Skip to content
Nexcentric
Free tool

What's your Essential Eight maturity level?

Eight questions, three minutes, no signup. You'll get your maturity level across all eight ASD mitigation strategies and a ranked list of what to fix first.

Free · No signup · 3 minutes

Where does your business actually sit?

Eight questions — one for each Essential Eight mitigation strategy. Answer honestly rather than optimistically; nobody sees your answers unless you choose to send yourself the report.

  • Your maturity level across all eight strategies
  • A ranked list of what to fix first
  • Plain English — no jargon, no sales pitch
  • Nothing to install, no account needed
The framework

The eight strategies you're being measured against

Published by the Australian Signals Directorate. Increasingly the benchmark cyber insurers and government tenders ask about by name.

1

Patch applications

Attackers scan the internet for known, unpatched software. Most breaches exploit a vulnerability that already had a fix available.

2

Patch operating systems

An unpatched operating system undermines every other control you have. It's also the first thing a cyber insurer asks about.

3

Multi-factor authentication

Stolen passwords are bought and sold in bulk. MFA is the single highest-value control against account takeover, and the cheapest to implement.

4

Restrict administrative privileges

If everyday accounts have admin rights, one careless click gives an attacker control of the whole environment.

5

Application control

Ransomware is a program that has to run. Application control stops anything you haven't approved from executing at all.

6

Restrict Microsoft Office macros

Macros in emailed documents remain a reliable way in. Most staff never need them, and blocking them costs nothing.

7

User application hardening

Browsers and PDF readers are the most attacked software you own. Turning off features nobody uses removes whole categories of attack.

8

Regular backups

Backups are what turns a ransomware incident into an inconvenience. Modern ransomware deliberately hunts for and deletes them first.

The Essential Eight Maturity Model is published by the Australian Signals Directorate at cyber.gov.au. Nexcentric is not affiliated with or endorsed by the ASD.

Questions

About the Essential Eight

What it is, whether it applies to you, and what this tool can and can't tell you.

What is the Essential Eight?

The Essential Eight is a set of eight cyber security mitigation strategies published by the Australian Signals Directorate. They are: patch applications, patch operating systems, multi-factor authentication, restrict administrative privileges, application control, restrict Microsoft Office macros, user application hardening, and regular backups. Each is assessed against four maturity levels, from Level 0 to Level 3.

Why is my overall level the lowest score rather than an average?

Because that's how ASD intends it to be read. Their guidance is that organisations should achieve the same maturity level across all eight strategies before progressing to a higher level. The strategies are designed to complement each other, so averaging would hide the single weak point an attacker would actually exploit.

Is this a formal Essential Eight assessment?

No. This is an indicative self-assessment based on your own answers, designed to show you roughly where you stand and what to prioritise. A formal assessment involves evidence gathering and technical verification against the ASD Assessment Process Guide, and shouldn't be replaced by a questionnaire. If you need assessed evidence for a tender, an insurer or an audit, that's a different piece of work and we can scope it.

Is the Essential Eight mandatory for my business?

It's mandatory for non-corporate Commonwealth entities under the Protective Security Policy Framework. For private businesses it isn't legally required, but it has become the de facto benchmark in Australia — cyber insurers, government tenders and enterprise procurement processes increasingly ask about Essential Eight maturity specifically.

What maturity level should we be aiming for?

For most small and medium Australian businesses, Maturity Level 1 is the sensible baseline and Level 2 is a realistic target if you handle sensitive client data or are being asked about your posture. Level 3 is aimed at organisations facing determined, adaptive attackers and is rarely proportionate for an SME.

Do I have to give you my email to see my result?

No. Your full result, the strategy-by-strategy breakdown and the priority list all appear on screen immediately. We only ask for an email if you want the written report sent to you — which is useful if you need to forward it to a board, an insurer or a client.

Knowing the gaps is the easy part

Closing them without breaking how your team works is the hard part. That’s the job. Book a free 30-minute review and we’ll tell you what’s worth doing first, what it costs, and what can wait.