Frameworks

ACSC Essential Eight (Australia)

Australia's eight mitigation strategies — the security baseline Australian buyers ask about first.

Book a demo

The Essential Eight, published by the Australian Cyber Security Centre, distills security into eight mitigation strategies scored across maturity levels. Australian government agencies are held to it, and Australian enterprise procurement increasingly expects suppliers to state their maturity level.

Eight strategies, three maturity levels

Application control, patch applications, configure Office macros, user application hardening, restrict admin privileges, patch operating systems, multi-factor authentication, and regular backups — each assessed at Maturity Level 1 to 3 against increasingly capable adversaries. The model's honesty is its strength: you claim a level, and every strategy must meet it.

How Compriska helps

Compriska tracks the eight strategies as evidenced controls with maturity scoring, cross-maps them to CIS Controls and ISO 27001 work you may already run, and produces the maturity statement Australian customers and agencies request.

Frequently asked questions

Is the Essential Eight mandatory?

For Australian federal non-corporate entities, yes (Maturity Level 2 target). For everyone else it's the de facto benchmark Australian buyers and insurers use to judge security posture.

Other frameworks

Automate Essential Eight with Compriska

See how cross-mapped controls, continuous evidence, and AI workflows change the cost of compliance.

Book a demo