Back to Cybersecurity

Cyber Essentials vs Essential Eight: UK and Australian Cyber Baselines Compared

Cyber Essentials vs Essential Eight illustration: UK blue and Australian ochre halves joined by puzzle pieces, five dots against eight

Short answer: Cyber Essentials is a UK government-backed certification with a pass/fail outcome across five technical control themes, renewed every year. The Essential Eight is an Australian maturity model of eight mitigation strategies, assessed against Maturity Levels Zero to Three rather than certified. They overlap heavily, so one well-designed control set can satisfy most of both.

Related guides:

Key takeaways

  • Cyber Essentials produces a certificate you can show a buyer. The Essential Eight produces a maturity rating per strategy, which you evidence through an internal or independent assessment.
  • About half of the Essential Eight maps strongly to Cyber Essentials: patching, admin privilege restriction and MFA appear in both, and malware defences and secure configuration overlap in part.
  • The Essential Eight goes further on application control, Microsoft Office macro settings, user application hardening and backups. Cyber Essentials goes further on firewalls and defining a formal scope boundary.
  • If you sell mostly into the UK, start with Cyber Essentials. If Australian government or enterprise buyers are driving deals, target Essential Eight Maturity Level One, then build towards Level Two.
  • Design controls once, map them to both frameworks, and collect evidence continuously so annual renewals and buyer questionnaires stop being fire drills.

How do Cyber Essentials and the Essential Eight compare at a glance?

They solve the same problem, a minimum cyber baseline for organisations, but one is a certification scheme and the other is a maturity model.

Cyber Essentials is run by the UK National Cyber Security Centre (NCSC), with the IASME consortium acting as the accreditation body and a network of certification bodies carrying out assessments. It comes in two tiers: Cyber Essentials, a verified self-assessment questionnaire, and Cyber Essentials Plus, which adds hands-on technical testing of your systems by an assessor. For a deeper look at the tiers, see our guide to Cyber Essentials vs Cyber Essentials Plus.

The Essential Eight comes from the Australian Cyber Security Centre (ACSC), part of the Australian Signals Directorate (ASD). It is a prioritised set of eight mitigation strategies, each measured against a maturity model. There is no official certificate: organisations assess themselves or engage an assessor, and report the maturity level they have reached.

Cyber Essentials Essential Eight
Owner UK NCSC, delivered via IASME and certification bodies Australian Signals Directorate's ACSC
Type Certification scheme Maturity model of mitigation strategies
Scope Five technical control themes across an organisation or a defined sub-set of it Eight mitigation strategies, primarily aimed at internet-connected IT networks
Assessment Verified self-assessment (Cyber Essentials) or self-assessment plus technical testing (Cyber Essentials Plus) Internal self-assessment or independent assessor, rated Maturity Level Zero to Three per strategy
Outcome Pass or fail, with a certificate A maturity level for each strategy
Renewal Certificate renewed annually No fixed renewal cycle; maturity should be reassessed regularly
Who requires it Some UK government contracts, plus many UK buyers and supply chains Many Australian non-corporate Commonwealth entities under the Protective Security Policy Framework (PSPF); commonly requested by Australian buyers

In practice, a UK buyer asks "Are you certified?", while an Australian buyer asks "What maturity level are you at?" A Cyber Essentials certificate does not mean you meet Essential Eight Maturity Level One, since backups, macros and application control can still sit at Level Zero.

Where do the controls overlap?

Most of the technical substance maps cleanly, which is why running both is far less work than it first looks.

The table below maps each Essential Eight strategy to the closest Cyber Essentials control theme. "Partial" means Cyber Essentials covers the intent but not the full depth the Essential Eight expects.

