For government suppliers, DISP applicants & cyber insurance requirements

An Honest Essential Eight Assessment.
Not Your MSP Marking Their Own Homework.

Essential Eight Assessment · Independent · Fixed Price

Fixed fee of $4,950 + GST. Covers all 8 strategies across all maturity levels. Plain-English report your board or insurer can actually read.

  • Fixed fee — $4,950 + GST, no surprises
  • Independent assessor — we don't manage your IT, so we have no reason to inflate findings
  • Covers all 8 mitigation strategies across all maturity levels
  • Plain-English report your board or insurer can actually read
  • Australian-owned and operated

Free Compliance Summary

Find Out Where You Stand Against the Essential Eight

Three questions. No sign-up. Under a minute. We'll send you a personalised summary of your likely compliance position.

Question 1 of 3

What's driving the need for an assessment?

Prefer to call or text? 0468 475 580·9am–5pm Mon–Fri

Trusted by organisations across industries

Client 1
Client 2
Client 3
Client 4
Client 5
Client 1
Client 2
Client 3
Client 4
Client 5
Client 1
Client 2
Client 3
Client 4
Client 5
The Problem

Most businesses get their E8 assessment done by the same company managing their IT.

That's a conflict of interest.

If your MSP did the work and they're also doing the assessment, they're marking their own homework. Findings get softened. Maturity levels get rounded up. You get a report that says you're more compliant than you are — and that's when cyber insurance claims get rejected, when tenders get pulled, and when breaches happen.

We're not your MSP. We don't manage your infrastructure. We have nothing to protect except our own credibility — which means you get an honest picture.

Who This Is For

Built for organisations that need a real answer.

Government contract bidders

Businesses bidding on government contracts that require documented E8 compliance.

DISP applicants and members

Applicants and members working toward ML2 requirements need an independent assessment on record.

Cyber insurance requirements

Underwriters are now requiring evidence of E8 controls before writing or renewing policies.

IT managers and business owners

Anyone who wants to know their actual maturity level before committing to remediation spend.

If you already have an MSP who's told you you're "basically compliant" but you've never had an independent set of eyes on it — this is for you.

FAQ

Common questions.

Is the Essential Eight mandatory for my business?

It's mandatory for Commonwealth government entities and increasingly expected for anyone in the defence supply chain (DISP), critical infrastructure, or bidding on government contracts. For private businesses, it's technically voluntary — but cyber insurers and enterprise procurement teams are actively requiring documented evidence of E8 maturity at ML2 as a condition of cover or contract award. If you deal with government or hold a cyber insurance policy, treat it as mandatory in practice.

What's the difference between your assessment and what my MSP offers?

Your MSP manages your environment, which means they have a conflict of interest in assessing it. We're an independent security firm with no stake in the outcome. We also go beyond interviews and documentation review — we technically test your controls against the ACSC's actual assessment process guide. That's what makes the report defensible to an insurer, auditor, or DISP assessor.

How long does it take?

The scoping call and technical assessment phase typically takes 1–3 days depending on environment size. You receive the completed report within 10 business days of assessment completion. Total elapsed time from kickoff to debrief is usually 2–3 weeks.

Will you also do the remediation work?

We can provide advisory support for remediation, but we deliberately separate assessment from implementation. Your existing MSP should execute the technical fixes — that's their job. Our role is to assess independently, give you a verified score, and tell them exactly what to fix. This keeps the independence of the assessment intact.

What maturity level should we target?

Most Australian SMBs should target ML2 — it's the ASD-recommended minimum and the level most cyber insurers and government clients expect to see. We'll confirm the right target for your situation on the scoping call.

Will my cyber insurer accept your report?

Yes — in most cases. Our reports are produced by an independent security firm, technically tested against the ACSC assessment process guide, and include a full evidence file with configuration exports and tool outputs. That's the format Australian cyber insurers require when they ask for "independent documentation" of E8 maturity. If your broker has a specific reporting format they want to see, let us know on the scoping call and we'll confirm compatibility before we start.

Do you assess cloud environments, on-premises, or both?

Both. The majority of Australian SMBs run a hybrid environment — typically Microsoft 365 or Azure in the cloud with some on-premises infrastructure or endpoints. We assess across your full environment, not just one component. The scoping call maps out exactly what's in scope so nothing gets missed and there are no surprises.

What do you need from us to run the assessment?

Read-only or scoped access to your environment — typically a combination of remote access, configuration exports, and a brief session with your IT lead or MSP. We'll send you a clear pre-assessment checklist after the scoping call so your team knows exactly what to prepare. Most businesses find the access requirements straightforward; if your MSP is cooperative, they can handle the access setup in a few hours.

Can we use the report for a DISP application?

Yes. Our assessment covers all eight controls against the ACSC assessment process guide — the same framework your DISP assessor references — and includes a technical evidence pack with configuration exports and documented findings. That's what a DISP submission needs. We've scoped the process so most defence SMBs can complete assessment and remediation within a 90-day window, which aligns with most DISP application timelines. If you're actively working toward a DISP submission, mention it on the scoping call so we can tailor the deliverables accordingly.

We've never had a formal assessment before. Where do we start?

Start by filling in the enquiry form below — it takes two minutes and helps us understand your environment and what's driving the need. We'll come back to you within one business day with a quote scoped to your situation. If you're not sure what maturity level to target or whether you're ready, the scoping call is the right place to work that out. There's no commitment required at that stage — it's just a conversation.

Deliverables

What you get.

A single fixed-fee engagement covering every one of the eight mitigation strategies across all three maturity levels.

Full written assessment report

Board-ready format, plain English. Written for stakeholders and insurers, not just your IT team.

Maturity level rating per control area

Each of the eight strategies rated with documented evidence you can hand to an auditor.

Prioritised remediation roadmap

What to fix first and what it will take — no generic advice, specific actions.

Verbal debrief with Rafe and Caleb

A call to walk through findings, answer questions, and explain what matters most.

No upsell to a managed security contract at the end. No lock-in. Just an honest report and a clear path forward.

Process

How it works.

01

Answer 3 quick questions

Tell us about your environment so we can confirm this is the right fit and scope the engagement correctly.

02

Book a scoping call

We'll jump on a 20-minute call to confirm scope, timeline, and access requirements. No sales pressure — if we're not the right fit, we'll tell you.

03

Assessment

We work through your environment systematically — no noise, no unnecessary disruption.

04

Report and debrief

You receive your full report within the agreed timeframe, followed by a debrief call to walk through findings and answer questions.

The people behind the work

Meet the team

Rafe Fredericks

Rafe Fredericks

Founder & Lead Assessor

Rafe founded Aussie Pentest after identifying a gap in accessible, transparent security work for Australian businesses. He leads every engagement personally — no handoffs, no outsourcing.

Caleb Brooke

Caleb Brooke

Co-Founder & Technical Lead

Caleb oversees remediations, report writing, and technical advisory. When you get a debrief call, you're talking to the people who actually ran the assessment.

Aussie Pentest is run by Rafe and Caleb — two cybersecurity practitioners who started this business to do honest, thorough work for Australian companies that are tired of getting vague reassurances from their IT provider. We're not a 200-person consultancy. We're not billing you for a graduate analyst's learning curve. When you engage us, you talk directly to the people doing the work.

Ready to get an honest picture of where you stand?

Three questions. No commitment. We'll send you a personalised compliance summary before you book anything.