Between where you are and where you need to be

Essential Eight Gap Analysis

Knowing your current maturity level is half the job. The other half is knowing which specific mitigations stand between you and the level you are required to reach.

An Essential Eight gap analysis compares your assessed maturity against your target, one mitigation strategy at a time, and turns the difference into an ordered list of work.

What it compares

Why the order matters

The Essential Eight is meant to be implemented as a package: partial coverage across all eight is generally weaker than full coverage of the higher-priority ones. The analysis surfaces where a single piece of work closes several gaps at once - patching and application control tend to be where that happens.

It also makes the cost of a target level visible before you commit to it in a contract.

What comes out

A prioritised remediation list, a per-strategy view of current against target, and a report that can go to a board or a client without being rewritten.

Note: Cyber Compliance is a self-assessment and reporting aid, not a certification, audit or legal advice. Outputs help you prepare and track gaps; confirm your position with a qualified auditor, certification body or legal adviser before relying on it.

Frequently asked questions

What is an Essential Eight gap analysis?

A comparison of your current maturity level against your target for each of the eight mitigation strategies, producing a prioritised list of the specific requirements you have not yet met.

What target maturity should we aim for?

It depends on who is asking. Contracts and regulators often specify a level; otherwise it follows from your own risk assessment. The tool works against whichever target you set.

Is this an official ACSC assessment?

No. It is a self-assessment tool built around the published Essential Eight Maturity Model. It does not replace an independent assessment where one is required.

Start your free trial