Essential Eight Assessment for Australian SMEs — What to Do Before the Framework Changes
· By Paul Harvey
An Essential Eight assessment for Australian SMEs is a structured review of your current cyber security posture against the ASD's Essential Eight Maturity Model — identifying your current maturity level, gaps against Maturity Level 1 or 2, and a prioritised remediation plan. With the Essential Eight being retired and replaced by Essentials for Enterprise IT, Australian SMEs need to complete an assessment now to understand their baseline before the transition.
What is the Essential Eight and why is it being retired?
The ASD Essential Eight is Australia's most widely adopted cyber security framework for small and medium businesses — eight controls covering application control, patching applications, Microsoft Office macro settings, user application hardening, restricting administrative privileges, patching operating systems, multi-factor authentication, and daily backups.
The framework is being retired in favour of Essentials for Enterprise IT — a more comprehensive framework that incorporates cloud security controls, Microsoft 365 and Azure-specific requirements, and AI security governance (aligned with the new Australian AI standards). The transition timeline has not been finalised but is expected in late 2026 or early 2027.
The implication for SMEs: organisations that have invested in Essential Eight Maturity Level 1 or 2 compliance will need to re-assess against the new framework. Starting the Essential Eight assessment now gives organisations a documented baseline to transition from — rather than starting from zero under the new framework.
What does an Essential Eight assessment for SMEs cover?
An Essential Eight assessment covers the eight controls in an SME-specific context:
- Application control — blocking unauthorised applications from executing (AppLocker or Windows Defender Application Control).
- Patch applications — third-party applications patched within 48 hours for critical vulnerabilities.
- Configure Microsoft Office macro settings — blocking macros from the internet unless specifically approved.
- User application hardening — blocking web browser plugins, Java, and Flash from processing internet content.
- Restrict administrative privileges — users without local admin rights, service accounts restricted, privileged access reviewed.
- Patch operating systems — Windows and macOS patched within 48 hours for critical vulnerabilities, managed via Intune.
- Multi-factor authentication — MFA enforced for all users across Microsoft 365, VPN, and remote access via Entra ID.
- Regular backups — daily backups of important data with tested restore capability, typically via Azure Backup.
Not sure what Essential Eight maturity level your business is at? Book an Essential Eight assessment → and we'll give you a clear picture of your current posture in under 2 weeks.
What maturity level should an Australian SME be targeting?
The ASD recommends all Australian businesses achieve Maturity Level 1 as a minimum — this covers the most common attack vectors used against SMBs. Maturity Level 2 is appropriate for businesses handling sensitive client data (legal, accounting, medical) or working with government or defence clients. Maturity Level 3 is typically only required for critical infrastructure or Defence Industry Security Program (DISP) members.
For most Australian SMBs, Maturity Level 1 achieved and documented is the realistic and valuable target — it satisfies the minimum requirements for most cyber insurance policies, government supplier requirements, and client due diligence questionnaires.
According to the ASD Annual Cyber Threat Report 2023–24, only 29% of Australian SMBs have achieved Maturity Level 1 compliance — meaning most SMBs still have gaps against the baseline the ASD considers minimum.
How does an Essential Eight assessment work for a 20–100 user Australian SMB?
A Mycelium 365 Essential Eight assessment for an Australian SMB typically takes 5–10 business days:
- 2–3 days — technical review (Microsoft 365 configuration, Intune policies, patching status, backup configuration, MFA coverage).
- 1–2 days — administrative review (policies, procedures, access management documentation).
- 2–3 days — written report.
The report includes a current maturity level rating for each of the eight controls, a gap analysis against Maturity Level 1, a prioritised remediation backlog with effort and cost estimates, and a 90-day action plan.
For businesses already on Microsoft 365 Business Premium with Mycelium 365 managed services, most Maturity Level 1 controls are already partially or fully satisfied — the assessment documents the existing controls and identifies the remaining gaps rather than starting from scratch.
How Mycelium 365 delivers Essential Eight assessments for Australian SMEs
Mycelium 365 delivers Essential Eight assessments across professional services, legal, accounting, construction, mining, and defence-adjacent SMEs in all six major Australian cities. Our assessment methodology is aligned to the ASD's maturity model and mapped to Microsoft 365 and Azure controls, so the report reflects your actual environment rather than a generic checklist.
The assessment connects directly to our governance and compliance readiness advisory and ongoing managed SOC — remediation is delivered by the same team that assessed the environment. See also our AI readiness assessment for the AI governance side under the new Essentials framework.
Frequently asked questions
What is the Essential Eight and does my business need to comply?
The Essential Eight is the Australian Signals Directorate's baseline cyber security framework — eight controls covering application control, patching, macro settings, application hardening, restricted admin privileges, OS patching, multi-factor authentication, and daily backups. Compliance is mandatory for federal government entities and increasingly required by cyber insurance policies, government suppliers, and client due diligence questionnaires. Most Australian SMEs need at least Maturity Level 1.
What Essential Eight maturity level should an Australian SMB target?
Maturity Level 1 is the realistic and valuable target for most Australian SMBs from 20 to 300 users — it satisfies the minimum requirements for most cyber insurance policies, government supplier requirements, and client due diligence. Maturity Level 2 is appropriate for legal, accounting, medical, or government-adjacent businesses handling sensitive data. Maturity Level 3 is typically only required for critical infrastructure or DISP members.
How long does an Essential Eight assessment take for a small business?
An Essential Eight assessment for a 20–100 user Australian SMB typically takes 5–10 business days — 2–3 days for technical review of Microsoft 365, Intune, patching, backups, and MFA; 1–2 days for administrative review of policies and access management; and 2–3 days for the written report with maturity ratings, gap analysis, and a 90-day remediation plan.
Is the Essential Eight being replaced in Australia?
Yes — the ASD Essential Eight is being retired and replaced by Essentials for Enterprise IT, a broader framework covering cloud security, Microsoft 365 and Azure-specific controls, and AI security governance. The transition is expected in late 2026 or early 2027. SMEs should complete an Essential Eight assessment now to establish a documented baseline before the new framework takes effect.
