Essential Eight compliance assessments for Australian small businesses

Understand where your cyber security stands, find your gaps, and get a step-by-step plan to close them — without hiring a consultant or learning to speak IT.

The Essential Eight — what and why

What is the Essential Eight, and why does your business need it?

The Essential Eight is a set of baseline security strategies from the Australian Signals Directorate (ASD) and its Australian Cyber Security Centre (ACSC). They’re designed to protect organisations against the most common cyber threats — ransomware, data breaches and unauthorised access among them. The maturity model runs across three levels, ML1 to ML3, so you can lift your security step by step rather than all at once.

For small businesses, the Essential Eight matters because it’s being asked for more and more. Some government tenders and contracts now require suppliers to demonstrate Essential Eight controls at a specified maturity level. Many cyber insurers want to see evidence of the controls it covers — multi-factor authentication, patching, backups — before they’ll issue or renew a policy, and some ask about the Essential Eight directly. And with cybercrime costing the average Australian small business $56,600 per reported incident (ASD Annual Cyber Threat Report 2024–25, self-reported), a structured approach to security is simply sensible risk management.

The catch is that the framework was written for IT security professionals. CyberSmart360 turns it into language and workflows built for business owners. The platform also supports assessments against the ACSC Security Principles, with more frameworks to follow.

Assessment approach

How a CyberSmart360 assessment works

The process is built so a non-technical business owner can complete a thorough assessment without outside help. Here’s what happens from start to finish.

STEP 1 — Create your organisation
Sign up, enter your business details (name, ABN/ACN, industry, location), and your account is ready. About two minutes.

STEP 2 — Choose your maturity level
Pick the Essential Eight maturity level you’re assessing against — ML1, ML2 or ML3. Not sure? ML1 is the right starting point for most small businesses, and the platform explains the differences so you can choose with confidence.

STEP 3 — Complete the guided assessment
Work through the 8 assessment domains, one at a time. Every question is in plain language, with context-sensitive help and examples from your industry. Answer Yes, Partially, No or Not Applicable, with room for notes. It auto-saves every 30 seconds.

STEP 4 — Receive your AI-powered analysis
Submit your assessment and get your results in about 60 seconds: your overall compliance score (0–100%), your maturity level, every gap identified, and an executive summary in plain English.

STEP 5 — Review your remediation plan
Your AI-generated 12-month action plan lays out every task needed to close your gaps, ranked by risk. Each one comes with a cost estimate, a timeframe, and clear guidance on whether it’s a job you can do yourself or one worth handing to a professional.

STEP 6 — Track, reassess, improve
As you work through the plan, follow your progress on the dashboard. Reassess to measure how far you’ve come, and weekly email summaries keep you on track.

What you get

Your assessment deliverables

Compliance score and gap analysis

A clear score from 0–100%, broken down by each Essential Eight domain. See exactly where you're compliant and where the gaps are, ranked by severity.

12-month remediation roadmap

A prioritised action plan with realistic cost estimates, timeframes, and DIY-versus-professional flags. Know what to tackle first and what to schedule for later.

AI-generated how-to guides

Step-by-step implementation guidance for every non-compliant control, written in plain language so you or your team can act on it directly.

Professional PDF report

An audit-ready compliance report suitable for government contracts, cyber insurance applications and board reporting. Generated in under 30 seconds.

Who this is for

Built for the businesses consultants overlook

CyberSmart360 is made for Australian small and medium businesses — the ones that need to be show compliance with a cybersecurity framework like Essential Eight but can’t justify $5,000 to $15,000 for a consultant engagement.

Trades and construction

Builders, electricians, plumbers and trades businesses that need Essential Eight compliance for government contracts and subcontracting requirements. You haven't got an IT department. You just need to get compliant and prove it.

Professional services

Accountants, lawyers, financial planners and consultants handling sensitive client data. Your clients trust you with their information, and your insurer wants evidence you're protecting it. CyberSmart360 gives you the compliance evidence without the compliance headache.

Healthcare and allied health

GP practices, dental clinics, physio practices and allied health providers with patient-data obligations. Understand where your security stands and show your position to insurers and other parties who ask.

Comparison

Essential Eight assessment: self-service platform vs traditional consultant

CyberSmart360 Traditional Consultant
Cost
$89/month
$5,000–$15,000 per assessment
Time to results
Under 2 hours
2–6 weeks
Expertise required
None — plain-language guidance
You need to explain your business to them
Reassessments
Included — reassess as you improve
Additional engagement, additional cost
Remediation plan
AI-generated, included
Often a separate deliverable at extra cost
Ongoing tracking
Built-in dashboard and reminders
Typically not included
Availability
Anytime, day or night
Consultant’s schedule

Frequently asked questions

Q: Do I need cyber security expertise to use CyberSmart360?
No. The platform is built for non-technical users. Every question comes with plain-language explanations and industry-specific examples. If you can answer questions about how your business uses technology, you can complete the assessment.

Q: How long does an assessment take?
Most people finish their first assessment in under two hours. You can save and come back any time — it auto-saves as you go.

Q: Will this satisfy my government tender or contract requirements?
CyberSmart360 provides assessments against the ACSC Essential Eight at all three maturity levels and generates audit-ready reports suitable for government contract submissions. Requirements vary between contracts, so we recommend confirming your specific contract’s exact compliance requirements.

Q: Can I reassess after making improvements?
Yes. Reassess to track your progress — we suggest doing it quarterly, or after you’ve completed significant remediation tasks.

Q: What frameworks do you support?
CyberSmart360 currently supports the ACSC Essential Eight (Maturity Levels 1, 2 and 3) and the ACSC Security Principles. Additional frameworks, including SMB-1001, ISO 27001, PCI-DSS and the ASD ISM, are on our roadmap.

Find out where you stand

Your first assessment is free for 7 days, with no credit card required. Complete it in under two hours and come away with your compliance score, your maturity level and a clear gap analysis — so you know exactly where you stand before you decide anything.