← Getting Started Getting Started

A client or insurer asked about your Essential Eight maturity. You need a real score β€” not a guess.

Enterprise clients, government procurement panels, and insurers are asking about Essential Eight maturity across their supply chains. The Essential Eight Scorecard gives you an independent maturity rating for each of the eight strategies at ML1 β€” built from evidence, not self-assessment. Delivered within two to three weeks of your evidence submission.

Get my Essential Eight scorecard ML1 maturity rating. Eight strategies. Fixed fee.

Four situations that lead to this assessment

"A bank's supplier questionnaire asked for our Essential Eight maturity level across all eight strategies. We left it blank."

Leaving it blank is not an answer. Your competitors didn't leave it blank.

"A government tender listed Essential Eight ML1 as a baseline requirement for suppliers. We want to bid."

You can't bid without an answer. And you can't answer without knowing your current state.

"Our insurer asked for evidence of Essential Eight maturity as a condition of coverage renewal. The policy is due in six weeks."

Six weeks is enough time if you start now. It won't be if you wait.

"A major client sent a letter: all suppliers must demonstrate Essential Eight ML1 within 90 days."

The supply chain requirement has arrived. This is how you respond to it.

Your MSP keeps your systems running. But Essential Eight maturity assessment isn't what MSPs are paid to do β€” and their estimate of your maturity is not what a client or insurer will accept. This is an independent scorecard based on evidence review.


All eight strategies at Maturity Level 1

Each strategy is assessed against the ASD's published ML1 criteria. You get a clear rating per strategy β€” not an averaged score that hides where the real gaps are.

Application Control

Only approved applications execute on workstations and servers

Patch Applications

Internet-facing services and high-risk applications patched within timeframes

Configure Office Macro Settings

Microsoft Office macros disabled or restricted to approved, signed macros

User Application Hardening

Web browser, PDF reader, and Flash/Java configured to reduce attack surface

Restrict Administrative Privileges

Admin accounts are privileged, separate, and used only for admin tasks

Patch Operating Systems

Operating systems patched within ASD-specified timeframes

Multi-Factor Authentication

MFA applied to remote access, cloud services, and privileged accounts

Regular Backups

Backups performed and tested. Critical data recoverable within defined timeframes.


A scorecard you can actually hand to the client who asked

πŸ“Š

Essential Eight Scorecard

A maturity rating for each of the eight strategies: below ML1 / ML1 partial / ML1 achieved. Rated against the ASD's published criteria β€” not an internal estimate.

πŸ“‹

Evidence review summary

What was reviewed for each strategy and what was absent or inadequate. You see the basis of every rating β€” so you understand what you need to improve, not just what score you got.

⚑

Priority action list

The highest-impact controls to address first, with a rationale for the sequencing. So you close the right gaps in the right order β€” especially if you're working to a client or insurer deadline.

πŸ“„

One-page summary

A plain-language summary of your scorecard, designed to be presented to the client, procurement panel, or insurer who made the original request.

πŸ“ž

45-minute debrief call

Walk through the scorecard in detail. Understand what each gap means and what the implementation path looks like β€” so you can give whoever asked a real timeline.


Evidence-based review β€” no system access required

Book and pay β€” no call required

Use the pricing configurator below to get your fixed price and book directly.

30-minute kickoff call

We confirm scope and walk through what evidence is needed for each strategy β€” so the questionnaire doesn't land as a surprise. If your MSP manages the technical controls, they will need to be involved in evidence gathering.

Structured evidence submission

Within 24 hours of kickoff, we send a questionnaire β€” one section per strategy β€” specifying exactly what evidence is needed. Policy document, configuration screenshot, process description, or vendor statement. You submit at your own pace.

Scorecard and debrief delivered

CyberCraft reviews your evidence against ASD ML1 criteria and delivers the full scorecard within seven to ten business days of evidence received. Debrief call included.


Fixed fee, tiered by organisation size and environment

Essential Eight Scorecard β€” Pricing Configurator

Three questions. Fixed price and delivery estimate displayed immediately.

$1,890 β€” 10 business days from evidence
↳ Pricing configurator coming soon. Contact us to get your fixed price now.

The scorecard is the starting point for implementation

Strategic

Essential Eight Implementation

Scorecard gaps map directly into a structured implementation programme. No rework, no duplication of evidence. Your priority action list becomes the implementation plan.

Essential Eight Implementation β†’
Getting Started

SMB1001 Readiness

SMB1001 and Essential Eight overlap significantly. If you're doing both, run them together β€” the evidence gathering is largely the same.

SMB1001 Readiness β†’
Getting Started

Security Health Check

The scorecard covers documentation and process. The Health Check shows what's actually visible from the outside. Together, they give you the full picture.

Security Health Check β†’

The client is waiting. Here is the scorecard that lets you answer them β€” and not just this time.

Get my Essential Eight scorecard

ML1 rating across all eight strategies. Evidence-based. No system access. Fixed fee.

Kaurna Acknowledgement

We acknowledge and pay our respects to the Kaurna people, the traditional custodians of the ancestral lands on which we work. We acknowledge the deep feelings of attachment and relationship of the Kaurna people to country and we respect and value their past, present and ongoing connection to the land and cultural beliefs.