
DEFINITION: What the Essential Eight is
The Essential Eight is a set of eight baseline mitigation strategies published by the Australian Signals Directorate through the Australian Cyber Security Centre, designed to protect organisations against the most common cyber threats. It is not a certification. It is a prioritised control baseline, assessed against defined maturity levels rather than passed or failed.
The eight strategies are application control, patching applications, configuring Microsoft Office macro settings, user application hardening, restricting administrative privileges, patching operating systems, multi-factor authentication, and regular backups.
Organisations are assessed against four maturity levels, from Maturity Level Zero, indicating weaknesses in the overall posture, through Maturity Levels One, Two, and Three, which correspond to increasing levels of adversary capability the controls are designed to withstand.
DEFINITION: What Essential Eight penetration testing means
Essential Eight penetration testing is security testing conducted to verify whether an organisation's Essential Eight controls function as claimed when subjected to realistic attack techniques. It is not one of the eight strategies, and the Essential Eight framework does not mandate it.
The distinction is important and frequently misrepresented by vendors. The Essential Eight tells an organisation which controls to implement. Penetration testing tells an organisation whether those controls actually work. A maturity self-assessment records what has been configured. A penetration test demonstrates what happens when someone attempts to defeat that configuration.
Who the Essential Eight actually applies to
Stating this accurately matters, because the scope is commonly overstated.
The Essential Eight is mandatory for non-corporate Commonwealth entities under Australian government policy. These organisations are required to implement the strategies and assess their maturity.
For everyone else, including private sector Australian businesses, the Essential Eight is not a legal requirement. It is a strongly recommended baseline. However, it increasingly appears as a contractual requirement in government procurement, in supply chain agreements with entities that are themselves bound by it, and in enterprise vendor assessments. Many Australian businesses encounter the Essential Eight not through regulation but through a customer contract.
An Australian business should therefore assess Essential Eight relevance by asking a practical question: does any customer, prospective customer, or partner contract reference it? If yes, it applies commercially regardless of whether it applies legally.
Where penetration testing verifies Essential Eight maturity

Five of the eight strategies produce outcomes that penetration testing can directly verify. Three are better verified through configuration review and process audit. Distinguishing between them prevents companies from paying for testing that cannot assess what they need assessed.
- Restricting administrative privileges is directly testable. A tester attempts privilege escalation from a standard account and determines whether administrative access can be obtained through means the control was intended to prevent.
- Multi-factor authentication is directly testable. A tester evaluates whether authentication can be completed without the second factor, whether the second factor can be bypassed through session handling weaknesses, and whether all access paths enforce it consistently rather than only the primary login.
- Patching applications and patching operating systems are partially testable. A tester can confirm whether unpatched components are present and exploitable in practice, which is a stronger statement than a patch report showing what is installed.
- Application control is partially testable. A tester attempts to execute unapproved code and determines whether the control blocks it in practice across the paths an attacker would realistically use.
- User application hardening is partially testable through examining whether hardening measures resist realistic attack techniques rather than only appearing in configuration.
Regular backups and Microsoft Office macro configuration are more effectively verified through configuration review and restoration testing than through penetration testing, though a tester may confirm whether backup systems are reachable and exploitable from a compromised position.
Your Last Pentest Is Already Out of Date
Every week you ship without continuous testing is a week a vulnerability goes unseen. See what Capture The Bug finds in your first engagement.
Book a demo
For Australian organisations working toward a specific Essential Eight maturity level, the useful step is identifying which strategies a penetration test can verify for their environment and which require a different assessment approach. Book a demo with Capture The Bug and get that mapped against a real environment.
The gap between self-assessed and verified maturity

The Essential Eight Maturity Model permits self-assessment, and many Australian organisations self-assess. This creates a specific and well-documented risk.
Self-assessment records intended configuration. It captures whether a control has been implemented according to the organisation's understanding of its own environment. It does not capture whether the control was implemented completely across every system, whether a legacy access path bypasses it, or whether an attacker can defeat it through a method the assessor did not consider.
The most common finding when penetration testing follows a self-assessment is not that a control was absent. It is that the control was present but incompletely applied, most often on a system, account, or access path that was outside the assessor's mental model of the environment.
A penetration testing service conducted against an environment that has already been self-assessed frequently identifies this category of gap, which is why organisations pursuing higher maturity levels or facing external scrutiny generally seek verification rather than relying on self-assessment alone.
How Essential Eight testing fits alongside other frameworks

Australian companies commonly face the Essential Eight alongside SOC 2, ISO 27001, or APRA CPS 234 requirements. These frameworks assess overlapping concerns from different angles.
The Essential Eight focuses on specific technical mitigations and maturity of implementation. SOC 2 and ISO 27001 focus on the operation of controls and management processes over time. APRA CPS 234 focuses on information security capability commensurate with threat exposure for regulated financial entities.
A single continuous testing programme, scoped to cover the environment within all relevant boundaries and reported with findings mapped to each framework's specific control expectations, produces evidence usable across all of them. Commissioning separate engagements for each framework generally duplicates work across largely identical technical surfaces. A CREST-certified penetration testing service structured this way reduces both cost and evidence assembly burden.
What this means for your roadmap
The accurate position is that the Essential Eight does not require penetration testing, and any provider stating otherwise is misrepresenting an Australian government framework. What penetration testing provides is verification that the eight strategies function under realistic conditions rather than only in documentation. For organisations that are legally bound to the Essential Eight, contractually bound through a customer agreement, or targeting Maturity Level Two or Three, the practical value of a penetration testing service is not compliance. It is knowing that the maturity level being reported is the maturity level actually achieved.
Plan Your Annual Pentesting Strategy the Right Way
Learn how modern SaaS companies structure pentesting across the year to reduce risk, stay compliant, and avoid last-minute panic before audits.
FAQ
Does the Essential Eight require penetration testing?
No. Penetration testing is not one of the eight mitigation strategies, and the Essential Eight framework does not mandate it. Penetration testing is used to verify whether the implemented strategies function effectively against realistic attack techniques, which self-assessment alone cannot confirm.
Is the Essential Eight mandatory for Australian businesses?
It is mandatory for non-corporate Commonwealth entities under Australian government policy. For private sector businesses it is a strongly recommended baseline rather than a legal requirement, though it frequently appears as a contractual obligation in government procurement and enterprise supply chain agreements.
Which Essential Eight strategies can penetration testing verify?
Restricting administrative privileges and multi-factor authentication are directly verifiable through testing. Application control, patching applications, patching operating systems, and user application hardening are partially verifiable. Regular backups and macro configuration are more effectively verified through configuration review and restoration testing.
What are the Essential Eight maturity levels?
There are four levels, from Maturity Level Zero through Maturity Level Three. Each level corresponds to increasing sophistication of adversary tradecraft that the implemented controls are intended to withstand, with higher levels requiring more complete and consistent implementation.
Can one testing programme cover Essential Eight, SOC 2, and ISO 27001?
Yes. These frameworks assess overlapping technical surfaces from different perspectives. A single continuous testing programme scoped across the relevant environment, with findings mapped to each framework's specific control expectations, produces evidence usable for all three without commissioning separate engagements.





