ACSC ESSENTIAL EIGHT
Government agencies and large enterprise customers are asking suppliers about their Essential Eight posture. We configure the controls, gather the evidence, and prepare you to answer confidently — whether that's for a tender response, customer due diligence, or a formal IRAP assessment.
THE PLATFORM
Current rating
5 of 8 controls at ML3
Block unapproved executables from running across all Windows devices. AppLocker policies configured with your approved application list, enforced via Intune.
Applications patched within 48 hours of critical release, two weeks for all others. Automatic updates configured in Intune with weekly compliance monitoring.
Macros disabled in internet-downloaded Office files. Digitally signed macros from trusted locations allowed. Configured via Intune and Group Policy.
Web browsers hardened — Java disabled, Flash blocked, advertisements blocked. PDF viewer configured to prevent script execution. Managed via Intune browser policies.
Admin accounts audited and reduced to minimum required. Privileged access managed via Entra ID PIM — just-in-time elevation for IT administrator tasks. No shared admin passwords.
Windows updated within 48 hours of critical patch release. Update rings configured in Intune. Devices out of compliance flagged weekly and escalated after seven days.
MFA required for all users and administrators. Phishing-resistant methods (FIDO2, Windows Hello for Business) enforced for privileged access. Legacy authentication blocked entirely.
Business-critical data backed up daily. M365 Backup enabled for SharePoint, OneDrive, and Exchange. Restore tested quarterly — last test confirmed 15-minute recovery for all services.
WHAT THIS GETS YOU
Customers are increasingly asking SMBs to demonstrate their cyber security posture before contracts are signed. "We take security seriously" is no longer enough — they want a maturity level and evidence to back it up.
Axel configures your Essential Eight controls, collects the evidence from your environment, and produces a maturity report you can share with confidence. If a formal IRAP assessment is required, we prepare you for that too — and stay alongside you through it.
WHAT'S INCLUDED
We configure the eight mitigation strategies in your Microsoft 365 environment — application control, patching, macro restrictions, MFA, and the rest — to your target maturity level.
Evidence pulled directly from Microsoft Defender and Entra — not self-reported. We produce a maturity report per mitigation that is audit-ready and shareable in tender responses.
If your customer or contract requires a formal IRAP assessment, we prepare your documentation pack and sit alongside you through the assessment — the same way we support DISP and ISO 9001.
THE PROCESS
We run a baseline read of your environment against the ACSC Essential Eight. You'll know within the first week where you currently sit and what it takes to reach your target maturity level.
We configure the required controls in your Microsoft 365 environment. Most businesses can reach Maturity Level 2 within two to three weeks from kickoff, depending on their starting point.
We pull evidence from Defender and Entra, produce your maturity report, and package it for customer due diligence or formal assessment submission.
If a formal IRAP assessment is required, we're in the room. We handle the technical questions, manage any findings, and stay available until the assessment is closed out.
If you're responding to a tender or customer due diligence request that asks for your Essential Eight maturity, book a call. We'll tell you where you sit, what it takes to get rated, and what it costs.
30 minutes. No sales deck. We'll tell you whether we can help and what it would cost.
Book a 30-minute call