Security / Essential Eight assessment and uplift

Essential Eight assessment and uplift to Maturity Level Two.

A government contract, an insurer or a supply chain questionnaire wants a maturity level. The assessment gives a control-by-control answer.

Sorami assesses all eight strategies against the ASD Essential Eight Maturity Model and reports a maturity level per strategy, with the evidence behind each score. Your overall level is the lowest strategy you fully meet, not an average, so one weak control sets the answer. ASD does not accredit assessors.

Score yourself first

Where you sit against Maturity Level Two

Sixteen questions, two per mitigation strategy. Answer no if you cannot show the evidence today.

Patching

Do you patch critical internet-facing vulnerabilities within 48 hours of release?

Is every application other than browsers and office software scanned fortnightly and patched within a month?

Authentication and privilege

Is your multi-factor authentication phishing-resistant for staff logging into internal systems?

Are privileged accounts disabled after 45 days of inactivity and revalidated at least yearly?

Administration paths

Are administrative tasks performed through jump servers rather than from daily-use laptops?

Are break glass, local administrator and service account credentials long, unique and centrally managed?

Application control

Is application control enforced on internet-facing servers as well as workstations?

Is the Microsoft recommended application blocklist deployed and its ruleset reviewed each year?

Macros and application hardening

Are Office macros blocked from making Win32 API calls?

Are browsers, office suites and PDF software hardened to ASD and vendor guidance, with settings locked?

Logging and response

Are PowerShell and command line process creation events centrally logged and protected from deletion?

Are logs from internet-facing servers analysed promptly, with incidents reported and the response plan enacted?

Backups

Are privileged accounts other than backup administrators blocked from modifying or deleting backups?

Has a restore to a common point in time been tested in a disaster recovery exercise this year?

Coverage

Does your patching evidence cover developer laptops and not only servers?

Do the eight strategies cover your cloud workloads and not only the Microsoft 365 estate?

16 questions. Answer them all and your score appears here.

Nothing is sent anywhere. The scoring runs in your browser.

Self-assessment. Not an audit or an assessment against the ASD model.

If the result is useful, send us the answers and we will scope the assessment against them.

Want to send this to a colleague? It has its own page: the Essential Eight Maturity Level 2 self-check, with the scoring bands explained.

The levels

Which level you will be asked for.

  • Maturity Level One covers widely available, opportunistic attacks.
  • Maturity Level Two is the level insurers and procurement teams usually name.
  • Maturity Level Three is asked for by government and Defence supply chains.

The model is scored per strategy. Your level is the lowest strategy you fully meet, not an average of the eight, so one weak control sets the answer for the whole assessment.

The eight strategies

What Maturity Levels One, Two and Three require.

What each maturity level adds, per mitigation strategy. Read from Appendices A to C of the November 2023 model.
Mitigation strategyMaturity Level OneMaturity Level Two addsMaturity Level Three adds
Patch applicationsOnline services scanned daily. Office software and browsers weekly. Critical online-service patches within 48 hours, everything else within two weeks.Adds a fortnightly scan of every other application. Those patch within one month.Critical office-suite and browser patches also move to 48 hours. Every unsupported application is removed.
Patch operating systemsInternet-facing systems scanned daily and workstations fortnightly. Critical internet-facing patches within 48 hours. Workstations within one month.No new requirements. This strategy is identical at Maturity Level One and Two, which catches most teams out.Adds fortnightly driver and firmware scanning. Critical workstation patches drop to 48 hours. Only the latest or previous release runs.
Multi-factor authenticationMFA on your own and third-party online services holding sensitive data. Also for customers of services holding sensitive customer data.Extends MFA to privileged and unprivileged users of internal systems. It must be phishing-resistant. MFA events are centrally logged and analysed.Adds MFA on access to data repositories. Phishing resistance extends across the remaining authentication paths.
Restrict administrative privilegesPrivileged requests validated when first raised. Dedicated privileged accounts blocked from internet and email. Separate privileged and unprivileged environments.Adds revalidation every 12 months and disablement after 45 days idle. Administration through jump servers. Managed break glass and service account credentials. Privileged events centrally logged.Adds just-in-time administration and platform-enforced credential protection against theft.
Application controlEnforced on workstations, across user profiles and temporary folders. Restricts executables, libraries and scripts to an approved set.Adds internet-facing servers and every remaining file location. Microsoft recommended blocklist deployed. Rulesets validated yearly. Allowed and blocked events logged.Adds every server and control over vulnerable drivers using the Microsoft driver blocklist.
Restrict Microsoft Office macrosMacros disabled unless there is a demonstrated business need. Internet-sourced macros blocked. Antivirus scanning on. Settings locked against users.Adds blocking macros from making Win32 API calls. That is the control that stops most macro payloads doing anything useful.Adds running macros only from trusted locations or with a trusted signature. Macro execution is logged.
User application hardeningInternet Explorer 11 removed. Browsers do not process Java or web advertisements from the internet. Browser settings locked against users.Adds ASD and vendor hardening for browsers, office suites and PDF software. Office blocked from child processes and code injection. PowerShell and command line logging required.Adds removing .NET Framework 3.5 and PowerShell constrained language mode.
Regular backupsBackups retained to business criticality and synchronised to a common point in time. Restoration tested in disaster recovery exercises.Adds blocking privileged accounts other than backup administrators from reaching, changing or deleting other accounts backups.Adds blocking every account other than backup administrators from reading any backup at all.
Included

