The Essential Eight is the most widely used cyber security baseline in Australia, and the maturity model is the part people get wrong. Organisations routinely claim "Maturity Level Two" when what they mean is that most strategies are somewhere near it. The model does not work that way, and neither do the assessors.
This guide covers the eight strategies, what separates the four levels, how a rating is actually calculated, and where uplift programmes tend to stall.
The eight mitigation strategies
Published by the Australian Signals Directorate through the Australian Cyber Security Centre, the Essential Eight are eight controls chosen because together they mitigate a large share of the intrusion techniques seen in practice:
- Patch applications — find and fix vulnerabilities in software before they are exploited.
- Patch operating systems — the same discipline for workstations, servers and network devices.
- Multi-factor authentication — make stolen credentials insufficient on their own.
- Restrict administrative privileges — limit what an adversary can do once inside.
- Application control — allow only approved code to execute.
- Restrict Microsoft Office macros — close a long-standing delivery route for malicious code.
- User application hardening — remove the browser and document features attackers rely on.
- Regular backups — make destructive attacks survivable.
The first four are often described as focused on preventing and limiting attacks, the rest on reducing attack surface and enabling recovery. In practice all eight are assessed together, and none of them is optional.
The four maturity levels
Each strategy is assessed against four levels, defined by the kind of adversary they are meant to defeat rather than by a percentage of controls implemented:
- Maturity Level Zero — not aligned with the intent of Level One. This is a description of weakness, not a target.
- Maturity Level One — mitigates adversaries using widely available commodity tradecraft, looking opportunistically across many targets.
- Maturity Level Two — mitigates adversaries with a modest step-up in capability, willing to invest more time in a target and in the effectiveness of their tools.
- Maturity Level Three — mitigates adaptive adversaries much less reliant on public tools, focused on evading detection and solidifying access.
How your rating is actually calculated
This is the part that catches people. Your Essential Eight maturity is the lowest level achieved across all eight strategies. Seven strategies at Level Two and one at Level One gives you Level One. Seven at Level Two and one that misses a single Level One requirement gives you Level Zero.
The model is deliberately unforgiving here. An adversary does not care that seven doors are locked. Reporting an average, or a "mostly Level Two", is the fastest way to lose credibility with an assessor.
ASD also expects levels to be implemented as a package rather than cherry-picked: you reach a level across all eight strategies before moving to the next, rather than taking the easy Level Three items while leaving Level One gaps open.
Assess against every maturity level
GRC Copilot ships the Essential Eight as four ready-made assessments — Maturity Levels Zero to Three — with the requirements, evidence tracking and gap reporting built in.
Try GRC Copilot free Generate an AI-powered assessment Download checklist Book a demo
Where uplift programmes stall
- Application control. Consistently the hardest strategy. It requires knowing what your organisation actually runs, and the discovery work is usually underestimated by an order of magnitude.
- Patch timeframes. Not the patching itself but the evidence that you met the window that applied - 48 hours where the vendor assessed the vulnerability as critical or a working exploit existed, two weeks otherwise. Without automated reporting this becomes a manual archaeology exercise at assessment time.
- Privileged access separation. Separate privileged and unprivileged environments is a genuine architectural change, not a policy.
- Logging at Level Two and above. Central logging is straightforward; retaining it usefully, and protecting it from modification at Level Three, is not.
- Macros. The technical settings are easy. Finding every business process that quietly depends on a macro is the project.
How to plan an uplift
- Baseline honestly. Assess against Level One first and find out whether you are actually at Level Zero. Most organisations that have never been assessed are.
- Fix the lowest strategy first. Because the rating is the minimum, effort spent on a strategy that is already ahead moves your number not at all.
- Instrument the evidence before the control. If you cannot report on patch age today, you will not be able to prove the timeframe in six months either.
- Complete a level before starting the next. Partial implementation across two levels assesses as the lower one.
