Black Shard

Essential Eight assessment, fixed scope.

Each of the eight mitigation strategies rated against the ASD maturity model, with the evidence behind each rating and an uplift plan.

Essential Eight assessment from $5,950 ex GST.

Fixed scope: maturity assessed against all eight controls, written report and an uplift plan.

Book a free 30-minute scoping callOpen a brief

Strategies rated against the ASD model
All eight
Sequenced by risk and effort
Uplift plan
CyberCert public registry
SMB1001:2026 Gold

What the fixed scope buys.

There is no Essential Eight certificate. What exists is the organisation’s claim and the evidence behind it, so the evidence is part of the deliverable.

  1. 1

    All eight strategies rated

    Each mitigation strategy rated from Maturity Level 0 to Maturity Level 3, against the requirements of your target level.

  2. 2

    Requirement, observation, gap

    For every strategy the report records the requirement, what was observed, and the gap between the two.

  3. 3

    A written report

    A current maturity rating across all eight strategies, with the observations behind each, citing the ASD model of November 2023.

  4. 4

    An uplift plan

    The technical and procedural changes required to reach the target level, sequenced by risk and effort.

  5. 5

    An evidence trail

    Evidence for each mitigation that can be handed to a customer, auditor or insurer.

How the assessment runs.

An assessment is a technical exercise. Each strategy is rated against the requirements of the target level. Most of it runs remotely against cloud tenancies, directories and endpoint management tooling.

The data collected for each strategy

What application control blocks, which accounts enforce multi-factor authentication and whether it is phishing-resistant, who holds administrative privilege and when it was last revalidated, the age of the oldest unpatched exploitable flaw, and whether a backup restore has been performed.

Which level to target

The level being asked for. Maturity Level 1 across all eight is the baseline supplier questionnaires commonly have in mind, and contracts touching government supply chains increasingly specify Level 2.

The rating is per strategy, and the ASD’s guidance is to reach the same level across all eight before targeting the next one, so seven strategies at Maturity Level 2 and one at Level 0 is a Level 0 result in practice.

The eight strategies assessed.

Four stop attacks landing, three limit how far an attacker gets, and one recovers the business afterwards.

  • Application control: Only approved software runs on your machines, and everything else is blocked.
  • Patch applications: Security fixes for the software you run, applied within timeframes that match how fast the flaw is being exploited.
  • Configure Microsoft Office macro settings: Macros from the internet are blocked, and the ones the business relies on are vetted and signed.
  • User application hardening: Browsers and productivity tools with the risky features switched off and legacy components removed.
  • Restrict administrative privileges: Admin rights held by the people who need them, in separate accounts, reviewed as roles change.
  • Patch operating systems: The same patching discipline applied to workstations, servers and network devices.
Multi-factor authentication and regular backups
  • Multi-factor authentication: A second factor on the services that matter, including remote access and administrative portals.
  • Regular backups: Backups tested by restoring them, held where a compromised account cannot delete them.

After the report: uplift.

Uplift runs as a milestone program: each mitigation lands, is evidenced and is confirmed working before the next one tightens. Black Shard can do the hands-on work or hand your IT provider a plan precise enough to execute, and verify each milestone.

Above the $5,950 starting price, cost follows the size of the environment: how many environments and tenancies, the size of the endpoint fleet, the attack surface in scope, and whether Black Shard executes the uplift or plans it.

A typical uplift program

Uplift is configuration work: multi-factor authentication enforced on remote access and administrative portals first, administrative privilege separated into dedicated accounts, a patch cadence with owners and the model’s timeframes, application control rolled out in audit mode before enforce, Office macros blocked from the internet, and backups restructured so a restore is rehearsed.

Book a free 30-minute scoping call

Where Black Shard stands.

Black Shard holds SMB1001:2026 Gold, Level 3, issued by CyberCert and active to 17 June 2027. The Essential Eight controls overlap substantially with SMB1001, so much of the evidence serves both.

Our Gold certificate on the registry

Recent work of this kind

  • Client confidential

    Essential Eight assessment and uplift: authentication, patching, privilege, backups.

Essential Eight assessment questions, answered

How much does an Essential Eight assessment cost?

An Essential Eight assessment starts at $5,950 ex GST, for a fixed scope: maturity assessed against all eight strategies, a written report and an uplift plan. Above that starting price, cost follows the size of the environment: how many environments and tenancies, the size of the endpoint fleet and the attack surface in scope. A free 30-minute scoping call settles the scope and the quote.

What does the fixed scope include?

A rating for each of the eight strategies against the target maturity level, the requirement, observation and gap behind every rating, a written report, an uplift plan sequenced by risk and effort, and an evidence trail for each mitigation.

Is the Essential Eight mandatory in Australia?

It is mandated for many Australian government entities. Agencies and large enterprises increasingly require a stated maturity level from suppliers, and insurers ask about the same controls at renewal. For a private business it is rarely a legal obligation and often a commercial one.

Does the ASD certify Essential Eight compliance?

No. The ASD publishes the model and its maturity requirements and does not certify or endorse anyone against it. A maturity claim rests on assessment evidence, which is why the evidence trail is part of the engagement.

What maturity level should we target?

The level being asked for. Maturity Level 1 is the common baseline for small and mid-sized businesses, and contracts in government supply chains increasingly specify Level 2. Targeting higher than the obligation is a risk decision to make deliberately.

Which version of the maturity model do you assess against?

The model the Australian Signals Directorate published in November 2023. Every rating in the assessment report cites that edition.

Can you do the uplift work, or only the assessment?

Both. Black Shard can perform the uplift directly: MFA enforcement, privilege separation, application control rollout, patch cadence and backup restructuring. Where an IT provider is in place, we hand over the plan and verify the work at each milestone.

Where do you assess?

Most of an assessment runs remotely against cloud tenancies, directories and endpoint management tooling.

How often should maturity be re-assessed?

After significant change to the environment, and before the rating is relied on commercially in a tender response or an insurance renewal. Environments drift: admin rights accumulate, patch cadences slip, temporary exceptions become permanent.

How is the Essential Eight different from SMB1001?

The Essential Eight is a maturity model with no certificate attached. SMB1001 is a certifiable standard. The controls overlap substantially, so an Essential Eight uplift produces much of the evidence an SMB1001 tier expects.

Tell us the maturity level you are being asked for.

Brisbane head office.

Book a free 30-minute scoping callOpen a briefinfo@blackshard.com.au