CyberSmart360

A desk in a modern office with a laptop displaying a government document, a cybersecurity report, glasses, a notebook, a mouse, and a coffee mug. In the background, three people work by a window overlooking a city.

It is usually about two-thirds of the way through the response schedule, between insurances and referees. “Describe your organisation’s implementation of the ASD Essential Eight, including the maturity level achieved.” There is a text box, a word limit, and a closing date that is closer than you would like.

The temptation is to write something that sounds compliant. This article is about why that is the worst option available to you, what the question is actually asking, and how to write an honest partial answer that reads as competent rather than weak. If the framework itself is new, our guide to what the Essential Eight is covers the basics in about five minutes.

Why the question is in your tender at all

The chain is short and worth understanding precisely, because it determines how much room you have.

The Protective Security Policy Framework is mandatory for Australian non-corporate Commonwealth entities — federal departments and most Commonwealth agencies — and requires them to implement Essential Eight Maturity Level Two mitigations. Corporate Commonwealth entities and wholly-owned Commonwealth companies are expected to treat the framework as better practice rather than being bound in the same way.

That obligation does not stop at the agency boundary. The PSPF states that each entity is accountable for the security risks arising from procuring goods and services, and must ensure contracted providers comply with relevant PSPF requirements. PSPF Policy 6 goes further: when developing procurement documents such as requests for tender and subsequent contracts, entities must include relevant security provisions and appropriate protections. The Department of Finance, in its guidance for suppliers, puts the same point from your side. The Commonwealth Procurement Rules require Australian Government organisations to consider and manage security risks associated with their procurements, including cyber security risk, in accordance with the PSPF.

ASD makes the underlying logic explicit in its supply chain guidance: an organisation transfers any cyber supply chain risk it holds to its customers. An agency that has to meet a baseline, and that will hand you its information, has to care what you do with it.

Here is the precise point, and it matters: the obligation binds the agency, not you. The Essential Eight is not law for a private supplier. It reaches you through a contract — which is why the requirement varies so much between one tender and the next, and why the answer to “what do we have to do” is always “read this tender”.

State, territory and local government requirements work the same way in principle but sit under their own instruments, and those instruments differ from each other, differ from the Commonwealth position, and are revised regularly. New South Wales, for example, mandates the Essential Eight for its agencies under the NSW Cyber Security Policy, while NSW councils sit under separate guidance again. Rather than work from a summary that will be out of date by the time you read it, check the current position for the jurisdiction you actually sell into.

The practical steps are the same wherever you are:

  • Find the cyber security policy or framework published by the relevant state or territory government (usually by its digital, ICT or cyber security agency) and check whether the Essential Eight is referenced, at what maturity level, and whether it applies to suppliers or only to agencies.
  • For councils, check the council’s own procurement terms. Local government is frequently covered by recommended guidance rather than a mandate, so what you are asked for is often the council’s contractual position rather than a legal obligation.
  • Read the tender, contract or supplier questionnaire in front of you as the authoritative statement of what you must meet. Agencies decide for themselves what they flow down to suppliers, so two buyers in the same state can ask you for different things.
  • Ask the buyer directly which document and which maturity level they are assessing you against, and by when. That single question resolves most ambiguity and costs nothing.

If in doubt, the safest working assumption is Essential Eight Maturity Level 1 across all eight strategies, because that is the most common baseline you will be asked to demonstrate — but confirm it rather than assume it.

Councils and private head contractors sit outside all of this. They ask because their own clients, insurers or risk committees have asked them, and they frequently copy the wording from a Commonwealth or state document without the surrounding context. That is worth knowing because a council questionnaire is often more negotiable than a Commonwealth one. We cover the general position in is the Essential Eight mandatory?.

Three different questions that look identical

Before writing anything, work out which of these you have been handed. They carry very different obligations and very different risk.

