Essential Eight Compliance

Essential Eight Compliance for Australian Businesses

The Essential Eight is Australia’s baseline cybersecurity framework, developed by the Australian Signals Directorate. GCIT has accredited Essential Eight assessors through TAFEcyber and helps businesses achieve compliance, prepare reports for tenders, and reduce cyber insurance premiums.
Accredited. Certified. Audited.
TAFEcyber Essential Eight Assessor certificationGCIT ISO 27001 certification badgeMicrosoft Solutions Partner for Modern Work badge

GCIT team working on Essential Eight compliance assessments for Australian businesses

Compliance is no longer optional for Australian businesses

The Optus and Medibank breaches changed how regulators, insurers, and customers evaluate cybersecurity. Insurance companies now increase premiums for non-compliant businesses. Government procurement increasingly requires demonstrable Essential Eight alignment. And frameworks like Essential Eight, ISO 27001, SMB 1001, CIS Controls, and NIST are crucial for Australian businesses that want to win contracts and reduce risk.
GCIT delivers Essential Eight compliance through three core services:
1
Essential Eight Aligned Managed IT Services
Every GCIT managed IT plan is built around Essential Eight controls. Patching, MFA, application control, backups, and endpoint protection are implemented from day one, not bolted on later.
2
Essential Eight Maturity Level Uplift
We help organisations reach their required Essential Eight maturity level, whether that’s Level One for a baseline, Level Two for sensitive data, or Level Three for critical infrastructure. We assess where you are, build a remediation plan, and implement the controls.
3
Essential Eight Assessment Reports
Our certified Essential Eight assessors (accredited through TAFEcyber) deliver formal assessment reports following the official ASD process guide. These reports are used for tenders, board reporting, insurance applications, and regulatory compliance.

Elliot Munro, GCIT CISO and certified Essential Eight Assessor

Elliot Munro
CISO, GCIT
Completed the TAFEcyber Essential Eight Assessment Course

94,000+
cybercrime reports received by the ASD in 2023-24, one every six minutes

$49,600
average cost of cybercrime per report for small businesses

$50M
maximum penalty under the Cyber Security Act 2024 for failure to report a ransomware payment within 72 hours

Australian Government Australian Signals Directorate (ASD) logo
Australian Cyber Security Centre (ACSC) logo

The Essential Eight
mitigation strategies

Eight strategies. One framework.

The Essential Eight is a set of mitigation strategies from the Australian Signals Directorate designed to make it harder for adversaries to compromise systems.

Control · Harden · Patch

Control what runs. Close the gaps.

  • Application control: only approved applications can execute on your devices
  • Patch applications: close known vulnerabilities in browsers, Office, and third-party software
  • Patch operating systems: keep Windows and macOS current
  • Configure Microsoft Office macro settings: block untrusted macros from executing
  • User application hardening: disable risky features in web browsers and PDF readers

Restrict · Verify · Recover

Restrict access. Verify identity. Ensure recovery.

  • Restrict administrative privileges: limit who has admin access to reduce attack surface
  • Multi-factor authentication: verify identity beyond passwords on every account
  • Regular backups: tested, automated, and recoverable when you need them

Get your E8 assessment →

Essential Eight maturity levels explained

The Essential Eight uses four maturity levels (0 through 3) to measure how well each strategy is implemented. Most small businesses should aim for Maturity Level One as a starting point. If you tender for government work or handle sensitive data, higher levels may be required.

0

Level Zero

Controls have not been implemented, or implementations are so incomplete they provide little meaningful protection against common cyber threats.

Recommended
1

Level One

Basic protection against opportunistic attacks from adversaries using commodity tools and automated techniques. Fundamental versions of each control implemented.

2

Level Two

More comprehensive control coverage with shorter patching timeframes, stricter access controls, and more sophisticated monitoring. Mandatory for Australian non-corporate Commonwealth entities under PSPF.

3

Level Three

Full alignment with the intent of each mitigation strategy. Protects against highly skilled, persistent adversaries who conduct extensive reconnaissance and develop custom malware.

Each strategy, mapped to real tools

We don’t just write a compliance report. We implement the controls using Microsoft 365, Microsoft Intune, and our managed security stack, then document everything in your compliance report.

1
Application control
ThreatLocker deployed across all endpoints. Only approved applications can execute. Ringfencing prevents approved apps from being weaponised.

2
Patch applications
Automated patching through Microsoft Intune with staged rollouts. Browsers, Office, PDF readers, and third-party apps kept current within 48 hours of release.

3
Configure Office macro settings
Macros blocked by default via Intune policy. Only digitally signed macros from trusted publishers are allowed where business requirements demand it.

4
User application hardening
Web browsers configured to block Flash, Java, and ads. PDF readers set to block JavaScript execution. Attack Surface Reduction rules enforced through Intune.

5
Restrict admin privileges
Local admin removed from standard users via Intune. Privileged accounts use separate credentials with just-in-time access through Microsoft Entra ID.

6
Patch operating systems
Windows Update for Business managed through Intune. OS patches deployed within 48 hours of release with testing rings to prevent disruption to your team.

7
Multi-factor authentication
MFA enforced on every account through Microsoft Entra Conditional Access. Phishing-resistant methods (FIDO2 keys, Authenticator app) preferred over SMS.

