ALVOR
Platform
Advisory
PricingBlog
Get Demo
ALVOR
Platform
Advisory
PricingBlog
Get Demo

Framework · Essential Eight · Assessment

How an Essential Eight assessment works.

There is no Essential Eight certificate. An assessment tests whether each control is in place and working, run by your own people or an independent assessor against ASD's October 2024 process guide. This page walks the four stages, the evidence ladder, the seven outcomes, and the exception rules that decide whether a level is met.

The four stagesThe maturity model

Four stages

Plan, scope, test, report.

ASD's process guide describes four stages that apply whether the assessor is internal or independent. The stage names below are ASD's; the detail is what each one asks of the system owner.

01

Plan and prepare

“The assessor plans and prepares for the assessment.”

The assessor and the system owner agree what the assessment will need: privileged and unprivileged accounts, devices, documentation, people and facilities; approval to run scripts and tools; how evidence will be collected and protected; where the report will be written; prior reports; and which service providers manage parts of the system. A test plan may be shared at this point.

02

Define scope and approach

“The assessor determines the scope and approach for the assessment.”

The target level is confirmed first, and the ladder is enforced: a system that has not demonstrated ML1 is not assessed against ML2. The boundary is written down along with anything excluded and why. The approach mixes interviews and document review with configuration review, scripts and tools, and agrees a sample of workstations, servers and network devices.

03

Assess the controls

“The assessor assesses the controls associated with each of the mitigation strategies.”

Each strategy is tested requirement by requirement at the target level. The guidance is cumulative, so an ML2 assessment concentrates on what ML2 adds to ML1. Findings are recorded against ASD's standard outcomes, and any compensating control for an exception is judged on whether it delivers the same protection as the control it replaces.

04

Write the report

“The assessor develops the security assessment report.”

ASD's assessment report template (November 2023) is the default. An assessor may use their own template for branding if every section from ASD's is present. The report documents scope, limitations, sample sizes, the outcome for every control, and whether the target level was met.

Stage wording from ASD's Essential Eight assessment process guide (October 2024).

Evidence quality

Screenshots lose to scripts.

ASD grades evidence on four levels and asks assessors to gather the highest they reasonably can. A screenshot proves a setting existed on one machine at one moment. A script run across the fleet proves the control is enforced.

“Conducting assessments using interviews, reports and screenshots will always be inferior to conducting assessments using scripts and tools.”

ASD, Essential Eight assessment process guide
Excellent

Testing a control with a simulated activity designed to confirm it is in place and working, such as trying to run an unapproved application against the application control ruleset.

Good

Reviewing the configuration of a system through the system's own interface to see whether it should enforce the expected policy.

Fair

Reviewing a copy of a system's configuration, such as a report or a screenshot, to see whether it should enforce the expected policy.

Poor

A policy or a verbal statement of intent: a control mentioned in a document, or described in an interview with the people who administer the system.

Outcomes

A strategy is met only when every control is effective.

ASD gives assessors seven standard outcomes. Two of them count towards the level. The other five do not, and a single one of them on a single control means the strategy, and therefore the level, cannot be claimed.

Not assessed

The control has not yet been assessed.

Effective

The organisation is effectively meeting the control's objective.

Alternate control

The objective is met through a different control that delivers the same protection.

Ineffective

The organisation is not adequately meeting the control's objective.

No visibility

The assessor could not get adequate visibility of the control's implementation.

Not implemented

The organisation has decided not to implement the control.

Not applicable

The control does not apply to the system or environment.

The package rule

ASD's guide is explicit: for a system owner to claim a strategy is implemented, every control in it must be assessed as Effective or Alternate control. If one is Ineffective, the maturity level cannot be claimed for that strategy, and a system is at the level of its weakest strategy.

Risk acceptance is not an exception

Deciding to accept the risk of skipping application control or MFA does not make the strategy Not applicable. Without a compensating control that delivers equivalent protection, the assessor records the strategy as Not implemented. The guide names this case because it is the one system owners most often try.

Exceptions

An exception is a decision with a compensating control, an owner and an expiry.

ASD's guide gives two worked examples. In the first, a low-risk Windows server cannot be patched, so the organisation assigns a risk owner, puts strong compensating controls in place and plans to decommission it within two months. The assessor lets the exception stand and the target level is still reachable.

