CMS IT Pty Ltd Talk to a Sydney tech02 8004 9251
ACSC Essential Eight · Sydney

Essential Eight compliance, without the consultant theatre

A tender, an insurer or a big client has asked where you sit against the Essential Eight. We assess your current maturity level, tell you honestly what it will take to reach the level you need, and then do the work. Flat rate, no lock-in.

SMB1001:2026 Gold certified ourselves Written report you can send your broker Zero lock-in contracts Sydney since 1996
Why this lands on your desk

Nobody asks about the Essential Eight for fun

It almost always arrives attached to something with a deadline. If one of these is why you are here, you are in the right place.

A tender or contract requires it

Government and enterprise buyers increasingly ask for an Essential Eight maturity level in the paperwork. Answering vaguely loses the bid; answering falsely is worse. We help you answer accurately, and close the gaps that matter before you submit.

Your cyber insurer is asking

Renewal questionnaires now map closely to these controls. Get them wrong and you face loaded premiums, exclusions, or declined cover — usually with a renewal date already in the diary. We fix them in the order the insurer actually cares about.

A client is auditing you

Your customer's security team wants evidence, not assurances. We produce documentation that stands up to review, and we know what it looks like from both sides — we hold SMB1001:2026 Gold certification ourselves.

The eight controls

What we assess, in plain English

The ACSC defines eight mitigation strategies and four maturity levels (0 to 3). Here is what each one actually means for a business your size.

  • 1 · Application controlOnly approved software can run. The control most businesses score zero on, and the one that stops most ransomware dead.
  • 2 · Patch applicationsBrowsers, Office, PDF readers and the rest, patched within the window your target maturity level demands — and evidenced, not assumed.
  • 3 · Configure Office macrosMacros blocked from the internet and restricted to vetted uses. Cheap to do, and a favourite entry point for attackers.
  • 4 · User application hardeningTurning off the risky features nobody uses — legacy scripting, unnecessary browser plugins, Flash-era leftovers still lurking in old builds.
  • 5 · Restrict admin privilegesWho can install software and change systems, reviewed and reduced. Usually the fastest score improvement available to an SMB.
  • 6 · Patch operating systemsWindows and server patching on a defined cadence, including the machine in the corner everyone forgot about.
  • 7 · Multi-factor authenticationOn email, remote access and anything internet-facing. The single control insurers ask about first.
  • 8 · Regular backupsBacked up, kept offline or immutable, and — the part almost everyone skips — actually test-restored.
How the engagement runs

Assessment first, then only the work you need

Most businesses do not need Maturity Level 3. Being told which level you actually need is half the value.

1

Free maturity assessment

We score all eight controls against Maturity Levels 0–3 and give you the written report. Yours to keep, and to send to your broker or the client asking, whether or not you engage us.

2

Agree the target level

Level 1 satisfies most insurers and commercial tenders. Level 2 and 3 cost meaningfully more. We tell you what the requirement in front of you actually demands, rather than selling you the maximum.

3

Close the gaps

Quick wins first — MFA, admin rights, macro settings — then the heavier items like application control. Work is scheduled around your trading hours and quoted up front.

4

Evidence and maintain

Documentation that stands up to an auditor, then ongoing monitoring so your level does not quietly slip back. Drift is the reason most businesses fail their second assessment.

Straight answers

The questions people actually ask

What maturity level do we actually need?

For most Australian SMBs facing an insurance questionnaire or a commercial tender, Maturity Level 1 is the realistic and sufficient target. Level 2 and 3 are aimed at organisations handling higher-risk data or contracting to government. Part of the free assessment is telling you which applies, because the cost difference between them is substantial and most providers will happily sell you the higher one.

Is the Essential Eight mandatory?

Not for private businesses in general. It is mandatory for non-corporate Commonwealth entities, and it is increasingly written into tenders, supply-chain requirements and insurance questionnaires — which is how it becomes mandatory in practice for the rest of us.

How long does the assessment take?

About a week for a typical SMB, mostly done remotely with a short on-site visit if you have your own servers. You get the written report at the end of it, at no cost.

What does the remediation cost?

It depends entirely on where you start. Businesses already on Microsoft 365 with MFA in place are often a few days of work away from Level 1. If you are running unpatched on-premise servers with shared admin passwords, it is a bigger job. The assessment produces a real quote instead of a guess — and it lists what you could reasonably do yourself.

Can you help us answer the insurer's questionnaire?

Yes. We map our findings to the questions your insurer or broker has actually asked, so you can answer accurately and evidence it. We will not help anyone answer a questionnaire dishonestly — that voids the cover you are paying for, which defeats the point.

Do we have to become a managed client?

No. Plenty of businesses take the assessment, fix things themselves or with their existing provider, and we never hear from them again. If you do want us to do the work it is the same flat-rate, no-lock-in arrangement as everything else we do.

No obligation

Book your free Essential Eight assessment

Tell us the deadline you are working to — a tender date, a policy renewal, a client audit — and we will tell you honestly whether it is achievable. A real person replies within one business day.

A real person replies within one business day. In a hurry, call 02 8004 9251.

By submitting, you agree to be contacted by CMS IT about your enquiry. We'll never share your details — see our privacy policy.