ComplianceEssential EightGovernment Suppliers
Essential Eight · Government Suppliers

Essential Eight for suppliers to Australian government

The short answer

The Protective Security Policy Framework mandates Maturity Level 2 for non-corporate Commonwealth entities — not for you. But those entities push the same bar down their supply chain, so as a supplier you meet Essential Eight requirements through contract clauses and tender conditions. What matters is knowing your current maturity level and evidencing it before the clause asks.

Where the requirement actually comes from

Get the mechanics right first, because they change how you respond. The Protective Security Policy Framework (PSPF) mandates that non-corporate Commonwealth entities — federal departments and agencies under the PGPA Act — reach Essential Eight Maturity Level 2. That mandate applies to the entities themselves. No policy document reaches across and binds your company.

What reaches you is a contract. Entities responsible for their own security posture don’t stop at their own network edge — they push requirements to the suppliers who hold their data, run their systems or sit inside their processes. So the Essential Eight arrives on your desk as a tender condition, a schedule in a services agreement, or a renewal clause that wasn’t in the last version. Legally it’s ordinary contract law; practically it’s the PSPF’s Maturity Level 2 bar, translated into commercial terms and pointed at you.

The Essential Eight itself is published by the Australian Signals Directorate through the Australian Cyber Security Centre at cyber.gov.au: eight mitigation strategies — application control, patch applications, configure Microsoft Office macro settings, user application hardening, restrict administrative privileges, patch operating systems, multi-factor authentication, regular backups — each assessed at Maturity Levels 0 to 3.

What supplier clauses ask for, and how to answer

Clauses vary more than the framework does. Broadly you’ll meet three shapes.

Clause shape What it says What a defensible answer looks like
Named maturity level “The supplier must maintain Essential Eight Maturity Level 2” An assessment establishing that level, plus operating evidence that it still holds
Unnamed compliance “The supplier must comply with the ACSC Essential Eight” Your current maturity level, stated per strategy, with the assessment behind it — and a clarifying question back, because ‘comply’ without a level is ambiguous
Assurance-specified “…verified by an independent assessment” or “…by an IRAP assessor” The named form of assurance, budgeted and scheduled — don’t substitute a self-assessment where independence is specified

Expect the clause at renewal, too, not just in new tenders. Agreements that were silent on the Essential Eight a term ago come back with a schedule that isn’t — and a renewal gives you less runway than a tender does, because the incumbent relationship makes “we’ll need eighteen months” a harder conversation than it would be at bid stage. If government revenue matters to your plan, the cheapest time to establish your maturity level is between contracts, when nobody is waiting on the answer.

Three things make any of these clauses answerable rather than alarming.

Know your level before you’re asked. Assessment against ASD’s published Essential Eight assessment process can be a self-assessment, an IRAP assessor, or a private consultancy or MSP — there’s no single central provider, and which you need depends on what the clause specifies. The mechanics matter: your overall maturity is the lowest level across the eight strategies, so one weak strategy sets the number you have to write down.

Keep the evidence alive. A maturity level is an operating state, not a certificate. Patch timeframes, MFA coverage, privilege reviews and backup tests all decay the moment nobody runs them — and government clauses tend to survive into the contract, where the buyer can ask you to demonstrate compliance mid-term, not just at signature. As an ISO 27001:2022 certified provider ourselves, we answer these clauses about our own platform routinely; the ones that go smoothly are always the ones where the evidence already exists.

Treat the clause as a floor, not a ceiling. The requirement usually reflects the buyer’s PSPF obligation, which means it won’t be negotiated away. Suppliers who treat Maturity Level 2 as a standing capability rather than a per-tender scramble answer the next clause — and there will be a next one — at the cost of a document, not a project. Our governance capability exists to keep exactly that posture current between contracts.

What most people get wrong

Answering the clause with a policy pack. Suppliers reach for what worked on commercial questionnaires — a security policy, an ISO certificate, a completed spreadsheet — and none of it answers a question whose unit of measure is a maturity level. The Essential Eight is deliberately technical: either unapproved executables are blocked or they aren’t; either patches landed inside the timeframe or they didn’t. An evaluator working from ASD’s assessment process will look past every document to the controls underneath. The suppliers who lose time here aren’t the insecure ones — they’re the ones who discovered the difference between “we have security” and “we are Maturity Level 2” inside a contract window instead of before it.

How Secure60 handles this

Tools hand you a to-do list. We do the list — and run the security behind it. For government suppliers that means establishing your real maturity level, running the uplift to the level your contracts name, and keeping the operating evidence current through our governance capability so each new clause is answered from file. Commercials are scoped to the engagement — book a readiness call and bring the contract.

Frequently asked questions

Does the PSPF apply to us as a supplier?

Not directly. The PSPF binds non-corporate Commonwealth entities — federal departments and agencies. What reaches you is contractual: those entities write Essential Eight requirements into their agreements and tenders, and that clause binds you the way any contract term does.

Which maturity level do government contracts usually ask for?

Maturity Level 2 is the common reference point, because it’s the level the PSPF mandates for the entities themselves. But contracts vary — some name Maturity Level 1, some say ‘Essential Eight compliance’ without a level. Read the clause; if it’s ambiguous, ask.

Do we need an IRAP assessment to supply government?

Only if the contract asks for it. IRAP assessors are ASD-endorsed and used where formal independent assurance is required, especially for OFFICIAL and PROTECTED environments. Plenty of supplier clauses accept a self-assessment against ASD’s assessment process with supporting evidence.

We're ISO 27001 certified. Does that cover the Essential Eight clause?

No. They overlap, but ISO 27001 certifies a management system while the Essential Eight is a specific set of technical mitigation strategies with maturity levels. A clause naming a maturity level needs an Essential Eight answer — see ISO 27001 or Essential Eight.

What evidence should we keep on file?

An assessment report — independent or self-assessment against ASD’s published process — plus the operating evidence behind it: patch records against timeframes, MFA coverage, privileged-account registers, backup restore tests. The assessment dates; the operating evidence keeps it alive.

Turn the clause into a plan.

Book a readiness call. We'll establish your current maturity level, map it against what your government contracts actually ask for, and scope the uplift.

Book a readiness call Run a pilot