The Essential Eight is a set of cybersecurity mitigation strategies developed by the Australian Cyber Security Centre (ACSC). It was created for Australian government agencies — but it's increasingly referenced in New Zealand, both in government procurement and in NZISM guidance.
Understanding what the Essential Eight actually is, how it maps to New Zealand's frameworks, and whether your organisation needs to implement it is increasingly important for any NZ compliance programme.
What the Essential Eight Covers
The Essential Eight is structured around eight mitigation strategies considered the most effective at reducing the risk of cyber incidents:
1. Application Control — prevent execution of unapproved applications, including malicious code. Only approved software can run on endpoints.
2. Patch Applications — patch operating systems and applications with known security vulnerabilities. The ACSC specifies timeframes: critical vulnerabilities within 48 hours, others within two weeks.
3. Configure Microsoft Office Macro Settings — block macros from the internet, allow only signed macros or macros from trusted locations. Macros are a primary malware delivery mechanism.
4. User Application Hardening — configure web browsers and other applications to block web advertisements, disable unneeded features. Reduces attack surface on endpoints.
5. Restrict Administrative Privileges — limit admin access to only those who need it for their role. Validate access regularly. Admin accounts should not browse the internet or read email.
6. Patch Operating Systems — patch operating systems with known security vulnerabilities, prioritising internet-facing systems.
7. Multi-Factor Authentication (MFA) — require MFA for all users, including administrators, accessing internet-facing services. Strong MFA (phishing-resistant) for privileged access.
8. Regular Backups — maintain backups of important data, software, and configuration. Test restoration regularly. Protect backups from modification and deletion.
Maturity Levels
The ACSC defines four maturity levels for Essential Eight implementation:
- Maturity Level Zero — not meeting the intent of any of the strategies
- Maturity Level One — partly aligned; basic cyber threats mitigated
- Maturity Level Two — more aligned; adversaries with intermediate capability mitigated
- Maturity Level Three — aligned; adversaries with advanced capability mitigated
Australian government agencies are required to achieve Maturity Level Two as a minimum. The full Essential Eight maturity model is published by the ACSC.
Essential Eight in New Zealand
The Essential Eight is not a mandatory New Zealand government standard — that's NZISM. But:
- NZISM incorporates controls that align strongly with all eight strategies
- The National Cyber Security Centre (NCSC) publishes guidance referencing Essential Eight strategies
- Many NZ government procurement contracts reference Essential Eight compliance
- Trans-Tasman agencies operating across both NZ and Australia often implement both
The NCSC's 2024 Cyber Threat Report identifies the same categories of threat — ransomware, phishing, credential compromise — that the Essential Eight was specifically designed to mitigate.
Mapping Essential Eight to NZISM
Most Essential Eight controls map directly to NZISM control families:
| Essential Eight | NZISM Chapter |
|---|---|
| Application Control | Software management, endpoint security |
| Patch Applications | Patch management, vulnerability management |
| Macro Settings | Email security, endpoint hardening |
| User Application Hardening | Endpoint configuration, browser controls |
| Restrict Admin Privileges | Access control, privileged account management |
| Patch Operating Systems | Operating system security, patch management |
| Multi-Factor Authentication | Authentication, identity management |
| Regular Backups | Business continuity, backup and recovery |
If you've implemented NZISM controls thoroughly, you'll have covered most Essential Eight requirements. AccreditAZ maps controls across both frameworks so you can assess your Essential Eight posture alongside your NZISM compliance.
Should You Implement the Essential Eight?
If you're a NZ government agency: implement NZISM. The Essential Eight is implicit within it. Assessing your Essential Eight posture separately is useful for benchmarking and for demonstrating compliance when working with Australian counterparts.
If you're a NZ private sector organisation in critical infrastructure, financial services, or health: the Essential Eight provides a practical, prioritised framework. The NCSC recommends its strategies as a baseline for all organisations.
If you're supplying services to Australian government: you likely have a direct requirement to implement the Essential Eight at a specific maturity level. Check your contract requirements carefully.
Read our guide on multi-framework compliance for how to manage NZISM, Essential Eight, and ISO 27001 together without duplicating effort.