Frameworks
Available nowEssential Eight
Eight prioritised mitigation strategies published by the Australian Cyber Security Centre, assessed by maturity level.
Overview
The Essential Eight is a set of prioritised mitigation strategies that make it substantially harder for adversaries to compromise systems.
Each strategy is assessed against maturity levels, so an organisation reports where it sits rather than simply whether a control exists. Maturity is expected to be achieved consistently across all eight strategies rather than unevenly.
It is widely used in Australian government supply chains and increasingly requested by private-sector buyers.
Who this is for
- Australian organisations and their suppliers
- Entities responding to government procurement requirements
- Teams that want a concrete technical baseline before broader certification
Governance areas
Application control
Preventing execution of unapproved applications and scripts.
Patching
Applications and operating systems patched within defined timeframes.
Configuration hardening
Macro settings and user application hardening applied consistently.
Administrative privileges
Restricting, reviewing and monitoring privileged access.
Authentication and recovery
Multi-factor authentication and regular, tested backups.
How NOVA supports this framework
- Record the target maturity level and the current assessed level per strategy
- Hold configuration and patching evidence against the strategy it supports
- Track uplift actions with owners and due dates
- Report maturity progression over time from the evidence record
Controls and evidence focus
- Patch compliance reporting with the date range it covers
- Backup test results including restoration verification
- Privileged access reviews with the approver recorded
- Application control and macro configuration baselines
Cross-framework reuse
Technical evidence supports ISO/IEC 27001 technological controls
Backup, patching and access evidence is reusable for SOC 2 security criteria
NOVA assists with readiness and evidence management. Certification, attestation and regulatory conclusions remain with authorised independent, regulatory or customer-appointed parties.
Structure
The eight mitigation strategies
The Australian Cyber Security Centre groups the eight strategies by the outcome they support. Maturity is expected to be achieved consistently across all eight rather than unevenly.
Application control
Prevent execution of unapproved applications, scripts, installers and drivers.
Patch applications
Apply patches to internet-facing and other applications within defined timeframes.
Configure macro settings
Restrict Microsoft Office macros to vetted sources and block them from the internet.
User application hardening
Harden browsers and common applications by disabling risky features.
Restrict administrative privileges
Limit, validate and regularly review privileged access to what the role requires.
Patch operating systems
Apply operating system patches within the timeframe set for the risk level.
Multi-factor authentication
Require multi-factor authentication for remote access and privileged actions.
Regular backups
Back up data, software and configuration, and test restoration regularly.
Assessment
Maturity levels
Each strategy is assessed against a maturity level rather than a simple present-or-absent test. NOVA records the target level and the current assessed level per strategy.
- 0
Maturity Level Zero
Weaknesses remain that an adversary could readily exploit. The strategy is not aligned to the intent of the model.
- 1
Maturity Level One
Partly aligned with the intent of the strategy, addressing adversaries using widely available techniques.
- 2
Maturity Level Two
Mostly aligned, addressing adversaries prepared to invest more time and to work around weaker controls.
- 3
Maturity Level Three
Fully aligned, addressing adaptive adversaries who target specific weaknesses and privileged credentials.
Evidence
Typical evidence held in NOVA
Essential Eight evidence is largely technical and time-bound, so the date range each artefact covers is recorded alongside it.
| Artefact | Typical source | Expected cadence |
|---|---|---|
| Patch compliance report | Endpoint or patch tooling | Monthly |
| Application control baseline | Configuration export | On change |
| Macro and browser hardening settings | Configuration export | Quarterly |
| Privileged access review | Identity provider export | Quarterly |
| Multi-factor coverage report | Identity provider export | Monthly |
| Backup restoration test | Manual upload with result | Quarterly |
NOVA supports the readiness decision. Final launch and risk decisions remain human decisions.
How it runs
Working through Essential Eight in NOVA
- Step 1
Set the target
Agree the maturity level required by your buyers or obligations, per strategy.
- Step 2
Assess current state
Record the current assessed level with the evidence that supports it.
- Step 3
Plan uplift
Raise uplift actions with owners and due dates for each gap between current and target.
- Step 4
Evidence continuously
Attach patching, hardening, access and backup evidence to the strategy it supports.
- Step 5
Report progression
Show maturity movement over time from the evidence record rather than a point-in-time claim.
Questions
Essential Eight questions we are asked
- Which maturity level should we target?
- It depends on the requirement you are meeting. Australian government supply chain requirements commonly reference a specific level; commercial buyers vary. NOVA records the target you set per strategy.
- Is an Essential Eight assessment an audit?
- Not in itself. Assessments may be performed internally or by an external assessor. NOVA maintains the assessed levels and supporting evidence either way.
- Does this overlap with ISO/IEC 27001?
- Substantially. Patching, access, backup and hardening evidence supports ISO/IEC 27001 technological controls and the SOC 2 security criteria as well.
Capabilities that support this framework
Pricing
Plans that cover Essential Eight
Plans are subscription entitlements on one workspace, so you can start with a single framework and widen scope later.
Launch
AUD $99 /month
A first certification or attestation programme run properly from the start.
- One activated framework
- Control ownership and review cadence
- Evidence mapping and reviewer validation
- Policy versioning and approval
Growth
Most chosenAUD $249 /month
Multiple frameworks on one shared control set, with reuse across requirements.
- Multiple activated frameworks
- Cross-framework control and evidence reuse
- Risk register with treatment and acceptance
- GitHub evidence connector
Professional
AUD $499 /month
Assurance-grade operation with external review workflows included.
- Everything in Growth
- Auditor Portal with scoped engagement access
- Trust Centre publication
- Asset register and classification
Enterprise
On request
Quoted per organisation against scope, users and assurance requirements.
- Everything in Business
- Scope defined per organisation
- Commercial terms agreed with Eredox
- Structured onboarding programme
Indicative amounts shown for planning purposes. All published prices require Eredox approval before they are contractually binding.
Getting started
How to start with Essential Eight
Four steps from an empty workspace to a reviewable readiness position.
- Step 1
Activate the framework
Create the workspace and activate Essential Eight so its requirements load into your control set.
- Step 2
Assign control ownership
Give each control a named owner and a review cadence, so accountability is recorded rather than assumed.
- Step 3
Map and validate evidence
Attach evidence to the requirements it supports and have a reviewer confirm it is current and sufficient.
- Step 4
Review readiness
Track gaps and readiness reporting, then decide with your assessor when the programme is ready for external review.
NOVA supports the readiness decision. Final launch and risk decisions remain human decisions.
Talk to us
Ask about Essential Eight
Tell us your scope, timeline and any assessment date you are working to. We will reply with what NOVA covers and what remains with your independent assessor.
NOVA assists with readiness and evidence management. Certification, attestation and regulatory conclusions remain with authorised independent, regulatory or customer-appointed parties.
See NOVA against your own compliance obligations
Start free to explore the workflow, or walk through your framework, evidence and reporting requirements with us.
NOVA supports the readiness decision. Final launch and risk decisions remain human decisions.