Security · supported
ACSC Essential Eight
The Australian Signals Directorate's eight mitigation strategies, assessed at maturity levels 1–3.
8 STRATEGIES, 152 REQUIREMENTS ACROSS MATURITY LEVELS, MODELLED AT ASD'S OWN RESOLUTION.
Who needs it
Who gets asked.
Typical driver: Defence and government supply chain, board reporting.
Defence industry and DISP members
Commonwealth and state government suppliers
MSPs asked to evidence client maturity
Anyone whose insurer or board asks 'what maturity level are we?'
On ISO Assist
How we run E8.
01
Every one of the 152 requirements is a row: owner, status, evidence, exceptions register.
02
Maturity level rolls up from the requirements, never from a self-declared score.
03
Evidence for 27001 controls is reused where it satisfies an E8 requirement, mapped once.
04
Exceptions register for compensating controls is a built-in register type.
05
Framework transitions, such as Essential Eight to the Essentials series, land as a content update, not a migration.
Sectors
Where E8 comes up.
Defence industry & supply chain
Meet the Essential Eight at the maturity level your contract names.
Worked exampleMSPs & IT providers
Run compliance for every client from one screen, with hard walls between them.
Worked exampleSoftware & SaaS
ISO 27001 first, SOC2 mapped from the same evidence.
Worked exampleSee E8 adopted in the demo.
14 days free, no card. Or book a demo and we will walk it with you.