Essential Eight for MSPs: assess every client without the spreadsheet
The Essential Eight is the Australian Cyber Security Centre's baseline for mitigating cyber incidents, and more clients are asking their MSP to prove where they stand. Here is how to assess it properly across a client base, and where tooling helps and where it can't.
What the Essential Eight is
The Essential Eight is a set of eight mitigation strategies published by the Australian Cyber Security Centre (ACSC): application control, patch applications, configure Microsoft Office macro settings, user application hardening, restrict administrative privileges, patch operating systems, multi-factor authentication, and regular backups.
Each strategy is assessed against maturity levels. Level 1 is a basic implementation that resists low-sophistication attacks. Level 2 is the usual target for most small and mid-sized businesses. Level 3 is aimed at higher-value targets and is generally reserved for clients with a specific driver such as government work or critical infrastructure.
Why MSPs get stuck assessing it
- It is evidence-heavy. A real assessment needs configuration data from each client's tenants and endpoints, not a questionnaire someone ticked from memory.
- It repeats. A score from last quarter does not describe the client today, and clients get asked again at renewal, audit and insurance time.
- It multiplies. Doing this by hand for twenty clients is a full-time job, which is why it usually gets sold as a one-off project rather than a service.
How Graften assesses Essential Eight maturity
Graften reads each client's connected environments with read-only credentials (Microsoft 365, AWS, Google Cloud, Alibaba Cloud and an on-premises agent) and maps the findings to the Essential Eight strategies. The Compliance module's gap report shows which of the eight are short of the client's target level, and why, based on those findings.
Not measured means not assessed. If Graften cannot read the evidence for a control, that control is recorded as not assessed with the reason, never as passed. A maturity level is withheld until enough of the strategies could actually be measured, so a thin audit cannot produce a flattering number.
Controls that depend on paperwork or on things no API can see still need a technician to review them. Graften marks those clearly so the report separates what was measured from what was attested.
From assessment to something a client reads
- A prioritised remediation roadmap, so the gap report turns into billable work.
- Branded client portals and scheduled reports, so the score is visible every month instead of once a year.
- Evidence packages for Essential Eight that an auditor or insurer can open through a time-limited link, with no Graften account needed.
Try the quick self-check first
If you only want a rough read on a client, the Essential Eight self-check on our home page takes a couple of minutes. It is self-reported and clearly a rough guide, not the automated audit.
Frequently asked questions
Does Graften certify a client as Essential Eight compliant?
No. The Essential Eight is assessed against ACSC guidance, and formal assessments are performed by independent assessors. Graften gathers and organises the evidence and shows the gaps, so the assessment is faster and the client is better prepared.
Which maturity level should an MSP target for a typical client?
Most small and mid-sized clients aim for Level 1 or Level 2. Level 3 usually applies where there is a regulatory or contractual reason. The gap report is built around the target level you set per client.
How often is the assessment refreshed?
Audits can run on a schedule, and scores are recalculated after each audit completes, so the number reflects recent evidence rather than a point-in-time project.