Free tool · No email required
Essential Eight maturity self-assessment
31 questions, about eight minutes. Scored the way the Australian Signals Directorate actually scores it, then turned into a ranked list of what to fix first.
0 / 31 answered
Unanswered questions count as not met, the same as “Not sure”.
Questions
About the Essential Eight maturity model
What the levels mean, who has to comply, and what this tool can and cannot tell you.
What is the Essential Eight maturity model?
It is the Australian Signals Directorate framework that rates how well an organisation has implemented eight mitigation strategies: patching applications, patching operating systems, multi-factor authentication, restricting administrative privileges, application control, restricting Microsoft Office macros, user application hardening, and regular backups. Each strategy is rated from Maturity Level Zero through to Maturity Level Three.
How is the overall maturity level calculated?
Your overall level is the lowest level achieved across all eight strategies, not an average. The model is also cumulative: you only reach a level once every requirement at that level and all levels below it is met. This is why one weak strategy holds the entire score down, and why closing Maturity Level One gaps is always the fastest way to improve.
What maturity level does my business actually need?
ASD recommends organisations select a target level based on the threats they realistically face. In practice most Australian small and mid-sized businesses are asked for Maturity Level One by cyber insurers and smaller tenders. Level Two is common where you hold sensitive client data or bid for government-adjacent work. Level Three is usually reserved for organisations where compromise would be severe.
Is the Essential Eight mandatory in Australia?
It is mandatory for non-corporate Commonwealth entities. For private businesses it is not legally mandated, but it has become the de facto standard: cyber insurance questionnaires, tender prequalification, and enterprise vendor assessments increasingly ask which maturity level you have reached.
Does this self-assessment prove compliance?
No. It is an indicative self-assessment designed to show you where you stand and what to prioritise. Formal assurance requires evidence: configuration exports, patch reports, backup restoration logs, and access reviews assessed by an independent party. This tool tells you where to look before you pay anyone to do that.
How long does it take to reach Maturity Level One?
For a small business with cloud email and a handful of devices, most Level One requirements are configuration changes rather than new spending, and are commonly achievable in a few weeks. The items that take longest are usually application control and getting backups genuinely isolated and tested.
Do you store my answers?
No. Everything stays in your browser for the duration of the session and is never transmitted to us. If you want a copy, use the print button to save the results as a PDF.
Indicative self-assessment based on the ASD Essential Eight Maturity Model. It is not a formal audit and does not by itself demonstrate compliance to an insurer, auditor, or tender panel. Answers stay in your browser and are never sent to us.