Quick answer: there is no universal price for Essential Eight implementation in Australia. The cost depends on the target maturity level, the systems inside the assessment boundary, the gaps already present, the evidence required and whether your team or a provider performs the work. Budget separately for assessment, remediation, tools or licences, operational maintenance and reassessment.
This guide is current to 29 July 2026. Published provider prices are labelled as examples, not market averages. The worksheet numbers are illustrative and are not quotes.
On this page
- Essential Eight status in July 2026
- What you are paying to implement
- The five Essential Eight cost stages
- Published price examples—not an Australian average
- Essential Eight implementation cost worksheet
- Illustrative 20-user scenario
- Questions that make quotes comparable
- Avoid the most common budget waste
- Frequently asked questions
Essential Eight status in July 2026
The ASD Essential Eight maturity model remains the operative public baseline. It defines Maturity Level Zero and three target maturity levels. ASD says organisations should select a target appropriate to their environment, implement each level progressively and reach the same level across all eight mitigation strategies before moving higher.
ASD announced a consultation in June 2026 on evolving the framework into an “Essentials” series. The consultation page says existing Essential Eight controls and investments are expected to align strongly with the proposed guidance. That is a reason to document decisions and avoid unnecessary lock-in—not a reason to stop patching, protecting accounts or testing backups while future guidance is developed.
ASD also states that there is no general requirement for independent Essential Eight certification. Independent assessment may still be required by a government policy, regulator or contract. Ask the customer or tender owner what evidence is actually required before buying an “audit” or “certification” package.
What you are paying to implement
| Mitigation strategy | Typical cost areas |
|---|---|
| Patch applications | Asset discovery, vulnerability scanning, application packaging, testing and deployment. |
| Patch operating systems | Supported operating systems, scanning, update rings, maintenance windows and exception handling. |
| Multi-factor authentication | Identity licences, authentication methods, enrolment, conditional access and support. |
| Restrict administrative privileges | Separate admin accounts, privileged-access processes, access reviews and workstation controls. |
| Application control | Policy design, allow-listing technology, testing, exception workflow and ongoing rule maintenance. |
| Restrict Microsoft Office macros | Policy configuration, trusted publishers or locations, code signing and business-process changes. |
| User application hardening | Browser, Office, PDF and scripting settings; compatibility testing and exception management. |
| Regular backups | Storage, retention, protected administration, monitoring, restore testing and recovery documentation. |
A product purchase is not the same as an implemented control. For example, buying endpoint-management software does not prove that every in-scope device is enrolled, patched within the required timeframe and producing usable evidence. The site’s Tanium, Intune and Configuration Manager comparison explains why platform capabilities and operational ownership need to be considered separately.
The five Essential Eight cost stages
1. Define the target and assessment boundary
Start with the business reason: internal risk reduction, a customer requirement, a government tender or formal assurance. Document which users, endpoints, servers, cloud services, networks and applications are in scope. A ten-person Microsoft 365 environment is not comparable to a multi-site hybrid estate with custom applications.
2. Assess the current state
ASD’s assessment process guide describes planning, scope, control assessment and reporting. It ranks tested or directly reviewed controls above screenshots, policies or verbal statements. A questionnaire-only review can be cheaper because it produces weaker evidence.
3. Remediate the gaps
Remediation is usually the less predictable part. It can include licensing, device enrolment, replacing unsupported systems, configuring policies, application testing, resolving exceptions, backup redesign, training and documentation. Business time matters too: application owners must test changes, staff must enrol in MFA and leaders must approve risk exceptions.
4. Operate and retain evidence
Maturity is not a one-off configuration. New starters, devices, applications and vulnerabilities change the environment. Include recurring ownership for patching, vulnerability scanning, access review, backup monitoring, restore testing, exception review and evidence retention.
5. Reassess
Reassessment confirms whether controls are still effective. Independence can matter when a tender or customer needs assurance; for an internal improvement cycle, the organisation may use its own team or provider. Confirm the required report format, sample size and evidence quality before comparing fees.