Essential Eight strategy Closest Cyber Essentials theme Coverage
Patch applications Security update management Strong
Patch operating systems Security update management Strong
Restrict administrative privileges User access control Strong
Multi-factor authentication User access control Strong for cloud services, partial elsewhere
Application control Malware protection (allow-listing is one accepted approach) Partial
User application hardening Secure configuration Partial
Configure Microsoft Office macro settings Secure configuration Weak, not addressed specifically
Regular backups Not covered None

And in the other direction, Cyber Essentials has two themes with only indirect Essential Eight equivalents:

  • Firewalls: boundary firewalls and host firewalls on devices are a core Cyber Essentials theme. The Essential Eight does not treat network perimeter controls as one of its eight strategies.
  • Secure configuration as a whole: removing unnecessary software and accounts, changing default passwords and disabling auto-run are broad Cyber Essentials requirements. The Essential Eight touches parts of this through user application hardening and macro settings, but it is narrower.

Where do they really differ?

The biggest differences are how success is measured, how deep certain controls go, and how scope is drawn.

Maturity levels vs pass/fail

Cyber Essentials is binary. Every applicable requirement must be met for the in-scope environment, and if one is not, you do not get the certificate until it is fixed.

The Essential Eight is graded. Each strategy is assessed at a level:

  1. Maturity Level Zero: weaknesses mean the organisation does not meet Level One.
  2. Maturity Level One: defends against opportunistic adversaries using commodity tools and techniques.
  3. Maturity Level Two: defends against adversaries willing to invest more time and effort.
  4. Maturity Level Three: defends against more adaptive adversaries who actively target the organisation.

The ACSC advises reaching the same level across all eight strategies before moving up, rather than being Level Three on MFA and Level Zero on backups. That balance matters more to a buyer than a single strong score.

Application control and macro settings

These are the two strategies where Cyber Essentials experience helps least. Essential Eight application control expects you to prevent unapproved executables, scripts and installers from running, typically starting with user profile and temporary folders at Level One and broadening at higher levels. Macro settings expect Microsoft Office macros to be blocked for users without a demonstrated business need, with tighter restrictions on macros from the internet. Neither has a direct Cyber Essentials requirement, so plan dedicated work here, especially if your workforce is on Windows and Microsoft 365.

Scope boundary

Cyber Essentials asks you to define exactly what is in scope: the whole organisation or a clearly separated sub-set, including cloud services, home workers and any personal devices that access organisational data. The certificate only speaks for that scope, and buyers increasingly check that it covers the systems handling their data.

The Essential Eight has no equivalent scoping ritual. It is written with Microsoft Windows-based, internet-connected networks in mind, and the ACSC acknowledges that other environments such as cloud platforms or operational technology may need alternative guidance. For a SaaS company running on a cloud provider with a Mac-heavy team, that means some interpretation is needed about how each strategy applies.

Backups

Cyber Essentials does not assess backups at all. The Essential Eight requires backups of important data, software and configuration settings, performed and retained according to business criticality, with restoration tested. For HealthTech vendors handling patient data, this is also the control that most often surfaces in buyer due diligence.

Which should you do first?

Start with whichever one your pipeline is asking for, but if both markets matter equally, Cyber Essentials is usually the faster first milestone.

Use this rule of thumb:

  • UK public sector or UK enterprise deals in flight: get Cyber Essentials first, then Cyber Essentials Plus if buyers or contracts ask for tested assurance. Our Cyber Essentials certification guide walks through the process.
  • Australian government or regulated Australian buyers in flight: target Essential Eight Maturity Level One across all eight strategies, then plan the path to Level Two, which is the level Australian government entities are commonly directed to reach.
  • Both markets, no urgent deadline: do Cyber Essentials first. Its five themes are the foundation of four or five Essential Eight strategies, and you walk away with a certificate. Then close the Essential Eight gaps: application control, macro settings, user application hardening and backups.

If you already hold ISO 27001 or are working towards it, both baselines slot in underneath it. Our comparison of Cyber Essentials vs ISO 27001 covers how the baseline and the management system relate.

How do you run both with one control set?

Write each control once in your own words, map it to both frameworks, and collect a single stream of evidence that satisfies both.

