Two different jobs get collapsed into the same word. Assessing your own practice against the Essential Eight is a supply-chain exercise with your admin plane at the centre of it. Assessing a client is a delivery exercise where you already know most of the answers, and where you are frequently the party responsible for the gaps you are about to write down. They need different scoping, different evidence and, arguably, different people.
This is written for MSP owners and technical leads, so it skips the framework primer. If you want that for a client, send them our plain-English guide to the Essential Eight rather than the ASD publication. It saves a meeting.
You are the supply-chain question now
ASD has been explicit about this for years. In its guidance for managed service providers, it notes that many of the compromises involving MSP customers occurred because the MSP itself was the initial point of compromise: the customer was not the initial victim, the MSP was the vector. The 2022 joint advisory with CISA, NCSC-UK, CCCS and NCSC-NZ said the same thing at greater length.
More usefully for understanding why the questionnaires are arriving: ASD’s customer-facing guidance tells organisations engaging an MSP to ensure their contract requires the MSP to maintain a good internal security culture and to implement cyber security guidance such as the Essential Eight, and to include cyber security incident notification clauses. That guidance is public, it is being read by procurement teams and insurers, and it is where the clause in your latest MSA came from.
The Essential Eight is not law for you. It is mandatory for non-corporate Commonwealth entities under the Protective Security Policy Framework; for a private MSP it is contractual. But the contractual pressure is now coming from three directions at once: client procurement, client insurers, and your own PI and cyber renewal. They are converging on the same evidence request.
Worth being blunt about scope when you assess yourself: the crown jewels are not your file server. They are the RMM, the PSA, the documentation platform, the backup consoles, the delegated admin relationships and the accounts that hold them. ASD’s MSP guidance goes to segmentation between customer trust zones, least-privilege administration, and multi-factor authentication on remotely accessible services used to reach customer networks. Any self-assessment that scopes out the admin plane because “that’s tooling, not the corporate network” is not an assessment, it is a marketing exercise.
Two different jobs
| Your own practice | A client environment | |
|---|---|---|
| Primary risk being assessed | Concentrated privileged access across many tenancies. One compromise, many victims. | That client’s own exposure, plus whatever you have inherited responsibility for. |
| Scope decision | Admin plane first: RMM, PSA, documentation, backup and identity tooling, technician workstations, privileged accounts. | Their internet-connected IT environment. ASD notes the Essential Eight was designed for internet-connected IT networks, not for enterprise mobility or operational technology. |
| Who owns the gaps | You. Cleanly. | Split three ways: in scope of the current agreement, out of scope, or client-retained. This split is the entire commercial conversation. |
| Evidence problem | Nobody audits you. Discipline has to be self-imposed. | You have the access to produce real evidence, which makes a paper-only answer indefensible if it is ever tested. |
| Independence | Self-assessment is legitimate. ASD states there is no requirement for Essential Eight implementations to be certified by an independent party. | Same in principle — but an implementation may need independent assessment where a government directive, a regulator or a contract requires it. |
| Cadence | Annual minimum, plus after any material change to the admin plane. | Tie to their financial year or their insurance renewal, whichever forces the budget conversation. |
The conflict of interest, and how to run it credibly
You are the assessor and the party responsible for a good share of the findings. Pretending otherwise damages you the moment a client’s broker or a new CIO reads the report properly. Handling it well is not complicated, but it does have to be deliberate.
- Declare it in the report. One sentence at the top: this assessment was conducted by the provider responsible for managing the environment, it is a self-assessment rather than an independent assessment, and here is what that means. Clients respect this. Auditors notice its absence.
- Classify every gap by ownership, not just by severity. In scope of the current agreement and not yet delivered; out of scope of the current agreement; or client-retained (their tenancy, their staff, their decision). A report that only ranks by risk lets everybody avoid the question of who was supposed to have done it.
- Do not mark a control compliant that you have not evidenced. The temptation is worst on the controls you configured yourself two years ago and have not verified since. Application control rulesets and backup restoration are the usual offenders.
- Record declined work as a dated risk acceptance, signed by the client. Where a gap exists because the client would not fund the remediation, that has to be on the record with a date and a name. It protects them, it protects you, and it converts an argument into a documented decision.