Published price examples—not an Australian average
Current provider pages illustrate how different products use the same “Essential Eight cost” language:
| Provider example | Published price checked | What the page describes |
|---|---|---|
| SecureLoop, 4 May 2026 | Gap analysis from $900; audit plus Microsoft 365 hardening from $1,900; audit plus “full remediation” from $2,800 | Fixed-price starting offers for its stated small-business assessment and remediation scope. GST treatment should be confirmed. |
| Otaris, 28 October 2025 | $79 per user/month for foundations, $139 for its full Maturity Level One plan, and $179 or $199 for its Levels Two and Three plans | Ongoing provider plans rather than a single independent assessment. Confirm inclusions, minimums and GST. |
Microsoft 365 Business Premium was listed by Microsoft Australia at $32.90 per user per month, paid yearly and excluding GST, when checked. It includes capabilities that may support parts of an implementation, but a subscription alone does not deliver or attest an Essential Eight maturity level.
Essential Eight implementation cost worksheet
| Budget line | Calculation | Your estimate |
|---|---|---|
| Scoping and initial assessment | Fixed fee or assessor hours × rate | $___ |
| Internal implementation labour | Staff hours × loaded internal cost | $___ |
| External remediation labour | Consultant/engineer hours × rate | $___ |
| New or upgraded licences | Users/devices × monthly amount × 12 | $___ |
| Hardware and legacy replacement | Unsupported devices, servers or security keys | $___ |
| Application testing and change | Business-owner hours and vendor fees | $___ |
| Documentation and training | Policies, procedures, admin and staff training | $___ |
| Ongoing operation | Monthly service/tools × 12 | $___ |
| Reassessment or assurance | Agreed frequency × assessment fee | $___ |
| Contingency | Documented percentage for discovered complexity | $___ |
| First-year total | Confirm GST basis and double counting | $___ |
Illustrative 20-user scenario
This fictional scenario demonstrates the worksheet; it is not indicative market pricing. Assume a 20-user professional-services business chooses Maturity Level One for one Microsoft 365 tenant and 24 Windows endpoints. It budgets $1,500 for assessment, 60 external engineering hours at an assumed $190 per hour, $45 per user per month for assumed additional tools and licensing, $2,000 of internal testing time and $2,500 for reassessment.
| Assessment | $1,500 |
| External implementation labour: 60 × $190 | $11,400 |
| Tools/licensing: 20 × $45 × 12 | $10,800 |
| Internal application testing and change | $2,000 |
| Reassessment | $2,500 |
| Illustrative first-year total | $28,200 |
The value of this example is the formula, not the total. Replace every assumption with a scoped quote or an internal cost. A business that already has capable management tools and clean device enrolment may need mainly configuration and evidence work; a business with unsupported systems and no asset inventory faces a different project.
Questions that make quotes comparable
- Which maturity level and exact systems are in scope?
- Is the engagement an assessment, remediation, managed operation, independent assurance or a combination?
- Which ASD assessment methods and evidence levels will be used?
- Does the quote test all eight strategies as a package, and how are samples chosen?
- Which licences, tools, hardware and business application changes are excluded?
- Who owns policies, scripts, configurations, reports and evidence after the engagement?
- How are exceptions documented, approved, monitored and reviewed?
- What recurring work is required to maintain the assessed state?
- Is independent assessment actually required by the contract or regulator?
ASD’s separate questions to ask managed service providers also cover the provider’s own security, secure administration, activity monitoring and vulnerability management. This matters because a provider may hold privileged access to many customer systems.
Avoid the most common budget waste
- Do not buy tools before confirming the target, scope and current gaps.
- Do not pay repeatedly for reports without funding remediation.
- Do not call a questionnaire a technical assessment when direct evidence is required.
- Do not force every system into an exception without reducing and approving the risk.
- Do not assume a security product replaces operational ownership.
Where endpoint security and operations overlap, the Tanium versus CrowdStrike comparison is a useful reminder to map each required control to a named platform, process and owner rather than a vendor logo.
Frequently asked questions
Is Essential Eight mandatory for every Australian business?
No. It is widely used as a baseline, while particular government policies, contracts or regulated settings may impose requirements. Confirm the rule that applies to your organisation.
Does an organisation need Essential Eight certification?
ASD says there is no general independent-certification requirement. An independent assessment may still be required by a directive, regulator or contract.
Should a small business target Maturity Level One?
ASD recommends choosing a target through a risk-based process. Its small-business guidance suggests starting with MFA, updates and backups, then considering Maturity Level One. A contractual requirement may set a different target.
Checked 29 July 2026. ASD guidance and provider prices can change. Reconfirm the current maturity model, contractual target, assessment scope, GST and written inclusions before approving work.