ASD Essential Eight Maturity Model

Self-Assessed Maturityis not maturity.

Most Essential Eight assessments are questionnaires completed by the team responsible for the controls. We assess what is externally observable — independently, with evidence.

9.3CVSS — cPanel bypass, exploited in Australia
30 AprilPatch released. Still exploited in July.
11.40Every cPanel version after it is affected
SMEsNamed repeatedly in ASD’s 2026 advisories

Passive only — no systems, networks or accounts are accessed at any point.

Everyone Self-Assesses. Almost Nobody Verifies.

The Essential Eight is the most widely referenced security baseline in Australia, and the overwhelming majority of assessments against it are questionnaires completed internally by the people responsible for the controls being assessed.

That is not dishonesty. It is structural. An internal team assesses against the asset list it holds, and that list records what the organisation believes it runs. The assets that produce incidents are, almost by definition, the ones nobody remembered.

The 2026 evidenceASD spent 2026 issuing advisory after advisory in which the operative instruction was the same: establish what is reachable from the internet, and reduce it. cPanel control panels. CMS admin paths. VPN gateways. Routers and firewalls. Almost none of it turned on a zero-day — the vulnerabilities were public, known and already patched. The gap was not intelligence. It was inventory.

Which Strategies Can Honestly Be Assessed From Outside

We are explicit about this, because a report that implies more coverage than it delivers is worse than no report.

Patch applications — externally assessable

Internet-facing applications and their versions can be fingerprinted from outside and matched against published vulnerability data. This is the strategy most directly linked to real Australian compromise in 2026, and the one an external assessment covers best.

Restrict administrative privileges — partially assessable

Whether administrative and management interfaces are reachable from the public internet is externally observable. Whether privilege is correctly restricted within those interfaces is not.

Patch operating systems — partially assessable

Where an internet-facing service discloses its platform, unsupported or outdated operating systems become visible. Where it does not, this strategy requires internal assessment.

Multi-factor authentication — partially assessable

Publicly reachable authentication portals can be observed, and corporate credentials appearing in published infostealer corpora indicate where MFA is doing the load-bearing work. Enforcement coverage itself requires internal verification.

Application control, macro settings, user application hardening, backups — not externally assessable

These four require internal access. We do not assess them, and we say so in the report rather than leaving the impression of coverage we do not have.

What You Receive

  • A verified external asset inventory — every hostname, subdomain and service attributable to your organisation, reconciled against what you believe you run
  • Internet-facing application and version fingerprinting, matched to published vulnerabilities and triaged using CISA KEV, EPSS and SSVC so you receive decisions rather than a severity histogram
  • Exposed administrative and management interfaces, including the categories named in ASD’s 2026 advisories
  • Forgotten and unowned web properties — campaign microsites, legacy domains, subsidiary and event sites running unpatched content management systems
  • Credential exposure in published breach and infostealer corpora
  • Strategy-by-strategy mapping with an explicit statement of what was assessed externally, what was partially assessed, and what requires internal verification
Passive Only — No Systems AccessedEvery BlackFlag Advisory assessment uses exclusively passive OSINT techniques against publicly available sources. No systems, networks or accounts are accessed, probed or tested at any point. No authorisation to test is required, and nothing we do can disrupt your operations.

Who This Is For

Organisations working toward a maturity level

Where a self-assessment exists and you want independent evidence for the parts that can be verified externally.

Government suppliers

Where a tender or contract specifies Essential Eight alignment and you need something more defensible than a completed questionnaire.

Australian small and medium businesses

The population ASD named repeatedly through 2026 — in the CMS exploitation campaign, in the ClickFix credential-harvesting campaign, and in managed service provider compromises.

Organisations planning for the framework’s retirement

ASD signalled in June 2026 that the Essential Eight will be retired within two years. The control objectives will not disappear. Knowing what you expose survives any change of framework.

How the Engagement Runs

Five steps. The only one that requires your time is the first and the last.

1. Scope

We agree the domains, entities or suppliers in scope and the frameworks the findings should be mapped to. Nothing else is required from you — no access, no credentials, no questionnaire to complete.

2. Passive collection

We observe what your organisation exposes using publicly available sources: certificate transparency logs, passive DNS, published vulnerability data, and public breach and infostealer corpora. No systems, networks or accounts are accessed, probed or tested at any point.

3. Analysis and triage

Findings are validated, deduplicated and prioritised against confirmed exploitation status, exploitation probability and asset exposure — not by severity score alone. Every finding carries the evidence that produced it.

4. Regulatory mapping

Each finding is mapped to the obligation it engages, so the report speaks in the language your Board, auditor, insurer or regulator already uses.

5. Delivery and walkthrough

A dual-audience report: a Board section stating the position in plain terms, and a technical section carrying reproducible evidence. We walk you through it, and we are available for the remediation questions that follow.

Frequently Asked Questions

The questions we are asked most often about assessing the Essential Eight from outside.

What is the ASD Essential Eight?

The Essential Eight is a set of eight baseline mitigation strategies published by the Australian Signals Directorate: patch applications, patch operating systems, multi-factor authentication, restrict administrative privileges, application control, restrict Microsoft Office macros, user application hardening, and regular backups. Organisations assess themselves against Maturity Level One, Two or Three.

Is the Essential Eight being retired?

In June 2026 ASD signalled its intention to retire the Essential Eight guidance framework within two years, to keep pace with a shifting threat environment. Organisations should continue applying it while planning for successor guidance. The underlying control objectives are unlikely to disappear; the packaging will change.

Which Essential Eight strategies can be assessed externally?

Several are directly observable from outside: patch status of internet-facing applications, exposure of administrative interfaces, and the presence of legacy or unsupported technology on the public perimeter. Others — macro settings, application control, backup regimes — require internal access and are outside the scope of a passive assessment. A BlackFlag Advisory report is explicit about which is which.

Can this replace an internal Essential Eight assessment?

No, and it is not intended to. A passive external assessment provides independent evidence for the externally observable strategies and identifies internet-facing assets that internal assessments routinely miss. It complements an internal maturity assessment rather than substituting for one.

Scope and packages are set out on the assessment packages page. If you are working toward a specific maturity level or responding to a government or client requirement, book a short call and we will scope against it.

Attestation Is Not Evidence.
We Provide the Evidence.

A BlackFlag Advisory assessment gives you an independent, externally verified view of the Essential Eight mitigation strategies that can be observed from outside your organisation — with the evidence attached.

Request an Assessment →
Assessments
AI Governance CPS 234 Essential Eight Privacy Act & APP 11 Third-Party Risk Tranche 2 Cyber Which one do I need? →
Intelligence
All briefings Romania land registry Tranche 2 commenced ASD advisories, 2026
Practice
GRC Partnerships Pricing Privacy
Start
Threat Scan Enquire Sample report