Service · 2–3 weeks
Essential Eight assessment
Maturity across all eight mitigation strategies, graded from your actual Microsoft 365, Entra ID and cloud configuration rather than a questionnaire, and attested by the engineer who ran it.
This is our Security Controls Assessment reported against the ACSC maturity model. Same engagement, same price — if your driver is ISO 27001, PCI-DSS or CPS 234 instead, we report it that way.
Fee
Additional cloud platforms and tenants are quoted at scoping. Half of what you pay, capped at $5,000, credits against engineering work within 90 days of payment.
Scope an assessmentMost assessments round up.
Ours rounds down.
What you get
A maturity rating that holds up
Graded level by level across all eight strategies, with both rules above applied. The number you can put in front of an insurer or a tender panel.
A named engineer’s attestation
Where no API can answer, an engineer reviews your evidence and signs the verdict, dated. Not a tool’s opinion with a logo on it.
A live findings readout
We walk your team through what we found and why it matters, and answer the questions the document can’t anticipate.
A prioritised, costed roadmap
Sequenced by what unblocks the next level, with effort and licence cost against each item. Several usually need no new spend.
How much of this is actually measured?
It’s the right question, and most vendors don’t answer it. Fewer than half the strategy levels can be read directly from cloud configuration. The rest — application and operating system patching, backups, macro governance, application control on unmanaged endpoints — are not exposed by any tenant API, for anyone. Those we assess from evidence you supply, and an engineer signs the verdict.
Read from your configuration
MFA enforcement, privileged role assignment, Conditional Access and everything else a cloud API will tell us. Each finding shows the literal configuration state as evidence.
Reviewed by an engineer, and dated
Where no API answers, we review the evidence you supply and record a verdict against a named engineer, with the date and the evidence relied on printed beside it. The date travels with the verdict everywhere it appears.
Your report prints the split on the grade itself — how many levels measured, how many attested. We would rather show you the composition than let you assume the whole number came from a scanner.
Questions we get asked
They averaged, we didn’t. You’re ML3 on seven strategies and ML1 on one, and an attacker only needs the one. If you want the flattering number we’ll show you that too, on the same page as the real one.
They can, and it’s often funded by Microsoft. It’s a pre-sales engagement designed to build the case for more licences, and it ends with recommendations rather than remediation. Take it — then bring us the parts that need fixing, because we have nothing to sell you at the end.
Access is read-only, provisioned as a time-bound application registration you create and can revoke yourself at any moment. The scanners run off our platform, so your credentials never reach it — it holds results only and cannot connect to your environment. Our data handling, sub-processors and retention are published on the trust page.
No. We don’t issue certification and no assessment makes you compliant with anything. What you get is an evidenced, defensible position on where you sit and what moves you up.
Scope, stated before you buy
We assess cloud-managed controls. Where endpoints aren’t managed from Intune, or where control lives on-premises, those levels can’t be measured — they’re assessed from your evidence and marked as attested. If most of your estate is on-premises, say so at scoping and we’ll tell you honestly whether this is the right engagement.
Try it smaller first
A Snapshot scans one cloud platform and returns findings with evidence for $1,000 ex GST. No maturity rating, no attestation — but it credits in full against this assessment within 90 days of paying for it.