Level 2 scope is often blurred
Assessment, remediation, licences and managed services are frequently combined. A single headline price can conceal which outcomes are actually included.
Insights from CYBORIUM
ASD has confirmed the direction of Essentials for enterprise IT. The detailed controls are not yet final. Procurement decisions made now still need clear scope, usable evidence and room to adapt.
The position now
ASD says the current Essential Eight will evolve into the first chapter of a broader Essentials series, grounded in the Information Security Manual and supported by practical tools and clearer implementation guidance.
ASD has not published the final controls, assessment tests, maturity model or transition timetable. Continue using the current Essential Eight baseline and avoid purchasing against requirements that do not yet exist.
View the ASD consultation update ↗What CYBORIUM is seeing
These are recurring procurement patterns, not universal rules. They are useful because each one changes the questions an organisation should ask.
Assessment, remediation, licences and managed services are frequently combined. A single headline price can conceal which outcomes are actually included.
An included assessment may lead directly into a multi-year managed service. The assessment price is not the only commercial decision.
Insurance, customer and supply-chain requirements can compress timelines. Urgency increases the need for disciplined requirements.
Control proof often sits across internal teams, cloud platforms and providers. A maturity claim is only as useful as the evidence an organisation can retain and test.
Six procurement tests
The public version gives you the questions. CYBORIUM’s full evaluation adds weighted criteria, provider evidence, commercial comparison and a defensible recommendation.
Name the maturity level, assessment boundary, included systems and evidence that constitutes completion.
Separate assessment, remediation, licensing, implementation, monitoring and internal effort.
If one party assesses and remediates, define the independence check before approving uplift spend.
Confirm scope reflects system criticality and control outcomes. Endpoint or user counts alone are insufficient.
Set re-assessment timing, evidence refresh, remediation obligations and the cost of proving maturity again.
Confirm data portability, log retention, tool ownership, transition support and termination rights.
What good looks like
RequirementsPrioritised outcomes, scope and evidence expectations.
Market comparisonSuitable providers tested against the same criteria.
Commercial clarityComparable total cost, dependencies and contract terms.
GovernanceA recommendation leaders can challenge and defend.
The engagement boundary
This page helps you recognise the right questions. The full CYBORIUM evaluation maps them to your systems, obligations, target maturity, provider evidence and commercial position.
No. ASD has indicated strong alignment with existing controls and investment. Continue using the current Essential Eight guidance until final Essentials for enterprise IT requirements and transition arrangements are published.
Set the target maturity level, assessment boundary, priority systems, evidence requirements, responsibility model and commercial scope. This makes provider responses comparable.
It can be efficient, but the potential conflict should be visible. Define an independent review or evidence-validation step before approving remediation spend.
CYBORIUM creates the requirement set, evaluation criteria, provider comparison, evidence record, commercial benchmark and negotiation pathway for the organisation’s actual environment.
CYBORIUM does not sell, deliver, operate, manage or invoice technology. We help your organisation evaluate the market and contract directly with the selected provider.