How do you actually get Essential Eight compliant, step by step?
Getting Essential Eight compliant runs in five steps: measure where you stand, pick a target maturity level that matches your risk, fix the identity and backup controls first, work through the remaining controls with evidence as you go, then keep it maintained, because maturity decays. Most small businesses should be targeting Maturity Level 1.
Before step one, a reframe that changes the whole plan: there is no Essential Eight certificate. No body certifies businesses against it, so compliant can only mean one thing, able to demonstrate a maturity level with evidence when someone asks, and the someones are multiplying: insurers, tender panels, larger customers, Defence. That means the goal of the exercise is not a plaque; it is a folder of proof and the controls behind it.
Step one: measure. You cannot plan a climb from an imagined base camp, and most businesses imagine theirs generously. A proper baseline assessment, ours is free and written, scores each of the eight controls from zero to three against evidence. Expect zeros; almost every first assessment contains them, they are the model working as designed, and the only wrong response is to negotiate with the score rather than the gap.
Step two: pick the target and write it down. Maturity Level 1 is the deliberate default, designed to defeat the commodity attacks that make up most real-world incidents. Level 2 belongs to businesses with contractual obligations, defence connections or elevated risk; Level 3 to those facing adversaries with advanced tradecraft, which is rarer than vendors imply. A one-line decision, we are targeting Level 1 by June, signed by an owner, does more for the project than any tool purchase, because every later argument about scope gets settled by pointing at it.
Step three: take the two wins that pay immediately. Multi-factor authentication on every account, admin accounts first, because stolen passwords are the front door of small-business compromise. Backups configured, protected from the network they back up, and, non-negotiably, test-restored, because an unproven backup is a hope with a schedule. Add the quick admin-rights pass, removing the administrator access that has accreted on ordinary accounts over the years. These three produce most of the early risk reduction and, usefully, most of the early evidence.
Step four is the grind, and honesty about it prevents abandoned projects. Application control, tools such as ThreatLocker deciding what may run, is powerful and disruptive if flipped on overnight, so it is deployed in learning mode first, piloted on a friendly group, with an exceptions process agreed before anyone's job is interrupted. Patching applications and operating systems becomes a cadence with a number attached, not a when-we-get-to-it. Office macro settings and user application hardening are the quiet controls: mostly configuration, mostly invisible to staff, endlessly forgotten. Work one control at a time to your target level, and capture evidence as you go, screenshots, exports, restore logs, an exceptions register, because reconstructing evidence months later is the most demoralising task in security.
A word on effort, without invented precision: for a typical small business starting near zero, the climb to a demonstrated Level 1 is measured in weeks to months, not days, and the variable is estate cleanliness, how documented, consistent and cloud-based your systems already are. It can be run as an internal project, or bought as a service; our plans deliver exactly this by tier, with full Maturity Level 1 at $139 per user per month. The sequence holds either way, and it is the sequence that carried a 24/7 freight operator to one hundred per cent Maturity Level 1 across five sites, with DISP accreditation standing on top of it afterwards.
Step five: maintain, because maturity is a garden, not a monument. Every new starter is an MFA enrolment and an access decision; every new laptop is an application-control and patching endpoint; every month without a tested restore quietly ages your strongest evidence. A monthly rhythm, patch compliance checked, restore tested, exceptions reviewed, new accounts audited, holds the level you paid to reach, and an annual reassessment proves it still exists.
Two closing caveats, so this plan stays honest. The Essential Eight is the baseline, not the ceiling: email security, staff awareness and your Privacy Act obligations live outside it and still matter. And Level 1 defeats commodity attacks, not determined, resourced adversaries, which is precisely why the levels above it exist. Start with the free baseline, the Cyber Security Scorecard, or call 1800 456 567 and we will walk the five steps against your actual systems.
Buy the climb as a service
Our plans deliver the uplift by tier: full Maturity Level 1 at $139 per user per month, Levels 2 and 3 above.
Other questions we are asked about this, answered the same way.
- 5 min
How much does an Essential Eight assessment cost?
The $2,000 figures widely quoted are assessor course fees, not business assessments. Here is what businesses actually pay, and when free is real.
Read the article - 5 min
The 3 levels of cyber protection, explained
Not every business needs the same security. We break down the Australian Government's Essential Eight Maturity Levels 1–3 in plain English — what each level actually means, who needs which, and how our Fortress, Knox and Titan plans map to them.
Read the article - 2 min
What should a venue do after a malware incident?
Contain, recover, then rebuild to a standard rather than back to what you had. Restoring the same setup restores the same exposure.
Read the article
Frequently asked questions
Questions? Let's talk.
Call 1800 456 567 or fill out the form.
- 30-minute discovery — no jargon, no pressure
- Plain-English Essential Eight Cyber Security Scorecard
- A clear plan tailored to your business