Essential Eight Verified

Essential Eight verification: maturity claims a relying party can check.

Essential Eight Verified is a cryptographic verification standard for conformance claims against the ACSC Essential Eight Maturity Model. Evidence artefacts (policy documents, telemetry, configuration snapshots and audit logs) are assessed by an Issuing Partner and sealed as a Verification Reconciliation Object that relying parties resolve at a public registry.

Why Essential Eight claims need verifying

The ACSC Essential Eight is a national security baseline. Maturity against it is asserted by the organisation that holds it, and the model has no standards body behind it. A government agency, a prime, an insurer or a managed service customer reading a maturity claim has no form in which to test it. Essential Eight Verified supplies that form.

The 8 controls

  • Application control
  • Patch applications
  • Configure Microsoft Office macro settings
  • User application hardening
  • Restrict administrative privileges
  • Patch operating systems
  • Multi-factor authentication
  • Regular backups

Each control is assessed against the ACSC maturity levels, and the determination records the maturity attested for each control.

What a determination records

FieldContent
Subject entityThe organisation whose claim is verified.
Attestation periodThe dates the determination covers.
Maturity per controlThe level attested for each of the 8 controls.
Evidence reconciliationThe outcome of reconciling each evidence artefact against the claim.
Issuing PartnerThe identity of the party that assessed the evidence.
Public anchorThe commitment that fixes the time of issue.

How a relying party checks one

The registry is public. A relying party queries by subject entity, by Issuing Partner or by anchor event, and reads the same record the subject holds. Verification outputs are deterministic: the same evidence and the same policy version produce the same result.

Who relies on it

  • Government agencies and primes assessing suppliers against an Essential Eight requirement.
  • Insurers pricing cyber cover against stated maturity.
  • Managed service providers evidencing maturity to customers.
  • Boards and audit committees that want maturity reported from evidence.

Where the specification sits

Essential Eight Verified is published at the IETF as draft-hillier-certisyn-essential-eight-verified-02, an individual submission open for review. The plain-language summary of every Certisyn specification is on the standards in plain language page.

Frequently asked

What is Essential Eight Verified?

Essential Eight Verified is a cryptographic verification standard for conformance claims against the ACSC Essential Eight Maturity Model. It is published at the IETF as the individual Internet-Draft draft-hillier-certisyn-essential-eight-verified.

What evidence does an assessment use?

Policy documents, telemetry records, configuration snapshots and audit logs that demonstrate conformance to the 8 controls across the maturity levels.

Who issues an Essential Eight determination?

Designated Issuing Partners assess the evidence and issue a Verification Reconciliation Object that binds the conformance claim to a public anchor.

How does a relying party check one?

A relying party queries the public attestation registry by subject entity, issuing partner or anchor event, and reads the maturity attested for each control with its attestation period.

Does the standard replace the ACSC model?

The standard sits beside the ACSC Essential Eight Maturity Model and addresses Essential Eight scope. The ACSC model remains the authority on what each maturity level requires.

Related