rulesmate.com.au — Compliance reference
https://rulesmate.com.au/insights/essential-eight-assessment-evidence-quality-ratings
Printed 28 August 2026
Essential Eight assessments: evidence quality, control ratings and what an assessor accepts
ASD grades evidence from excellent to poor and rates every control. How the ratings work and why one ineffective control sinks a whole maturity level.
Organisations routinely report an Essential Eight maturity level to a board, an insurer or a Commonwealth customer, then lose that level the first time an independent assessor tests it. The gap is almost never about which controls exist. It is about what counts as evidence and how a single failed control propagates.
The Australian Signals Directorate publishes the rules for both. The Essential Eight assessment process guide sets out the assessment method, the evidence hierarchy and the standardised outcomes, alongside the Essential Eight maturity model itself. This article is about that assessment machinery — not about what each of the eight strategies requires, which is covered in Essential Eight maturity levels explained.
Why most self-assessed maturity claims fail an independent assessment
Because a self-assessment usually rests on the weakest evidence ASD recognises. A statement that a control is in place, supported by a policy document, is expressly the lowest grade of evidence in the guide. An independent assessor testing the same control will attempt to break it, and the result frequently differs.
This matters commercially. Federal suppliers handling OFFICIAL: Sensitive data are assessed under Right Fit For Risk — see the RFFR glossary entry and Essential Eight ML2 for federal contractors — and the assessed maturity, not the claimed one, is what the customer records.
The four levels of evidence quality
ASD's guide defines four grades and directs assessors to seek the highest quality reasonably practicable. Knowing the hierarchy tells you exactly what to prepare.
| Grade | What it is | Example |
|---|---|---|
| Excellent | Testing a control with a simulated activity designed to confirm it is in place and effective | Attempting to run a test application to check application control rulesets |
| Good | Reviewing the configuration of a system through the system's own interface | Opening the policy in the management console and reading the enforced setting |
| Fair | Reviewing a copy of a system's configuration | A report or screenshot said to reflect the setting |
| Poor | A policy or verbal statement of intent | Sighting a control mentioned in documentation, or being told about it in an interview |
The gap between "good" and "fair" is the one organisations underestimate. A screenshot is a claim about a configuration; the console is the configuration. If you can arrange live console access and a controlled test window for the assessor, you materially improve the grade of evidence supporting your own result.
The seven assessment outcomes
Every control receives one of ASD's standardised outcomes. Assessors are directed to use these terms rather than inventing their own.
| Outcome | Meaning |
|---|---|
| Not assessed | The control has not yet been assessed |
| Effective | The organisation is effectively meeting the control's objective |
| Alternate control | The objective is being met effectively through an alternate control |
| Ineffective | The organisation is not adequately meeting the control's objective |
| No visibility | The assessor could not obtain adequate visibility of the control's implementation |
| Not implemented | The organisation has decided not to implement the control |
| Not applicable | The control does not apply to the system or environment |
Two of these are worth planning around. No visibility is not a neutral result — it is a failure to evidence, and it counts against you exactly as an unimplemented control does when the assessor rolls up the maturity determination. Alternate control is available, but the compensating control must provide an equivalent level of protection to the one recommended under the Essential Eight; the assessor evaluates whether it addresses the intent of the original control and is implemented effectively.
The all-or-nothing rule that catches most organisations
This is the single most consequential rule in the guide, and it surprises people every time.
For a system owner to claim a mitigation strategy is implemented, all controls specified within that strategy must be assessed as *effective* or *alternate control*. If even one control within a strategy is assessed as *ineffective*, the system owner cannot claim to have met the requirements for that maturity level. And because the maturity level for a system is determined across all eight strategies, if one or more strategies are deemed not implemented, the target maturity level for the system cannot be claimed to have been met.
The practical implications:
- There is no partial credit. Seven strategies at Maturity Level Two plus one at Maturity Level One is Maturity Level One.
- A single overlooked control — an unexpired privileged account, one unhardened browser setting — collapses the whole claim.
- Remediation should be sequenced by *which strategy is furthest behind*, not by which fix is easiest, because the laggard sets your rating.
Before an assessment, run your own control-by-control inventory and look for the single weakest item in each strategy. The Essential Eight tool is a starting point for that inventory.
Risk acceptance is not implementation
ASD is direct on this point: assessors must not allow risk acceptance as a justification for not implementing an entire mitigation strategy. If a system owner has risk-accepted not implementing application control or multi-factor authentication, then without adequate compensating controls the mitigation strategy is treated as not implemented.
This defeats a common governance pattern in which a risk register entry, signed by an executive, is offered in place of a control. It may be a legitimate business decision. It is not a maturity level. If you have deliberately declined a strategy, expect the assessed rating to reflect it and plan your customer conversations accordingly.
