Essential Eight Uplift · Australia

Essential Eight ML2done properly.

ACSC Essential Eight Maturity Level 2 uplift for Australian federal contractors, NFPs, and regulated businesses. Baseline assessment, control implementation under fixed price, and the audit trail that holds up at attestation.

0
Controls
ML2
Maturity target
Fixed
Price
  • Fixed-price quotes. No hourly billing surprises.
  • Zero data loss. Across 500+ migrations.
  • Unlimited local support. Australian team, no offshore.
  • Technology-agnostic. Best fit, not highest margin.
The eight controls

All eight, to ML2, with evidence.

Each control implemented with the technical configuration, the operating procedure, and the audit trail. ACSC ISM-aligned. Ready for attestation.

01

Application control

AppLocker, WDAC, or modern endpoint protection allow-listing. Only approved applications execute. Block list maintained, exceptions documented.

02

Patch applications

Internet-facing apps patched ≤48h after critical release. Tooling: Intune, Patch My PC, WSUS, or third-party. Cadence audited.

03

Configure MS Office macros

Macros from the internet blocked. Only signed macros from trusted locations execute. Enforced via GPO or Intune.

04

User application hardening

Web browsers, PDF readers, and Office hardened. Flash and Java disabled. Ads blocked at the browser level via policy.

05

Restrict administrative privileges

Privileged accounts separated from daily-use accounts. JIT (Just-in-Time) elevation, conditional access, regular access reviews.

06

Patch operating systems

Same cadence as applications. Workstations and servers, internal and internet-facing. Patching evidence retained.

07

Multi-factor authentication

MFA on all internet-facing services, privileged actions, and important data repositories. Phishing-resistant where possible.

08

Regular backups

Daily backups, tested quarterly, retention matched to business continuity needs. Offline or immutable copy for ransomware resilience.

How the uplift runs

Baseline first. Fixed-price plan, then execute.

We don't sell "advisory engagements" that hand you a spreadsheet of recommendations. We implement the controls, configure the tooling, document the evidence, and stay on for attestation.

  1. 01

    Baseline assessment

    1-2 weeks. Current-state mapping against ML0/1/2/3 across all eight controls. Output: gap register + fixed-price implementation plan.

  2. 02

    Quick-wins phase

    4-8 weeks. MFA across all services, patching tooling deployment, macro hardening. The fastest improvements to risk posture.

  3. 03

    Application control & admin

    3-6 months. AppLocker/WDAC rollout, privileged account separation, JIT elevation, conditional access. Longest piece because of legacy-app testing.

  4. 04

    Evidence & attestation

    Ongoing. Audit trail packaged for your contracting entity, ASD, or internal audit. We stay on through attestation rather than handing over halfway.

FAQ

Essential Eight questions Australian buyers ask.

Free systems review

Get your free systems review.

We’ll review your current stack, identify what’s slowing your team, and send a clear action plan. Whether you work with us or not.

500+ projects delivered
Zero data loss guaranteed
Fixed-price. No surprises
Australian team. No offshore

No obligation. We respond within 24 hours.

Start the conversation

Ready to lift to ML2 with evidence?

Book a baseline assessment. We'll map your current state across all eight controls and quote the uplift under fixed price. Whether you work with us or not.