The compliance question, answered honestly
Zero Trust closes three of the Essential Eight. Not eight.
Vendors like to imply that a SASE platform delivers the Essential Eight. It doesn't, and any assessor will say so. Here is the mapping we actually stand behind — what Cloudflare One genuinely covers, what it only partly covers, and what still has to come from your endpoint and backup stack. You should expect this level of candour from anyone quoting you compliance work.
| Essential Eight strategy | Coverage | What the Cloudflare One / SASE stack does | What still has to come from elsewhere |
|---|---|---|---|
| Multi-factor authenticationLimit extent of incidents | Strong | Cloudflare Access enforces MFA per application through your existing Entra ID or Google Workspace identity provider — and can require a second factor or hardware security key in front of internal apps that have no native MFA at all, including legacy line-of-business systems. | The identity provider itself, MFA enrolment and phishing-resistant method rollout (Entra Conditional Access, FIDO2 keys). |
| Restrict administrative privilegesLimit extent of incidents | Strong | Access scopes each admin console to named groups with short session lifetimes and a device-posture requirement. Cloudflare Tunnel means internal admin interfaces are never published to the internet and have no inbound firewall rule to attack. | Local and domain administrator rights on the endpoints and servers themselves — that stays with Entra, Intune and your privileged-access process. |
| User application hardeningPrevent malware delivery | Strong | Gateway filters DNS, HTTP and network traffic — blocking advertising, malicious categories and risky file types before they reach the device. Browser Isolation renders untrusted sites remotely so browser exploit code never executes on the endpoint at all. | Browser and Office configuration baselines pushed to the device (Intune / GPO), and disabling unneeded features in the applications themselves. |
| Application controlPrevent malware execution | Partial | CASB and Shadow IT discovery reveal and block unsanctioned SaaS; Gateway can block executable and script downloads by file type. This governs the SaaS and download layer. | Endpoint executable allowlisting — the actual control ASD is asking for. That is Windows Defender Application Control or AppLocker, and there is no cloud substitute. |
| Patch applicationsPrevent malware delivery | Partial | WARP device posture can refuse access to any device running an out-of-date OS or application version, so an unpatched laptop simply cannot reach the data. Digital Experience Monitoring shows you the fleet. | Actually applying the patches, and the vulnerability scanning cadence ML1 requires. That is Intune, WSUS or your RMM. |
| Patch operating systemsLimit extent of incidents | Partial | Same posture gating as above. Note that this control is also where your firewall sits — ML1 requires internet-facing network devices to be patched within 48 hours where an exploit exists, and unsupported ones to be removed entirely. | OS patch deployment on endpoints and servers — and replacing the edge hardware, which is the firewall end-of-life project. |
| Configure Microsoft Office macro settingsPrevent malware delivery | Not covered | Cloudflare Email Security reduces exposure by blocking macro-bearing attachments before delivery, but this is risk reduction — it is not the control. | Macro policy enforced through the Microsoft 365 Apps admin centre, Intune or GPO, with trusted-location and macro-signing rules. |
| Regular backupsRecover data & availability | Not covered | Nothing in the SASE stack backs up data. We won't claim otherwise. | A backup platform with immutable copies and — the part most firms skip — a documented, dated restore test. Insurers ask for the restore date, not the backup schedule. |
The edge half
Replacing the firewall is not on this list as its own strategy — but an unsupported internet-facing device is an outright ML1 failure condition on both patching controls, because ML1 explicitly requires that services no longer supported by a vendor are removed. Replacing it closes that specific failure. It does not, by itself, make you ML1 — ASD determines your overall maturity level from your lowest-scoring strategy, so the other seven still have to hold up. Network segmentation delivered in the same project is an ISM and insurer expectation rather than an Essential Eight control — useful, but we won't sell it to you as compliance.
See the firewall end-of-life offer →One thing your next auditor will raise: the Essential Eight is being retired
Is the Essential Eight still current?
Yes. On 24 June 2026 the Australian Signals Directorate confirmed it will retire the Essential Eight over roughly two years and replace it with the Essentials series. It remains the framework in force today and is still what tenders, insurers and client questionnaires reference.
What is replacing the Essential Eight?
The Essentials series — separate domain-specific chapters for enterprise IT, cloud and operational technology, rather than one universal checklist. Consultation on the first chapter, Essentials for enterprise IT, closed on 12 July 2026.
Will the work we have done on the Essential Eight be wasted?
No. ASD has confirmed the controls carry across and map into the new guidance. The one genuine implication is that the Essentials series makes cloud and shared-responsibility boundaries explicit — which is precisely the gap an identity-aware access layer is built to close.
Does Cloudflare Zero Trust cost anything for a small firm?
Cloudflare Zero Trust is free for up to 50 users and US$7 per user per month beyond that. For most Australian professional-services firms the licence cost of the access layer is zero. Oramatel is not a Cloudflare reseller and takes no margin on Cloudflare licensing.
Want this assessed against your actual environment?
The Exposure Audit tells you where you sit on the two patching controls today, in writing, against your real device inventory.
Book the exposure auditThis mapping is Oramatel's own professional assessment of how Cloudflare One / SASE services contribute to the ASD Essential Eight Maturity Model (November 2023 revision). It is not endorsed by, or produced in conjunction with, the Australian Signals Directorate, the Australian Cyber Security Centre or Cloudflare, Inc., and it is not a maturity assessment. Coverage in any specific environment depends on configuration and must be evidenced individually. Assessment current August 2026.