Skip to content
TrustedZoneTrustedZone

Essential Eight Maturity Self-Assessment

Walk through eight controls, answer up to four questions each, get a maturity level estimate per control and an overall heatmap. Results are kept in the URL so you can share or revisit them. No login. No tracking.

v0.1 abbreviated · Roughly 5 minutes · How this is scored
1. Application Control

Only approved applications can execute on workstations and servers.

Maturity estimate: not started

2. Patch Applications

Internet-facing services and apps with vulnerabilities are patched within timeframes.

Maturity estimate: not started

3. Configure Microsoft Office Macro Settings

Macros from untrusted sources are blocked; trusted ones are controlled.

Maturity estimate: not started

4. User Application Hardening

Browsers, PDF readers, and Office are hardened against common attack vectors.

Maturity estimate: not started

5. Restrict Administrative Privileges

Admin privileges are restricted, validated, and isolated from user activity.

Maturity estimate: not started

6. Patch Operating Systems

OS vulnerabilities are patched within timeframes; unsupported OS is removed.

Maturity estimate: not started

7. Multi-factor Authentication

MFA is required for users, privileged users, and access to sensitive data.

Maturity estimate: not started

8. Regular Backups

Important data is backed up regularly, tested, and protected from tampering.

Maturity estimate: not started

How this self-assessment is scored

Each of the eight controls has up to four questions, ordered roughly from baseline practice (Maturity Level 1) up to advanced practice (Maturity Level 3). Your maturity estimate for a control is the highest level for which you can answer "yes" to all preceding questions:

  • ML0 — none of the four questions answered yes.
  • ML1 — first question yes (baseline implementation).
  • ML2 — first two yes.
  • ML3 — first three yes (the advanced row covers depth).

This is a v0.1 abbreviated self-check, not a formal assessment. The official ASD Essential Eight Maturity Model has more specific criteria per level, distinguishes mitigation strategies for different platforms, and is intended to be assessed against evidence rather than self-reported answers. For a formal read of where you sit — including the supporting evidence an authorising officer or auditor would expect — talk to us about a Stage 1 Essential Eight advisory engagement.

Source: ACSC — Essential Eight Maturity Model.

No data is sent anywhere. Your answers live entirely in your browser's URL. Closing the tab clears them unless you've copied the shareable link. For a formal assessment, email harry@trustedzone.com.au.