ACSC ESSENTIAL EIGHT

A real Essential Eight maturity rating — documented, evidenced, and defensible.

Government agencies and large enterprise customers are asking suppliers about their Essential Eight posture. We configure the controls, gather the evidence, and prepare you to answer confidently — whether that's for a tender response, customer due diligence, or a formal IRAP assessment.

THE PLATFORM

All eight controls. Evidence for each one. One place to see your rating.

Essential Eight Workspace ML2 current · ML3 target
Meridian Engineering Pty Ltd
ML2

Current rating

Maturing

5 of 8 controls at ML3

5 At ML3 Target met
3 At ML2 In progress
14 Evidence items This week
0 Open gaps All active
Essential Eight controls

Block unapproved executables from running across all Windows devices. AppLocker policies configured with your approved application list, enforced via Intune.

AppLocker policy export Intune device compliance report

Applications patched within 48 hours of critical release, two weeks for all others. Automatic updates configured in Intune with weekly compliance monitoring.

Patch compliance report Intune update policy screenshot

Macros disabled in internet-downloaded Office files. Digitally signed macros from trusted locations allowed. Configured via Intune and Group Policy.

Intune config profile export Group Policy Object screenshot

Web browsers hardened — Java disabled, Flash blocked, advertisements blocked. PDF viewer configured to prevent script execution. Managed via Intune browser policies.

Browser policy config screenshot Edge security baseline export

Admin accounts audited and reduced to minimum required. Privileged access managed via Entra ID PIM — just-in-time elevation for IT administrator tasks. No shared admin passwords.

Admin account audit report Entra PIM configuration screenshot

Windows updated within 48 hours of critical patch release. Update rings configured in Intune. Devices out of compliance flagged weekly and escalated after seven days.

OS patch compliance report Intune update ring configuration

MFA required for all users and administrators. Phishing-resistant methods (FIDO2, Windows Hello for Business) enforced for privileged access. Legacy authentication blocked entirely.

Conditional access policy screenshot MFA registration report Legacy auth sign-in log (zero entries)

Business-critical data backed up daily. M365 Backup enabled for SharePoint, OneDrive, and Exchange. Restore tested quarterly — last test confirmed 15-minute recovery for all services.

M365 Backup configuration export Quarterly restore test record
Entra ID and logging
Active
Conditional access
All users · phishing-resistant MFA
Active
Microsoft Defender
Cloud protection + ASR rules
Active
Entra ID audit logs
180-day retention · SIEM export
Active
Defender for Endpoint
All 12 devices enrolled
Active
Sensitivity labels
UNOFFICIAL · OFFICIAL · OFFICIAL:Sensitive
Active
Intune device management
12 devices enrolled · all compliant

WHAT THIS GETS YOU

Something you can show a customer — and stand behind.

Customers are increasingly asking SMBs to demonstrate their cyber security posture before contracts are signed. "We take security seriously" is no longer enough — they want a maturity level and evidence to back it up.

Axel configures your Essential Eight controls, collects the evidence from your environment, and produces a maturity report you can share with confidence. If a formal IRAP assessment is required, we prepare you for that too — and stay alongside you through it.

WHAT'S INCLUDED

Configured controls and documented evidence.

Control configuration

We configure the eight mitigation strategies in your Microsoft 365 environment — application control, patching, macro restrictions, MFA, and the rest — to your target maturity level.

  • Application control policy
  • Patch management for OS and applications
  • Microsoft Office macro restrictions
  • User application hardening
  • MFA enforcement across all accounts
  • Admin privilege restriction

Evidence collection and reporting

Evidence pulled directly from Microsoft Defender and Entra — not self-reported. We produce a maturity report per mitigation that is audit-ready and shareable in tender responses.

  • Maturity level 0–3 rating per mitigation
  • Evidence sourced from Defender and Entra logs
  • Gap report with specific remediation steps
  • Shareable executive summary for customer due diligence
  • Tender-ready maturity statement

Assessment support

If your customer or contract requires a formal IRAP assessment, we prepare your documentation pack and sit alongside you through the assessment — the same way we support DISP and ISO 9001.

  • IRAP assessment preparation
  • Assessor briefing and technical liaison
  • Finding response and remediation
  • Ongoing maturity monitoring after accreditation

THE PROCESS

From baseline to rated.

  1. 1

    Current state assessment

    We run a baseline read of your environment against the ACSC Essential Eight. You'll know within the first week where you currently sit and what it takes to reach your target maturity level.

  2. 2

    Control configuration

    We configure the required controls in your Microsoft 365 environment. Most businesses can reach Maturity Level 2 within two to three weeks from kickoff, depending on their starting point.

  3. 3

    Evidence collection and reporting

    We pull evidence from Defender and Entra, produce your maturity report, and package it for customer due diligence or formal assessment submission.

  4. 4

    We sit with you through the assessment

    If a formal IRAP assessment is required, we're in the room. We handle the technical questions, manage any findings, and stay available until the assessment is closed out.

A customer is asking about your cyber posture. Have an answer.

If you're responding to a tender or customer due diligence request that asks for your Essential Eight maturity, book a call. We'll tell you where you sit, what it takes to get rated, and what it costs.

30 minutes. No sales deck. We'll tell you whether we can help and what it would cost.

Book a 30-minute call