Module 8 and the capstone of StartCloud's Essential Eight for Australian Business pathway, in five short units with a knowledge check: why ASD requires no independent certification and the three situations where independent assessment may still be required, what counts as evidence versus what does not, how to answer an insurer or tender questionnaire without overstating or underselling, and the monthly, quarterly and yearly rhythm that stops a maturity position decaying.
Proving It: Assessments and Awkward Questions
Do you need to be certified?
This is the question every business asks, and there is a lot of marketing built on getting the answer slightly wrong. So here it is straight from ASD.
ASD says so plainly. There is no Essential Eight certificate to buy, no register to appear on, and nobody who can officially bless you. If a vendor implies you must be certified by them, that is a sales position rather than a rule.
There is an important exception, and it is the reason the question keeps coming up. ASD notes that an implementation may need to be assessed by an independent party in three specific situations.
Common if you supply to, or are part of, a Commonwealth entity.
Where your industry's regulator requires it of you.
The most common one for private businesses. A big customer writes it into the contract.
Assess yourself, honestly, and keep the evidence. If a contract later demands an independent assessment, you will be ready for it instead of starting from scratch under a deadline. ASD publishes an Essential Eight assessment process guide setting out how assessments should be conducted, which is worth reading before you pay anyone to do one for you.
An assessor, an insurer or a customer's auditor is asking one question in different words: show me, do not tell me. Evidence is what turns a claim into a position.
- A configuration screenshot showing the policy applied, with the date
- A report listing every user and whether MFA is enforced
- A restore test with the date, what was restored, and who watched
- A patching report showing what is installed, not what was requested
- A written exception, with its approval and its review date
- "Our IT provider handles that"
- An invoice for a security product
- A policy document nobody has implemented
- A licence entitlement, as opposed to an enforced setting
- Somebody's memory of turning it on a while back
You do not need a compliance platform. Eight folders in SharePoint, each holding the evidence for one control with the date on it, will carry you through almost any questionnaire. The trick is capturing it as you go rather than reconstructing it the week a tender is due.
The form arrives, it is long, and it is due Friday. Two failure modes here, and they pull in opposite directions.
Ticking yes because it is nearly true, or because you assume your provider has it covered. This is the dangerous one. An insurance claim can be reduced or refused over an answer on a proposal form, and a contract can be lost when an audit contradicts what you said.
Ticking no because you are not perfect, when the control is genuinely in place with one documented exception. Businesses lose work over this too, and it is entirely avoidable. Partial with detail beats a bare no.
State what is in place, name the exception, and give the date you are fixing it by. Three sentences, no hedging.
"Multi-factor authentication is enforced for all staff on all Microsoft 365 services. One service account used by our accounting integration is excluded, documented and approved, with access restricted by IP. We are moving it to a supported method by 30 November."
These forms are often filled in by an IT provider and signed by a director. If you are the one signing, make sure you can explain each answer, because you are the one making the representation. A short conversation before it goes back is worth far more than an argument afterwards.
The last thing worth knowing is that an Essential Eight position is perishable. Everything in it decays quietly, without anyone doing anything wrong.
Staff join and leave, and admin rights get granted for a good reason on a busy day and never taken back. Module 9 of the Microsoft 365 pathway exists precisely because of this.
The application that was supported when you assessed is end of life eighteen months later, and nothing announces it.
One documented exception is fine. Nobody notices when it becomes six, because each one seemed reasonable on the day.
New systems get added and never included in the backup. The restore that worked last year has not been tried since.
Monthly: check patching actually happened. Quarterly: review who has admin rights and test a restore. Yearly: reassess all eight and refresh the evidence folders. Put those in a calendar with a name against them. That is the whole maintenance program, and it is the difference between a position you can defend and one you used to have.
That is the pathway. You know where the Essential Eight comes from and who asks about it, what the maturity levels actually mean, what all eight controls involve, where to start, and how to prove it. That is more than most business owners in this country can say, and it is enough to hold your own in a conversation with an insurer, an auditor or a customer.
- cyber.gov.au: Essential Eight maturity model, including the position on independent certification
- cyber.gov.au: Essential Eight explained, and the assessment process guide
Checked against ASD guidance at the time of writing (August 2026). This module is general information, not legal or insurance advice. If a contract or a regulator sets a specific requirement for you, read that requirement rather than relying on a summary.
Knowledge check
5 quick questions. Get 4 right and the module is yours.
1. Does a business need to be certified against the Essential Eight by an independent party?
2. Which of these counts as evidence that MFA is in place?
3. A questionnaire asks whether you restrict admin privileges. You do, except for one documented and approved exception. What do you answer?
4. Why does an Essential Eight position decay?
5. Who should be able to explain the answers on a security questionnaire?