The Essential Eight is a set of mitigation strategies published by the Australian Signals Directorate (ASD). Procuring support for it requires more than asking a provider whether it can deliver an assessment or deploy a set of products. The organisation needs a defined target maturity, an evidence standard and a clear boundary between assessment, remediation and ongoing operation.
CYBORIUM helps Australian organisations compare Essential Eight providers through a structured, vendor-neutral sourcing process. The selected provider pays CYBORIUM a capped fee. The client contracts directly with that provider, and CYBORIUM does not sell, deliver, operate or invoice the technology.
Start with the maturity target
ASD’s maturity model describes three maturity levels. The right procurement starts by confirming which systems, users and business units are in scope, the current evidence position and the maturity level the organisation is seeking. A provider should not set the target without understanding the organisation’s threat exposure, obligations and operating constraints.
Record assumptions before approaching the market. These include legacy systems, privileged access arrangements, application compatibility, remote administration, patching constraints and recovery requirements. If an exception is likely, require the provider to explain the risk, the compensating control and the path to closure.
Separate assessment from implementation
An assessment should show how each finding was tested and what evidence supports the result. An implementation proposal should explain the technical change, service dependency, responsible party and acceptance test. Combining both into one broad statement of work can make it difficult to tell whether the provider has identified the problem or merely proposed its preferred products.
Where independence matters, consider separating the assurance decision from the sale of technology. At minimum, disclose commercial relationships and require the scoring method to remain stable across all providers.
Evidence to require from providers
A useful response should contain more than a maturity claim. Ask for:
- a control-by-control assessment method mapped to the current ASD maturity model;
- sample evidence for policy, configuration, technical testing and operating practice;
- a documented treatment for exclusions, exceptions and inherited controls;
- implementation sequencing that accounts for business disruption and change windows;
- acceptance criteria for each remediation activity;
- roles for internal teams, the provider and any technology vendor;
- ongoing evidence collection and reassessment arrangements; and
- a complete commercial model, including licences, services, integrations and recurring support.
How CYBORIUM scores Essential Eight proposals
Assessment integrity
The provider should explain how it tests each strategy, how it handles conflicting evidence and how it distinguishes design from operation. A document review alone rarely proves that a control works in practice.
Implementation fit
The proposed controls must work with the organisation’s applications, identities, endpoints and operating model. Ask shortlisted providers to walk through the most difficult environment first, not the easiest demonstration case.
Evidence and assurance
Require outputs that an internal assurance team, auditor or executive decision owner can understand. Findings should identify the tested scope, evidence date, result, exception and owner. Avoid scores that cannot be traced back to an observable control.
Commercial clarity
Compare the full cost of reaching and maintaining the target maturity. Include technology licences, implementation, testing, training, managed services, reassessment and likely change requests. Test price assumptions against user, device and data growth.
A procurement sequence that reduces rework
- Confirm the in-scope environment and target maturity.
- Collect available policies, configurations, test results and exception records.
- Convert each gap into a requirement and acceptance test.
- Issue one evidence pack and one response structure to the market.
- Score written evidence before demonstrations or commercial negotiation.
- Run scenario-based workshops with the shortlisted providers.
- Contract against deliverables, evidence and acceptance criteria.
- Plan reassessment and operating ownership before implementation closes.
CYBORIUM’s role in the decision
CYBORIUM can structure the requirements, coordinate provider engagement, compare responses, test commercial assumptions and support negotiation. The organisation retains the decision and contracts directly with the chosen provider.
The result should be a defensible provider decision and a practical path to the target maturity. It should not be a generic compliance report or a product list presented as an Essential Eight programme.
Primary references
Reviewed by Michael Kazantzis for CYBORIUM on 22 July 2026. This guide explains CYBORIUM’s procurement evaluation method. It does not provide legal or regulatory advice.
Related from CYBORIUM
- Technology Market Expertise
- Strategic Sourcing
- Governance, Risk & Compliance (GRC) as a Service: The Complete Guide for Australian Enterprises in 2026
- Procurement Governance for Enterprise Technology Buying in Australia
- Governance, Risk & Compliance (GRC) Platforms: The Complete Guide for Australian Enterprises in 2026



