Free Essential Eight self-check
Eight questions, one per strategy. See where you likely stand in about a minute, and send the result to a client or colleague with a link.
This is a quick self-check based on your own answers. It is not an Essential Eight maturity assessment, which needs evidence from real systems. Use it to spot likely gaps, then verify.
Answer for yourself or for a client
What the eight strategies ask for
The Essential Eight comes from the Australian Cyber Security Centre. Each strategy is assessed at maturity levels 1 to 3. A "yes" above means you believe the strategy is consistently in place; a real assessment tests that with evidence.
What to do with the result
- Gaps shown above: start with multi-factor authentication, patching and backups. They are the most commonly exploited and usually the quickest to improve.
- "Not sure" counts as a gap. If you cannot show evidence, an assessor or insurer will treat it the same way.
- For an MSP: run this with each client and compare it with what your tooling actually measures. Here is how MSPs assess it from real evidence.
Frequently asked questions
Is this the official Essential Eight assessment?
No. It is a self-reported checklist. Formal assessments are performed by independent assessors against ACSC guidance.
Is my data stored?
No. Your answers stay in your browser. The share link carries the eight yes/no answers in the address itself, nothing else, and nothing is sent to Graften.
How do I check a client rather than myself?
Answer for their environment. Copy the link to send the result to them, or connect their environment to Graften for measured results.