What it isWhat it means for you
Self-assessmentYou describe your position in your own words, usually stating a maturity level or a per-strategy position. Most common in tenders under moderate value or where you will not hold classified information.Lowest burden, but not low stakes — your description becomes part of your tender response and is usually warranted as accurate. Keep the working behind it.
AttestationA signed statement, often by a director or authorised officer, confirming a specific position. Sometimes a schedule to be executed rather than a text box.Materially higher stakes. Someone is putting their name to it. Do not sign an attestation drafted more optimistically than the evidence supports, and do not sign one describing a level nobody in the business has assessed.
EvidenceArtefacts must be provided with the response or on request — an assessment report, policies, configuration evidence, or a third-party assessment.Highest burden and, oddly, the easiest to answer honestly, because there is nowhere to be vague. If you have done the work you can supply it; if you have not, the gap is visible immediately.

One further distinction worth checking: whether the tender asks for a self-assessment or for an independent assessment. ASD states there is no requirement for an Essential Eight implementation to be certified by an independent party, although an implementation may need to be assessed by one where required by a government directive, a regulatory authority or a contract. Establishing which you have been asked for can halve the perceived cost of responding.

What “evidence” usually means in practice

Suppliers often assume evidence means a certificate. It rarely does. What an evaluator is generally looking for is that a considered process happened and produced records.

  • A dated assessment against the Essential Eight, showing a position per strategy rather than a single headline claim.
  • Evidence that multi-factor authentication is enforced across all users, not merely available: a configuration or policy export, or a screenshot of the enforcement setting.
  • A patching approach with actual timeframes, and something showing it is being met rather than aspired to.
  • A backup schedule, the date of the last tested restore, and what the test showed.
  • A current list of who holds administrative access, and the process for granting it.
  • Your approved software position and how it is enforced on workstations.
  • An incident response plan, with named roles and who gets called.
  • A remediation plan for anything not yet in place, with dates and an owner against each item.
  • Who performed the assessment, when, and whether it was internal or independent.

That last item matters more than suppliers expect. An assessment declared as internal and dated is credible. An undated assessment of unclear origin invites the follow-up question you least want.

Why overstating your position is the worst available option

An optimistic answer feels like the safe commercial choice at 4pm on the day before close. It is not, because it fails in three predictable ways and each of them arrives after you have already committed resources.

The first is the audit. Government contracts commonly include a right to audit or to require evidence during the term. The claim you made in the response schedule is the thing that gets tested, and by then you are the incumbent with staff allocated.

The second is the incident. If something happens while you hold agency information, the response schedule becomes a document about what you said you had in place. That is a much harder conversation than the one about the incident itself.

The third is the next tender. Panel arrangements and repeat procurement mean the same agency reads your answers again in two years. An answer that has silently improved without any work being done is noticed, and unlike the other two failure modes this one costs you the relationship without any incident at all.

Read your tender conditions on this point rather than relying on general statements. Responses are typically given with a warranty that the information is accurate, and the consequences of inaccuracy, from exclusion from evaluation to termination, sit in the conditions of tender themselves. They are usually shorter and clearer than people expect.

The commercial point underneath all of this: evaluators are not scoring you against perfection. They are scoring you against the other respondents, most of whom are in a comparable position, and against a risk judgement about whether you can be relied upon. A candid partial answer with a plan reads as a business that knows what it is doing. An unsupported “yes, we are compliant” reads as a business that has not looked.

What a credible partial answer looks like

Structure it in three parts, in this order, and keep it factual.

Current position. State it per strategy, with a date, and be specific about method. “As at 12 August 2026 we completed an internal self-assessment against the ACSC Essential Eight maturity model, targeting Maturity Level 1. We meet the Level 1 requirements for six of the eight mitigation strategies. We do not currently meet them for application control or user application hardening.”

What is in place, with evidence available. “Multi-factor authentication is enforced for all users across email, our file storage and our line-of-business system. Operating system and application patching is managed with automatic updates and monitored monthly. Backups run daily, cover applications and settings, and were last restore-tested on 3 July 2026. Administrative access is held by two staff, each with a separate administrator account. Evidence of each can be provided on request.”

What is scheduled, with dates and an owner. “Application control is scheduled for implementation across all workstations by 31 March 2027, with device management to be deployed by 30 November 2026 as a prerequisite. Both items are owned by the Operations Manager and funded in the current financial year.”

Three sentences per part, no adjectives, dates on everything. That is a stronger response than a paragraph asserting compliance, because every claim in it is checkable and the gaps are stated rather than found.

Answering when you cannot answer well yet

Sometimes the honest position is that you have never assessed yourself and the tender closes on Friday. That is more common than the industry admits and it is still answerable.

