Essential Eight Compliance and What Insurers Ask For

Essential Eight Compliance

Table of Contents

There is no Essential Eight certificate. The Australian Signals Directorate does not certify businesses against the framework, there is no pass mark, and there is no badge that expires after 12 months.

That surprises people, because most other frameworks work the other way. ISO 27001 has accredited certification bodies and a certificate you can put in a tender response. The Essential Eight has a maturity model and an assessment process, and nothing that gets stamped. So when a client, an insurer or a prime contractor asks whether you are essential Eight compliant, there is no document that settles it.

This post covers what Essential Eight compliance means, who asks for proof, what they accept as proof, and how to run the process when nobody in your business does security full time.

What Essential Eight compliance means

Essential Eight compliance means you have implemented all eight mitigation strategies to a target maturity level, and you can demonstrate it through a point-in-time assessment against ASD’s maturity model.
Three parts of that matter:

  1. All eight: Your maturity level is set by your weakest control. Seven controls at Level Two and one at Level Zero puts you at Level Zero, which catches a lot of businesses that have implemented the accessible controls well, but left application control alone because it’s harder.
  2. To a target level: There is no single state of compliance. You are compliant at Maturity Level One, Two or Three, against a target you have chosen or that someone has set for you. Australia’s current cyber security strategy positions Maturity Level Two as the recommended baseline for most organisations, with Level Tree reserved for critical infrastructure.
  3. Point in time: An assessment describes your environment on the day it was assessed. Controls drift. Staff change, systems get added, a patch cycle slips. A twelve-month-old assessment describes a business that may no longer exist in that form.

For a plain-English breakdown of the eight controls themselves, start with what the Essential Eight is.

Who asks for proof and what they accept

Three groups drive most Essential Eight compliance work in Australian businesses: insurers, government buyers and enterprise clients running supply chain checks.

Cyber insurers

Underwriting has moved well past a signed declaration. Insurers now use detailed technical questionnaires, external security ratings and maturity evidence to price a policy, and documented Maturity Level Two satisfies most underwriter criteria. The practical effect for a 30-person firm is that the questions on the renewal form have become specific enough that guessing shows.

Government tenders

If you sell into federal or state government, a credible maturity claim is now part of getting shortlisted, and some contracts specify a minimum level outright.

Enterprise clients

Large customers increasingly push their own security obligations down to suppliers. If you hold their data or connect to their systems, their vendor risk questionnaire will ask where you sit.

What all three accept is an assessment report, not a certificate. The report shows your maturity level per control, the evidence behind each rating, and what remains open. Where they differ is how much the trust who wrote it.

A self-assessment and an independent assessment are not weighted the same

You can self-assess against the Essential Eight, and ASD publishes the maturity model openly so that you can. Boards, insurers and enterprise customers give more weight to an independent assessment and the reason is structural.

When the team that implemented your controls also assesses them, ambiguous findings tend to get read charitably. “We patch regularly” is a reasonable thing to believe about your own environment. “Here are the patch compliance reports for the last three months, showing every device inside the 48-hour window for internet-facing applications” is a different claim, and the gap between the two is where most self-assessments overstate.

There is also the problem of not knowing what to look for. A backup vault sitting in the same Azure subscritpion as production will pass a casual review and fail a Level Two assessment, because the requirement is a separately controlled environment with its own credentials. You only catch that if you are testing against the specific requirement.

The workable model for most businesses is a provider who runs the controls continuously, with an independent cyber security audit once a year to confirm the level holds.

Compliance is an evidence problem, not a control problem

This is the part that catches businesses out, and it is worth stating plainly: most organisations that fail an Essential Eight assessment have the control switched on. What they cannot do is prove that it has been running.

An assessor does not accept that MFA is enforced because you say it is. They ask for the conditional access policy configuration, they check which systems are in scope, and they confirm SMS has been removed as a fallback rather than just de-prioritised. Each control has an equivalent artefact:

  • Patching: A compliance report from your device management platform showing patch status against the required windows, over a period, not a snapshot.
  • Backups: A written record of a quarterly test restoration, naming what was recovered and the outcome.
  • Application control: The allowlist itself, plus the audit logs and the exception process for approving new software.
  • Administrative privileges: An account inventory showing separated admin accounts, with evidence they cannot access email or browse the web.
  • MFA: The policy export showing method, scope and enforced systems.


None of that exists unless someone generates it and files it as they go. Reconstructing twelve months of evidence the week before an assessment is where compliance projects blow out, and it is the single most common reason a business that is genuinely well managed scores badly.

How to run Essential Eight compliance without a dedicated security person

Most businesses of this size have an IT contact who is already stretched, or an external provider handling day-to-day support. Compliance is achievable in that setup, provided it is treated as an operating rhythm rather than a project. In order:

  1. Set your target level and write it down. Without a stated target, “improving our security” has no finish line and no way to report progress.
  2. Get a baseline assessment. You cannot sequence remediation without knowing which control sits where. This also gives you the report to hand to an insurer while the rest of the work is underway.
  3. Assign an owner to each control. Name a person or a provider against each of the eight with cadence attached: who checks patch compliance and when, who runs the quarterly restore test, who reviews the application control exception queue. “IT looks after it” is how controls quietly lapse between assessments.
  4. Automate reporting, keep the record. Microsoft 365 environments can generate much of the evidence automatically through Intune. The part that needs a human is filing it somewhere each month so the audit trail exists when it is asked for.
  5. Book an independent assessment annually. It confirms the level holds and produces the document your insurer and your tender responses need.


What stalls most businesses here is the absence of a named owner and a set cadence, which is exactly what an ongoing managed service agreement is built to provide.

The framework’s retirement does not change what to do now

ASD confirmed in June 2026 that the Essential Eight will be replaced with a new Essentials series, with the two running side-by-side for around 12 months before the Essential Eight is retired.

That does not put compliance work on hold. The Essential Eight remains the active framework, and it’s still what insurers, tenders and contracts reference today. The replacement is outcomes-based, which means the evidence habit described above carries across almost entirely.

A business that can already produce configuration records and test logs is in good shape for the transition. A business relying on a ticked checklist has more work ahead.

Windstil provides cyber security consulting for Australian businesses. Our active clients enjoy a structured, ongoing approach to Essential Eight, with clear prioritisation, consistent progress and guidance to improve their maturity over time.

Subscribe to our newsletter

  Stay informed with practical IT and cyber security insights, along with company updates, announcements, and the work we’re doing with businesses like yours.