Published 08 July 2026
Essential Eight self-assessment: a step-by-step guide
A consultant-led Essential Eight assessment costs thousands of dollars. For a large enterprise with complex systems, that's often money well spent. For a typical Australian small business (a dozen laptops, Microsoft 365 or Google Workspace, a cloud accounting package) a structured self-assessment gets you most of the insight for none of the cost. Here's how to do one properly.
Update, 18 July 2026: the Essential Eight is transitioning to the new Essentials series over roughly two years. Self-assess against the current model as described below. It remains the published framework, and ASD says existing work carries across.
What a self-assessment is (and isn't)
You answer structured questions about your own environment, honestly, against the ASD's published criteria. That's it. Done well, it gives you an indicative maturity level per control and, more usefully, shows exactly which gaps are holding you back.
It is not an audit or a certification. Nobody independently checks your answers, so the result is only as honest as what you put in. That's fine for what it's actually for: knowing where you stand, deciding what to fix first, and having documented answers ready for brokers and customers. Just resist the urge to mark yourself generously.
Before you start: three ground rules
- "Unsure" is a valid answer. Don't know whether your browsers block internet ads? Say so. The ACSC's own assessment guidance treats unknowns as "no" until confirmed. An unverified control is an unmet one.
- Answer for the whole business, not your best-configured laptop. One machine where everyone has admin rights drags the control down for the whole business.
- The person answering should be able to check. Whoever runs your IT, in-house or your MSP, should either answer the technical questions or verify yours.
What to check, control by control
Work through the eight controls one at a time. The short version:
- Multi-factor authentication: Do email and other services holding sensitive data need a second sign-in step? For admins? For everyone? Is it something the user physically has, not just security questions?
- Regular backups: Do backups run on a schedule that matches how much data you can afford to lose? Can ordinary accounts delete them? Have you ever actually done a test restore?
- Patch applications: Do browsers, office suites, PDF readers and antivirus update within two weeks of a release, and within 48 hours for critical fixes to internet-facing services? Is anything end-of-life?
- Patch operating systems: Same questions for Windows/macOS and your firewall or router firmware. Anything running an OS the vendor has abandoned?
- Restrict administrative privileges: Who has admin rights, and did anyone approve that? Do admins have separate everyday accounts? Would unused admin access ever get switched off?
- Restrict Microsoft Office macros: Are macros blocked for staff without a business need, especially in files from the internet? (No Microsoft Office? This control may not apply to you.)
- User application hardening: Do browsers block Java and ads from the internet? Is Internet Explorer 11 gone? Can staff change browser security settings?
- Application control: Can staff computers run only approved programs? This is the hardest control for small businesses. Plenty sit at Level 0 here, and knowing that honestly is the whole point.
How the scoring works
Each control lands somewhere from Level 0–3. Levels are cumulative (Level 2 needs everything at Level 1 too), and a control's level is the highest one where all criteria are met. Your overall maturity is your lowest applicable control, because attackers use the weakest door. Most insurers and frameworks treat Level 2 as the sensible target for small businesses. Level 1 is the baseline. Level 3 adds advanced measures like MFA on data repositories and tighter patch timeframes.
What to do with the result
A score on its own does nothing. What you do next is where the value is:
- Fix the weakest control first. It sets your overall score, and it's usually your most exploitable gap.
- Confirm your "unsure" answers. Each one you verify might lift a level without spending a cent.
- Write it down. Dated results plus written policies are the documentation brokers and enterprise customers actually ask for.
- Book in a re-assessment. Once a year at minimum, ideally before your insurance renewal.
Doing it the easy way
You can absolutely do all this yourself from the ACSC's published documents and a spreadsheet. The model is public and free. The catch is time: transcribing criteria, mapping questions, and working out levels by hand.
The Veritas Cyber free self-assessment wraps the same exercise into about 20 minutes. Plain-English questions with the underlying ACSC criterion shown for each, conservative handling of "unsure", automatic level calculation, and an indicative snapshot across all eight controls at the end. You don't need an account, and your answers stay in your browser unless you choose to save them.
Whichever way you do it, the principle holds: an honest look beats a hopeful guess. Every improvement starts with knowing where you really stand.
This is a self-assessment based on your own answers. It is not a certification, audit, or guarantee of security or insurance outcomes, and is not legal or insurance advice. Results are indicative, reflect the information you provided, and are assessed against a representative subset of the ASD Essential Eight Maturity Model (November 2023).