- Offer independence rather than resisting it. If a client wants a third party to assess the environment you manage, help them scope it. The alternative — appearing to want to be the only one holding the pen — costs more trust than the review costs you in findings.
The uncomfortable version of this: the first assessment of a client you have held for five years will make you look bad. Doing it anyway, with dates and ownership attached, is what makes the second one credible.
Scoping a client assessment without lying to yourself
ASD’s assessment process guide is worth reading properly before you build a methodology. Two points from it do most of the work.
First, clarify the target maturity level with the system owner before scoping, because the Essential Eight is required to be implemented and assessed as a package. If a client has never demonstrated Maturity Level One, you do not begin an assessment against Maturity Level Two. This is the single most useful thing to have in writing when a client’s questionnaire response has “ML2” typed into it on the strength of having Conditional Access and Defender.
Second, Maturity Level Zero exists to capture cases where the Level One requirements are not met, and ASD advises achieving the same maturity level across all eight strategies before moving up. Practically, that means a client with excellent patching and no application control is not “mostly ML2”. Reporting a per-strategy result alongside a single overall level is the honest way to present it, and it also happens to be the version that sells remediation, because the weakest strategy is visible rather than averaged away.
For the cloud-heavy SMB environments most of us run, the predictable pressure points are application control on workstations, phishing-resistant multi-factor authentication once you move past Level One, centralised logging and analysis appearing at Level Two, and backups where the requirement is not that they exist but that restoration to a common point in time is tested as part of a disaster recovery exercise, and that everyday accounts cannot modify or delete them. The first and last of those are where most SMB environments genuinely sit at zero.
Doing it repeatably without building a spreadsheet monster
Every MSP that takes this seriously builds the same artefact: a workbook, forked per client, colour-coded, understood by one person. It works for about eighteen months. Then the failure modes arrive together. Client copies drift apart so results are not comparable; there is no evidence trail behind a green cell; you cannot diff this year against last year to show improvement; ASD updates the maturity model and thirty forked copies quietly go stale; and the person who built it moves on.
What repeatable actually requires is unglamorous:
- The same question set every time, versioned against a specific release of the framework.
- A per-control evidence reference — where the proof lives, not just the answer.
- A comparable score, so an assessment twelve months apart is a trend and not two opinions.
- An output a non-technical client can read without you presenting it.
- A remediation sequence with indicative costs, because “here are 40 gaps” is not a deliverable, it is a problem you have handed back.
That last point is where most assessment work fails commercially. A ranked gap list ends the meeting; a costed twelve-month plan starts a scope.
Where CyberSmart360 fits — and where it does not
Straight version first, because this reader will check. CyberSmart360 is a single-organisation assessment platform, not a multi-tenant partner console. There is no partner portal today, no view across a client base from one login, and no client switcher. If you need to manage thirty tenancies from one screen, that does not exist here yet and no amount of framing changes it.
What it does do: a structured plain-language assessment against 186 controls across the Essential Eight and the ACSC Security Principles, with every control rewritten for 44 industries — 8,184 published translations. That is 152 Essential Eight controls across Maturity Levels 1 to 3, and 34 ACSC Security Principles controls. A client in construction or accounting answers questions about their own systems rather than about executables and control panel applets. Output is a compliance score, a ranked gap report, a costed 12-month remediation plan, evidence tracking and a downloadable PDF report you can put in front of a client.
The plan limits, stated plainly so you can do the arithmetic: Detail is on the plans and pricing page. The free trial is 7 days, 1 user, 1 assessment, and does not include remediation plans.
