The Essential Eight comes up constantly in general practice IT conversations, usually with the implication that your practice is failing to meet something it is legally required to meet. That framing is wrong, and it leads practices to spend money in the wrong order.
This guide sets out what the Essential Eight actually is, whether it applies to you, which parts genuinely matter in a general practice, and how it lines up with the accreditation requirements you are already assessed against.
No. The Essential Eight is guidance published by the Australian Signals Directorate, not legislation. The obligation to reach a specific maturity level applies to non-corporate Commonwealth entities, which must meet Maturity Level Two as a minimum under the Protective Security Policy Framework. A privately owned general practice is not a Commonwealth entity and carries no such obligation.
ASD is also explicit that there is no requirement to have an Essential Eight implementation certified by an independent party. Assessment by a third party only comes into play where a government directive, a regulator, or a contract requires it.
What does bind your practice: the Privacy Act 1988, the Notifiable Data Breaches scheme, and the RACGP Standards you are accredited against. Anyone telling you the Essential Eight is mandatory for your practice is either mistaken or selling something.
Because it has become the common language for cyber security in Australia. Insurers score against it. Larger organisations ask about it in contracts. Incident reviews map back to it. When a health service or a government program asks about your security posture, the Essential Eight is usually the vocabulary the question is written in.
There is also a practical argument. The eight strategies were chosen because they address the attack methods ASD actually observes, drawn from its incident response and penetration testing work. They are a defensible starting point even for a practice with no external obligation at all.
The useful reframing: treat the Essential Eight as a checklist you choose to use because it is good, not a standard you are failing. That changes what you spend and in what order.
The model defines four levels, Maturity Level Zero through Maturity Level Three. Zero means minimally aligned with the intent of a strategy. Three means fully aligned. The levels are designed to correspond to increasing adversary capability, so Three is built for targeted attackers with time and resources.
For a general practice with no contractual obligation, Maturity Level One is the sensible target. It addresses the bulk of opportunistic attacks, which is what actually threatens a practice. Chasing Level Three in a ten-person clinic means spending heavily against a threat model that does not match who is attacking you.
The rule that catches people out: ASD applies the strategies as a package. Organisations are advised to reach a consistent level across all eight before moving up. Seven strategies at Level Two and one at Level Zero is not “nearly Level Two” — the weakest control sets your position.
The eight strategies are summarised below in the order a practice should work through them, then covered in full in ASD’s order.
| Where to start | Strategy | What it means in your practice |
|---|---|---|
| 1 | Multi-factor authentication | A second factor on email and remote access, where most opportunistic compromises begin. |
| 2 | Regular backups | Backups proven by actually restoring them, with the result written down. |
| 3 | Restrict administrative privileges | Day-to-day work does not happen from an account that can change anything. |
| 4 | Restrict Microsoft Office macros | Macros from the internet disabled. Most practices have no legitimate need for them. |
| 5 | Patch applications | Clinical system, browsers and PDF readers kept current, including the forgotten long tail. |
| 6 | Patch operating systems | No machines running past their support date, or isolated where they cannot be replaced. |
| 7 | User application hardening | Browser and Office features that are commonly exploited and rarely needed, turned off centrally. |
| 8 | Application control | Only approved software runs. Demanding to maintain, and rarely proportionate in a small clinic. |
Sequencing is our recommendation for general practice, not an ASD ranking — ASD treats the eight as a package.
This is the connection worth making, because it turns optional guidance into work you have to do anyway.
Criterion C6.4 requires individual password-protected access to clinical software with access matched to authorisation. That is the same ground as restricting administrative privileges, and multi-factor authentication strengthens it. C6.4 requires a business continuity and information recovery plan with backups behind it. That is the regular backups strategy almost exactly. C6.4 requires patient information to be kept out of public view, which depends on workstation configuration that user application hardening and privilege restriction both support.
Four of the eight strategies do double duty as accreditation evidence. If you are working toward accreditation anyway, you are already partway to Maturity Level One without having framed it that way.
The mapping runs the other way too — if you have not worked through the accreditation side yet, start there. We covered all five sub-indicators in our guide to the IT requirements for RACGP accreditation.
Two stand out, for different reasons.
Application control is the most technically demanding and the least proportionate for a small clinic. It requires knowing and approving everything that runs, and maintaining that as software changes. In a practice of fifteen people it usually costs more attention than the risk justifies.
Patching operating systems is hard for a different reason: equipment. A practice may have a machine that cannot be updated because it drives a device whose vendor never supported anything newer. That is not a technical failure, it is a procurement constraint, and the answer is isolation and a replacement plan rather than pretending the risk is not there.
The other six are largely achievable with configuration and discipline rather than significant spend.
In this order, because it puts risk reduction ahead of completeness:
The first three address most of what actually happens to practices. The rest is worth doing, but not before those.
Evidence, not assertion. For each strategy you should be able to produce something showing the control operates: a patching report, a list of accounts with administrative rights and when it was last reviewed, a record of a completed restore test, the configuration applied to Office and browsers.
Insurers increasingly ask about the Essential Eight by name on renewal questionnaires. Answering those accurately matters — a claim can turn on whether the controls you attested to were actually in place.
Worth noting: ASD does not certify implementations, and no one can sell you an official Essential Eight certificate. What you can have is a documented, honest assessment of where you sit against each strategy.
The Essential Eight is not a legal obligation for your practice, and treating it as one leads to spending in the wrong order. Treated properly, it is a well-evidenced checklist that overlaps substantially with accreditation work you already have to do.
Bluebird IT works exclusively with healthcare organisations across Western Australia, and general practice is a core part of that work. We support Best Practice and Medical Director environments, and our clients reach us with a typical response time of under 5 minutes during business hours.
If you would like an honest assessment of where your practice sits against each of the eight strategies — written so it can go to your insurer or your accreditation assessor — we can work through it with you. You can read more about our IT support for WA GP practices and medical centres.
If your practice runs Best Practice, we cover the clinical software side as well — see our Bp Premier support for WA practices for what that includes.

We'll learn about your organisation, your clinical systems, and what's keeping you up at night.

If we're the right fit, you'll select the IT service agreement that best suits your organisation.

With Bluebird IT managing your technology, your team can do what they do best — delivering outstanding care to your patients.