ECSO Readiness Assessment
For energy entities designated as Systems of National Significance under SOCI Act Part 2C.
Learn moreEvaluate cybersecurity maturity against the Australian Energy Sector Cyber Security Framework v2 with Security Profile targeting.
The AESCSF v2 Cyber Security Maturity Assessment provides a comprehensive framework for evaluating your organisation's cybersecurity posture against the Australian Energy Sector Cyber Security Framework Version 2. With up to 161 questions across 11 domains (scaled by Security Profile), this assessment supports AEMO cyber security reporting obligations and SOCI Act alignment, with references to Cyber and Infrastructure Security Centre (CISC) guidance.
The assessment features Security Profile targeting (SP1/SP2/SP3), automatically filtering questions based on your organisation's required security profile—95 questions for SP1, 139 for SP2, and 161 for SP3. Each question includes contextual help text explaining the control intent, specific evidence guidance detailing what documentation supports your response, target Maturity Indicator Level (MIL), and per-question notes fields for documenting your assessment rationale.
Maturity is measured on a four-level MIL scale: MIL0 (not performed), MIL1 (initial/ad-hoc), MIL2 (managed/documented), and MIL3 (optimised/measured). Each Security Profile defines target MIL levels for every question, enabling precise gap identification between current and required maturity states.
Organisation branding with logo upload ensures your exported reports are presentation-ready for Board meetings, AEMO submissions, and executive briefings. Through structured evaluation criteria designed for energy sector operational environments, you will assess your organisation's IT and OT security posture across all AESCSF domains.
This assessment is designed for:
Organisations using this assessment typically gain:
The assessment comprehensively evaluates AESCSF v2 across 11 domains:
The assessment supports AESCSF Security Profile levels with automatic question filtering:
Select your target Security Profile at assessment start and the tool automatically filters questions, adjusts target MIL levels, and tailors scoring and recommendations to your required level. Gap analysis clearly distinguishes between SP1 baseline gaps, SP2 enhanced requirements, and SP3 advanced expectations.
Every assessment question includes contextual support to ensure consistent, high-quality responses:
For SOCI-regulated entities, protecting information about your security posture is as important as the assessment itself. This tool is designed with critical infrastructure data handling requirements in mind:
Your security posture information stays exactly where it should—within your organisation's control.
Board-ready report featuring your organisation's logo and branding, formatted for executive circulation, AEMO submissions, and stakeholder briefings.
Visual chart and detailed breakdown of maturity scores across all 11 AESCSF domains, sorted by performance with MIL status indicators.
Gaps organised by Security Profile level (SP1/SP2/SP3) with question reference, current vs target MIL, and specific recommendations.
High, medium, and low risk gaps with clear categorisation to focus remediation efforts on what matters most.
Actionable recommendations prioritised by Security Profile level, risk rating, and implementation effort.
Summary of evidence documentation status by Security Profile level, tracking what's been provided vs what's missing.
Comprehensive terminology definitions including Asset Register, CIRMP, Cyber Incident, Defence in Depth, IT, OT, SCADA, and energy sector regulatory terms for stakeholder clarity.
Comprehensive workbook with 7 worksheets for detailed analysis, tracking, and remediation management.
Detailed scoring breakdown by domain with percentages, question counts, and maturity status.
Full gap listing with question reference, domain, current MIL, target MIL, SP level, and recommendations.
Filterable view of gaps categorised by risk severity for targeted remediation planning.
Sortable action list with columns for tracking owner, status, due date, and completion.
Complete record of every assessment response with question text, answer, MIL score, notes, and evidence provided.
Dedicated worksheet tracking evidence documentation status for each question requiring supporting materials.
Reference links to AEMO guidance, ACSC resources, SOCI Act information, and energy sector security materials.
Consistent methodology enables annual reassessment aligned to AEMO reporting cycles and continuous improvement tracking.
Get immediate access to the AESCSF v2 Cyber Security Maturity Assessment Tool.
Organisations frequently combine this assessment with complementary frameworks to address multiple governance requirements.
For energy entities designated as Systems of National Significance under SOCI Act Part 2C.
Learn moreExtend EDM domain coverage with comprehensive vendor and supply chain assessment.
Learn moreHave questions about how our assessments work?
Read the Enterprise Assessment FAQ →