What the assessor will actually do, strategy by strategy
The guide provides assessment guidance for each control, ordered by effectiveness of method. The pattern is consistent: demonstrate it live, then show the configuration, then show a copy, then talk about it.
| Strategy | Typical highest-grade test |
|---|---|
| Application control | Attempt to write to and execute from every location on the file system accessible to a user, using verification tooling |
| Patch applications | Review vulnerability scanner configuration and scan history, checking scan scope and timestamps |
| Configure Office macro settings | Generate a Resultant Set of Policy report and read the macro notification settings applied by group policy |
| User application hardening | Read the attack surface reduction rules in the policy report and test browser behaviour directly |
| Restrict administrative privileges | Attempt to browse the internet as a privileged user; query the directory for privileged accounts with no expiry or excessive expiry |
| Patch operating systems | Review scanner coverage of workstations, servers, drivers and firmware against the required cadence |
| Multi-factor authentication | Observe privileged and unprivileged users authenticating, and check whether the method is phishing-resistant where required |
| Regular backups | Review retention and synchronisation, then test whether privileged accounts can access, modify or delete backups |
Note how many of these are *destructive of a paper claim*. "We have application control" is a poor-grade statement; an assessor writing an executable into a user-writable directory and running it produces excellent-grade evidence one way or the other.
The maturity determination also weighs whether the assessor could test across an accurate representative sample of workstations, laptops, servers and network devices, and whether any exceptions have been accepted by an appropriate authority through a formal exception process. Informal exceptions are exceptions all the same, and they will appear in the report.
Preparing an evidence pack that survives testing
Practical preparation, in order of value:
- Arrange live access, not screenshots. Console access under supervision, plus a controlled test window, moves your evidence up two grades.
- Nominate a representative sample yourself. Build the device inventory before the assessor does, including laptops and network devices. Undisclosed device classes cause a *no visibility* rating.
- Close the formal exception process. Every exception needs a named accepting authority and a documented compensating control that addresses the intent of the original control.
- Test your own weakest control in each strategy. The all-or-nothing rule means the weakest control, not the average, determines the rating.
- Collect system-generated evidence continuously. Logs, scan histories and policy reports gathered in the ordinary course are far stronger than a bundle assembled the week before fieldwork.
- Map the overlap. Much of this evidence also answers CPS 234 and supports incident readiness under SOCI reporting. See the cyber security and SOCI hub for the broader picture, and ISO 27001 vs the Essential Eight if you are also being asked for a certificate.
Finally, be careful with vendor tooling claims. ASD notes that vendor products named in its guidance are illustrative only and are not endorsed. A tool that reports your maturity is producing a self-assessment, and a self-assessment is not what your customer is buying.
Frequently asked
What counts as good evidence in an Essential Eight assessment?
ASD's assessment process guide defines four grades. Excellent evidence is testing a control with a simulated activity, such as attempting to run a test application against application control. Good evidence is reviewing configuration through the system's own interface. Fair evidence is a copy of configuration such as a report or screenshot. Poor evidence is a policy document or a verbal statement of intent.
What happens if one Essential Eight control is assessed as ineffective?
The entire mitigation strategy is treated as not implemented for that maturity level. ASD's guide states that all controls specified within a mitigation strategy must be assessed as effective or alternate control for the system owner to claim it. If one or more strategies are not implemented, the target maturity level for the system cannot be claimed to have been met. There is no partial credit.
Can we risk-accept an Essential Eight strategy we have chosen not to implement?
You can make that business decision, but it does not preserve your maturity rating. ASD directs assessors not to allow risk acceptance as a justification for not implementing an entire mitigation strategy. Without adequate compensating controls, the strategy is assessed as not implemented and the maturity level falls accordingly.
What does a 'no visibility' outcome mean?
It means the assessor was unable to obtain adequate visibility of a control's implementation. It is not a neutral result — it behaves like a failure when the maturity determination is rolled up. The usual causes are undisclosed device classes, unavailable systems during fieldwork, or refusal to grant read access to a management console.
Are compensating controls allowed?
Yes, through the 'alternate control' outcome, but the bar is specific. The assessor must be satisfied that the compensating control provides an equivalent level of protection to the control recommended under the Essential Eight, addresses the intent of the original control, and is implemented effectively. A partial mitigation recorded in a risk register does not qualify.
Is a self-assessment enough for a Commonwealth customer?
Usually not. Federal suppliers handling OFFICIAL: Sensitive data are generally assessed under the Right Fit For Risk approach, which relies on independent assessment rather than self-reporting. A self-assessment is useful for internal planning and for sequencing remediation, but the maturity level a customer records is the assessed one.
Related
Related reading
Essential Eight maturity levels explained (ML1, ML2, ML3)
The Australian Signals Directorate's Essential Eight has four maturity levels. This guide explains ML0 to ML3, what each requires, and which level applies to government-connected businesses.
Essential Eight ML2 for federal contractors: a guide to Right Fit For Risk
Federal subcontractors handling OFFICIAL: Sensitive data must meet ASD Essential Eight Maturity Level 2 under Right Fit For Risk. Here's what each of the 8 strategies actually means at ML2.
ISO 27001 vs the Essential Eight: which framework for Australian business
ISO 27001 vs Essential Eight for Australian business: how the two frameworks differ, who each suits, certification vs maturity levels, and when to do both.
IRAP assessments and hosting Australian government data: the certification path
How an IRAP assessment works, what an IRAP assessor can and cannot give you, and how the Hosting Certification Framework sits alongside it (checked August 2026).
Obligations covered
© Rules Mate · Source citations at the end · Information current as at 28 August 2026
Printed from https://rulesmate.com.au/insights/essential-eight-assessment-evidence-quality-ratings