Australia · ACSC Essential Eight · Maturity Levels 1-3

Essential Eight Compliance Automation

Automate the ACSC Essential Eight inside CATAAM — application control, patching, macro & user-application hardening, admin restriction, MFA and backups, assessed across Maturity Levels 1-3. Cross-mapped to ISO 27001 and SOC 2 — and the only platform that also proves the controls work.

Where the Essential Eight stands today

The Essential Eight is maintained by the Australian Cyber Security Centre (ACSC) and is the cybersecurity lingua franca in Australia — mandatory for federal government and the baseline nearly every commercial buyer, government supplier and regulated business benchmarks against. Maturity Level 2 is the common commercial target. Because its strategies are technical — patching, MFA, admin restriction, backups — the Essential Eight is where CATAAM’s automated evidence collection is at its strongest, and where an ISO 27001 or SOC 2 program gives you a head start.

Every Essential Eight strategy, covered

CATAAM ships the Essential Eight as a first-class framework across all eight mitigation strategies and Maturity Levels 1-3 — with the automatable strategies validated by native tests and the rest tracked with managed evidence.

1. Application Control

Allowlisting restricts execution of executables, libraries, scripts, installers, compiled HTML and control-panel applets on workstations (ML1), extending to internet-facing and all servers with Microsoft-recommended block rules and central logging (ML2+).

2. Patch Applications

Internet-facing application vulnerabilities are patched or mitigated within 48 hours when an exploit exists (two weeks otherwise), backed by automated asset discovery and fortnightly vulnerability scanning — and unsupported applications are removed.

3. Configure Microsoft Office Macros

Macros are disabled for users without a business need, macros from the internet are blocked, users cannot change the settings, and (ML2+) only sandboxed or trusted-publisher-signed macros run with antivirus scanning and central logging.

4. User Application Hardening

Web browsers block Java and web ads from the internet, Internet Explorer 11 is disabled or removed, legacy .NET and PowerShell 2.0 are removed, and PowerShell script-block logging is enabled — hardened per ACSC guidance.

5. Restrict Administrative Privileges

Privileged access is validated on request, revalidated at least every 12 months, disabled after 45 days of inactivity, blocked from internet/email/web, and (ML2+) administered through jump servers with privileged and unprivileged environments segregated.

6. Patch Operating Systems

OS and internet-facing-service vulnerabilities are patched within 48 hours when exploited (two weeks / one month otherwise) across workstations, servers and network devices, with fortnightly-to-weekly scanning and no unsupported operating systems.

7. Multi-Factor Authentication

MFA protects internet-facing services, third-party services handling sensitive data and all privileged users (ML1), becoming phishing-resistant and extended to all users of internet-facing services and important data repositories with central logging (ML2+).

8. Regular Backups

Important data, software and configuration are backed up and retained per business-continuity requirements, restoration is tested during disaster-recovery exercises, and unprivileged accounts cannot access, modify or delete backups.

Prove your controls — don’t just claim them

The Essential Eight is a maturity model, and most tools let you self-assess your way to a maturity level. CATAAM validates each technical strategy with an evidence-gated test: a control passes only on confirmed proof pulled from your live environment — patch currency, MFA enforcement, privileged-access restriction, backup configuration. And because CATAAM is also an attack-surface and breach-simulation platform, it goes one step further than any pure GRC tool — it attacks your own environment to prove the mitigations actually stop the techniques the Essential Eight is designed to block, feeding those findings straight into your evidence.

One evidence set, cross-mapped: satisfy the Essential Eight, ISO 27001 and SOC 2 from the same controls, so the multi-framework burden doesn’t multiply.

How it works

01

Enrol and inherit the Essential Eight program

Enrol your organization in Essential Eight. CATAAM scaffolds all eight strategies across Maturity Levels 1-3 and inherits a library of supporting policies (patching, access control, backup, hardening) automatically — pick your target maturity and scope the rest.

02

Connect your stack, discover your estate

Connect cloud, identity, MDM and endpoint tools. CATAAM discovers your real assets so patching, MFA, admin restriction and backup posture are validated against your live environment — not a spreadsheet — and vendor-specific tests only appear for what you actually run.

03

Validate the technical strategies with proof

CATAAM’s automated iASM and vendor tests directly validate the automatable strategies — patch currency, MFA enforcement, privileged-access restriction and backup configuration. A control passes only on confirmed evidence pulled from your environment, so your maturity claim is proof, not self-assessment.

04

Track maturity and stay assessment-ready

Watch each strategy roll up to its maturity level, close gaps with due dates and owners, and hand an assessor a tokenized, read-only evidence portal for an Essential Eight Maturity Model assessment.

Essential Eight FAQ

What is the Essential Eight and who needs it?
The Essential Eight is a set of eight prioritised mitigation strategies published by the Australian Cyber Security Centre (ACSC) to protect against common cyber threats. It is mandatory for Australian federal non-corporate Commonwealth entities and has become the de-facto baseline the wider Australian market — enterprises, government suppliers and regulated businesses — measures itself against. It is assessed against Maturity Levels 0-3.
How does CATAAM automate Essential Eight compliance?
CATAAM ships Essential Eight as a first-class framework covering all eight strategies across Maturity Levels 1-3. The four most automatable strategies — patch applications, patch operating systems, restrict administrative privileges and multi-factor authentication — are validated by native tests against your live cloud, identity and endpoint tooling, while application control, macro configuration, user-application hardening and backups are tracked with managed, evidence-gated controls.
What is Maturity Level 2, and is that what we should target?
The Essential Eight defines Maturity Levels 1 through 3, each raising the bar on how comprehensively and quickly each strategy is implemented. Maturity Level 2 is the common commercial target for most organisations — a meaningful, defensible posture without the highly-resourced-adversary assumptions of ML3. In CATAAM you set your target maturity and mark higher-level requirements out of scope, so the readiness score reflects the level you are actually working toward.
We already have ISO 27001 or SOC 2 — do we start Essential Eight from scratch?
No. The Essential Eight overlaps heavily with the technical controls of ISO 27001 and SOC 2 — patching, MFA, privileged access and backups. CATAAM cross-maps a single evidence set across all of them, so an ISO 27001 or SOC 2-certified organisation auto-satisfies much of the Essential Eight and only builds the genuinely E8-specific requirements like application control and macro hardening.
Can CATAAM prove the Essential Eight is actually working, not just configured?
Yes — this is CATAAM’s strongest fit for the Essential Eight. Beyond validating configuration, CATAAM runs internal attack-surface management and breach & attack simulation against your own environment, so you can demonstrate that patching, MFA and hardening genuinely stop the techniques the Essential Eight is designed to mitigate — evidence that a pure GRC checklist tool cannot produce.

WATCH

The Essential Eight, explained

Two minutes: what the Essential Eight is, who must comply, its four maturity levels, how it overlaps with ISO 27001 and SOC 2, and how CATAAM automates it into a live maturity report.

Get Essential Eight-ready with CATAAM

Enrol in the Essential Eight framework, reuse the security evidence you already have, and prove your mitigation strategies actually work — transparently priced from $149/mo.