Skip to main content
NOVACompliance

Frameworks

Available now

Essential Eight

Eight prioritised mitigation strategies published by the Australian Cyber Security Centre, assessed by maturity level.

Overview

The Essential Eight is a set of prioritised mitigation strategies that make it substantially harder for adversaries to compromise systems.

Each strategy is assessed against maturity levels, so an organisation reports where it sits rather than simply whether a control exists. Maturity is expected to be achieved consistently across all eight strategies rather than unevenly.

It is widely used in Australian government supply chains and increasingly requested by private-sector buyers.

Who this is for

  • Australian organisations and their suppliers
  • Entities responding to government procurement requirements
  • Teams that want a concrete technical baseline before broader certification

Governance areas

Application control

Preventing execution of unapproved applications and scripts.

Patching

Applications and operating systems patched within defined timeframes.

Configuration hardening

Macro settings and user application hardening applied consistently.

Administrative privileges

Restricting, reviewing and monitoring privileged access.

Authentication and recovery

Multi-factor authentication and regular, tested backups.

How NOVA supports this framework

  • Record the target maturity level and the current assessed level per strategy
  • Hold configuration and patching evidence against the strategy it supports
  • Track uplift actions with owners and due dates
  • Report maturity progression over time from the evidence record

Controls and evidence focus

  • Patch compliance reporting with the date range it covers
  • Backup test results including restoration verification
  • Privileged access reviews with the approver recorded
  • Application control and macro configuration baselines

Cross-framework reuse

Technical evidence supports ISO/IEC 27001 technological controls

Backup, patching and access evidence is reusable for SOC 2 security criteria

NOVA assists with readiness and evidence management. Certification, attestation and regulatory conclusions remain with authorised independent, regulatory or customer-appointed parties.

Structure

The eight mitigation strategies

The Australian Cyber Security Centre groups the eight strategies by the outcome they support. Maturity is expected to be achieved consistently across all eight rather than unevenly.

1

Application control

Prevent execution of unapproved applications, scripts, installers and drivers.

2

Patch applications

Apply patches to internet-facing and other applications within defined timeframes.

3

Configure macro settings

Restrict Microsoft Office macros to vetted sources and block them from the internet.

4

User application hardening

Harden browsers and common applications by disabling risky features.

5

Restrict administrative privileges

Limit, validate and regularly review privileged access to what the role requires.

6

Patch operating systems

Apply operating system patches within the timeframe set for the risk level.

7

Multi-factor authentication

Require multi-factor authentication for remote access and privileged actions.

8

Regular backups

Back up data, software and configuration, and test restoration regularly.

Assessment

Maturity levels

Each strategy is assessed against a maturity level rather than a simple present-or-absent test. NOVA records the target level and the current assessed level per strategy.

  1. 0

    Maturity Level Zero

    Weaknesses remain that an adversary could readily exploit. The strategy is not aligned to the intent of the model.

  2. 1

    Maturity Level One

    Partly aligned with the intent of the strategy, addressing adversaries using widely available techniques.

  3. 2

    Maturity Level Two

    Mostly aligned, addressing adversaries prepared to invest more time and to work around weaker controls.

  4. 3

    Maturity Level Three

    Fully aligned, addressing adaptive adversaries who target specific weaknesses and privileged credentials.

Evidence

Typical evidence held in NOVA

Essential Eight evidence is largely technical and time-bound, so the date range each artefact covers is recorded alongside it.

ArtefactTypical sourceExpected cadence
Patch compliance reportEndpoint or patch toolingMonthly
Application control baselineConfiguration exportOn change
Macro and browser hardening settingsConfiguration exportQuarterly
Privileged access reviewIdentity provider exportQuarterly
Multi-factor coverage reportIdentity provider exportMonthly
Backup restoration testManual upload with resultQuarterly

NOVA supports the readiness decision. Final launch and risk decisions remain human decisions.

How it runs

Working through Essential Eight in NOVA

  1. Step 1

    Set the target

    Agree the maturity level required by your buyers or obligations, per strategy.

  2. Step 2

    Assess current state

    Record the current assessed level with the evidence that supports it.

  3. Step 3

    Plan uplift

    Raise uplift actions with owners and due dates for each gap between current and target.

  4. Step 4

    Evidence continuously

    Attach patching, hardening, access and backup evidence to the strategy it supports.

  5. Step 5

    Report progression

    Show maturity movement over time from the evidence record rather than a point-in-time claim.

Questions

Essential Eight questions we are asked

Which maturity level should we target?
It depends on the requirement you are meeting. Australian government supply chain requirements commonly reference a specific level; commercial buyers vary. NOVA records the target you set per strategy.
Is an Essential Eight assessment an audit?
Not in itself. Assessments may be performed internally or by an external assessor. NOVA maintains the assessed levels and supporting evidence either way.
Does this overlap with ISO/IEC 27001?
Substantially. Patching, access, backup and hardening evidence supports ISO/IEC 27001 technological controls and the SOC 2 security criteria as well.

Pricing

Plans that cover Essential Eight

Plans are subscription entitlements on one workspace, so you can start with a single framework and widen scope later.

Launch

AUD $99 /month

A first certification or attestation programme run properly from the start.

  • One activated framework
  • Control ownership and review cadence
  • Evidence mapping and reviewer validation
  • Policy versioning and approval
Compare plans

Growth

Most chosen

AUD $249 /month

Multiple frameworks on one shared control set, with reuse across requirements.

  • Multiple activated frameworks
  • Cross-framework control and evidence reuse
  • Risk register with treatment and acceptance
  • GitHub evidence connector
Compare plans

Professional

AUD $499 /month

Assurance-grade operation with external review workflows included.

  • Everything in Growth
  • Auditor Portal with scoped engagement access
  • Trust Centre publication
  • Asset register and classification
Compare plans

Enterprise

On request

Quoted per organisation against scope, users and assurance requirements.

  • Everything in Business
  • Scope defined per organisation
  • Commercial terms agreed with Eredox
  • Structured onboarding programme
Compare plans

Indicative amounts shown for planning purposes. All published prices require Eredox approval before they are contractually binding.

Getting started

How to start with Essential Eight

Four steps from an empty workspace to a reviewable readiness position.

  1. Step 1

    Activate the framework

    Create the workspace and activate Essential Eight so its requirements load into your control set.

  2. Step 2

    Assign control ownership

    Give each control a named owner and a review cadence, so accountability is recorded rather than assumed.

  3. Step 3

    Map and validate evidence

    Attach evidence to the requirements it supports and have a reviewer confirm it is current and sufficient.

  4. Step 4

    Review readiness

    Track gaps and readiness reporting, then decide with your assessor when the programme is ready for external review.

NOVA supports the readiness decision. Final launch and risk decisions remain human decisions.

Talk to us

Ask about Essential Eight

Tell us your scope, timeline and any assessment date you are working to. We will reply with what NOVA covers and what remains with your independent assessor.

NOVA assists with readiness and evidence management. Certification, attestation and regulatory conclusions remain with authorised independent, regulatory or customer-appointed parties.

Forms are not connected yet. Please email compliance@eredox.com.

See NOVA against your own compliance obligations

Start free to explore the workflow, or walk through your framework, evidence and reporting requirements with us.

NOVA supports the readiness decision. Final launch and risk decisions remain human decisions.