About this Framework
Maturity Level Zero signifies weaknesses in an organisation's overall cyber security posture that, when exploited, could compromise the confidentiality of its data or the integrity and availability of its systems and data. An organisation sits at Maturity Level Zero whenever it is not fully aligned with the intent of Maturity Level One. This assessment is therefore a triage rather than a target: it tests the Maturity Level One intent across all eight mitigation strategies so an organisation can establish whether it currently sits at Level Zero and which strategies are responsible. Because an Essential Eight rating is the lowest level achieved across all eight strategies, a single unmet strategy places the whole organisation at Maturity Level Zero.
Key Control Domains
Who Needs This?
- Organisations beginning an Essential Eight programme
- Organisations that have never formally assessed against the Essential Eight
- Boards and executives needing a defensible baseline
- Managed service providers triaging a client estate
- Organisations preparing an uplift to Maturity Level One
Compliance Benefits
- Fast baseline across all eight mitigation strategies
- Identifies exactly which strategies are blocking Maturity Level One
- Evidence-backed starting point for an uplift programme
- Prioritised remediation plan with named owners
- Board-ready statement of current cyber security posture
Official Reference
Assessment Details
Share this Assessment
Share this permanent link with your team, clients or auditors.
https://grcopilot.app/frameworks/acsc-essential-eight-maturity-level-0