Free tool · No email required

Essential Eight maturity self-assessment

31 questions, about eight minutes. Scored the way the Australian Signals Directorate actually scores it, then turned into a ranked list of what to fix first.

0 / 31 answered

01Patch applications

Unpatched software is the most commonly exploited way into a small business network.

ML1

Are critical security patches for internet-facing software applied within 48 hours of release?

Covers anything reachable from the internet: your website, VPN, remote access, and online services.

ML1

Do you run an automated vulnerability scan of internet-facing services at least daily?

ML2

Are patches for office productivity software, browsers, email clients, PDF readers, and security products applied within two weeks?

ML3

Are applications that are no longer supported by the vendor removed from all systems?

End-of-life software cannot be patched, so it stays exploitable indefinitely.

02Patch operating systems

An unpatched operating system undermines every control layered above it.

ML1

Are critical operating system patches for internet-facing servers applied within 48 hours?

ML1

Are operating systems on workstations and servers patched within one month of release?

ML2

Do you scan for missing operating system patches at least fortnightly across all devices?

ML3

Have all operating systems that are no longer vendor-supported been replaced?

Includes forgotten machines: the old server in the cupboard, a spare laptop, point-of-sale terminals.

03Multi-factor authentication

MFA stops the overwhelming majority of account takeovers, including those using stolen passwords.

ML1

Is MFA enabled for every staff member on email and all internet-facing business systems?

Every staff member, not most. One exempt account is the account an attacker will find.

ML1

Is MFA required for third parties and contractors who access your systems?

ML2

Is MFA required for all privileged and administrator accounts?

ML3

Is your MFA phishing-resistant (security keys, passkeys, or certificate-based) rather than SMS codes?

SMS and one-time codes can be relayed by a convincing fake login page. Hardware keys cannot.

04Restrict admin privileges

A compromised administrator account gives an attacker your entire environment at once.

ML1

Do staff use standard (non-administrator) accounts for everyday work such as email and browsing?

ML1

Are requests for privileged access validated before being granted, rather than handed out by default?

ML2

Are privileged accounts prevented from accessing the internet, email, and web services?

ML3

Is privileged access reviewed and revoked automatically when it is no longer needed?

Including former staff and finished contractors.

05Application control

Stops unapproved executables, scripts, and installers from running at all.

ML1

Are users prevented from installing or running unapproved software on work devices?

ML2

Is application control enforced on servers as well as workstations?

ML3

Do you maintain an allow-list of approved applications, with ASD-recommended blocking rules applied?

06Restrict Office macros

Macros in emailed documents remain a reliable delivery route for ransomware.

ML1

Are Microsoft Office macros disabled for staff who do not have a demonstrated business need?

ML1

Are macros blocked in files that arrive from the internet or email?

ML2

Are macro security settings locked so users cannot change them?

ML3

Are only macros that are digitally signed by a trusted publisher permitted to run?

07User application hardening

Removes legacy browser and document features attackers rely on.

ML1

Are web browsers configured to block Java and web advertisements from the internet?

ML1

Is Internet Explorer 11 disabled or removed from all devices?

ML2

Are browser, Office, and PDF reader security settings hardened and locked against user changes?

ML3

Are PowerShell and command-line activity logged centrally and monitored?

08Regular backups

Tested, isolated backups are the difference between a bad day and paying a ransom.

ML1

Are backups of important data, software, and settings performed and retained according to a defined schedule?

ML1

Have you successfully restored from backup in a test within the last three months?

An untested backup is a hypothesis, not a backup.

ML2

Are backups stored so that staff accounts cannot modify or delete them?

Ransomware routinely encrypts backups reachable from a compromised account.

ML3

Are privileged accounts other than backup administrators prevented from modifying or deleting backups?

Unanswered questions count as not met, the same as “Not sure”.

Questions

About the Essential Eight maturity model

What the levels mean, who has to comply, and what this tool can and cannot tell you.

What is the Essential Eight maturity model?

It is the Australian Signals Directorate framework that rates how well an organisation has implemented eight mitigation strategies: patching applications, patching operating systems, multi-factor authentication, restricting administrative privileges, application control, restricting Microsoft Office macros, user application hardening, and regular backups. Each strategy is rated from Maturity Level Zero through to Maturity Level Three.

How is the overall maturity level calculated?

Your overall level is the lowest level achieved across all eight strategies, not an average. The model is also cumulative: you only reach a level once every requirement at that level and all levels below it is met. This is why one weak strategy holds the entire score down, and why closing Maturity Level One gaps is always the fastest way to improve.

What maturity level does my business actually need?

ASD recommends organisations select a target level based on the threats they realistically face. In practice most Australian small and mid-sized businesses are asked for Maturity Level One by cyber insurers and smaller tenders. Level Two is common where you hold sensitive client data or bid for government-adjacent work. Level Three is usually reserved for organisations where compromise would be severe.

Is the Essential Eight mandatory in Australia?

It is mandatory for non-corporate Commonwealth entities. For private businesses it is not legally mandated, but it has become the de facto standard: cyber insurance questionnaires, tender prequalification, and enterprise vendor assessments increasingly ask which maturity level you have reached.

Does this self-assessment prove compliance?

No. It is an indicative self-assessment designed to show you where you stand and what to prioritise. Formal assurance requires evidence: configuration exports, patch reports, backup restoration logs, and access reviews assessed by an independent party. This tool tells you where to look before you pay anyone to do that.

How long does it take to reach Maturity Level One?

For a small business with cloud email and a handful of devices, most Level One requirements are configuration changes rather than new spending, and are commonly achievable in a few weeks. The items that take longest are usually application control and getting backups genuinely isolated and tested.

Do you store my answers?

No. Everything stays in your browser for the duration of the session and is never transmitted to us. If you want a copy, use the print button to save the results as a PDF.

Indicative self-assessment based on the ASD Essential Eight Maturity Model. It is not a formal audit and does not by itself demonstrate compliance to an insurer, auditor, or tender panel. Answers stay in your browser and are never sent to us.