ASD Essential Eight readiness checklist (free)

Use this free ASD Essential Eight readiness checklist to gauge your cyber security maturity across all eight mitigation strategies. Select Yes / Partial / No for each item β€” we’ll calculate your score by domain and generate a PDF you can use in risk discussions, audit prep and uplift planning.

What this covers

All eight ASD Essential Eight strategies: Application Control, patching, macros, user application hardening, admin privileges, OS patching, MFA and backups β€” mapped to practical, evidence-ready questions.

How scoring works

Select Yes = 2, Partial = 1, No = 0 for each item. We calculate an overall readiness score plus a domain-by-domain breakdown.

Free PDF output

Download a free, branded PDF readiness report with a score dial, domain bars, top gaps and detailed responses. Your details are sent via a secure AWS endpoint and used only to share the report and relevant security, privacy and AI governance updates.

ISO 27001 ISO 27701 ISO 42001 Essential Eight SOC 2 DISP / ISM / IRAP

Application Control

Allow-lists for approved executables, libraries, scripts and MSI.

0/0 answered

Patch Applications

Timely patching of Internet-facing and high-risk apps.

0/0 answered

Configure MS Office Macros

Block or tightly control macros from the Internet.

0/0 answered

User Application Hardening

Disable risky features (e.g., Flash/Java, ads, web trackers).

0/0 answered

Restrict Admin Privileges

Least privilege, approvals, and JIT/JEA patterns.

0/0 answered

Patch Operating Systems

Meet SLAs for OS patches with centralised visibility.

0/0 answered

Multi-Factor Authentication

MFA for remote, privileged and sensitive access.

0/0 answered

Regular Backups

Tested, immutable/tamper-evident backups and restores.

0/0 answered
0%
Not started

Answer the questions to see your readiness.

πŸ“ž Microsoft Teams