Your Essential Eight assessment cost depends on the scope and depth of the review. Before comparing prices, establish which systems will be examined, how the assessor will verify the controls and what you will receive when the work is finished.
The short answer
Published Australian offers include a baseline review at $3,500–$5,000 with GST treatment unstated, an assessment from A$8,500 excluding GST and a Telstra assessment at $20,000 excluding GST. These are different packages, with the inclusions and pricing qualifications set out below. Budget separately for the assessment, the work needed to fix gaps, any additional technology and the effort to maintain the controls. A report identifies your position; improving that position needs its own plan and budget.
Perhaps a customer has requested evidence of your cyber security controls. Your board may want a clearer view of risk, or your IT team may need an independent check before committing to improvements. The assessment should answer that specific business need.
This guide explains published Australian prices, the differences behind them and the questions to ask before accepting a proposal. For help defining your own engagement, explore Stanfield IT’s Essential Eight assessment and implementation services.
How much does an Essential Eight assessment cost?
Providers package assessments differently. A baseline gap review can involve less work than an engagement with broader technical validation, detailed evidence and formal reporting. Employee count is a useful starting point, but it does not explain the whole environment.
The following published offers illustrate that difference. They are examples of individual services, rather than a market average or a Stanfield IT price list.
| Provider and offer | Published price | Included in the public description | Clarify before comparing |
|---|---|---|---|
| Auresta: baseline assessment | $3,500–$5,000 GST treatment and currency code are not stated. | Essential Eight scorecard, prioritised gaps and an executive summary. | Confirm AUD pricing, GST, system limits and the extent of technical verification. |
| CISO Advisory Australia: assessment | From A$8,500 Excluding GST. | A maturity rating supported by evidence and an analysis of gaps. The fixed fee is confirmed after scoping. | Confirm the systems, target level and testing method covered by the starting price. |
| Telstra Enterprise: assessment | $20,000 Excluding GST; Australian service offering. | Scoping workshops, environment assessment, report, presentation and a tailored roadmap. | Confirm system limits and technical verification depth. Implementation is not listed as a deliverable. |
Prices are reproduced as published. These are different service offers, not equivalent quotes, endorsements or a measured market range. The Telstra page uses “$” without an explicit currency code; CISO Advisory explicitly states AUD.
Before using any of these figures in a budget, ask the provider to confirm eligibility, current pricing, GST treatment and the exact statement of work. Your Essential Eight assessment cost should be tied to that agreed scope. A lower fee can be appropriate for a narrower question. A higher fee needs to be justified by the coverage and deliverables your business requires.
What are you actually paying to have assessed?
The Essential Eight is a set of cyber security mitigation strategies published by the Australian Signals Directorate (ASD). An assessment examines implementation against an agreed maturity target and scope. For an introduction to the levels, see our Essential Eight maturity model guide.
Start by distinguishing the service being offered:
| Service | Useful for | Check before relying on it |
|---|---|---|
| Self-assessment questionnaire | Starting a conversation and recording what your team believes is in place. | Answers are self-reported. They do not establish that the controls have been technically verified. |
| Gap or readiness review | Finding likely shortfalls and planning improvement work. | Ask how much evidence is examined and whether the work supports a maturity conclusion. |
| Technical maturity assessment | Establishing findings against agreed criteria using evidence and technical checks. | Confirm scope, testing depth, limitations, reporting and who will accept the result. |
Commercial labels are not standardised. A service called an “audit” may be a detailed assessment or a short review. Read the method and deliverables before deciding whether two proposals are comparable.
ASD’s assessment process guide describes a progression from interviews and documentation to technical examination. Asking whether a policy exists gives different assurance from checking whether the relevant control operates across the systems in scope.
What changes your Essential Eight assessment cost?
The systems included in the review
Two businesses with 50 staff can require different amounts of assessment work. One may have a single Microsoft 365 environment and consistently managed laptops. Another may also have local servers, separate identity systems, specialist applications and equipment managed by several suppliers.
Agree which users, devices, servers, applications and environments are included. Record exclusions explicitly. Otherwise, a proposal can appear comprehensive while leaving out systems that matter to the customer or manager requesting the assessment.
The maturity target and evidence depth
The target determines which requirements are examined. The assessor should explain how evidence will support each finding, where sampling is used and how unverified items will be recorded.
For example, a statement that backups run every night leaves recovery untested. Depending on the requirements and agreed method, the assessor may also need configuration evidence and records demonstrating recovery testing. Producing, examining and resolving gaps in evidence takes time.
ASD’s maturity model requires the relevant requirements to be met to achieve a level. Strong controls in one area do not compensate for unmet requirements elsewhere. Ask for findings against the requirements, including gaps and limitations, rather than relying on an averaged score.
How ready your business is to participate
Missing asset records, unavailable administrators and scattered documentation can delay the work. Appoint someone to coordinate evidence and access, involve your current IT provider early, and identify systems that need a separate supplier’s help.
Request a preparation list before the engagement begins. To keep your Essential Eight assessment cost under control, agree which delays or scope changes can trigger fees and how additional work must be approved.
The report and follow-through
A technical report, management briefing, prioritised remediation plan and subsequent reassessment are distinct deliverables. Some proposals include several; others stop at the initial findings.
