The Essential Eight consulting market in Australia ranges from genuinely evidence-based assessors to questionnaire mills that will happily rate you Maturity Level Two without ever looking at a configuration. Since the rating you buy will eventually be tested — by an auditor, a tender panel, a cyber insurer or an actual attacker — choosing the consultant is choosing how defensible that rating will be. This guide sets out what a competent Essential Eight consultant actually does, what it should cost, and the red flags that predict an expensive do-over.
What a competent consultant actually does
- Assesses against evidence, not answers. ACSC’s own assessment guidance is built on demonstrated controls. A proper consultant inspects configurations, samples endpoints and tests controls across all eight mitigation strategies — application control, patching (applications and operating systems), macro settings, user application hardening, administrative privileges, multi-factor authentication and backups.
- Rates true maturity, including the uncomfortable number. If every assessment a consultant performs lands conveniently at the client’s target level, the assessments are marketing.
- Delivers a costed uplift roadmap, sequenced by risk. A gap list without costs and priorities is a to-do list; a roadmap is something a board can fund. See our guide to what an assessment should cost.
- Re-assesses after remediation, so the improved rating is demonstrable rather than aspirational.
What it should cost
As a reference point, CISO Advisory Australia publishes its fees: an evidence-based maturity assessment from $8,500, and a combined assessment plus uplift program from $18,000 (AUD ex GST, fixed fee). Market prices vary with environment size and target maturity level, but if a quote is dramatically below that range, ask precisely what evidence will be collected — the honest answer is usually “a questionnaire”. Our Essential Eight service page details the method behind the numbers.
Red flags, in order of expense
- The desktop assessment. No configuration inspection, no sampling, no testing — a rating built on what your own staff believe is true. It collapses the first time a tender panel or insurer asks for the evidence pack.
- The conflicted assessor. A consultant who also sells the remediation tooling, the managed service or the licenses has a financial interest in what the assessment finds. Independence is not a nicety; it is what makes the rating usable in front of third parties.
- The perpetual uplift. Vague roadmaps with no costs, no sequence and no end state keep consultants engaged and boards confused. Demand a defined target maturity level and a date.
- The compliance-theatre special. A consultant who promises Maturity Level Three quickly, for everyone, has misunderstood either the framework or their client — ML3 is a significant engineering undertaking, not a document set. Our guide to common Essential Eight mistakes covers the patterns.
Specific advice for councils and government suppliers
Local government faces the sharpest version of this choice: citizen data, ageing systems, state audit-office attention and lean budgets. A council buying an Essential Eight assessment should insist on public-sector references, plain-English reporting a councillor can follow, and a roadmap costed against a council budget cycle — see our dedicated guidance on Essential Eight for local government and our government and council practice. Suppliers to federal and state government should confirm the consultant can map findings to the contractual maturity level their agreements actually require, not a generic benchmark.
Seven questions to ask before you engage anyone
- Will you inspect configurations and sample systems, or rely on our answers?
- Who performs the assessment — and what is their background?
- Do you sell any product, license or managed service that could appear in the roadmap?
- What does the evidence pack look like — can we see a redacted sample?
- Is the fee fixed, and what exactly does it include?
- Is re-assessment after remediation included or priced?
- Will the rating survive an auditor, insurer or tender panel asking “prove it”?
CISO Advisory Australia answers all seven in writing before an engagement begins — fixed fee, evidence-based, no products, no commissions. If you want the rating your board can actually rely on, book a scoping call.
Frequently asked questions
What should an Essential Eight consultant actually do?
Assess your true maturity (ML1–ML3) against ACSC guidance by inspecting configurations, sampling systems and testing controls — not by scoring a questionnaire — then deliver a gap analysis and a prioritised, costed uplift roadmap, and re-assess after remediation so the rating is defensible to an auditor, tender panel or insurer.
How much does an Essential Eight consultant cost?
CISO Advisory Australia publishes its fees: an evidence-based maturity assessment from $8,500 and a combined assessment plus uplift program from $18,000, AUD ex GST, fixed fee. Quotes dramatically below that level usually describe a desktop review rather than an evidence-based assessment.
Can we just self-assess against the Essential Eight?
You can, and it is a useful starting point — but a self-assessment rests on what your own team believes is true, and it carries no independent weight with tender panels, insurers or auditors. Organisations facing external scrutiny need a rating someone independent has evidenced.
What are the biggest red flags when choosing an Essential Eight consultant?
Questionnaire-only 'assessments' with no configuration inspection; assessors who also sell the remediation tooling or managed services their roadmap recommends; vague uplift plans with no costs, sequence or end state; and anyone promising Maturity Level Three quickly — ML3 is a significant engineering undertaking, not a document set.
Need this handled for your organisation?
Confidential and no obligation. We respond the same business day — on-site same day / next business day, or remote, Australia-wide. Prefer to talk now? Call us 24/7 on 07 2112 8502.