Essential Eight compliance software built for Australian teams

Track Essential Eight maturity, collect evidence, and stay audit-ready with certified assessor reviews - designed, owned, and operated onshore.

From tick-box tracking to audit-ready maturity

Many organisations only discover their Essential Eight gaps when an audit deadline appears. Constant gives you a live view of maturity across all eight strategies so remediation is continuous, not reactive.

Whether you are working toward Maturity Level 1, 2, or 3, the platform maps your controls, evidence, and assessor findings to the ACSC model your auditors expect.

Constant is purpose-built around the ACSC maturity model - so ML1, ML2, and ML3 requirements stay visible for every strategy, with evidence and remediation attached.

Maturity you can defend

Essential Eight is not a checkbox list - maturity levels change what good looks like for each strategy. Constant keeps ML1-ML3 requirements, evidence, and assessor findings in one place so you can show real progress between audits.

Built for Australian organisations

  • Government and councils working toward ACSC Essential Eight maturity
  • DISP suppliers and defence-adjacent organisations with onshore requirements
  • MSPs managing Essential Eight across client portfolios
  • Teams preparing for cyber insurance or customer security questionnaires

Eight strategies. Expand for detail

Each Essential Eight strategy has distinct maturity expectations. Expand a strategy to see how Constant helps you track it.

Track allowlisting scope from user profiles and temp folders through workstations, internet-facing servers, and full server coverage with central logging - with evidence that policies are enforced.

Map patch SLAs by maturity level - from internet-facing apps within two weeks through critical patches within 48 hours - and attach scan results and change records as evidence.

Assess macro controls from blocking internet macros to allowing only vetted macros in trusted locations, with configuration evidence and exception handling.

Track hardening baselines across user applications and browsers, including central policy enforcement at higher maturity levels.

Evidence privileged account hygiene, dedicated admin workstations, MFA, and just-in-time access with session logging as you move from ML1 to ML3.

Align OS patching to maturity timeframes and prove coverage with inventory, vulnerability, and change evidence.

Track MFA coverage from privileged and remote users through phishing-resistant MFA for all users, with enrolment and policy evidence.

Document backup scope, restoration testing, retention, and immutable or offline backups required at higher maturity levels.

Built for every maturity level

Constant maps your controls and evidence to the ACSC Essential Eight model across ML1, ML2, and ML3.

Strategy ML1 ML2 ML3
Application control Block execution from user profiles and temp folders Application control on workstations and internet-facing servers Application control on all servers with central logging
Patch applications Patch internet-facing apps within 2 weeks of release Patch non-internet-facing apps within 1 month Patch all apps within 48 hours of critical release
Configure Microsoft Office macros Block macros from the internet Block macros in files from untrusted sources Only allow vetted macros in trusted locations
User application hardening Harden user applications per ACSC guidance Extended hardening including web browsers Full hardening with central policy enforcement
Restrict administrative privileges Limit admin accounts and validate requests Dedicated admin workstations and MFA Just-in-time access with full session logging
Patch operating systems Patch internet-facing OS within 2 weeks Patch all OS within 1 month Patch all OS within 48 hours of critical release
Multi-factor authentication MFA for privileged users and remote access MFA for all users accessing important data Phishing-resistant MFA for all users
Regular backups Backup important data and test restoration Synchronise backups with retention policy Immutable, offline backups with tested recovery

What you get with Constant

Maturity dashboard

See your position across all eight strategies with clear ML1-ML3 indicators and progress over time.

Evidence collection

Centralise control evidence, assign owners, and track what is complete before assessors arrive.

Certified assessor review

Combine platform visibility with human judgement from Essential Eight professionals who understand Australian environments.

Onshore by design

Australian-owned infrastructure and support - critical for DISP suppliers, government, and defence-adjacent organisations.

Essential Eight FAQs

Start your compliance journey today

Choose the right plan for your organisation. Scale seamlessly as your compliance needs evolve.

Ready to simplify your compliance process?

Book a demo and see constant in action.

All Paid Plans Include

  • Certified assessors

  • Automated evidence collection

  • Unlimited assessor reviews

  • AI-powered pre-reviews

  • Real-time compliance dashboards

  • Priority support

  • Advanced reporting & exports

  • Single sign-on (SSO)

  • Audit-ready documentation

  • Role-based access controls

  • API & integrations

  • Australian data residency