Back to blog
Australia & APAC

Essential Eight Maturity Level Zero: what it means and how to get out of it

Level Zero is not a starting grade, it is a finding. What puts an organisation there, why a single unmet requirement is enough, and the shortest defensible route to Level One.
GRC Copilot Team
Essential Eight Maturity Level Zero: what it means and how to get out of it

Maturity Level Zero is not the bottom rung of a ladder. It is the assessment you get when you are not fully aligned with the intent of Maturity Level One — and because an Essential Eight rating is the lowest level achieved across all eight strategies, one unmet requirement in one strategy is enough to put the entire organisation there.

That single rule surprises more Australian organisations than anything else in the model. Teams with mature patching, real MFA and tested backups still assess at Level Zero because application control was never implemented on workstations.

What Level Zero actually says

ASD describes Maturity Level Zero as signifying weaknesses in an organisation's overall cyber security posture which, when exploited, could compromise the confidentiality of its data, or the integrity or availability of its systems and data. It is a description of exposure, not a stage of a programme.

Practically, you are at Level Zero if any one of the following is true:

  • Any of the eight mitigation strategies falls short of a single Level One requirement.
  • A control is implemented but you cannot evidence it — from an assessor's position these are the same thing.
  • A control is implemented in part of the environment. Scope gaps are gaps.

The five findings that most often cause it

  • No application control at all. The most common single cause. Many organisations have never attempted it, and Level One requires it on workstations for executables, libraries, scripts, installers, compiled HTML, HTML applications and control panel applets.
  • Unsupported software still in the estate. One end-of-life application or operating system that has not been removed or replaced fails the requirement outright, regardless of compensating controls.
  • MFA that does not cover everything. Enabled for staff email but not for the third-party service holding sensitive data, or available but not enforced.
  • Patch timeframes not evidenced. Patching happens, but nobody can show that online services were patched inside the window that applied - 48 hours for vendor-critical vulnerabilities or working exploits, two weeks otherwise.
  • Backups never restored. Backups run nightly, but restoration to a common point in time has never been tested as part of a disaster recovery exercise.
Notice how many of these are evidence problems rather than control problems. Roughly half the organisations that assess at Level Zero are technically closer to Level One than their rating suggests — they simply cannot prove it.

Find out whether you are at Level Zero

GRC Copilot ships a Maturity Level Zero triage assessment that tests the Level One intent across all eight strategies and tells you exactly which ones are responsible.

Getting out: a defensible sequence

  1. Assess all eight strategies against Level One. Not the ones you think are weak — all eight. The blocker is frequently the strategy nobody was worried about.
  2. Separate "not implemented" from "not evidenced". These need completely different work. The second is usually faster and cheaper, and it moves your rating just as much.
  3. Fix unsupported software first. It is binary, it is visible, and it fails you on two strategies at once.
  4. Start application control discovery immediately. It has the longest lead time by far. Beginning it in month one and finishing in month six beats starting in month five.
  5. Instrument patch reporting before chasing patch speed. You cannot demonstrate a two-week timeframe you were never measuring.
  6. Run one restoration test and keep the record. This closes a Level One requirement in an afternoon.

What to tell your board

Level Zero sounds alarming in a board pack, and executives often read it as "we have no security". Explain the arithmetic: the rating is the minimum across eight strategies, so it describes the weakest one rather than the whole posture. Then show which strategies are at Level One already, name the ones that are not, and give dates. A Level Zero rating with a credible plan reads far better than an inflated claim that collapses under assessment.

Frequently asked questions

Can we report a partial maturity level, such as Level One in six of eight strategies?

You can report strategy-by-strategy detail, and you should — it is far more useful internally. But your overall Essential Eight maturity is the lowest level achieved, so the headline figure remains Level Zero until every strategy meets Level One.

Is Level Zero common?

Yes, particularly among organisations that have never formally assessed. Application control and unsupported software are the usual causes, and both are easy to overlook until someone tests against the specific requirements.

How long does it take to reach Level One?

It depends almost entirely on application control and on how much unsupported software you are carrying. Organisations with a clean estate and existing MFA often get there in a quarter; those with legacy systems and no application allowlisting should plan for considerably longer.

Does a compensating control help?

The maturity model is written as specific requirements rather than objectives to be met by any means. Compensating controls are worth documenting and are relevant to your overall risk position, but they do not generally substitute for a requirement when the level is assessed.

Key takeaways

  • One unmet Level One requirement in one strategy puts the whole organisation at Level Zero.
  • Level Zero is a finding about your weakest strategy, not a verdict on your whole posture.
  • Split "not implemented" from "not evidenced" — the second is usually the quicker win.
  • Start application control discovery on day one; it has the longest lead time of the eight.
#essential-eight #maturity-level-zero #acsc #australia #gap-analysis #baseline