AccreditAZ

← All articles

Essential Eight · 7 min read · Published 12 April 2026 · Reviewed 17 August 2026

The Essential Eight in New Zealand: What It Is and Why It Matters

Developed by the ACSC for Australian government agencies, the Essential Eight is now widely referenced in New Zealand. Here's what it covers, how it maps to NZISM, and whether you need to implement it.

The Essential Eight is a set of cybersecurity mitigation strategies developed by the Australian Cyber Security Centre (ACSC). It was created for Australian government agencies — but it's increasingly referenced in New Zealand, both in government procurement and in NZISM guidance.

Understanding what the Essential Eight actually is, how it maps to New Zealand's frameworks, and whether your organisation needs to implement it is increasingly important for any NZ compliance programme.

What the Essential Eight Covers

The Essential Eight is structured around eight mitigation strategies considered the most effective at reducing the risk of cyber incidents:

1. Application Control — prevent execution of unapproved applications, including malicious code. Only approved software can run on endpoints.

2. Patch Applications — patch operating systems and applications with known security vulnerabilities. The ACSC specifies timeframes: critical vulnerabilities within 48 hours, others within two weeks.

3. Configure Microsoft Office Macro Settings — block macros from the internet, allow only signed macros or macros from trusted locations. Macros are a primary malware delivery mechanism.

4. User Application Hardening — configure web browsers and other applications to block web advertisements, disable unneeded features. Reduces attack surface on endpoints.

5. Restrict Administrative Privileges — limit admin access to only those who need it for their role. Validate access regularly. Admin accounts should not browse the internet or read email.

6. Patch Operating Systems — patch operating systems with known security vulnerabilities, prioritising internet-facing systems.

7. Multi-Factor Authentication (MFA) — require MFA for all users, including administrators, accessing internet-facing services. Strong MFA (phishing-resistant) for privileged access.

8. Regular Backups — maintain backups of important data, software, and configuration. Test restoration regularly. Protect backups from modification and deletion.

Maturity Levels

The ACSC defines four maturity levels for Essential Eight implementation:

Australian government agencies are required to achieve Maturity Level Two as a minimum. The full Essential Eight maturity model is published by the ACSC.

Essential Eight in New Zealand

The Essential Eight is not a mandatory New Zealand government standard — that's NZISM. But:

The NCSC's 2024 Cyber Threat Report identifies the same categories of threat — ransomware, phishing, credential compromise — that the Essential Eight was specifically designed to mitigate.

Mapping Essential Eight to NZISM

Most Essential Eight controls map directly to NZISM control families:

Essential EightNZISM Chapter
Application ControlSoftware management, endpoint security
Patch ApplicationsPatch management, vulnerability management
Macro SettingsEmail security, endpoint hardening
User Application HardeningEndpoint configuration, browser controls
Restrict Admin PrivilegesAccess control, privileged account management
Patch Operating SystemsOperating system security, patch management
Multi-Factor AuthenticationAuthentication, identity management
Regular BackupsBusiness continuity, backup and recovery

If you've implemented NZISM controls thoroughly, you'll have covered most Essential Eight requirements. AccreditAZ maps controls across both frameworks so you can assess your Essential Eight posture alongside your NZISM compliance.

Should You Implement the Essential Eight?

If you're a NZ government agency: implement NZISM. The Essential Eight is implicit within it. Assessing your Essential Eight posture separately is useful for benchmarking and for demonstrating compliance when working with Australian counterparts.

If you're a NZ private sector organisation in critical infrastructure, financial services, or health: the Essential Eight provides a practical, prioritised framework. The NCSC recommends its strategies as a baseline for all organisations.

If you're supplying services to Australian government: you likely have a direct requirement to implement the Essential Eight at a specific maturity level. Check your contract requirements carefully.

Read our guide on multi-framework compliance for how to manage NZISM, Essential Eight, and ISO 27001 together without duplicating effort.

Manage your NZISM, ISO 27001, Essential Eight and PSR compliance in one place.

Start free trial →