Most Australian businesses hear about the Essential Eight and immediately assume the hard part is fixing the gaps. In practice, the hard part is understanding what your gaps actually are. A first Essential Eight assessment done cold, without preparation, tends to produce two outcomes: a demoralised leadership team who now believe the business is in worse shape than they thought, and a punch-list of remediations so long that nothing gets done. Both are avoidable with a small amount of pre-work.
Why the first assessment is emotionally loaded
The Essential Eight is deliberately opinionated. It sets specific expectations about patching timelines, application control, user privilege boundaries, macro handling, backup practices, and hardening of user applications. It is possible to score at Maturity Level Zero on several of these while genuinely doing a good job of the fundamentals. The assessment does not always reward the pragmatism that actually protects businesses.
Going into an assessment without setting that expectation invites a bad conversation. The business owner sees a report that reads like a failed exam, blames IT (unfairly), and either overreacts by throwing money at the loudest gap or underreacts by dismissing the whole framework. Neither is what the exercise is for.
The pre-assessment checklist
A short list of things worth doing before scheduling the formal assessment.
Gather the inventory. Assessors will ask for a list of endpoints, servers, SaaS applications, network devices, and administrative accounts. Assemble the list before they arrive, not during the meeting. Most SMBs discover in this step alone that their inventory has drifted from reality, a useful finding in itself.
Document your patching cadence. Not what the policy says; what actually happens. When were Windows patches last applied to the fleet? When were third-party applications last updated? When did the network devices’ firmware last change? Assessors want observable behaviour, not aspiration.
Locate your backups. Where are they, how often are they tested, and could you restore a specific critical system today. If the answer to any of those is uncertain, fix it before the assessment rather than have the auditor find it.
Confirm your privilege structure. Who has domain admin. Who has M365 global admin. Who has admin on the accounting system. In many SMBs this list is significantly larger than management believes.
Test your incident response. Not a full drill; just walk through the plan verbally with the leadership team for an hour. If the plan does not exist, write one before the assessment.
Get a rough score before the formal assessment
The most useful preparation is a self-assessment that gives you an honest starting position. Formal auditor assessments are expensive and slow, but a free self-assessment can be run in an afternoon and gives leadership a realistic view of where they will land.
CyberSafeCheck’s free posture assessment maps directly to the Essential Eight (plus ISO 27001, Privacy Act, and SMB1001) and produces a scored PDF report. Running it before you commission a formal assessment lets you fix the obvious gaps in advance, calibrate expectations with the leadership team, and avoid discovering surprises when the meter is running.
Choose the target maturity level realistically
The Essential Eight defines Maturity Level 1, 2, and 3. For most Australian SMBs, targeting Maturity Level 1 as an initial goal is realistic and defensible. Maturity Level 2 is a substantial commitment. Maturity Level 3 is largely aimed at organisations with heightened threat profiles (critical infrastructure, defence supply chain, some government) and is genuinely expensive.
The pre-assessment conversation should be about which level the business is targeting, not whether they should target the highest one. An honest ML1 story is more valuable to insurers, customers and regulators than a fantasy ML2 program that will never actually be delivered.
The bottom line
The Essential Eight is not a test that businesses pass or fail. It is a framework for making cyber posture legible to non-technical decision-makers. A well-prepared first assessment sets the leadership up for a productive next twelve months. A cold, unprepared assessment sets them up for a difficult conversation and a stalled program. Preparation is the cheapest thing you can do to make the exercise pay back.