Graften / Essential Eight for MSPs

Essential Eight for MSPs: assess every client without the spreadsheet

The Essential Eight is the Australian Cyber Security Centre's baseline for mitigating cyber incidents, and more clients are asking their MSP to prove where they stand. Here is how to assess it properly across a client base, and where tooling helps and where it can't.

What the Essential Eight is

The Essential Eight is a set of eight mitigation strategies published by the Australian Cyber Security Centre (ACSC): application control, patch applications, configure Microsoft Office macro settings, user application hardening, restrict administrative privileges, patch operating systems, multi-factor authentication, and regular backups.

Each strategy is assessed against maturity levels. Level 1 is a basic implementation that resists low-sophistication attacks. Level 2 is the usual target for most small and mid-sized businesses. Level 3 is aimed at higher-value targets and is generally reserved for clients with a specific driver such as government work or critical infrastructure.

Why MSPs get stuck assessing it

How Graften assesses Essential Eight maturity

Graften reads each client's connected environments with read-only credentials (Microsoft 365, AWS, Google Cloud, Alibaba Cloud and an on-premises agent) and maps the findings to the Essential Eight strategies. The Compliance module's gap report shows which of the eight are short of the client's target level, and why, based on those findings.

Not measured means not assessed. If Graften cannot read the evidence for a control, that control is recorded as not assessed with the reason, never as passed. A maturity level is withheld until enough of the strategies could actually be measured, so a thin audit cannot produce a flattering number.

Controls that depend on paperwork or on things no API can see still need a technician to review them. Graften marks those clearly so the report separates what was measured from what was attested.

From assessment to something a client reads

Try the quick self-check first

If you only want a rough read on a client, the Essential Eight self-check on our home page takes a couple of minutes. It is self-reported and clearly a rough guide, not the automated audit.

Frequently asked questions

Does Graften certify a client as Essential Eight compliant?

No. The Essential Eight is assessed against ACSC guidance, and formal assessments are performed by independent assessors. Graften gathers and organises the evidence and shows the gaps, so the assessment is faster and the client is better prepared.

Which maturity level should an MSP target for a typical client?

Most small and mid-sized clients aim for Level 1 or Level 2. Level 3 usually applies where there is a regulatory or contractual reason. The gap report is built around the target level you set per client.

How often is the assessment refreshed?

Audits can run on a schedule, and scores are recalculated after each audit completes, so the number reflects recent evidence rather than a point-in-time project.

Related guides

See it on one of your own clients

Connect a client, run an audit and see what is measured and what is not. 14-day full-access trial.

Start free trial

No credit card required · See pricing