Ask to see a redacted sample report. You should be able to understand what was examined, what supports the findings and what action follows. Confirm whether implementation estimates are included, indicative or separately quoted.
Budget for the work after the assessment
The assessment fee is one part of the decision. Set out four budget lines so management can see the initial commitment and the potential follow-on work.
Implementation might involve changing administrator access, configuring application control, tightening device settings or improving backup arrangements. Those changes need owners, testing and an agreed rollout. Some may affect how staff sign in or use software.
Before buying more technology, establish what your existing tools can support and what remains uncovered. Microsoft’s Essential Eight guidance describes relevant Microsoft capabilities. Owning a licence does not demonstrate that the required controls are configured and operating across your assessment scope.
Confirm the one-off and recurring amounts separately, along with any minimum term. Allow for your own team’s time and ask who will check that the completed work addresses the findings. If the environment needs preparation, our Microsoft 365 support services provide a starting point for that discussion.
Comparing two assessment proposals for a 50-person business
Illustrative scenario only. This is not a Stanfield IT client case study or a quotation.
A 50-person professional-services firm is asked by a prospective customer for evidence of its Essential Eight maturity. The firm requests two proposals.
Proposal A
Readiness review
Interviews with the IT manager, a review of supplied documents and a list of likely gaps. Technical verification and reassessment are excluded.
This may help the firm plan improvements. It needs to confirm whether the customer will accept that level of evidence.
Proposal B
Technical assessment
An agreed system scope and maturity target, evidence collection, technical checks, documented findings and a management briefing. Remediation is quoted separately.
This provides a different depth of work. The firm still needs to confirm the customer’s required scope and assessor independence.
The sensible first step is to obtain the customer’s requirements in writing. That prevents paying for a report that cannot answer the original request, or commissioning more work than the decision needs. Once both providers quote against the same requirements, the price comparison becomes useful.
Use this checklist to compare assessment quotes
Ask each provider to answer the same questions in writing. Resolve material differences before choosing on price.
| Compare | Ask the provider |
|---|---|
| Purpose and acceptance | Will this engagement produce the evidence our customer, board or procurement team requires? |
| Scope | Which environments, systems and users are included? What is excluded? |
| Criteria | Which published framework version and maturity target will you use? |
| Method | What interviews, document reviews and technical checks are included? What will be sampled? |
| Assessor | Who performs and reviews the work? How will any independence requirement be met? |
| Evidence and access | What must we supply, how is access controlled, and how will evidence be stored and handled afterwards? |
| Deliverables | Do we receive control findings, limitations, a management summary and a prioritised action plan? |
| Fees and changes | Is the fee fixed for this scope? Is GST included? What can trigger an additional charge? |
| Timing and responsibilities | What are the delivery milestones, access dependencies and responsibilities on each side? |
| After the report | Are remediation, follow-up questions and reassessment included or separately priced? |
When requesting a quote, describe your reason for the assessment, approximate user and device numbers, main systems, current IT provider and required completion date. Include the actual customer requirement where you can. The provider can then identify what needs clarifying before pricing.
Ask for recommendations you can use with your own IT team or another provider. Clear findings, evidence references and responsibilities make the report useful beyond the original engagement.
Essential Eight assessment cost: your questions answered
Is a free Essential Eight assessment enough?
A self-assessment is useful for an initial discussion. Stanfield IT’s free Essential Eight scorecard is based on your answers and provides an indicative starting point. It does not technically verify your systems. If another organisation requires assessed maturity, establish what evidence and assessment method it will accept.
Will the assessment include fixing the gaps?
Only if the proposal explicitly includes implementation. Ask for the assessment fee, remediation work, additional technology and reassessment to be identified separately. Before approving the assessment, make sure any commitment to follow-on work is explicit.
Do we receive an Essential Eight certificate?
Ask what documentation the provider will issue. The report should record scope, findings and assessed maturity. ASD sets no general requirement for independent certification, although government, regulatory or contractual requirements may call for independent assessment. Confirm what the requesting organisation will accept before commissioning the work.
Can we use our current IT provider?
Your current provider can help gather evidence and implement improvements. Whether it can perform the assessment depends on the purpose and any independence requirement. Resolve that point with whoever will rely on the report before appointing an assessor.
Is this the same as a penetration test?
No. An Essential Eight assessment examines specified controls against maturity criteria. A penetration test investigates exploitable weaknesses within an agreed testing scope. One does not automatically provide the other’s coverage. If a customer requests both, ask for separate scopes and deliverables.
How often should an assessment be repeated?
Agree the review cycle around your risk, material system changes and any customer or policy requirements. Ask when reassessment is needed after remediation and who maintains the evidence between reviews. A dated assessment describes the environment examined; it does not establish that controls will remain effective indefinitely.
Plan the next step
Get an assessment quote with the scope clearly defined
Stanfield IT helps Sydney businesses assess their Essential Eight controls, plan improvements and manage the work that follows. Our Frenchs Forest team can work alongside your internal IT team or existing provider.
Tell us why you need the assessment, which systems are involved and when you need the findings. We can discuss the scope, evidence, reporting and implementation options before preparing a proposal.