What the assessment covers

  • Control-by-control assessment, per strategy and per level.
  • Evidence review, not a questionnaire you fill in yourself.
  • A maturity report written for the requester to read.
  • Uplift plan prioritised by the level you were asked for.
  • Coverage of AWS and Azure workloads, not only endpoints.
Excluded

What we do not do

  • No endorsement. ASD does not accredit assessors or providers.
  • Endpoint management and security product licences.
  • Round-the-clock monitoring of the controls we assess.
  • Deciding for the requester whether your level is enough.
Cloud gaps

Where cloud-first teams usually miss it.

  • Patching measured on servers, never on developer laptops.
  • Application control on workstations but not internet-facing servers.
  • MFA on the console, with long-lived CLI keys untouched.
  • Backups held in the same account as the workload.
  • A break glass account shared, with credentials in a wiki.
  • Macros blocked by policy that users can still change.

Two of the eight strategies are endpoint controls that no cloud setting can satisfy, so a well-configured account is not an ML2 organisation. The Essential Eight ML2 guide for AWS and Azure maps every strategy onto cloud services and names the two that do not map. If the gap is in the cloud estate itself, a cloud security review finds it faster than an assessment does.

The Essential Eight does not reach AI agents at all. The eight agent controls added in the September 2026 ISM carry no Essential Eight mapping, so reaching ML3 does not address any of them.

Want a number before you read further? The two minute ML2 self-check at the top of this page scores all sixteen questions in your browser.

A different question

This is not a penetration test.

An Essential Eight assessment measures coverage. It asks whether each of the eight controls is implemented at the level you were asked for, and whether you can evidence it.

A penetration test measures exploitability. It asks whether a specific application or network can be broken, and reports the paths that worked. You can pass an assessment and still fail a test, because the two answer different questions.

If the requester wants an attacker to try, you need penetration testing instead.

Questions before you book

Practical answers.

Which version of the model do you assess against?

The ASD Essential Eight Maturity Model, November 2023 release, last updated 27 November 2023. It remains the current published model.

Is Sorami ASD-endorsed or IRAP assessed?

No. Sorami is not an ASD-endorsed, IRAP or government-certified provider. We assess against the published model and say so plainly in the report.

How is the overall level decided?

Per strategy, then by the weakest one. Your level is the lowest strategy you fully meet, not an average across the eight.

Is an assessment a penetration test?

No. An assessment measures whether the eight controls are implemented and evidenced. A penetration test measures whether a specific system can be broken.

Does the Essential Eight cover our cloud workloads?

It applies to the systems you run, which includes cloud infrastructure. Many assessments stop at Microsoft 365 and miss identity, patching and backups in AWS or Azure.

Is the Essential Eight being replaced?

ASD consulted on a proposed Essentials series in mid 2026 and that consultation has closed. No final guidance is published, so the November 2023 model is still what requesters ask you to meet.

Let’s scope it

Ready to scope an Essential Eight assessment?

Send the requester wording and the level they named. We confirm scope and fee before any work starts.

Request a quote

Last reviewed: