Most organisations meet the Essential Eight through a contract rather than a statute. That distinction matters, because the obligation, the evidence expected and the consequences of falling short are entirely different depending on which route reaches you.
Here is who is actually covered in Australia, and how.
Commonwealth entities: the direct mandate
Australian non-corporate Commonwealth entities are subject to the Protective Security Policy Framework, which requires implementation of the Essential Eight. This is the closest thing to a hard mandate in the Australian landscape, and it comes with reporting obligations to go with it.
The specific maturity level required, and the timing, have been adjusted across successive PSPF updates. If you are an entity in scope, take the requirement from the current framework rather than from secondary guidance — including this article.
Critical infrastructure: the SOCI Act route
The Security of Critical Infrastructure Act imposes risk management programme obligations on responsible entities for critical infrastructure assets across sectors including energy, water, healthcare, financial services, communications, data storage and processing, transport, food and grocery, defence industry, and higher education.
The Act requires a critical infrastructure risk management programme addressing cyber and information security hazards. It does not simply say "implement the Essential Eight", but the Essential Eight is the recognised Australian yardstick for that hazard category, and it is commonly how entities demonstrate the cyber component. State and sector regulators frequently reference it directly.
State and territory government
Several state and territory governments have adopted the Essential Eight in their own cyber security policies and frameworks, sometimes with their own target maturity levels and reporting cycles. If you operate in or supply to a state jurisdiction, check that jurisdiction's policy rather than assuming the Commonwealth position applies.
Show your Essential Eight position on demand
GRC Copilot ships all four maturity levels as ready-made assessments, so you can evidence your position for a tender, a regulator or a customer without rebuilding it each time.
Try GRC Copilot free Generate an AI-powered assessment Download checklist Book a demo
Suppliers and contractors: the route that reaches everyone else
This is how most private organisations encounter the Essential Eight. It arrives as:
- Tender requirements. Government procurement increasingly asks for a stated maturity level, and sometimes for evidence rather than an assertion.
- Contract clauses. Once written into a contract, the Essential Eight becomes a contractual obligation with the usual consequences for misrepresentation.
- Flow-down. A prime contractor bound by the requirement pushes it to subcontractors, which is how it reaches organisations several steps removed from government.
- Customer assurance. Large Australian enterprises now ask for it in vendor security questionnaires regardless of any government connection.
Contractual exposure deserves more caution than a statutory one. Overstating your maturity in a tender response is a representation you may have to defend later, and unlike a regulator, a counterparty has a direct commercial incentive to test it.
What about the Privacy Act?
The Privacy Act does not require the Essential Eight. Australian Privacy Principle 11 requires reasonable steps to protect personal information, and what counts as reasonable is judged against, among other things, prevailing practice. The Essential Eight is the most widely recognised statement of prevailing practice in Australia, so it is relevant evidence of reasonableness even where it is not the standard being applied.
With the Notifiable Data Breaches scheme in place, that becomes practical rather than theoretical: after a breach, the question of whether your steps were reasonable is asked with hindsight, and a documented Essential Eight position is a useful answer.
What to do if you are not sure
- Check whether you are a responsible entity for a critical infrastructure asset under the SOCI Act — the sector list is broader than most organisations assume.
- Search your current contracts for Essential Eight, ACSC and ASD references. Obligations you already signed are the ones most often missed.
- Assess against Level One regardless. If it reaches you later through a tender, having a real position beats scrambling to produce one against a deadline.
- Record which route applies to you. Statutory, contractual and voluntary adoption call for different evidence and different reporting.
Frequently asked questions
Is the Essential Eight law in Australia?
It is not a standalone law. It is mandated for Commonwealth entities through the Protective Security Policy Framework, and it functions as the recognised benchmark for the cyber hazard obligations that the SOCI Act imposes on critical infrastructure entities. For everyone else it arrives contractually or voluntarily.
Do small businesses need to comply?
There is no general legal requirement. In practice, small businesses supplying government or larger enterprises are increasingly asked for it, and ACSC guidance for small business is built on the same eight strategies.
Does the Essential Eight apply to cloud services we consume?
Yes, in the sense that the requirements follow your data and your users rather than your data centre. MFA on third-party services holding sensitive data, patching of online services, and backup protection all reach into what you consume rather than only what you host.
We are certified to ISO 27001. Is that accepted instead?
Generally not as a substitute. ISO 27001 evidences a management system across a scope you defined; the Essential Eight is eight prescriptive controls with specific timeframes assessed on their own terms. Certification helps considerably with the underlying substance but does not answer the maturity level question.
Key takeaways
- Commonwealth entities are mandated through the PSPF; confirm the current level from the framework itself.
- Critical infrastructure entities meet it through SOCI Act risk management obligations.
- For everyone else it arrives through tenders, contracts and flow-down — and contractual claims get tested.
- The Privacy Act does not require it, but it is strong evidence of reasonable steps after a breach.