A practical sequence for a small team:

  1. Build a unified control list. Start from the Essential Eight strategies and the Cyber Essentials themes, and merge duplicates. For example, one "security patching" control covers Cyber Essentials security update management and both Essential Eight patching strategies.
  2. Set the stricter requirement as the standard. Where the frameworks differ on timeframes or depth, adopt whichever is tighter for your target maturity level, so meeting your own control automatically meets both.
  3. Define scope once. Use the Cyber Essentials scope boundary as your master asset inventory: devices, cloud services, user accounts and networks. Apply the Essential Eight strategies to the same inventory so there are no gaps between the two views.
  4. Add the Essential Eight-only controls. Application control, Office macro settings, user application hardening and backups become additional controls in the same library, owned by named people.
  5. Automate evidence. Device management reports, patch status, MFA enforcement settings, admin group membership and backup job results can be pulled from your tooling on a schedule rather than screenshotted once a year.
  6. Test before you are tested. Run an internal Essential Eight self-assessment and a Cyber Essentials Plus style vulnerability check on a sample of devices before booking an assessor.
  7. Keep a single calendar. Track the Cyber Essentials renewal date and your Essential Eight reassessment cadence together, so the evidence you refresh serves both.

A short dual-framework checklist to keep handy:

  • Patching timeframes meet the stricter of the two frameworks
  • MFA enforced for cloud services, remote access and privileged users
  • Admin rights removed from day-to-day accounts
  • Application control deployed on workstations
  • Office macros blocked unless there is an approved business need
  • Browsers and office apps hardened
  • Backups run, retained and restore-tested

How SecureSlate helps

SecureSlate gives you a single control library that you can map to both Cyber Essentials and the Essential Eight, so each patching, access or backup control is written once and tracked against every framework it supports. Automated evidence collection from your cloud and SaaS stack keeps proof of MFA enforcement, admin access and configuration current, and policy templates help you document the Essential Eight-only areas such as application control and backups.

Our risk register and vendor risk management features help you track the gaps you have not closed yet and the suppliers inside your scope, while audit-ready exports and a trust center make it easy to share your certificate status and maturity evidence with UK and Australian buyers. SecureSlate helps you map and track controls; certification and maturity assessments are still carried out by the relevant certification bodies or assessors.

Start your free SecureSlate trial

FAQ

Is the Essential Eight the Australian equivalent of Cyber Essentials?

They are the closest counterparts, since both set a minimum cyber baseline promoted by a national cyber agency. The key difference is that Cyber Essentials is a certification with a pass/fail outcome, while the Essential Eight is a maturity model with no official certificate. The control content overlaps substantially but not completely.

Does Cyber Essentials certification count towards the Essential Eight?

Not formally. There is no mutual recognition between the schemes. In practice, the work you do for Cyber Essentials covers much of the patching, admin privilege, MFA and malware ground, which gives you a head start on Essential Eight Maturity Level One.

Can a UK company use the Essential Eight, or an Australian company get Cyber Essentials?

Yes. Both frameworks are publicly available, and organisations outside each country can follow them. Cyber Essentials certification is open to organisations based outside the UK, and Australian buyers may accept an Essential Eight assessment from an overseas supplier. Check what each buyer or contract actually specifies.

Which maturity level should a SaaS vendor aim for?

Maturity Level One across all eight strategies is a sensible starting target for most SMB vendors. If you sell to Australian government entities or large regulated organisations, expect to be asked about Level Two. Aim for a consistent level across the strategies rather than a high score on a few.

Disclaimer (legal note)

This article is for general information only and is not legal, regulatory or professional advice. Requirements vary by framework, industry and jurisdiction. Consult qualified advisors for your specific obligations.

Need compliance without the complexity?

SecureSlate automates ISO 27001, SOC 2, GDPR, HIPAA, and more. Built for growing teams. See it in action.

Find compliance gaps in 30 seconds

Filed under:

Author: SecureSlate Team

4.9(409 reviews)

Keep reading

Sep 30, 2026 · Cybersecurity

AWS Foundational Technical Review: FTR Checklist and Prep Guide for SaaS Teams

Sep 30, 2026 · Cybersecurity

BSI C5 compliance checklist: how SaaS and cloud providers prepare for a C5 attestation

Sep 29, 2026 · Cybersecurity

AI-Generated Code Security: How to Keep AI-Assisted Development Safe and Audit-Ready

View more posts
Jamie
Virtual Agent

Hi! I'm Jamie. Curious about your current compliance challenges and how automation might help your team?