Essential Eight Verified is a cryptographic verification standard for conformance claims against the ACSC Essential Eight Maturity Model. Evidence artefacts (policy documents, telemetry, configuration snapshots and audit logs) are assessed by an Issuing Partner and sealed as a Verification Reconciliation Object that relying parties resolve at a public registry.
The ACSC Essential Eight is a national security baseline. Maturity against it is asserted by the organisation that holds it, and the model has no standards body behind it. A government agency, a prime, an insurer or a managed service customer reading a maturity claim has no form in which to test it. Essential Eight Verified supplies that form.
Each control is assessed against the ACSC maturity levels, and the determination records the maturity attested for each control.
| Field | Content |
|---|---|
| Subject entity | The organisation whose claim is verified. |
| Attestation period | The dates the determination covers. |
| Maturity per control | The level attested for each of the 8 controls. |
| Evidence reconciliation | The outcome of reconciling each evidence artefact against the claim. |
| Issuing Partner | The identity of the party that assessed the evidence. |
| Public anchor | The commitment that fixes the time of issue. |
The registry is public. A relying party queries by subject entity, by Issuing Partner or by anchor event, and reads the same record the subject holds. Verification outputs are deterministic: the same evidence and the same policy version produce the same result.
Essential Eight Verified is published at the IETF as draft-hillier-certisyn-essential-eight-verified-02, an individual submission open for review. The plain-language summary of every Certisyn specification is on the standards in plain language page.
Essential Eight Verified is a cryptographic verification standard for conformance claims against the ACSC Essential Eight Maturity Model. It is published at the IETF as the individual Internet-Draft draft-hillier-certisyn-essential-eight-verified.
Policy documents, telemetry records, configuration snapshots and audit logs that demonstrate conformance to the 8 controls across the maturity levels.
Designated Issuing Partners assess the evidence and issue a Verification Reconciliation Object that binds the conformance claim to a public anchor.
A relying party queries the public attestation registry by subject entity, issuing partner or anchor event, and reads the maturity attested for each control with its attestation period.
The standard sits beside the ACSC Essential Eight Maturity Model and addresses Essential Eight scope. The ACSC model remains the authority on what each maturity level requires.