Given that, there are two patterns that work and one that does not.
| Pattern | Assessment |
|---|---|
| Your own practice, your own subscription | Works well. One organisation, your admin plane in scope, an annual re-assessment you can diff, and a PDF you can attach to a client questionnaire or an insurance renewal. This is the highest-value use for most MSPs and it is the one clients are actually asking you to evidence. |
| The client holds the subscription, you are the second user | Works well, and is cleaner than it first appears. The assessment, the evidence and the report live in the client’s own tenancy; you do the work as their second user. It sidesteps the data-custody question, it survives you losing the account, and it means the client owns the artefact they will eventually hand to their insurer. The trade-off is that it is a cost line in their budget, not yours. |
| One subscription covering your whole client base | Does not work. Each subscription covers a single organisation, and assessments are scoped to that organisation. Running client assessments inside your own account would mix client data into your tenancy, which is the wrong answer for a security provider regardless of what the licence permits. |
If a genuine multi-tenant partner capability is what would make this useful to you, say so. That feedback shapes what gets built next, and it is more useful to us than a signup that does not fit.
The maturity-level conversation with a client who wants a tick
The client is not being unreasonable. Something arrived asking for a maturity level, they want it answered, and they do not want a project. The conversation goes better if you separate three things they have merged.
What was actually asked. Read the questionnaire. It usually specifies a level, and it usually asks for a self-assessment, not a certification. ASD states there is no requirement for Essential Eight implementations to be certified by an independent party, though independent assessment may be required by a government directive, a regulator or a contract. Establishing that the client needs a documented self-assessment rather than an audit often halves the perceived cost in the first five minutes. Where the request has come through a formal procurement, our guide to answering Essential Eight questions in government tenders is written for the client to read directly.
What is true today. Give them the per-strategy picture and the overall level. Where they sit at Maturity Level Zero on a strategy, say so and say why: usually application control or untested restores. This is where the “package” point earns its keep. You are not being difficult, you are quoting the framework.
What it would take. A dated plan with a sequence and indicative costs, aligned to their financial year. Quarterly milestones. The controls that move the needle first — multi-factor authentication coverage, patch cadence with actual timeframes, privileged account separation — ahead of the ones that take real project effort.
And accept “not this year” as an outcome, provided it is written down and signed. A documented risk acceptance is a legitimate answer under a risk-based approach; an undocumented one is your problem in two years. If the budget conversation is the blocker, our breakdown of what Essential Eight compliance costs is written for the client rather than for you, and can be sent ahead of the meeting.
Frequently asked questions
Is the Essential Eight mandatory for MSPs?
No. It is mandatory for non-corporate Commonwealth entities under the Protective Security Policy Framework. For an MSP it arrives contractually. Note that ASD’s own guidance to organisations engaging an MSP recommends the contract require the provider to implement cyber security guidance such as the Essential Eight.
Should we self-assess or bring in a third party?
Self-assessment is legitimate and is what most client questionnaires are asking for. Bring in a third party when a contract, a regulator or a government directive requires independence, when a client explicitly asks, or when the environment being assessed is one you built and manage and the finding matters commercially.
What maturity level should a typical SMB client target?
Maturity Level One across all eight strategies, unless a contract or regulator specifies otherwise. ASD advises achieving the same level across all eight before moving up, so a client scattered between Level Zero and Level Two is a Level One programme, not a Level Two one.
Can one CyberSmart360 subscription cover all my clients?
No. A subscription covers a single organisation, with 2 users and 10 assessments on Standard. The two patterns that work are assessing your own practice on your own subscription, or having the client hold a subscription with you added as the second user. There is no multi-tenant partner console today.
Does a self-assessment satisfy a client’s insurer?
That depends entirely on the insurer and the policy wording, and it is worth reading rather than assuming. What consistently helps is a dated assessment, per-control evidence references, and a remediation plan with committed dates. Insurers respond better to a documented programme in progress than to a set of ticks with nothing behind them.
Start with your own practice
If you assess one environment this quarter, assess your own. It is the one your clients are asking about, the one nobody else is auditing, and the one where a compromise is not a single incident. CyberSmart360 will take you through the Essential Eight and the ACSC Security Principles and produce a scored assessment, a ranked gap report, a costed 12-month remediation plan and a client-ready PDF. The free 7-day trial at cybersmart360.com needs no credit card and covers one user and one assessment; remediation plans are on the paid tier. Plan detail is on the plans and pricing page, and if you want the broader principles-based framework alongside the Essential Eight, we cover it in the ACSC Security Principles guide.
This article is general information about a security framework and the obligations that commonly sit around it. It is not legal, tax or professional advice, and it does not replace advice specific to your business or practice.