Skip to main content
Rules Mate

Essential Eight assessments: evidence quality, control ratings and what an assessor accepts

Rules Mate Editorial7 min read

ASD grades evidence from excellent to poor and rates every control. How the ratings work and why one ineffective control sinks a whole maturity level.

Organisations routinely report an Essential Eight maturity level to a board, an insurer or a Commonwealth customer, then lose that level the first time an independent assessor tests it. The gap is almost never about which controls exist. It is about what counts as evidence and how a single failed control propagates.

The Australian Signals Directorate publishes the rules for both. The Essential Eight assessment process guide sets out the assessment method, the evidence hierarchy and the standardised outcomes, alongside the Essential Eight maturity model itself. This article is about that assessment machinery — not about what each of the eight strategies requires, which is covered in Essential Eight maturity levels explained.

Why most self-assessed maturity claims fail an independent assessment

Because a self-assessment usually rests on the weakest evidence ASD recognises. A statement that a control is in place, supported by a policy document, is expressly the lowest grade of evidence in the guide. An independent assessor testing the same control will attempt to break it, and the result frequently differs.

This matters commercially. Federal suppliers handling OFFICIAL: Sensitive data are assessed under Right Fit For Risk — see the RFFR glossary entry and Essential Eight ML2 for federal contractors — and the assessed maturity, not the claimed one, is what the customer records.

The four levels of evidence quality

ASD's guide defines four grades and directs assessors to seek the highest quality reasonably practicable. Knowing the hierarchy tells you exactly what to prepare.

GradeWhat it isExample
ExcellentTesting a control with a simulated activity designed to confirm it is in place and effectiveAttempting to run a test application to check application control rulesets
GoodReviewing the configuration of a system through the system's own interfaceOpening the policy in the management console and reading the enforced setting
FairReviewing a copy of a system's configurationA report or screenshot said to reflect the setting
PoorA policy or verbal statement of intentSighting a control mentioned in documentation, or being told about it in an interview

The gap between "good" and "fair" is the one organisations underestimate. A screenshot is a claim about a configuration; the console is the configuration. If you can arrange live console access and a controlled test window for the assessor, you materially improve the grade of evidence supporting your own result.

The seven assessment outcomes

Every control receives one of ASD's standardised outcomes. Assessors are directed to use these terms rather than inventing their own.

OutcomeMeaning
Not assessedThe control has not yet been assessed
EffectiveThe organisation is effectively meeting the control's objective
Alternate controlThe objective is being met effectively through an alternate control
IneffectiveThe organisation is not adequately meeting the control's objective
No visibilityThe assessor could not obtain adequate visibility of the control's implementation
Not implementedThe organisation has decided not to implement the control
Not applicableThe control does not apply to the system or environment

Two of these are worth planning around. No visibility is not a neutral result — it is a failure to evidence, and it counts against you exactly as an unimplemented control does when the assessor rolls up the maturity determination. Alternate control is available, but the compensating control must provide an equivalent level of protection to the one recommended under the Essential Eight; the assessor evaluates whether it addresses the intent of the original control and is implemented effectively.

The all-or-nothing rule that catches most organisations

This is the single most consequential rule in the guide, and it surprises people every time.

For a system owner to claim a mitigation strategy is implemented, all controls specified within that strategy must be assessed as *effective* or *alternate control*. If even one control within a strategy is assessed as *ineffective*, the system owner cannot claim to have met the requirements for that maturity level. And because the maturity level for a system is determined across all eight strategies, if one or more strategies are deemed not implemented, the target maturity level for the system cannot be claimed to have been met.

The practical implications:

  • There is no partial credit. Seven strategies at Maturity Level Two plus one at Maturity Level One is Maturity Level One.
  • A single overlooked control — an unexpired privileged account, one unhardened browser setting — collapses the whole claim.
  • Remediation should be sequenced by *which strategy is furthest behind*, not by which fix is easiest, because the laggard sets your rating.

Before an assessment, run your own control-by-control inventory and look for the single weakest item in each strategy. The Essential Eight tool is a starting point for that inventory.

Risk acceptance is not implementation

ASD is direct on this point: assessors must not allow risk acceptance as a justification for not implementing an entire mitigation strategy. If a system owner has risk-accepted not implementing application control or multi-factor authentication, then without adequate compensating controls the mitigation strategy is treated as not implemented.

This defeats a common governance pattern in which a risk register entry, signed by an executive, is offered in place of a control. It may be a legitimate business decision. It is not a maturity level. If you have deliberately declined a strategy, expect the assessed rating to reflect it and plan your customer conversations accordingly.

