Sometimes yes. The honest answer depends on your environment, not on which option you found first, and there are situations where a platform is the wrong tool and we will say so plainly below.
CyberSmart360 sells a self-service assessment platform, so read this knowing that. The reason it is worth writing fairly is that a business which engages a consultant for the right reasons has a good outcome, and a business that buys software when it needed an engineer has a bad one that eventually becomes our problem too. If the framework is unfamiliar, start with our guide to what the Essential Eight is.
The question underneath the question
You are not choosing a supplier. You are deciding who does which of three genuinely different jobs.
| The job | What it involves | Typically done well by |
|---|---|---|
| Assessment | Establishing where you stand against each requirement, with a record of what you found and when. | A platform, for a straightforward environment. A consultant, where the environment is complex or where independence is required. |
| Remediation | Actually configuring, buying, replacing and building — device management, application control rulesets, backup architecture, hardware. | A consultant or your IT provider. No assessment platform does this, including ours. |
| Maintenance | Keeping patch timeframes met, testing restores, reviewing access, re-assessing annually as the model is updated. | Your own people, or a managed service. This is where most one-off projects quietly unravel. |
Most bad outcomes come from buying one and assuming it covers the others. A consultant engagement that ends at a report leaves you with remediation you have not scoped. A platform subscription leaves you with a plan nobody has been asked to execute. Neither is a failure of the thing you bought; it is a failure to say what you were buying it for.
When a consultant is the right answer
Genuinely, and in these situations do not let cost talk you out of it.
- You run your own infrastructure. Servers, a domain, on-premises line-of-business applications, site-to-site connectivity, legacy systems that cannot be updated without breaking something. Almost every hard question in the Essential Eight becomes an engineering question in this environment, and engineering questions need an engineer.
- You have an incident in progress or suspect one. Stop reading about frameworks. Get incident response help, and report it. ASD operates the Australian Cyber Security Hotline on 1300 CYBER1. Assessment comes afterwards.
- A contract, regulator or government directive requires an independent assessment. ASD states there is no general requirement for an Essential Eight implementation to be certified by an independent party, but it also states that independent assessment may be required by a government directive, a regulatory authority or a contract. If yours does, a self-assessment does not satisfy it, whoever produced it.
- You are targeting Maturity Level 2 or 3. The requirements above Level 1 pull in phishing-resistant multi-factor authentication, centralised logging and analysis, privileged access management and driver control. These are design problems, not settings.
- There is nobody internally who will own it. Not “nobody technical” — nobody who will be accountable for it finishing. A platform gives that person structure; it cannot be that person.
- Your environment is complex for its size. Multiple sites, a recent acquisition, two identity systems that half-merged, an industry-specific application nobody fully understands. Complexity, not headcount, is what determines difficulty here.
- You need someone to argue with. A good consultant will tell you your target maturity level is wrong, or that a control your board wants is not worth the disruption. Software will not do that.
A well-scoped consulting engagement in these circumstances is good value, and nothing below is an argument against it.
When a self-service platform is enough
- Your systems are predominantly managed cloud services. Email, file storage, accounting and your main line-of-business application are subscriptions someone else patches. A large share of the framework is then configuration you can verify and change yourself.
- You have never formally assessed and need to know where you stand. The first assessment is mostly discovery, and discovery does not require a specialist — it requires a structured question set and honest answers.
- Something external has asked and you need a documented position. A tender schedule, an insurance proposal form, a client questionnaire. What is wanted is usually a dated self-assessment with evidence, not an audit.
- You need to budget before you commit. Deciding what to spend requires knowing what the gaps are and roughly what each costs, which is an assessment problem, and it is cheaper to solve before you brief anyone.
- You are targeting Maturity Level 1 and someone will own the work. Level 1 is largely configuration and habit, plus two or three items that need real effort.
When doing it entirely yourself makes sense
If you are technically capable, the business is small, and everything runs in cloud services, you can work through the ACSC maturity model directly and implement most of Level 1 without buying anything. It is free, ASD publishes the requirements openly, and there is nothing dishonourable about it.
The two failure modes are consistent enough to predict. It stalls: the quick controls get done, application control and device management do not, and the effort ends part-complete. And nothing is documented, so when the client questionnaire arrives you have improved your security and cannot demonstrate it. If you go this route, the mitigation is to write down what you did and when, in whatever form you will genuinely maintain. Our Maturity Level 1 guide sets out every requirement if you want to work through it yourself.
The hybrid path, which is the right answer more often than either extreme
Assess first with a platform. Take the result to a consultant or your IT provider as a defined scope of work.