  • Say what you actually have. Most businesses already meet several Level 1 requirements without knowing it: multi-factor authentication, automatic updates, supported operating systems, a backup that runs. Describe those specifically rather than claiming a level.
  • Do not invent a maturity level. A stated level is a specific technical claim against a published model, and it is the single easiest thing for an evaluator to test. If you have not assessed, say you have not assessed and give a date by which you will have.
  • Do not write “our IT provider manages this” unless you know what they manage. Ask them, in writing, before the response goes in. It is a common answer and it collapses immediately under a follow-up question.
  • Use the tender Q&A process. Asking the contact officer to clarify what maturity level is expected, and whether a self-assessment is sufficient, is normal, permitted and does not count against you. It occasionally reveals that the requirement is softer than the wording suggested.
  • Commit to a date and mean it. “We will complete a documented Essential Eight self-assessment by 30 September 2026 and provide the results on request” is a real answer. It is assessable, and if you win the work it becomes a commitment you can meet.

One reassurance while you are in the tender documents: the Department of Finance states you do not need to hold a security clearance to respond to tenders for Australian Government work, and that there are many opportunities that carry no particular personnel security requirements. Personnel needing ongoing access to security classified resources is a different situation. Suppliers regularly self-exclude from work they were eligible for because they conflated the two.

Where CyberSmart360 fits

Tender security schedules arrive on a deadline and ask a question that takes structured work to answer. A dated assessment already sitting on file turns that into a copy-and-paste. CyberSmart360 works through 186 controls across the Essential Eight and the ACSC Security Principles, translated for 44 industries, and produces a compliance score, a gap report ranked by priority, evidence tracking against each control and a costed 12-month remediation plan, in a dated PDF report you can attach to the response. That gives you both halves of a credible answer: a defensible current position and a funded forward plan. Our Maturity Level 1 guide sets out what it measures against.

Frequently asked questions

Do we need a security clearance to bid for government work?

Not generally. The Department of Finance states you do not need a security clearance to respond to tenders for Australian Government work, and that many opportunities carry no particular personnel security requirements. Clearances are required where personnel need ongoing access to security classified resources.

Do we need to be certified against the Essential Eight?

ASD states there is no requirement for an Essential Eight implementation to be certified by an independent party. An independent assessment may be required by a government directive, a regulator or a contract, so read the schedule. Most tenders at small business scale ask for a self-assessment.

What maturity level will a tender ask for?

It varies by agency, by jurisdiction and by what information you will hold. Maturity Level Two is the mandatory baseline for non-corporate Commonwealth entities themselves, but that is not automatically what a supplier is asked for. Where a schedule does not state a level, Level 1 is the sensible position to assess and report against, and it is worth asking the contact officer.

Can we win work with a partial answer?

Frequently, yes — unless the schedule sets a stated level as a mandatory condition of participation, which it will say explicitly. Evaluators are making a risk judgement, and a specific, dated, evidenced partial position with a funded plan compares well against vague assurances from other respondents.

What if our IT is fully outsourced?

You are still the respondent and the obligation is still yours. Ask your provider in writing which controls they manage, which remain yours, and what evidence they can supply. Attribute accurately in the response. An evaluator would rather read “our provider manages patching and backups; access control and device policy are managed in-house” than a blanket claim nobody can substantiate.

Assess before the schedule arrives, not after

Security schedules do not come with generous timeframes, and the worst version of this work is doing it in the week before close. Assess once, date it, keep the report, refresh it annually. Every tender after that reuses the same evidence. The free 7-day trial at cybersmart360.com needs no credit card and gives you one user and one assessment. Detail is on the plans and pricing page..

This article is general information about responding to security requirements in procurement. It is not legal advice, and it does not replace reading the conditions of the tender you are responding to.

Related Post

The Essential Eight for Accounting Practices: Client Data, Obligations and Where to Start

A twelve-person accounting practice holds something almost no other business of that size holds: several…

The Essential Eight for Builders and Construction Firms

The tender pack lands, and somewhere behind the insurances, the safety management plan and the…

Do You Need a Consultant for the Essential Eight?

Sometimes yes. The honest answer depends on your environment, not on which option you found…