All insights

How long does an Essential Eight assessment and uplift take?

5 min readBy Brendon Whiting, Founder · 4 May 2026

The assessment itself takes days to a couple of weeks, driven by how quickly evidence can be gathered. The uplift that follows is measured in weeks to months: the quick controls land in the first fortnight, application control needs a piloted rollout, and a demonstrated Maturity Level 1 for a typical small business is a one-to-three-month project, not a purchase.

Few providers give this answer plainly, because the truthful version has variables in it, and variables make weak marketing. But refusing to give a shape at all is worse, so here is the shape, with the drivers named, and you can place your own business along each one. Two businesses of identical size can sit a month apart on this timeline for reasons that have nothing to do with technology. The drivers, named up front: estate cleanliness, decision speed, and how much of the work is bought as a service rather than scheduled around the day jobs.

The assessment phase first. Scoping is a conversation, evidence-gathering is the substance: identity exports, patch reports, admin lists, backup and restore logs. In a documented, cloud-based business with one administrator, that is days. In an undocumented estate with a server nobody owns and three generations of ex-provider settings, it stretches toward a couple of weeks, and the stretching is itself a finding. The report should follow within days of the evidence, and if an assessor cannot say when yours lands, ask why.

Uplift opens with a fast fortnight, and it should feel fast. Multi-factor authentication is enrolled, admin accounts first; backups are configured properly and, crucially, a restore is performed and logged; accumulated admin rights are stripped from daily-driver accounts. These moves are mostly configuration, they produce immediate risk reduction, and they generate the project's first real evidence, which matters for morale as much as for audit trails. A fortnight that produces MFA exports and a restore log has already changed your next insurer conversation.

Then the pace changes, deliberately. Application control is the schedule's honest centre: it runs in learning mode to see what your business actually uses, pilots on a tolerant group, grows an exceptions process, and only then enforces widely, several weeks by design, because the alternative is stopping someone's work mid-deadline and spending the saved time on apologies. Patching, meanwhile, becomes a cadence with a number attached, and a cadence cannot be demonstrated until it has run a few cycles. Macro settings and application hardening slot in throughout, quick individually, easy to forget collectively.

This is also why demonstrated maturity has a tail that cannot be compressed: some evidence is inherently time-shaped. A patch cadence proven over cycles, a restore log with more than one entry, an exceptions register with history, these cannot exist on day ten no matter the budget, which is precisely what makes them convincing to an insurer or a panel later. It is also why compliance in days offers deserve the suspicion they earn: whatever is being produced that fast, it is not this. Plan backwards from it: if a dated requirement is coming, the cadence evidence needs to start now, not the month before.

What actually blows timelines out, in observed order: decision latency, an approval that waits two weeks costs two weeks; estate surprises, the unknown server, the line-of-business app that fights application control; and exceptions arguments without a process, which turn configuration questions into politics. Of the three, decision latency is the one entirely within your control, worth knowing before anyone blames the technology. What compresses timelines: a named internal owner with authority to say yes, a clean or cloud-first estate, and buying the climb as a managed service, ours delivers Maturity Level 1 as the $139 tier, where the sequence, tooling and evidence-capture are already built.

The deadline caveat, because sometimes the tender is next month: triage truthfully. The fast fortnight is achievable and real; state the assessed level you hold today, the target, and the dated plan between them. Panels and insurers respond better to a true trajectory than to a claimed arrival, and the difference is discoverable later in exactly the way you do not want. If you want the clock started this week, the baseline is free: the Cyber Security Scorecard, or 1800 456 567.

See the phases before you start

We run an uplift the way we run onboarding: PRINCE2-managed, with weekly updates, so you always know which phase you are in and what evidence exists so far.

Frequently asked questions

You can make real progress in a week, MFA enrolled, a restore tested, admin rights trimmed, and you cannot credibly demonstrate Maturity Level 1 in one, because some controls prove themselves over cycles. Treat instant-compliance offers as a signal about the seller: whatever they are promising to produce in a week, it is not evidence.

Application control, and the reason is cultural rather than technical. Deciding what software may run touches every team's habits, so it is deployed in learning mode, piloted, and given an exceptions process before full enforcement, deliberately across weeks. Rushed application control does not fail quietly; it stops someone's work mid-deadline and burns the project's goodwill.

Partially, and that is the model behaving correctly. A new platform, an office move or an acquisition changes the estate the maturity described, so the affected controls need reassessing and their evidence refreshing. The disciplines you built, patch cadence, enrolment habits, restore testing, carry over, which is why the second climb is always faster than the first.

Questions? Let's talk.

Call 1800 456 567 or fill out the form.

  • 30-minute discovery — no jargon, no pressure
  • Plain-English Essential Eight Cyber Security Scorecard
  • A clear plan tailored to your business

Prefer to talk?

Call 1800 456 567

Powered by Calendly — your data is handled securely.

Our office · Level 2, 25 Grenfell Street, Adelaide

By submitting, you agree to our terms and privacy policy. No spam — ever.