All insights

How do you actually get Essential Eight compliant, step by step?

6 min readBy Brendon Whiting, Founder · 12 June 2026

Getting Essential Eight compliant runs in five steps: measure where you stand, pick a target maturity level that matches your risk, fix the identity and backup controls first, work through the remaining controls with evidence as you go, then keep it maintained, because maturity decays. Most small businesses should be targeting Maturity Level 1.

Before step one, a reframe that changes the whole plan: there is no Essential Eight certificate. No body certifies businesses against it, so compliant can only mean one thing, able to demonstrate a maturity level with evidence when someone asks, and the someones are multiplying: insurers, tender panels, larger customers, Defence. That means the goal of the exercise is not a plaque; it is a folder of proof and the controls behind it.

Step one: measure. You cannot plan a climb from an imagined base camp, and most businesses imagine theirs generously. A proper baseline assessment, ours is free and written, scores each of the eight controls from zero to three against evidence. Expect zeros; almost every first assessment contains them, they are the model working as designed, and the only wrong response is to negotiate with the score rather than the gap.

Step two: pick the target and write it down. Maturity Level 1 is the deliberate default, designed to defeat the commodity attacks that make up most real-world incidents. Level 2 belongs to businesses with contractual obligations, defence connections or elevated risk; Level 3 to those facing adversaries with advanced tradecraft, which is rarer than vendors imply. A one-line decision, we are targeting Level 1 by June, signed by an owner, does more for the project than any tool purchase, because every later argument about scope gets settled by pointing at it.

Step three: take the two wins that pay immediately. Multi-factor authentication on every account, admin accounts first, because stolen passwords are the front door of small-business compromise. Backups configured, protected from the network they back up, and, non-negotiably, test-restored, because an unproven backup is a hope with a schedule. Add the quick admin-rights pass, removing the administrator access that has accreted on ordinary accounts over the years. These three produce most of the early risk reduction and, usefully, most of the early evidence.

Step four is the grind, and honesty about it prevents abandoned projects. Application control, tools such as ThreatLocker deciding what may run, is powerful and disruptive if flipped on overnight, so it is deployed in learning mode first, piloted on a friendly group, with an exceptions process agreed before anyone's job is interrupted. Patching applications and operating systems becomes a cadence with a number attached, not a when-we-get-to-it. Office macro settings and user application hardening are the quiet controls: mostly configuration, mostly invisible to staff, endlessly forgotten. Work one control at a time to your target level, and capture evidence as you go, screenshots, exports, restore logs, an exceptions register, because reconstructing evidence months later is the most demoralising task in security.

A word on effort, without invented precision: for a typical small business starting near zero, the climb to a demonstrated Level 1 is measured in weeks to months, not days, and the variable is estate cleanliness, how documented, consistent and cloud-based your systems already are. It can be run as an internal project, or bought as a service; our plans deliver exactly this by tier, with full Maturity Level 1 at $139 per user per month. The sequence holds either way, and it is the sequence that carried a 24/7 freight operator to one hundred per cent Maturity Level 1 across five sites, with DISP accreditation standing on top of it afterwards.

Step five: maintain, because maturity is a garden, not a monument. Every new starter is an MFA enrolment and an access decision; every new laptop is an application-control and patching endpoint; every month without a tested restore quietly ages your strongest evidence. A monthly rhythm, patch compliance checked, restore tested, exceptions reviewed, new accounts audited, holds the level you paid to reach, and an annual reassessment proves it still exists.

Two closing caveats, so this plan stays honest. The Essential Eight is the baseline, not the ceiling: email security, staff awareness and your Privacy Act obligations live outside it and still matter. And Level 1 defeats commodity attacks, not determined, resourced adversaries, which is precisely why the levels above it exist. Start with the free baseline, the Cyber Security Scorecard, or call 1800 456 567 and we will walk the five steps against your actual systems.

Buy the climb as a service

Our plans deliver the uplift by tier: Essential Eight foundations at $79 per user per month, full Maturity Level 1 at $139, Levels 2 and 3 above.

Frequently asked questions

Multi-factor authentication, with tested backups immediately behind it. MFA blunts the most common attack, stolen and phished passwords, for the least money and disruption, and a proven restore turns ransomware from an existential threat into a bad week. Both also generate evidence quickly, which builds momentum for the slower controls.

They will, constantly, during the climb, but the model scores you at your weakest control: seven controls at Level 2 and one at Level 0 is an overall maturity of Level 0. That rule feels harsh and is deliberate, because attackers use the weakest door. It is also why finishing a level beats starting the next one.

Probably not. Level 3 addresses adversaries who target you specifically with advanced tradecraft, and it demands operational discipline most small businesses cannot justify. Level 1 is the sensible target for most, Level 2 where contracts, defence work or elevated risk demand it. Let your obligations and your risk pick the level, not ambition.

Questions? Let's talk.

Call 1800 456 567 or fill out the form.

  • 30-minute discovery — no jargon, no pressure
  • Plain-English Essential Eight Cyber Security Scorecard
  • A clear plan tailored to your business

Prefer to talk?

Call 1800 456 567

Powered by Calendly — your data is handled securely.

Our office · Level 2, 25 Grenfell Street, Adelaide

By submitting, you agree to our terms and privacy policy. No spam — ever.