What does an Essential Eight assessment cost in Australia?
Short answer
CyberByte Security's Essential Eight Assessment is priced from $12,000 ex GST, as a fixed price for the agreed scope, and typically takes 2–3 weeks. The price moves with the scope: the target maturity level, the systems inside the assessment boundary, the sample of devices tested, how much evidence can be tested directly rather than taken from interviews, and how many exceptions need review.
Written by Muhammad Gulzar, Founder & Principal Security Consultant
Principal Security Consultant · Enterprise & government experience · 10+ years across IT, cloud & cyber
Last reviewed October 2026 · General information only, current as at the review date — not professional advice for your specific circumstances.
Who this is for
This article is for organisations of roughly 20–200 staff that have been asked for their Essential Eight maturity, whether by a cyber insurer's questionnaire, a client's supplier review, a tender or the board, and need a realistic budget before they approach a provider. It explains the cost drivers using the Australian Signals Directorate's (ASD) own assessment guidance, so you can compare quotes on scope rather than on the headline number.
What is an Essential Eight assessment, exactly?
The Essential Eight is ASD's set of eight mitigation strategies, measured against a maturity model with four levels, from Maturity Level Zero to Maturity Level Three. The current model was last updated in November 2023. Maturity Level Zero exists to capture situations where the requirements of Maturity Level One are not met; Levels One to Three are based on mitigating increasing levels of attacker tradecraft and targeting. If you need a refresher on the eight strategies themselves, start with the Essential Eight, explained for boards.
ASD's Essential Eight assessment process guide (October 2024) describes four stages: planning and preparation, determining the scope and approach, assessing the controls for each mitigation strategy, and developing the security assessment report. Every one of those stages takes assessor time, and time is what a fixed price ultimately reflects.
ASD is also clear that there is no requirement for organisations to have their Essential Eight implementation certified by an independent party. It notes, however, that an independent assessment may be needed where a government directive or policy, a regulatory authority or a contractual arrangement requires one. That second situation is often why an organisation of this size starts asking about cost.
What drives the price?
Five factors do most of the work. Each one changes how much testing, review and reporting an assessor has to do.
- Target maturity level. ASD's guide says the Essential Eight is required to be implemented and assessed as a package. An organisation that has not previously had an assessment demonstrating Maturity Level One should not begin an assessment against Maturity Level Two until it has done so. Each step up adds requirements to test.
- The assessment boundary. ASD calls the scope the assessment boundary, and it is agreed with the system owner before testing starts. One Microsoft 365 tenant and a single office is a smaller job than several tenants, on-premises servers and a second site. Anything left out should be documented in the report with a justification.
- Sample size. ASD asks assessors to agree sample sizes with the system owner, aiming for a reasonable representative sample of workstations (including laptops), servers and network devices.
- Evidence quality. ASD grades evidence as excellent (testing a control with a simulated activity), good (reviewing configuration through the system's own interface), fair (reviewing reports or screenshots) and poor (a policy or a verbal statement of intent). Higher-quality evidence takes more hands-on time, but it gives you a conclusion you can stand behind.
- Exceptions. Where a control has a documented exception, the assessor reviews whether the compensating controls address the intent of the original control. ASD lists what exception records should contain and notes that exceptions should not be approved beyond one year.
The method matters too. ASD's guide states that assessments using interviews, reports and screenshots are inferior to assessments using scripts and tools, because tools can check many devices at once and pick up issues people miss. Tool-based testing needs your approval and some set-up, which is part of what you are paying for.
What should a fixed-price assessment include?
Compare quotes on what you will actually receive, not only the price. CyberByte Security's Essential Eight Assessment includes:
- A maturity scorecard across all eight mitigation strategies (ML0–ML3).
- An executive one-pager that explains the risk in business language.
- A prioritised remediation roadmap with indicative effort, dependencies and cost ranges where supportable.
- A technical findings pack for your IT team or managed service provider.
ASD publishes an Essential Eight assessment report template and asks assessors who use their own branded template to include all of its sections. It is reasonable to ask any provider whether their report does. You can see the shape of our reports on the sample deliverables page.
Questions to ask before you accept a quote
- Which maturity level will be assessed, and why that level?
- What is inside and outside the assessment boundary, and will exclusions be documented with a justification?
- Will controls be tested with scripts and tools, or mainly assessed through interviews and screenshots?
- What sample of workstations, servers and network devices will be tested?
- Is remediation included, or quoted separately?
- How are scope changes and variations agreed before extra work begins?
Cost and timeline
CyberByte Security's Essential Eight Assessment is from $12,000 ex GST and typically runs over 2–3 weeks. That figure is the starting point for a typical small organisation. More users, sites, tenants or systems mean more scope, and the exact fixed price for the agreed scope is confirmed in writing after a short scoping call, before you commit. Project terms are 50% on commencement and 50% on delivery.
Closing the gaps is separate work. A Security Remediation Sprint is from $8,000 ex GST, and every published price is on the packages page.
How CyberByte would approach it
An engagement would follow our Assess, Engineer, Advise model. To assess, we would first confirm the target maturity level and the boundary with you, sign the authorisation and rules of engagement, and agree the device sample. We would then test each strategy, favouring scripts and tools over interviews where your environment allows, and rate it against the maturity model. Every gap would be ranked by risk and effort. If you then wanted help closing the gaps, that could be scoped as a fixed-price remediation sprint, and a re-assessment could evidence the uplift. Ongoing advice could follow through the Security Partnership.
Start with a quick self-check
If you are not sure where you stand, the free Essential Eight Readiness Checklist below gives a high-level read before you spend anything. When you are ready, request a scoping call and we will confirm the scope and a fixed price. Full details of the service are on the Essential Eight Assessment page.
Common questions
Is an Essential Eight assessment a certification?
No. ASD states that there is no requirement for organisations to have their Essential Eight implementation certified by an independent party. An assessment gives you an evidenced view of your maturity when it was assessed. Insurers, clients and tenders set their own requirements, so an assessment is designed to support those conversations rather than guarantee an outcome.
Which maturity level should we be assessed against?
ASD says organisations should identify a target maturity level suitable for their environment, considering how attractive they are to malicious actors and the consequences of an incident. If an insurer, client or tender names a level, that is the natural starting point. Without a previous assessment demonstrating Maturity Level One, ASD's guidance is to be assessed against Level One first.
Can we assess ourselves?
Yes. ASD publishes the maturity model, the assessment process guide, example test plans and a report template. ASD's Information Security Manual also says people conducting security assessments should be independent of the system being assessed, which is one reason contracts and policies sometimes ask for an external assessor.
How long does an assessment take?
Our Essential Eight Assessment typically takes 2–3 weeks. The main variables are the size of the boundary and how quickly evidence and access can be provided.
Authoritative sources
Essential Eight Readiness Checklist
Drop your email and we'll send the Essential Eight Readiness Checklist straight to your inbox.
No spam. Unsubscribe from marketing at any time.
Request a scoping call
Talk to a senior advisor.
A 20-minute scoping call: tell us what's prompting this, and we'll tell you the smallest credible engagement that solves it. Fixed price for the agreed scope, no obligation.
- 10+ years across IT, cloud & cyber
- Enterprise & government experience
- Principal consultant-led delivery
- Independent & Australian-owned
- Melbourne-based · Australia-wide