
Short answer: There is no published price for Essential Eight compliance, so this guide covers cost drivers and effort, not dollar figures. The Essential Eight is free guidance from the Australian Signals Directorate (ASD). Your spend is the effort to implement and prove the controls, which grows with each maturity level and is usually heaviest for application control and privileged access.
Related guides:
Key takeaways
- The Essential Eight Maturity Model itself costs nothing. You pay in staff time, tools, consultant help and, if you choose one, an independent assessment.
- ASD advises reaching the same maturity level across all eight strategies before moving up, so your budget is set by your weakest strategy, not your strongest.
- In our relative estimate, patching, backups and Office macro settings are the easiest to lift, while application control and restrict administrative privileges take the most effort. ASD's Commonwealth data shows government entities also lag on those two.
- Maturity Level Two requires phishing-resistant multi-factor authentication for users of online services, plus timely analysis of event logs. Maturity Level Three widens scope to more servers, drivers and log sources, adding ongoing operational work.
- Budget per strategy and per level with the worksheet below, rather than looking for a single quoted price.
What drives Essential Eight compliance cost and effort?
Essential Eight compliance cost depends mainly on your target maturity level, environment size, legacy technology and how you prove compliance.
The eight mitigation strategies in ASD's Essential Eight Maturity Model are patch applications, patch operating systems, multi-factor authentication, restrict administrative privileges, application control, restrict Microsoft Office macros, user application hardening and regular backups. The page was last updated on 27 November 2023, and that version is still the published model at the time of writing (5 October 2026). It defines Maturity Level Zero through Three, each resisting a more capable adversary: opportunistic commodity attackers at Level One, attackers who try to bypass weak MFA at Level Two, and adaptive attackers who steal tokens and pivot through networks at Level Three.
These factors move your cost the most:
- Target maturity level. Each level expands scope (more systems) and depth (stricter settings, logging and review).
- Endpoint and server count. Ten laptops on one operating system is a different job from hundreds of mixed devices.
- Legacy and unsupported software. Anything that cannot be patched or hardened must be replaced, isolated or risk-accepted.
- Existing tooling. If your current platforms support the required settings, much of the work is configuration, not purchase.
- Internal skills. Gaps in application control or privileged access expertise may need contractors.
- Evidence and assessment. Proving controls work through testing takes time every cycle.
A note on timing: on 15 June 2026 ASD opened consultation on evolving the Essential Eight into a broader "Essentials" series, starting with a chapter called Essentials for Enterprise IT. Feedback closed on 12 July 2026, and ASD states that organisations already using the Essential Eight can expect strong alignment with their existing controls and investments. Until replacement guidance is final, plan against the published maturity model.
Which strategies take the most effort? Our relative estimate
In our judgement, application control and restrict administrative privileges take the most effort, while patching, backups and macro settings are the easiest to lift to Maturity Level One.
ASD's data points the same way. Under the Protective Security Policy Framework, non-corporate Commonwealth entities must implement all eight strategies to at least Maturity Level Two. Yet in ASD's Commonwealth Cyber Security Posture in 2025 report, 46 percent of surveyed entities were at Level Two or above for restrict administrative privileges and 48 percent for application control, compared with 67 percent for patch applications. Only 22 percent reached Level Two overall, up from 15 percent in 2024.
The table below is our relative effort estimate, not ASD guidance. It assumes a Windows-centric SMB or SaaS company with cloud identity and managed endpoints, and your tiers will differ.
| Strategy | Cost drivers | Our estimate: ML1 | Our estimate: ML2 | Our estimate: ML3 |
|---|---|---|---|---|
| Patch applications | Vulnerability scanning, software inventory, removing unsupported apps, testing updates | Low | Medium | Medium |
| Patch operating systems | Endpoint management, server maintenance windows, replacing end-of-life OS versions, firmware and drivers at ML3 | Low | Medium | High |
| Multi-factor authentication | Identity provider licensing, phishing-resistant authenticators such as security keys, coverage of all users and data repositories | Low | Medium | High |
| Restrict administrative privileges | Separate admin accounts, access reviews, jump servers, just-in-time admin and secure admin workstations at ML3 | Medium | High | High |
| Application control | Allowlisting tooling, rule design, exception process, servers in scope at ML2 and ML3, ongoing rule maintenance | Medium | High | High |
| Restrict Microsoft Office macros | Inventory of business macros, policy settings, code signing and trusted publishers at ML3 | Low | Low | Medium |
| User application hardening | Browser and Office hardening policies, PowerShell logging, removing legacy components at ML3 | Low | Medium | Medium |
| Regular backups | Backup platform, immutability, access separation, restoration testing | Low | Medium | Medium |
Our reasoning: strategies that are mostly configuration of tools you already own tend to stay cheaper. Strategies that change how people work, such as who can install software or hold admin rights, need design, testing, exception handling and support.
How does effort change from Maturity Level One to Three?
Each level in the November 2023 model adds both more systems in scope and more ongoing work to operate the controls, so expect effort to rise at every step.
Maturity Level One is mostly a hardening project: application control on workstations, MFA on online services, separate admin accounts and defined patch timeframes. A small, modern environment can often do this with existing tooling.
Maturity Level Two is where operating effort appears. The model requires event logs, such as those from internet-facing servers, to be analysed in a timely manner to detect cybersecurity events. MFA for users of online services must be phishing-resistant (Level Three extends this to systems and data repositories), periodic revalidation of privileged access is required (see the November 2023 model for the exact level-by-level wording), and application control extends to internet-facing servers. In our view, this is the point where you need someone, or a service, to watch the logs.
