Framework · Essential Eight · Assessment
There is no Essential Eight certificate. An assessment tests whether each control is in place and working, run by your own people or an independent assessor against ASD's October 2024 process guide. This page walks the four stages, the evidence ladder, the seven outcomes, and the exception rules that decide whether a level is met.
Four stages
ASD's process guide describes four stages that apply whether the assessor is internal or independent. The stage names below are ASD's; the detail is what each one asks of the system owner.
01
Plan and prepare
“The assessor plans and prepares for the assessment.”
The assessor and the system owner agree what the assessment will need: privileged and unprivileged accounts, devices, documentation, people and facilities; approval to run scripts and tools; how evidence will be collected and protected; where the report will be written; prior reports; and which service providers manage parts of the system. A test plan may be shared at this point.
02
Define scope and approach
“The assessor determines the scope and approach for the assessment.”
The target level is confirmed first, and the ladder is enforced: a system that has not demonstrated ML1 is not assessed against ML2. The boundary is written down along with anything excluded and why. The approach mixes interviews and document review with configuration review, scripts and tools, and agrees a sample of workstations, servers and network devices.
03
Assess the controls
“The assessor assesses the controls associated with each of the mitigation strategies.”
Each strategy is tested requirement by requirement at the target level. The guidance is cumulative, so an ML2 assessment concentrates on what ML2 adds to ML1. Findings are recorded against ASD's standard outcomes, and any compensating control for an exception is judged on whether it delivers the same protection as the control it replaces.
04
Write the report
“The assessor develops the security assessment report.”
ASD's assessment report template (November 2023) is the default. An assessor may use their own template for branding if every section from ASD's is present. The report documents scope, limitations, sample sizes, the outcome for every control, and whether the target level was met.
Stage wording from ASD's Essential Eight assessment process guide (October 2024).
Evidence quality
ASD grades evidence on four levels and asks assessors to gather the highest they reasonably can. A screenshot proves a setting existed on one machine at one moment. A script run across the fleet proves the control is enforced.
“Conducting assessments using interviews, reports and screenshots will always be inferior to conducting assessments using scripts and tools.”
Testing a control with a simulated activity designed to confirm it is in place and working, such as trying to run an unapproved application against the application control ruleset.
Reviewing the configuration of a system through the system's own interface to see whether it should enforce the expected policy.
Reviewing a copy of a system's configuration, such as a report or a screenshot, to see whether it should enforce the expected policy.
A policy or a verbal statement of intent: a control mentioned in a document, or described in an interview with the people who administer the system.
Outcomes
ASD gives assessors seven standard outcomes. Two of them count towards the level. The other five do not, and a single one of them on a single control means the strategy, and therefore the level, cannot be claimed.
Not assessed
The control has not yet been assessed.
Effective
The organisation is effectively meeting the control's objective.
Alternate control
The objective is met through a different control that delivers the same protection.
Ineffective
The organisation is not adequately meeting the control's objective.
No visibility
The assessor could not get adequate visibility of the control's implementation.
Not implemented
The organisation has decided not to implement the control.
Not applicable
The control does not apply to the system or environment.
The package rule
ASD's guide is explicit: for a system owner to claim a strategy is implemented, every control in it must be assessed as Effective or Alternate control. If one is Ineffective, the maturity level cannot be claimed for that strategy, and a system is at the level of its weakest strategy.
Risk acceptance is not an exception
Deciding to accept the risk of skipping application control or MFA does not make the strategy Not applicable. Without a compensating control that delivers equivalent protection, the assessor records the strategy as Not implemented. The guide names this case because it is the one system owners most often try.
Exceptions
ASD's guide gives two worked examples. In the first, a low-risk Windows server cannot be patched, so the organisation assigns a risk owner, puts strong compensating controls in place and plans to decommission it within two months. The assessor lets the exception stand and the target level is still reachable.
In the second, a cloud service has MFA available but the organisation decides enabling it is not worth the effort or the user complaints, and accepts the risk instead. No compensating control, no managed exception. The assessor records the strategy as not implemented and the target level is lost.
The difference between the two is not the gap. Both systems had one. The difference is whether the gap was turned into a documented decision that someone owns and someone will revisit.
Exception record
What ASD expects on file
Field list follows the exception documentation requirements in ASD's assessment process guide, including that exceptions should not be approved beyond one year.
In Alvor
Preparing for an assessment usually means a month of collecting screenshots into a folder. The alternative is a record that has been carrying owners, evidence and dates since the controls were installed.
Status is set by an assessment, a check, or a recorded override
There is no status dropdown. A control turns green because an audit assessment said so, because an automated check against AWS, Entra ID or Okta passed, or because an admin recorded an override with a reason and an expiry. Every path is audit-logged, so a green control always traces to a named assessor and dated evidence.
ComplianceEvidence carries a valid-until date
Each artefact has an expiry. The dashboard sorts evidence into fresh, expiring, stale and missing, so the gap between what you believe and what an assessor will find shows up months before the assessment does.
ComplianceExceptions live in the risk register
An exception is a risk with an owner, a compensating control, a residual rating and an expiry, which is the nine-field record ASD asks for. The assessor reads a decision rather than a missing control.
Risk ManagementThe audit log cannot be edited after the fact
Every audit entry is fingerprinted and each fingerprint includes the one before it. Editing, deleting or reordering an entry breaks the chain and shows up under Verify. An assessor can check for themselves that the record was not tidied up the week before.
Security ManagementQuestions
The maturity model itself does not require one; ASD's process guide covers self-assessment and independent assessment alike. Your obligations may. The PSPF reporting cycle, a contract with a prime, or an insurer can each ask for an independent read. Many IRAP assessors also run Essential Eight assessments, but IRAP itself assesses against the ISM.
Get started
Whether you lead security, run IT, manage compliance, or sit in the C-suite - we'll show you your view.