AESCSF v2 Assessment
Energy sector entities often combine ECSO readiness with AESCSF maturity assessment for broader SOCI Act coverage.
Learn moreAssess readiness for the six Enhanced Cyber Security Obligations under SOCI Act Part 2C for Systems of National Significance.
The ECSO Readiness Assessment provides a structured framework for evaluating your organisation's preparedness against the Enhanced Cyber Security Obligations (ECSO) under the Security of Critical Infrastructure Act 2018 Part 2C. With 108 questions across 6 domains, this assessment is specifically designed for entities designated as Systems of National Significance (SoNS).
The assessment directly maps to the six ECSO requirements, enabling you to evaluate your readiness for incident response plan adoption, cyber security exercises, vulnerability assessments, system information provision, government security software installation, and cyber security incident reporting.
Through structured evaluation criteria aligned to SOCI Act requirements and supporting guidance, you will assess your organisation's capability to meet these enhanced obligations when directed by the Australian Government.
This assessment is designed for:
Organisations using this assessment typically gain:
The assessment is structured across the six ECSO requirements:
The Enhanced Cyber Security Obligations apply to Systems of National Significance — critical infrastructure assets of the highest criticality to Australia. While ECSO directions are discretionary government powers, designated entities must be prepared to comply when directed. This assessment helps organisations proactively build capability rather than reacting to government directions.
For SoNS entities, information about your security posture and gaps is itself highly sensitive. This tool is specifically designed with national security considerations in mind:
Your ECSO readiness information remains under your complete control—as it should be for systems of national significance.
Board-ready overview with readiness scores for each ECSO requirement, exportable to Word format for executive and regulator circulation.
Findings mapped to specific ECSO requirements with risk ratings, exportable to Excel for remediation tracking.
Charts showing readiness by ECSO requirement, suitable for Board presentations and regulatory engagement preparation.
Actionable recommendations ranked by compliance criticality and implementation complexity.
Consistent methodology enables periodic reassessment to demonstrate ongoing readiness and continuous improvement.
Tell us a little about your organisation and we will walk you through what the ECSO assessment covers and how access works.
Enquire about accessCyberAssure tools are structured self-assessments. They help you evaluate your own readiness, identify gaps, prioritise remediation and prepare for formal assessment. They are not a certification, conformity assessment, audit or legal advice, and CyberAssure is not a notified body, accredited certifier or auditor.
We design our question sets to address the requirements we identify as applicable, and we publish a coverage map showing which provisions each question is drawn from. Because these regimes evolve, and because which requirements apply depends on facts about your own organisation and products, we cannot warrant that a question set addresses every requirement applicable to you. Identifying the full scope of your obligations remains your responsibility.
CyberAssure is not affiliated with, endorsed by, or accredited by the Department of Home Affairs, the Cyber and Infrastructure Security Centre, or any standards or regulatory body.
Organisations frequently combine this assessment with complementary frameworks to address multiple governance requirements.
Energy sector entities often combine ECSO readiness with AESCSF maturity assessment for broader SOCI Act coverage.
Learn moreNIST CSF provides complementary coverage for organisations seeking alignment to international frameworks alongside SOCI Act.
Learn moreHave questions about how our assessments work?
Read the Enterprise Assessment FAQ →