This is better than either pure option for reasons that have nothing to do with who sells what.
- Your quotes become comparable. Three providers quoting against the same specific gap list are quoting the same job. Three providers quoting against “we need to do the Essential Eight” are quoting three different jobs, and the cheapest is usually the smallest.
- The engagement is bounded. Open-ended discovery is the most expensive phase of any consulting engagement and the one you are least equipped to supervise. Doing the discovery yourself removes it.
- You keep the assessment. When the engagement ends, the record of where you started and what was found stays with you, in a form you can update next year rather than re-purchase.
- You can tell whether the work was delivered. A per-control record before and after is the only practical way a non-technical owner verifies that what was quoted was done.
- It handles the independence problem. Where the party assessing is also the party being assessed — your IT provider reviewing systems it built — that should be declared, not hidden. Splitting assessment from remediation makes the declaration unnecessary.
What to hand a provider: the gap report showing the position on each requirement, the target maturity level, the date of the assessment, what you have already fixed, what you want them to do and what you will keep in-house. That brief takes an afternoon to produce and it changes the quality of the response you get.
What this costs, and why there is no number here
Consulting engagements for this work vary enormously, and the variation is driven by your starting position rather than by the framework: how many devices, whether you run your own servers, what your existing licensing already covers, how much hardware is too old to support current software, and how much of the remediation you will do yourself. A figure quoted without reference to those is not an estimate.
We are not going to publish a consultant price range we cannot substantiate, and you should be sceptical of vendor pages that do — a wide range presented next to a subscription price is a rhetorical device, not information.
What is worth doing before you talk to anyone is understanding what drives the number, which we set out in what Essential Eight compliance costs — including the questions to ask a provider so the quotes you receive are comparable.
What CyberSmart360 does, and what it does not
Price first. A free 7-day trial, no credit card, one user and one assessment. Detail is on the plans and pricing page.
What it does: takes you through 186 controls across the Essential Eight and the ACSC Security Principles, translated for 44 industries, at whichever maturity level you are targeting. It produces a compliance score, a gap report ranked by priority, evidence tracking against each control, a costed 12-month remediation plan, and a dated PDF report you can send to a client, an insurer or a tender panel.
What it does not do: any of the remediation. It will not configure multi-factor authentication, build an application control ruleset, deploy device management, design a backup architecture or replace a machine running an unsupported operating system. It is not an independent assessment and does not satisfy a requirement for one. It gives you no one to ring at 2am. And it does not remove the need for someone in your business to own the work.
If you finish reading and conclude you need a consultant, that is a legitimate outcome of this article. Consider running the free trial first anyway. Arriving at that conversation with a per-control position and a prioritised list changes it from a discovery exercise you are paying for into a scoped piece of work you can evaluate.
Frequently asked questions
Is a consultant assessment more credible than a self-assessment?
For most purposes, no, provided the self-assessment is dated, evidenced and declared as a self-assessment. ASD states there is no general requirement for independent certification. Where a contract, regulator or government directive specifically requires independent assessment, that is a different question and a self-assessment will not do.
Can our existing IT provider do this?
Often, and they have an advantage: they already know the environment. Two things to settle first. Ask whether they have done Essential Eight work before or are learning on your time. That is a fair question, fairly asked. And recognise that they will be assessing systems they built and manage, which should be declared in the report rather than left unsaid.
Can we start with a platform and bring in a consultant later?
That is the hybrid path above, and for a small business on managed cloud services it is usually the best sequence. Assess, prioritise, do the parts you can, then engage help for the parts you cannot, with a defined scope.
What if we need Maturity Level 2?
You can assess against Level 2 on a platform. Note, though, ASD’s guidance that you should not be assessed against Level 2 until Level 1 has been demonstrated, and that the framework should be implemented and assessed as a package. Reaching Level 2 in most small environments involves design work that benefits from a specialist.
How long does an assessment take?
A self-service assessment of a straightforward small business environment is a task for an afternoon, provided you know what systems you have and who has access to them. If you do not, finding out is the first real piece of work and it is worth doing regardless of which route you take.
Whichever route you take, start with the assessment
Every option here works better when you know where you stand. The most expensive version of this project is committing money before that. The free 7-day trial at cybersmart360.com needs no credit card and covers one user and one assessment. If the result tells you the job is bigger than a subscription, you will have a document that makes the next conversation a good deal shorter. Pricing detail is on the plans and pricing page.
This article is general information about a security framework and the obligations that commonly sit around it. It is not legal, tax or professional advice, and it does not replace advice specific to your business or practice.