Australia / Essential Eight
Essential Eight · Evidence-first
Essential Eight assessment that produces evidence, not slide decks
ASD's assessment process ranks simulated control tests and live configuration above screenshots, and screenshots above policies. We map requirements to enforcement points, build evidence-producing controls, and engineer the uplift. AiRAT is not an IRAP assessor.
ASD opened consultation on 15 June 2026 to evolve the Essential Eight into a new Essentials series. Current guidance remains published; we version assessments and design for remapping.
Assessment phases
Four phases: each with a named artefact.
Scope & baseline
Week 1
Environment inventory, current maturity snapshot, Essentials transition watchpoint
- Record Essential Eight model and assessment-guide version used
- Map each strategy to enforcement points in your environment
- Identify which strategies block a uniform maturity level
Evidence review
Weeks 1–2
Evidence-quality matrix per strategy (simulated test / live config / screenshot / policy)
- Prefer simulated tests and live configuration over exported screenshots
- Collect patch-age data, MFA logs, privileged-access lifecycle evidence
- Identify central platforms that can generate reusable evidence (SIEM, EDR, IAM, backup)
Gap remediation
Programme
Engineering backlog with owners, timelines and retest criteria
- Application control, hardening, logging and backup protection uplift
- Phishing-resistant MFA and privileged-access lifecycle controls
- Patch cadence automation with measurable SLAs
Retest & handover
Close-out
Updated evidence pack, retest results and escalation trail
- Re-run failed or fair-evidence controls with stronger test methods
- Document residual risks and management escalation where required
- Hand over evidence mappings for internal audit or independent assessor review
Deliverables
What a buyer receives: week by week.
- Requirement → enforcement point → evidence mapping spreadsheet
- Evidence-quality rating per strategy (excellent / good / fair / poor)
- Simulated-test plan for controls that currently rely on screenshots
- Engineering remediation backlog with retest criteria
- ASD Essentials transition watchpoint and remapping checklist
AiRAT is not an IRAP assessor and does not provide IRAP assessments. Essential Eight does not require universal independent certification, but your policy, regulator or contract may.
Related proof
Evidence engineering in production environments.
Multi-cloud compliance uplift for a lean security team
- Continuous posture checks across AWS, Azure and GCP
- Evidence packs mapped to compliance frameworks
- Automated control monitoring instead of annual screenshot cycles
Read case study →Essential Eight ML2 evidence in 2026 →
Common questions
Is AiRAT an IRAP assessor?
No. AiRAT can perform Essential Eight gap assessments and uplift engineering, but we are not IRAP assessors and do not provide IRAP assessments.
Is the Essential Eight being replaced in 2026?
ASD is consulting on an evolution into a new Essentials series (consultation opened 15 June 2026). Current Essential Eight guidance remains published. Continue uplift while versioning the assessment and preparing to remap to final guidance.
What evidence do Essential Eight assessors prefer?
ASD's assessment process guide ranks simulated control testing and direct review of live configuration above copied configurations or screenshots, with policy statements or verbal assertions as the weakest evidence.
Can we be ML2 if only some strategies meet ML2?
ASD expects organisations to achieve the same maturity level across all eight mitigation strategies before moving to a higher level.
Do you provide a certification score?
No. We produce an evidence-quality matrix and gap backlog, not a fake certification score. Independent assessment may be required by your policy, regulator or contract.