Back to blog
Frameworks

The Essential Eight Maturity Model: a complete guide

What the eight mitigation strategies are, how the four maturity levels differ, why your rating is the lowest level you achieve across all eight, and how to plan an uplift that survives assessment.
GRC Copilot Team
The Essential Eight Maturity Model: a complete guide

The Essential Eight is the most widely used cyber security baseline in Australia, and the maturity model is the part people get wrong. Organisations routinely claim "Maturity Level Two" when what they mean is that most strategies are somewhere near it. The model does not work that way, and neither do the assessors.

This guide covers the eight strategies, what separates the four levels, how a rating is actually calculated, and where uplift programmes tend to stall.

The eight mitigation strategies

Published by the Australian Signals Directorate through the Australian Cyber Security Centre, the Essential Eight are eight controls chosen because together they mitigate a large share of the intrusion techniques seen in practice:

  • Patch applications — find and fix vulnerabilities in software before they are exploited.
  • Patch operating systems — the same discipline for workstations, servers and network devices.
  • Multi-factor authentication — make stolen credentials insufficient on their own.
  • Restrict administrative privileges — limit what an adversary can do once inside.
  • Application control — allow only approved code to execute.
  • Restrict Microsoft Office macros — close a long-standing delivery route for malicious code.
  • User application hardening — remove the browser and document features attackers rely on.
  • Regular backups — make destructive attacks survivable.

The first four are often described as focused on preventing and limiting attacks, the rest on reducing attack surface and enabling recovery. In practice all eight are assessed together, and none of them is optional.

The four maturity levels

Each strategy is assessed against four levels, defined by the kind of adversary they are meant to defeat rather than by a percentage of controls implemented:

  • Maturity Level Zero — not aligned with the intent of Level One. This is a description of weakness, not a target.
  • Maturity Level One — mitigates adversaries using widely available commodity tradecraft, looking opportunistically across many targets.
  • Maturity Level Two — mitigates adversaries with a modest step-up in capability, willing to invest more time in a target and in the effectiveness of their tools.
  • Maturity Level Three — mitigates adaptive adversaries much less reliant on public tools, focused on evading detection and solidifying access.

How your rating is actually calculated

This is the part that catches people. Your Essential Eight maturity is the lowest level achieved across all eight strategies. Seven strategies at Level Two and one at Level One gives you Level One. Seven at Level Two and one that misses a single Level One requirement gives you Level Zero.

The model is deliberately unforgiving here. An adversary does not care that seven doors are locked. Reporting an average, or a "mostly Level Two", is the fastest way to lose credibility with an assessor.

ASD also expects levels to be implemented as a package rather than cherry-picked: you reach a level across all eight strategies before moving to the next, rather than taking the easy Level Three items while leaving Level One gaps open.

Assess against every maturity level

GRC Copilot ships the Essential Eight as four ready-made assessments — Maturity Levels Zero to Three — with the requirements, evidence tracking and gap reporting built in.

Where uplift programmes stall

  • Application control. Consistently the hardest strategy. It requires knowing what your organisation actually runs, and the discovery work is usually underestimated by an order of magnitude.
  • Patch timeframes. Not the patching itself but the evidence that you met the window that applied - 48 hours where the vendor assessed the vulnerability as critical or a working exploit existed, two weeks otherwise. Without automated reporting this becomes a manual archaeology exercise at assessment time.
  • Privileged access separation. Separate privileged and unprivileged environments is a genuine architectural change, not a policy.
  • Logging at Level Two and above. Central logging is straightforward; retaining it usefully, and protecting it from modification at Level Three, is not.
  • Macros. The technical settings are easy. Finding every business process that quietly depends on a macro is the project.

How to plan an uplift

  1. Baseline honestly. Assess against Level One first and find out whether you are actually at Level Zero. Most organisations that have never been assessed are.
  2. Fix the lowest strategy first. Because the rating is the minimum, effort spent on a strategy that is already ahead moves your number not at all.
  3. Instrument the evidence before the control. If you cannot report on patch age today, you will not be able to prove the timeframe in six months either.
  4. Complete a level before starting the next. Partial implementation across two levels assesses as the lower one.

Read next

Audit

Australia & APAC

Buyer Guides

Checklists

Comparisons

Frequently asked questions

Is the Essential Eight mandatory in Australia?

It is mandatory for some Commonwealth entities under the Protective Security Policy Framework, and it is increasingly written into government procurement and contracts. For most private organisations it is not a legal requirement, but it is the de facto expected baseline and often flows down contractually.

What maturity level should we target?

ASD advises selecting a target level based on the adversaries you expect to face. Level One suits organisations concerned with opportunistic attacks; Level Two is the common target for entities holding sensitive data or subject to government requirements; Level Three suits those facing determined, targeted adversaries.

Does ISO 27001 certification cover the Essential Eight?

Not directly. ISO 27001 is a management system across a scope you define; the Essential Eight is eight prescriptive technical controls with specific timeframes. A certified ISMS will have much of the substance, but the specific requirements and timeframes are assessed on their own terms.

How often should we reassess?

At least annually, and after any significant change to the environment. Maturity slips quietly — an unpatched acquisition or a new SaaS platform can drop a strategy a level without anyone noticing.

Key takeaways

  • Your rating is the lowest level achieved across all eight strategies, not an average.
  • Maturity Level Zero is a description of weakness, never a target.
  • Effort belongs on your weakest strategy, because that is the one setting your number.
  • Application control and patch evidence are where uplift programmes most often stall.
#essential-eight #acsc #asd #maturity-model #australia #complete-guide