In the second, a cloud service has MFA available but the organisation decides enabling it is not worth the effort or the user complaints, and accepts the risk instead. No compensating control, no managed exception. The assessor records the strategy as not implemented and the target level is lost.

The difference between the two is not the gap. Both systems had one. The difference is whether the gap was turned into a documented decision that someone owns and someone will revisit.

Exception record

What ASD expects on file

9 fields
  1. 01Detail, scope and justification for the exception
  2. 02Detail, scope and justification for each compensating control
  3. 03Expected lifetime of the compensating controls
  4. 04When the compensating controls will next be reviewed
  5. 05System risk rating before and after the compensating controls
  6. 06Any caveats placed on the use of the system
  7. 07Acceptance by an appropriate authority of the residual risk
  8. 08When the exception will next be considered, and by whom
  9. 09Approval valid for no more than one year

Field list follows the exception documentation requirements in ASD's assessment process guide, including that exceptions should not be approved beyond one year.

In Alvor

The evidence the assessor asks for is already in the record.

Preparing for an assessment usually means a month of collecting screenshots into a folder. The alternative is a record that has been carrying owners, evidence and dates since the controls were installed.

Status is set by an assessment, a check, or a recorded override

There is no status dropdown. A control turns green because an audit assessment said so, because an automated check against AWS, Entra ID or Okta passed, or because an admin recorded an override with a reason and an expiry. Every path is audit-logged, so a green control always traces to a named assessor and dated evidence.

Compliance

Evidence carries a valid-until date

Each artefact has an expiry. The dashboard sorts evidence into fresh, expiring, stale and missing, so the gap between what you believe and what an assessor will find shows up months before the assessment does.

Compliance

Exceptions live in the risk register

An exception is a risk with an owner, a compensating control, a residual rating and an expiry, which is the nine-field record ASD asks for. The assessor reads a decision rather than a missing control.

Risk Management

The audit log cannot be edited after the fact

Every audit entry is fingerprinted and each fingerprint includes the one before it. Editing, deleting or reordering an entry breaks the chain and shows up under Verify. An assessor can check for themselves that the record was not tidied up the week before.

Security Management
Essential Eight uplift with Alvor AdvisoryAssessed against the ISM instead? IRAP explainedThe ISMWhat replaces the Essential Eight

Questions

Common questions about Essential Eight assessments

The maturity model itself does not require one; ASD's process guide covers self-assessment and independent assessment alike. Your obligations may. The PSPF reporting cycle, a contract with a prime, or an insurer can each ask for an independent read. Many IRAP assessors also run Essential Eight assessments, but IRAP itself assesses against the ISM.

Get started

See how Alvor works for your role

Whether you lead security, run IT, manage compliance, or sit in the C-suite - we'll show you your view.

Request DemoView Pricing
ALVOR

Security architecture management and compliance: connected into one source of truth.

Security,
Simplified.

Platform

  • Overview
  • AI Assistant
  • Secure by Design
  • Asset Management
  • Risk Management
  • Compliance
  • Policy
  • Security Management
  • Third-Party Risk Management
  • Business Continuity

Capabilities

  • Security Architecture
  • Security Design Review
  • Threat Modeling
  • Dependency Mapping
  • Data Governance
  • Components & SBOM
  • System Security Plan
  • Deployment models

Solutions

  • All solutions
  • CISO
  • Security architect
  • GRC lead
  • Engineering leader
  • Startups
  • Mid-Market
  • Enterprise
  • Regulated & Sovereign
  • Australia

Frameworks

  • ISO 27001
  • SOC 2
  • NIST CSF
  • HIPAA
  • GDPR
  • ISM
  • IRAP
  • Essential Eight
  • ASD Essentials
  • SABSA
  • PCI DSS
  • CMMC
  • FedRAMP
  • Control alignment

Advisory

  • Advisory overview
  • Assess
  • Architect
  • Build
  • Operate
  • All engagements

Company

  • About
  • Blog
  • Security
  • Pricing
  • Compare Alvor

© 2026 Alvor Pty Ltd · ABN 40 700 022 546 · All rights reserved.

PrivacyTermsCookie PolicyDisclosure