Free tool · no signup · Australian ACSC framework

Essential Eight Maturity Assessment

Rate your organisation across all eight ACSC mitigation strategies and get your overall Maturity Level, a per-strategy breakdown, and exactly which strategies to lift first.

For each of the eight strategies, pick the description that best matches you today. Your overall maturity is the lowest strategy — the ACSC model treats the Essential Eight as a set, so one weak strategy caps the whole score.

1

Application control

Only approved applications are allowed to execute; everything else is blocked.

2

Patch applications

Internet-facing and productivity apps are patched fast; unsupported apps removed.

3

Configure MS Office macro settings

Office macros are blocked or tightly controlled and logged.

4

User application hardening

Browsers and apps are hardened — no Flash/ads/Java, hardened settings enforced.

5

Restrict administrative privileges

Admin access is minimised, validated, and separated from day-to-day accounts.

6

Patch operating systems

OS on internet-facing and internal systems patched fast; unsupported OS removed.

7

Multi-factor authentication

MFA is enforced for users, admins and third-party access — phishing-resistant at higher levels.

8

Regular backups

Backups are frequent, tested by restoration, and protected from tampering.

0/8 strategies rated — rate all eight to see your maturity level.

Directional self-assessment based on the ACSC Essential Eight Maturity Model — not an official assessment or IRAP evaluation. Your formal maturity depends on tested evidence across your whole environment. Nothing you enter leaves your browser.

The Essential Eight, explained

What is the Essential Eight maturity model?

The Essential Eight is a set of eight mitigation strategies from the Australian Cyber Security Centre (ACSC/ASD) that, together, prevent the most common cyber attacks. The Maturity Model grades how well you implement them across four levels — Maturity Level 0 (not aligned) through Maturity Level 3 (resilient against adaptive, targeted adversaries). This tool gives you a directional maturity level in a couple of minutes.

What are the eight strategies?

Application control, patch applications, configure Microsoft Office macro settings, user application hardening, restrict administrative privileges, patch operating systems, multi-factor authentication, and regular backups. The first four largely prevent malware delivery and execution; the rest limit the extent of incidents and support recovery.

Why is my overall maturity the lowest strategy, not an average?

The ACSC is explicit that the Essential Eight should be implemented as a package and assessed as a whole: you only achieve Maturity Level N when every one of the eight strategies meets Level N. A single weak strategy caps your overall rating — which is why this tool reports the minimum across all eight, not an average, and shows you exactly which strategies are holding you back.

What maturity level do we need?

The ACSC recommends organisations select a target maturity level based on the threats most relevant to them; many Australian government entities are directed toward Maturity Level 2. Level 1 stops opportunistic, non-targeted attacks; Level 2 resists attackers who invest more effort and use phishing-resistant techniques; Level 3 is aimed at adaptive, targeted adversaries.

Is this an official Essential Eight assessment?

No — it is a free, directional self-assessment to help you find gaps and prioritise. A formal rating requires tested evidence across your whole environment, typically via an assessor. What this tool (and CATAAM) do is get you to a defensible maturity level faster: CATAAM automates the evidence for MFA, patching, admin restriction and backups, and continuously proves those controls operate.