What the assessor will actually do, strategy by strategy

The guide provides assessment guidance for each control, ordered by effectiveness of method. The pattern is consistent: demonstrate it live, then show the configuration, then show a copy, then talk about it.

StrategyTypical highest-grade test
Application controlAttempt to write to and execute from every location on the file system accessible to a user, using verification tooling
Patch applicationsReview vulnerability scanner configuration and scan history, checking scan scope and timestamps
Configure Office macro settingsGenerate a Resultant Set of Policy report and read the macro notification settings applied by group policy
User application hardeningRead the attack surface reduction rules in the policy report and test browser behaviour directly
Restrict administrative privilegesAttempt to browse the internet as a privileged user; query the directory for privileged accounts with no expiry or excessive expiry
Patch operating systemsReview scanner coverage of workstations, servers, drivers and firmware against the required cadence
Multi-factor authenticationObserve privileged and unprivileged users authenticating, and check whether the method is phishing-resistant where required
Regular backupsReview retention and synchronisation, then test whether privileged accounts can access, modify or delete backups

Note how many of these are *destructive of a paper claim*. "We have application control" is a poor-grade statement; an assessor writing an executable into a user-writable directory and running it produces excellent-grade evidence one way or the other.

The maturity determination also weighs whether the assessor could test across an accurate representative sample of workstations, laptops, servers and network devices, and whether any exceptions have been accepted by an appropriate authority through a formal exception process. Informal exceptions are exceptions all the same, and they will appear in the report.

Preparing an evidence pack that survives testing

Practical preparation, in order of value:

  1. Arrange live access, not screenshots. Console access under supervision, plus a controlled test window, moves your evidence up two grades.
  2. Nominate a representative sample yourself. Build the device inventory before the assessor does, including laptops and network devices. Undisclosed device classes cause a *no visibility* rating.
  3. Close the formal exception process. Every exception needs a named accepting authority and a documented compensating control that addresses the intent of the original control.
  4. Test your own weakest control in each strategy. The all-or-nothing rule means the weakest control, not the average, determines the rating.
  5. Collect system-generated evidence continuously. Logs, scan histories and policy reports gathered in the ordinary course are far stronger than a bundle assembled the week before fieldwork.
  6. Map the overlap. Much of this evidence also answers CPS 234 and supports incident readiness under SOCI reporting. See the cyber security and SOCI hub for the broader picture, and ISO 27001 vs the Essential Eight if you are also being asked for a certificate.

Finally, be careful with vendor tooling claims. ASD notes that vendor products named in its guidance are illustrative only and are not endorsed. A tool that reports your maturity is producing a self-assessment, and a self-assessment is not what your customer is buying.

Frequently asked

What counts as good evidence in an Essential Eight assessment?

ASD's assessment process guide defines four grades. Excellent evidence is testing a control with a simulated activity, such as attempting to run a test application against application control. Good evidence is reviewing configuration through the system's own interface. Fair evidence is a copy of configuration such as a report or screenshot. Poor evidence is a policy document or a verbal statement of intent.

What happens if one Essential Eight control is assessed as ineffective?

The entire mitigation strategy is treated as not implemented for that maturity level. ASD's guide states that all controls specified within a mitigation strategy must be assessed as effective or alternate control for the system owner to claim it. If one or more strategies are not implemented, the target maturity level for the system cannot be claimed to have been met. There is no partial credit.

Can we risk-accept an Essential Eight strategy we have chosen not to implement?

You can make that business decision, but it does not preserve your maturity rating. ASD directs assessors not to allow risk acceptance as a justification for not implementing an entire mitigation strategy. Without adequate compensating controls, the strategy is assessed as not implemented and the maturity level falls accordingly.

What does a 'no visibility' outcome mean?

It means the assessor was unable to obtain adequate visibility of a control's implementation. It is not a neutral result — it behaves like a failure when the maturity determination is rolled up. The usual causes are undisclosed device classes, unavailable systems during fieldwork, or refusal to grant read access to a management console.

Are compensating controls allowed?

Yes, through the 'alternate control' outcome, but the bar is specific. The assessor must be satisfied that the compensating control provides an equivalent level of protection to the control recommended under the Essential Eight, addresses the intent of the original control, and is implemented effectively. A partial mitigation recorded in a risk register does not qualify.

Is a self-assessment enough for a Commonwealth customer?

Usually not. Federal suppliers handling OFFICIAL: Sensitive data are generally assessed under the Right Fit For Risk approach, which relies on independent assessment rather than self-reporting. A self-assessment is useful for internal planning and for sequencing remediation, but the maturity level a customer records is the assessed one.

Related

Related reading