Maturity Level Three widens scope again. Application control reaches non-internet-facing servers and drivers, administration moves to just-in-time access and secure admin workstations, patch timeframes tighten for more software, and logs from servers and workstations must be analysed in a timely way. Consider whether Level Three is justified for your highest-value systems or required by customers.
To weigh the investment, see our guide to the cost of non-compliance.
Where does the budget go: tooling, people or assessment?
Your budget splits across tooling, people time, assessment and indirect costs. The balance depends on what you already own and the skills on your team.
Tooling. Check what you already license first. Common needs are endpoint management for application control and hardening, a vulnerability scanner, phishing-resistant MFA, log analysis from Level Two, privileged access tooling at Level Three and immutable backups.
People. Expect effort in design (rules, exceptions), rollout (pilots, user support) and operation (patch cycles, access reviews, log triage).
Assessment and evidence. ASD's Essential Eight Assessment Process Guide, last updated October 2024, ranks evidence from excellent (testing a control with a simulated activity) through good and fair down to poor (a policy or verbal statement of intent). Gathering good or excellent evidence across a representative sample of workstations, servers and network devices takes time. The guide names tools that can help, including ASD's Essential Eight Maturity Verification Tool and free vulnerability scanners.
Indirect costs. Plan for hardware refreshes, legacy application replacements and rollout productivity loss. In the Commonwealth posture report, entities said the most significant reasons for continued use of legacy IT were a lack of dedicated funding and a lack of a viable replacement.
Do you need an external Essential Eight assessment?
Usually not by law: ASD states there is no requirement to have an Essential Eight implementation certified by an independent party unless a government or regulatory requirement says otherwise.
That leaves three practical options:
| Approach | When it fits | Cost profile |
|---|---|---|
| Internal self-assessment | Early gap analysis, tracking progress, low external pressure | Staff time only, lowest cash cost |
| Internal assessment with external spot check | You need credibility with customers but have in-house skills | Moderate, scoped consultant time |
| Independent external assessment | Government contracts, enterprise or healthcare buyers asking for third-party assurance | Highest, repeats on a cycle |
If a government agency or enterprise customer asks for your Essential Eight maturity in a questionnaire or contract, ask early whether a self-assessment is acceptable or whether they expect independent assurance. Cyber insurers may also ask about controls such as MFA and backups, but requirements vary, so check your own policy.
How should you budget and sequence the work?
Budget per strategy and per maturity level, reach Level One across all eight first, then fund the next level based on risk and customer demand.
A practical sequence for an SMB or SaaS company:
- Run a gap assessment and record your real level for every strategy.
- Fix the cheap wins: patching cadence, macro settings, backups and MFA on online services.
- Start the hard two early at Level One: separate admin accounts and workstation application control.
- Close Level One across all eight before starting Level Two work, in line with ASD's guidance.
- Plan Level Two operations: logging, analysis and phishing-resistant MFA, then extend application control to internet-facing servers.
- Decide on Level Three by system, focusing on crown-jewel assets and customer requirements.
Use this worksheet to build your estimate. Fill in your own numbers for each row.
| Strategy | Current level | Target level | Tooling to buy or upgrade | Internal hours | External help (days) | Indirect costs (hardware, replacements) | Annual run cost |
|---|---|---|---|---|---|---|---|
| Patch applications | |||||||
| Patch operating systems | |||||||
| Multi-factor authentication | |||||||
| Restrict administrative privileges | |||||||
| Application control | |||||||
| Restrict Office macros | |||||||
| User application hardening | |||||||
| Regular backups | |||||||
| Assessment and evidence |
Add a contingency line for legacy surprises. HealthTech teams should also align this budget with privacy obligations; our guide to the Australian Privacy Principles for small business explains when the Privacy Act applies.
How SecureSlate helps
SecureSlate lets you track the Essential Eight as a framework in a single control library, with each strategy's controls and evidence in one place. Automated evidence collection and stored evidence, such as MFA settings and admin access reviews, can be mapped to each requirement, and the risk register helps you track gaps you have not closed yet. Controls can be mapped to other frameworks you run, such as ISO 27001 or SOC 2, and exports of your evidence help you prepare for an assessment.
Start your free SecureSlate trial to track your Essential Eight controls and evidence in one place.
FAQ
How much will the Essential Eight cost my business?
There is no set price. The framework is free, and your cost depends on target maturity level, environment size, legacy technology and whether you use external assessors. Estimate it per strategy with the worksheet above.
Which Essential Eight strategy is the most expensive?
In our relative estimate, application control and restrict administrative privileges need the most design, tooling and change management. ASD's 2025 Commonwealth posture report shows both had among the lowest rates of Maturity Level Two achievement among surveyed Commonwealth entities.
Is Essential Eight Maturity Level One enough?
It depends on your threat profile and customers. Level One defends against opportunistic attacks using commodity tradecraft. ASD advises choosing a target level that suits your environment. Non-corporate Commonwealth entities must reach at least Level Two, so check what your government or enterprise customers expect.
Will the Essential Eight be replaced?
ASD consulted in June and July 2026 on evolving it into an Essentials series, starting with Essentials for Enterprise IT. ASD says existing Essential Eight investments will align strongly with the new guidance, so work done now is not wasted.
Disclaimer (legal note)
This article is for general information only and is not legal, regulatory or professional advice. Requirements vary by framework, industry and jurisdiction. Consult qualified advisors for your specific obligations.
Need compliance without the complexity?
SecureSlate automates ISO 27001, SOC 2, GDPR, HIPAA, and more. Built for growing teams. See it in action.
Find compliance gaps in 30 seconds