Essential Eight
About the Essential Eight
The Essential Eight is a set of baseline cyber security mitigation strategies recommended by the Australian Cyber Security Centre (ACSC): application control, patching applications, configuring Microsoft Office macro settings, user application hardening, restricting administrative privileges, patching operating systems, multi-factor authentication, and regular backups. Organisations are assessed against a maturity level (ML0–ML3) for each strategy — it isn't a pass/fail "compliant" status.
Our Current Position
Aligned with, not assessed against, the Essential Eight
Agend is not currently certified or self-assessed against the Essential Eight, and we do not claim a maturity level. The Essential Eight is primarily an organisation- and endpoint-hardening framework rather than a SaaS product standard — it applies partly to our internal corporate IT and partly to our hosting providers, not solely to our product.
Our platform runs on Vercel and Supabase (AWS), who hold independently-attested certifications (SOC 2, ISO 27001) covering operating-system patching, infrastructure backups, and physical/environmental controls — a genuine strength for the strategies that sit at the hosting layer.
Where we already align well:
- Multi-factor authentication (TOTP) is built and available today — enforcing it for all privileged/admin roles is a configuration change, not a build
- Row-level, tenant-isolated access control is the default across our platform architecture
- Secrets are stored in a managed vault, not in application code or plaintext config
- Operating-system patching and infrastructure backups are handled by our hosting providers under their own certifications
What we're actively working on, in priority order:
- Enforcing multi-factor authentication for all privileged and administrative roles across our systems
- Tightening administrative-privilege controls and adding a tamper-evident audit trail for privileged actions
- Automated dependency-update and vulnerability-scanning tooling in our build pipeline, with a documented patch SLA
- Documenting our backup and retention policy, including a tested restoration drill
- A documented internal baseline for the organisation- and endpoint-level strategies (application control, Office macro policy, browser/application hardening, endpoint OS patching) that a formal assessment would also expect
This is an active, tracked programme, not a completed assessment. We're happy to share our roadmap toward a target maturity level and complete a security questionnaire on request.
Questions about our Essential Eight posture can be directed to security@agend.com.au.