8
Regular backups
Automated cloud backup of Microsoft 365 data, endpoints, and servers. Restores tested regularly. Backups stored separately from production to protect against ransomware.

GCIT Essential Eight assessor conducting a compliance review with a client

Microsoft Solutions Partner for Modern Work

Microsoft Solutions Partner
GCIT implements Essential Eight controls natively through the Microsoft 365 ecosystem, including Intune, Entra ID, Defender for Endpoint.

Is your business ready for Essential Eight compliance?

These are the questions we work through during an Essential Eight discovery workshop. If you can’t confidently answer most of them, you likely have gaps that need addressing.
Do you know which applications are approved to run on your devices?+
Application control means only whitelisted software can execute. If users can install anything, you’re exposed to malware, ransomware, and unauthorised tools that create compliance gaps.
How quickly are security patches applied to your operating systems and applications?+
The Essential Eight requires patching within specific timeframes. For Maturity Level One, critical patches should be applied within one month. Many businesses we assess have devices months behind on updates.
Is MFA enforced on every user account, including admin accounts?+
MFA is the single most effective control against credential theft. It’s required at every maturity level. We frequently find businesses where admin accounts, the most privileged and most targeted, lack MFA enforcement.
Are macros blocked by default in Microsoft Office?+
Macros remain a common malware delivery method. The Essential Eight requires macros from the internet to be blocked, and only signed macros from trusted locations should be permitted.
When was your last backup restore tested?+
Having backups isn’t enough. The Essential Eight requires that backups are tested regularly to confirm they can actually be restored. We test restores as part of our managed IT services, not just set and forget.

Not sure which maturity level you need?

Most small businesses should target Maturity Level One as a solid starting point. If you handle sensitive government data or healthcare records, you may need Level Two or higher. We’ll assess where you are now and recommend the right target based on your industry, size, and risk profile.
We’ll tell you what you actually need, not what sells.

Need an E8 report for a tender?

We hear this regularly. A client needs to demonstrate Essential Eight compliance for a government contract or enterprise procurement process, and they need the report quickly. GCIT has accredited assessors through TAFEcyber who can evaluate your current posture, implement the gaps, and produce a detailed compliance report outlining every control.
Unlike ISO 27001, there’s no formal certificate issued by the ASD. Your report is your proof of compliance.

GCIT Essential Eight assessment team

Your certified Essential Eight assessment team

Essential Eight Assessors
TAFEcyber Essential Eight Assessor

Certified Management Systems
ISO 27001 Information Security
ISO 9001 Quality Management
ISO 14001 Environmental Management

Microsoft Certifications
Microsoft Solutions Partner for Modern Work
Microsoft Certified Expert
Microsoft Certified Associate
Microsoft Certified Fundamentals

Essential Eight compliance FAQ

Is Essential Eight compliance mandatory for all Australian businesses?+
Essential Eight compliance is mandatory for Australian Government entities under the Protective Security Policy Framework. For private businesses it’s not legally required, but it is increasingly expected by insurers, procurement teams, and enterprise clients. If you tender for government contracts or want to reduce cyber insurance premiums, demonstrable alignment is essential.
Do you get a certificate for Essential Eight compliance?+
No. Essential Eight doesn’t have a formal certificate issued by the ASD. Compliance is demonstrated through a detailed report outlining the controls, how your business addresses each strategy, and your current maturity level. GCIT’s accredited assessors through TAFEcyber produce this report for you.
What maturity level should my business aim for?+
Most small to medium businesses should start with Maturity Level One. This covers the fundamentals: patching, MFA, application control, and backups. If you handle sensitive government data, healthcare records, or financial information, you may need Level Two or higher. We assess your risk profile and recommend the right target.
How long does it take to achieve Essential Eight compliance?+
For businesses already using Microsoft 365 with a managed IT provider, achieving Maturity Level One typically takes 4 to 8 weeks. This includes the initial assessment, implementing any missing controls, and producing the compliance report. Existing GCIT clients are often already partially aligned through our standard security baseline.
How does Essential Eight relate to ISO 27001?+
They’re complementary. ISO 27001 is an international standard covering the entire information security management system, including policies, risk management, and governance. Essential Eight is specifically focused on eight technical mitigation strategies. GCIT is certified to ISO 27001 and uses both frameworks to give clients comprehensive coverage. Learn more about our cybersecurity approach.
Will Essential Eight compliance reduce my cyber insurance premiums?+
In most cases, yes. Insurance companies increase premiums for non-compliant businesses and reduce them for businesses that can demonstrate strong controls. Having a formal Essential Eight compliance report, combined with controls like MFA, endpoint protection, and regular patching, gives your insurer confidence and typically results in better premiums and broader coverage. We work with clients to align their cybersecurity posture to what insurers look for.

Reviewed by Elliot Munro, CISO at GCIT

Get your Essential Eight compliance assessment

Whether you need a compliance report for a tender, want to reduce your insurance premiums, or just want to know where you stand, we’ll give you a clear picture. No scare tactics, no jargon, just practical guidance from accredited assessors.
Or call us directly
1300 369 111
Contact Us · Microsoft Solutions Partner · Email Security



Ready to secure and simplify your IT? Talk to a GCIT expert today.