Essential Eight Enabler

Remote access and logging contributions without E8 certification claims.

Trustholm supports MFA, logging export, and execution integrity as enablers-Essential Eight remains a customer mitigation program.

Essential Eight Enabler

Framework evidence framing before detailed tables below.

Modern office workspace representing public sector IT programs

Compliance framing

Essential Eight Enabler

Map Trustholm capabilities to your assessor program with honest Shipped/Gap rows-not vendor certification claims.

  • Reproduce audit export in trial
  • Download trust pack for binders
  • Regional hub cross-links
Gaprows published openly
Download trust pack

This page describes product capabilities for your control matrix. Trustholm does not hold SOC 2, ISO 27001, IRAP, Essential Eight, CMMC, Cyber Essentials, NIS2, or framework certification badges.

The Australian Essential Eight is a customer mitigation strategy-not a product certification. Trustholm contributes to remote access and logging narratives where MSPs must demonstrate MFA for administrators, execution integrity for scripts, and exportable audit trails. ACSC maturity levels are measured at the agency or customer program level; no SaaS vendor replaces that assessment with a product badge.

Mitigation strategies we touch most directly: Restrict administrative privileges maps to portal RBAC, role separation between script authors and approvers where workflows require it, opt-in just-in-time privilege elevation (time-boxed grants with approval, justification, and MFA for technicians without standing write rights), and tenant-scoped administration without shared superuser accounts across customers.

Multi-factor authentication maps to portal MFA flows for privileged access. Regular backups and patch applications remain customer-operated-Trustholm documents agent footprint and signing policy, not OS baseline compliance or backup product integration.

Logging and monitoring narrative: Security audit export provides category-filtered execution and administration events designed for assessor review, distinct from HTTP request logs used for operational troubleshooting. MSPs serving government clients cite export slices in SSP appendices alongside their broader logging stack.

Native Sentinel connector integration is backlog; JSON and CSV export ships today-do not overclaim SIEM automation.

Enabler contributions: MFA enforcement for portal users, signed script policy before execution, security audit export separate from HTTP logs, Security Center practitioner checklist for tenant administrators, agent polling credential model with tenant binding, and honest evidence tables on the trust hub.

Customer-operated mitigations: patching cadence, Office macro policies, application control, restrict-administrative-privileges tiering models, and endpoint hardening per ACSC guides remain your obligations. Trustholm does not operate your email gateway, macro policies, or workstation imaging standards.

MSP positioning: Government-facing MSPs include Trustholm vendor evidence in customer SSPs while the agency assessor evaluates the customer system boundary. Pair this page with IRAP consumer responsibility content and your incident response testing artifacts.

Avoid procurement language implying product-level Essential Eight compliance. When customers ask for maturity level scores, clarify that Trustholm supplies enabler artifacts-not a product-level maturity rating.

Position Trustholm in your SSP as a remote management enabler with documented gaps (e.g. native Sentinel connector backlog). Do not claim Essential Eight compliance for the product. Your customer owns mitigation maturity scores and compensating controls outside Trustholm.

TopicEvidenceStatusNotes
MFA for administratorsTenant MFA enforcementShippedCustomer implements broader E8 mitigations
Logging for remote accessScript execution audit; export for assessorsShipped-
Essential Eight certificationProduct is an enabler, not an E8-certified productGap-

Frequently asked questions

Does Trustholm satisfy Essential Eight?

No product alone satisfies Essential Eight. Use Trustholm evidence for applicable mitigations (MFA, logging, execution integrity) within your broader program.

Which E8 strategies does Trustholm touch?

Most directly: restrict administrative privileges (RBAC), multi-factor authentication, and logging/monitoring via security audit export. Patch and macro strategies remain customer-operated.

Can government MSPs cite this page?

Use as supporting vendor documentation in your SSP. Pair with IRAP consumer responsibility content and your agency assessor guidance.

Do you support ACSC hardening guides?

Endpoint hardening is customer and agent-configuration territory. Trustholm documents agent footprint and signing policy-not OS baseline compliance.

What about privileged access management?

Portal RBAC and MFA are in scope. Privileged access workstations and tiering models are customer architecture decisions documented separately.

Is there Essential Eight certification for SaaS?

We do not claim E8 certification. Avoid language implying product-level E8 compliance in procurement responses.