Skip to content

Australia / Essential Eight

Essential Eight · Evidence-first

Essential Eight assessment that produces evidence, not slide decks

ASD's assessment process ranks simulated control tests and live configuration above screenshots, and screenshots above policies. We map requirements to enforcement points, build evidence-producing controls, and engineer the uplift. AiRAT is not an IRAP assessor.

ASD opened consultation on 15 June 2026 to evolve the Essential Eight into a new Essentials series. Current guidance remains published; we version assessments and design for remapping.

Read the ML2 evidence guide →

Assessment phases

Four phases: each with a named artefact.

Scope & baseline

Week 1

Environment inventory, current maturity snapshot, Essentials transition watchpoint

  • Record Essential Eight model and assessment-guide version used
  • Map each strategy to enforcement points in your environment
  • Identify which strategies block a uniform maturity level

Evidence review

Weeks 1–2

Evidence-quality matrix per strategy (simulated test / live config / screenshot / policy)

  • Prefer simulated tests and live configuration over exported screenshots
  • Collect patch-age data, MFA logs, privileged-access lifecycle evidence
  • Identify central platforms that can generate reusable evidence (SIEM, EDR, IAM, backup)

Gap remediation

Programme

Engineering backlog with owners, timelines and retest criteria

  • Application control, hardening, logging and backup protection uplift
  • Phishing-resistant MFA and privileged-access lifecycle controls
  • Patch cadence automation with measurable SLAs

Retest & handover

Close-out

Updated evidence pack, retest results and escalation trail

  • Re-run failed or fair-evidence controls with stronger test methods
  • Document residual risks and management escalation where required
  • Hand over evidence mappings for internal audit or independent assessor review

Deliverables

What a buyer receives: week by week.

  • Requirement → enforcement point → evidence mapping spreadsheet
  • Evidence-quality rating per strategy (excellent / good / fair / poor)
  • Simulated-test plan for controls that currently rely on screenshots
  • Engineering remediation backlog with retest criteria
  • ASD Essentials transition watchpoint and remapping checklist

AiRAT is not an IRAP assessor and does not provide IRAP assessments. Essential Eight does not require universal independent certification, but your policy, regulator or contract may.

Send assessment context

Related proof

Evidence engineering in production environments.

Multi-cloud compliance uplift for a lean security team

  • Continuous posture checks across AWS, Azure and GCP
  • Evidence packs mapped to compliance frameworks
  • Automated control monitoring instead of annual screenshot cycles
Read case study →

Essential Eight ML2 evidence in 2026 →


Common questions

Is AiRAT an IRAP assessor?

No. AiRAT can perform Essential Eight gap assessments and uplift engineering, but we are not IRAP assessors and do not provide IRAP assessments.

Is the Essential Eight being replaced in 2026?

ASD is consulting on an evolution into a new Essentials series (consultation opened 15 June 2026). Current Essential Eight guidance remains published. Continue uplift while versioning the assessment and preparing to remap to final guidance.

What evidence do Essential Eight assessors prefer?

ASD's assessment process guide ranks simulated control testing and direct review of live configuration above copied configurations or screenshots, with policy statements or verbal assertions as the weakest evidence.

Can we be ML2 if only some strategies meet ML2?

ASD expects organisations to achieve the same maturity level across all eight mitigation strategies before moving to a higher level.

Do you provide a certification score?

No. We produce an evidence-quality matrix and gap backlog, not a fake certification score. Independent assessment may be required by your policy, regulator or contract.

Get started

Leave your email - we'll reach out.

Share your work email and we'll follow up with a tailored note on security, AI, or data programmes - usually within one business day.

No spam. We only use your email to respond to this request.

Explore services →