Read next
Audit
- The Essential Eight assessment: what an assessor actually checks — Assessors test rather than take your word for it. How the assessment works, the evidence that satisfies each strategy, the sampling that cat…
Australia & APAC
- Application control: the hardest of the Essential Eight, and how to get it done — Application control blocks more Essential Eight programmes than any other strategy. Why discovery is the real project, what the requirement…
- Does the Essential Eight apply to cloud and SaaS? — Yes, and the scope follows your data and users rather than your data centre. Which requirements reach into cloud services, what the provider…
- Essential Eight backups: why working backups still fail the assessment — Backups almost always exist. The requirements that fail are restoration testing and backup access control — and the second is what decides w…
- Essential Eight macros and user application hardening: closing the document attack path — Two strategies that share one target: the browser and document software users open untrusted content with. What each maturity level requires…
- Essential Eight Maturity Level One: the requirements, strategy by strategy — What Level One actually asks for across all eight mitigation strategies, the requirements most often missed, and the evidence an assessor wi…
- Essential Eight Maturity Level Three: the requirements and what they demand — Phishing-resistant MFA, just-in-time administration, application control everywhere, macros restricted to sandboxed or signed execution, and…
- Essential Eight Maturity Level Two: what changes from Level One — Level Two adds tighter patch windows, MFA for privileged users, application control on internet-facing servers, real hardening of Office and…
- Essential Eight Maturity Level Zero: what it means and how to get out of it — Level Zero is not a starting grade, it is a finding. What puts an organisation there, why a single unmet requirement is enough, and the shor…
- Essential Eight MFA: what counts, and what phishing-resistant really means — Which users and services need MFA at each maturity level, why two passwords and SMS codes fall short in different ways, and what phishing-re…
- Essential Eight patching: hitting the two-week and 48-hour windows — Two of the eight strategies are patching, and both are measured in elapsed time. The scanning cadence, the windows per asset class, why unsu…
- Essential Eight: restricting administrative privileges without stopping work — Separate environments, no internet from privileged accounts, jump servers, inactivity limits and just-in-time administration. The requiremen…
- From Essential Eight Maturity Level One to Two: a 90-day plan — The Level One to Two jump is mostly logging and privileged access discipline. A sequenced plan that front-loads the long-lead items and leav…
- The ASD Information Security Manual explained — The ISM is the full control catalogue behind the Essential Eight: hundreds of controls organised by cyber security principle, marked by clas…
- Who must comply with the Essential Eight in Australia? — Where the Essential Eight is legally mandated, where it arrives through procurement and contracts, and how it interacts with the SOCI Act an…
Buyer Guides
- What the Essential Eight actually costs, level by level — Where the money goes at each maturity level, which strategies dominate the effort, the costs that surprise people, and how to build a busine…
Checklists
- Essential Eight evidence checklist: what to have ready for each strategy — A strategy-by-strategy list of the artefacts an assessor will ask for, what makes each one sufficient, and the evidence gaps that most often…
Comparisons
- Essential Eight vs ISO 27001: which one does your organisation need? — One is eight prescriptive technical controls with fixed timeframes; the other is a management system across a scope you define. What each pr…
- Essential Eight vs NIST CSF: prescriptive controls or a risk framework? — One tells you exactly what to do and measures whether you did it; the other structures how you think about risk across the whole programme.…
Frequently asked questions
Is the Essential Eight mandatory in Australia?
It is mandatory for some Commonwealth entities under the Protective Security Policy Framework, and it is increasingly written into government procurement and contracts. For most private organisations it is not a legal requirement, but it is the de facto expected baseline and often flows down contractually.
What maturity level should we target?
ASD advises selecting a target level based on the adversaries you expect to face. Level One suits organisations concerned with opportunistic attacks; Level Two is the common target for entities holding sensitive data or subject to government requirements; Level Three suits those facing determined, targeted adversaries.
Does ISO 27001 certification cover the Essential Eight?
Not directly. ISO 27001 is a management system across a scope you define; the Essential Eight is eight prescriptive technical controls with specific timeframes. A certified ISMS will have much of the substance, but the specific requirements and timeframes are assessed on their own terms.
How often should we reassess?
At least annually, and after any significant change to the environment. Maturity slips quietly — an unpatched acquisition or a new SaaS platform can drop a strategy a level without anyone noticing.
Key takeaways
- Your rating is the lowest level achieved across all eight strategies, not an average.
- Maturity Level Zero is a description of weakness, never a target.
- Effort belongs on your weakest strategy, because that is the one setting your number.
- Application control and patch evidence are where uplift programmes most often stall.