ACSC Essential Eight
What is ACSC Essential Eight?
Australian Cyber Security Centre Essential Eight Maturity Model: eight prioritised mitigation strategies with three maturity levels.. It comprises 24 controls organised across 8 domains, and applies in Australia.
How ACSC Essential Eight maps to other frameworks
All 24 controls, each one mapped to the equivalent requirement in other standards, with the evidence that carries across and the mappings that were judged and rejected shown alongside. No account needed to look.
See the control mappings →The 8 domains ACSC Essential Eight groups its controls into
Frameworks that share controls with ACSC Essential Eight
Each of these has at least one control mapped to a control in ACSC Essential Eight. The number is how many ACSC Essential Eight controls are shared, counted from the mapping graph.
NIST SP 800-53 Rev 5
24 shared controlsCIS Controls v8
24 shared controlsASD Strategies to Mitigate Cyber Security Incidents
24 shared controlsFedRAMP Moderate
23 shared controlsFedRAMP High
23 shared controlsNIST SP 800-53 Rev 5 MODERATE
20 shared controlsNIST SP 800-171 Rev 3
20 shared controlsAzure Security Benchmark
20 shared controlsImplementation guides for frameworks that overlap ACSC Essential Eight
Training on frameworks that overlap ACSC Essential Eight
There is no course on ACSC Essential Eight itself. These cover frameworks that share controls with it, so the material carries across even though the standard named is different.
Where ACSC Essential Eight overlaps with the standards you already hold
What ACSC Essential Eight means in your sector
What ACSC Essential Eight means for your job
Questions people ask about ACSC Essential Eight
What is ACSC Essential Eight?
How many controls does ACSC Essential Eight have?
Where does ACSC Essential Eight apply?
What frameworks does ACSC Essential Eight map to?
How do I get started with ACSC Essential Eight compliance?
Query ACSC Essential Eight programmatically
ACSC Essential Eight, its 24 controls and every mapping into other standards are available over a REST endpoint and an MCP server, so an agent can read them directly. The free tier is 10 calls a day and needs no signup.
ACSC Essential Eight API reference and MCP config →What ACSC Essential Eight requires, control by control
How much of another standard ACSC Essential Eight already covers
Each crosswalk is judged control by control, and the mappings that were rejected are kept alongside the ones that held.
- ACSC Essential Eight to ANSSI Guide d'hygiene informatique (42 mesures, v2.0) crosswalk
- ACSC Essential Eight to ASD Strategies to Mitigate Cyber Security Incidents crosswalk
- ACSC Essential Eight to AWS Well-Architected Security Pillar crosswalk
- ACSC Essential Eight to Azure Security Benchmark crosswalk
- ACSC Essential Eight to C5 (Germany) crosswalk
- ACSC Essential Eight to CIS Controls v8 crosswalk
- ACSC Essential Eight to Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 crosswalk
- ACSC Essential Eight to CMMC 2.0 crosswalk
How ready are you for ACSC Essential Eight?
Answer 25 questions and get a professional readiness report with gap analysis, maturity scores, and prioritised action items. Results in 5 minutes.