For questions about a specific control (macros, backups, MFA, etc.), see that control's page.
- Is Essential Eight ML1 enough for my business?
- For most mid-market Australian businesses without specific regulatory obligations, ML1 is a reasonable first target and a fair answer to most insurance questionnaires in 2026. If you're in financial services under APRA, a defence supply chain, an RTO with ASQA obligations, or a mid-tier law firm with corporate-client audits, expect the bar to keep moving toward ML2 over the next 24 months.
- Who actually audits Essential Eight compliance?
- The ACSC does not audit private-sector Essential Eight compliance. Your auditors are effectively: your cyber insurance broker (via the renewal questionnaire), your larger corporate clients (via their vendor-security processes), and increasingly your sector regulator (APRA, ASIC, Law Society, ASQA). Each uses their own scoring, but the Essential Eight is the common language underneath.
- How does the Essential Eight map to our cyber insurance questionnaire?
- It maps closely but imperfectly. Most Australian cyber insurance renewal questionnaires now cover the same concepts (MFA coverage, patch cadence, privileged access, backups, training) and often reference the Essential Eight directly. Your broker will score against their own criteria, but an ML1 business typically clears a renewal questionnaire without flagging red issues. We've filled in enough of these to know which questions and answers actually move the premium and which don't.
- Do we have to do all eight controls, or can we pick?
- The Essential Eight is scored as a package. Your overall maturity is the weakest control, not the average. Being ML2 on seven controls and ML0 on one means you're at ML0 overall. That's deliberate: the controls are designed to work together, and attackers go through the weakest one.
- Can you give us a rough budget and timeline for the ML0 to ML1 move?
- It depends on your starting posture and environment size, but a typical mid-market business we haven't worked with before sits somewhere in the mid-ML0 range on assessment, and reaches ML1 within 90 to 180 days of deliberate work. For clients already on our Managed IT Complete stack, ML1 is usually a posture we maintain by default, not a separate project.