A client or a tender asked
"State your Essential Eight maturity level and attach evidence."
A questionnaire or contract clause names a level, the deadline is real, and nobody can point to evidence of where you are.
A two-week Essential Eight maturity assessment scores all eight strategies and tells you which level you need. If it is Level 1, go ahead within 90 days and your assessment payment becomes month one of a six-month programme, at one fixed price. If it is Level 2, the report prices that before you commit.
For organisations of up to 100 seats. Ex GST.
What you get
Rated 5.0 out of 5. 5.0 on Google · Australia-based staff · Sydney, since 2014
Why you are here
It usually arrives one of three ways. Whichever one brought you here, the first step is the same.
"State your Essential Eight maturity level and attach evidence."
A questionnaire or contract clause names a level, the deadline is real, and nobody can point to evidence of where you are.
The answers you have are best guesses, and the policy is written on them.
"Are we covered?"
The honest answer is "we think so." Your IT team is stretched, the MSP says everything is fine, and nobody has checked.
All three need the same thing first: an evidenced score against the eight strategies.
How you buy this
You commit to a two-week assessment and nothing else. The programme only exists if the report says you need it.
$3,950 once, ex GST
All eight strategies scored, Level 0 to 3, with evidence. You keep the scorecard, the target recommendation and a sequenced plan with owners and indicative tooling costs, whoever does the work.
"Where are we, and which level do we actually need?"
The report decides
Then the programme, with your assessment counted as month one. $23,700 in total. See the programme →
A shorter engagement, or a deeper one, estimated in the report before you commit to anything. Indicative term 6 to 9 months.
Not sure whether you need Level 1 or Level 2? How to tell which maturity level you need
Already at the level you need. The report says so, and you owe nothing further. The plan is still yours.
No programme is sold before the report is written. The scoping call decides whether the assessment itself is the right first step.
The deliverable
The assessment is written to be useful to whoever does the work, including someone who is not us.
Maturity scorecard. Every strategy scored Level 0 to 3, with the evidence behind each score.
Target recommendation. The level your obligations actually require, in writing.
Prioritised remediation roadmap. Effort, owner and order per strategy, with tooling gaps and their indicative costs named.
Yours to keep. Take it to your MSP, your incumbent, or a competitor of ours. It is written to survive that.
Section 3 · Remediation plan
Section 2 · Maturity scorecard
Level 0 to 3
Essential Eight maturity assessment
Current level, target level and the
sequenced plan to close the distance.
Essential Eight pricing
This is the second purchase, and it only exists if the report calls for it. Compliance here means reaching and holding the level your report recommends: for most organisations, Level 0 to Level 1 over six months, then staying there.
Step 2 · Remediation
$23,700 to Level 1
6 payments of $3,950, the first of which is your assessment. Up to 100 seats. Ex GST.
Cybereen licences included. The compliance platform runs in your own tenant for the term, inside the price.
After the uplift
$2,800 per month
Ongoing. Stay at level between audits. Ex GST.
Cybereen licences included. Your tenant stays live for as long as monitoring runs, inside the monthly price.
Already at Level 1 or 2? That uplift is estimated in your assessment report before you commit, typically over 6 to 9 months.
This is the one place the page states what is in and out, so nothing turns up in month four.
The programme price is for the outcome. The monthly split is for your cash flow, and it does not change if you reach Level 1 early.
In the price
Our service, for up to 100 seats
Cybereen platform licences for the term
Re-assessment and the evidence pack
Named in the plan before you commit
Third-party product licences
Hardware
Anything above 100 seats, priced at the scoping call
Level 1 is delivered with tooling from our partners, so you are not assembling eight point products to reach a baseline. The plan names what you need, what you already own and what each costs. Only Cybereen sits inside the price.
Start here
Go ahead within 90 days of your assessment and it is included in the six-month plan, not added on top.
Your name and work email is all we need. Thirty minutes with a senior consultant; if something smaller than this programme would do, we say so.
"I feel like I've got a great cybersecurity team when I've got Cliffside. They leave no stone unturned."
Leah Christiansen · Security Manager, DeltaPAE · Read the case study →
Rated five out of five.
"…a report that was packed with actionable items and in priority order. This made it super clear to us what we needed to work on."
The programme
Gate · plan agreed first
01 · Weeks 1 to 2
All eight strategies scored with evidence, not interviews alone. Target level recommended in writing.
02 · Week 3
Plan presented to leadership: sequence, effort, owners, exclusions and the monthly price. You decide with the full picture.
03 · To month 6
Strategies hardened in priority order alongside your IT team or MSP. Monthly report: done, in progress, blocked and by whom.
04 · Month 6
Re-assessment against the target level, gaps closed, evidence pack issued.
Six months assumes you go ahead straight after the readout. Using the full 90-day window moves the finish date by the same amount. Outcome B engagements typically run 6 to 9 months.
Timelines assume your IT team or MSP completes assigned actions within agreed windows. Where they do not, we tell you early and in writing.
Our commitment
If a strategy is not at level, the report says so. Anything beyond the agreed scope is quoted in writing before it starts.
Rated five out of five.
"Because of their support and honest advice, our security posture is much better than what it was six months back. Would absolutely recommend their services. Great value for money is an added bonus."
Rated five out of five.
"…excellent, professional and have been a pleasure to work with on our networking projects. Very forthcoming with information on what they're doing and how configuration has been implemented."

Senior Security ConsultantEssential Eight lead
Ajay leads Cliffside's governance, risk and compliance work, Essential Eight included. He runs the assessment and stays on the engagement through to the re-assessment at the end of the programme.
Ajay works within Cliffside's security engineering and architecture team. Cliffside's own information security management system is certified to ISO/IEC 27001:2022 by BSI.
Thirty minutes, no slides. We ask about your environment, your obligations and who is asking for evidence, and tell you whether the assessment is the right first step or if something smaller would do.
Our Essential Eight page covers the eight strategies, the four maturity levels and a self-assessment checklist you can run before you talk to anyone.