Back to blog
Australia & APAC

Essential Eight Maturity Level Two: what changes from Level One

Level Two adds tighter patch windows, MFA for privileged users, application control on internet-facing servers, real hardening of Office and browsers, and centralised logging. The delta, and what it costs.
GRC Copilot Team
Essential Eight Maturity Level Two: what changes from Level One

Maturity Level Two targets an adversary willing to invest more time in you specifically, and more effort in the effectiveness of their tools. They use well-known tradecraft, but they apply it deliberately and they expect to meet some resistance. Level One assumes the attacker moves on when the easy path closes; Level Two assumes they do not.

The jump from Level One to Level Two is the largest in the model in terms of operational change, because it introduces two things Level One barely touches: detection, and disciplined privileged access.

What actually changes

Patch timeframes tighten

  • Scanning extends to all other applications at least fortnightly, not just the browser and productivity layer.
  • Scanning of the productivity and browser layer stays weekly, and the two-week patch window carries over from Level One.
  • Operating system scanning splits: daily for internet-facing, fortnightly for everything else.

The requirement did not get conceptually harder. The operational tempo did, and so did the reporting burden.

Multi-factor authentication becomes phishing-resistant

  • MFA extends to privileged and unprivileged users of systems, not only online services.
  • MFA for online services, online customer services and systems must be phishing-resistant. This lands at Level Two, not Level Three, and it is the single largest cost in the step.
  • Successful and unsuccessful MFA events centrally logged, and event logs protected from unauthorised modification and deletion.

Privileged access gets disciplined

  • Privileged access revalidated at least annually — not granted once and forgotten.
  • Privileged accounts disabled after 45 days of inactivity.
  • Administrative activities conducted through jump servers.
  • Credentials for break glass, local administrator and service accounts long, unique, unpredictable and managed.
  • Privileged access events and privileged account and group management events centrally logged.

Track the Level Two delta

GRC Copilot ships Maturity Level Two as its own assessment, so you can see exactly which requirements are new since Level One and evidence each one.

Application control extends to servers

  • Implemented on internet-facing servers as well as workstations.
  • Microsoft's recommended application blocklist implemented.
  • Rulesets validated at least annually.
  • Allowed and blocked execution events centrally logged.

Hardening becomes real

Level One asked for four browser settings. Level Two asks for hardening of browsers, Microsoft Office and PDF software in line with ASD and vendor guidance, plus specific behavioural restrictions:

  • Office unable to create child processes, create executable content, inject code into other processes, or activate OLE packages.
  • PDF software unable to create child processes.
  • Users unable to change Office or PDF security settings.
  • Macros blocked from making Win32 API calls, with macro execution events logged.
  • Blocked PowerShell script executions centrally logged.

Backups get access control

  • Privileged accounts, other than backup administrators, unable to access, modify or delete backups belonging to other accounts.
This one matters more than its single bullet suggests. It is the requirement that stops a domain administrator compromise from becoming an unrecoverable event, which is precisely how modern ransomware operations play out.

What Level Two costs

Budget for three things that Level One did not require:

  • A logging destination and someone to own it. Central logging is a requirement at Level Two across MFA, privileged access, application control and macros. Log volume and retention become a real line item.
  • Jump server infrastructure and the process change that goes with it. Administrators will resist this; plan for it.
  • Patch tempo. Moving the productivity layer to two weeks usually means automating what was a monthly manual cycle.

Organisations that treat Level Two as "Level One plus a few settings" tend to discover the logging requirement late, when it is a procurement exercise rather than a configuration change.

Frequently asked questions

Is Level Two the level Australian government entities must meet?

Essential Eight requirements apply to Commonwealth entities through the Protective Security Policy Framework, and Level Two is commonly cited as the expectation. Because the specific obligation and timing have changed over successive policy updates, confirm the current requirement for your entity type against the framework itself rather than relying on general guidance.

Can we go straight from Level Zero to Level Two?

You can plan for it, but you will still pass through Level One, because Level Two requirements build on Level One rather than replacing them. Sequencing the work as one programme is sensible; claiming Level Two while Level One requirements are open is not.

How much log retention is needed?

The model requires central logging of specified events rather than naming a retention period. Set retention against your own incident response and regulatory needs — long enough to investigate an intrusion discovered months after it began, which in practice means considerably longer than most default settings.

Do jump servers apply to cloud administration too?

The intent is that administrative activity happens from a controlled, hardened path rather than from a general-purpose workstation. Apply the same reasoning to cloud administration consoles; assessors will expect consistency rather than an on-premises-only interpretation.

Key takeaways

  • Level Two introduces detection AND response: central logging, log analysis, and reporting incidents to the CISO and ASD.
  • Privileged access moves from restricted to actively managed and reviewed.
  • Backup access control at this level is what makes ransomware survivable.
  • The hidden cost is logging infrastructure and patch tempo, not the individual settings.
#essential-eight #maturity-level-two #acsc #australia #privileged-access #logging #hardening