero when most things are in place?

Almost certainly the weakest-link rule. Overall maturity equals your lowest-scoring strategy, so seven strategies at Level Two and one at Level Zero is an organisation at Level Zero. This is deliberate on ASD's part — the eight strategies are designed to complement each other, and ASD's guidance is to reach the same level across all eight before moving up. The result page names the strategies holding the score down.

  • The Essential Eight, explained

    The Essential Eight is ASD's baseline set of eight cyber security mitigation strategies for internet-connected corporate IT. This hub explains what each strategy requires, who must implement it, and what ASD has announced about the proposed Essentials series.

  • Essential Eight requirements matrix

    What each Essential Eight strategy requires at Maturity Levels One, Two and Three: timeframes, scanning intervals and controls introduced at higher levels. Sourced line by line from the November 2023 maturity model.

  • Essential Eight glossary

    A sourced guide to terms used in ASD's Essential Eight publications and in the separate instruments that make the framework mandatory for some organisations.

Essential Eight

Need this assessed rather than self-scored?

We assess your maturity across all eight strategies against evidence rather than answers, show you where you actually stand, and do the remediation.