GRCCopilot
Sign In
Australian Signals Directorate (ASD) / Australian Cyber Security Centre (ACSC)

ACSC Essential Eight - Maturity Level 3

Full alignment for adaptive adversaries that evade detection and exploit weak configuration

Start Assessment Create Free Account
8
Controls
149
Questions
Active
Status

About this Framework

Maturity Level Three of the ASD Essential Eight Maturity Model focuses on adversaries who are more adaptive and much less reliant on public tools and techniques. They exploit weaknesses in a target's cyber security posture, such as older software or inadequate logging and monitoring, and focus on evading detection and solidifying their access once inside. This is the most demanding level: phishing-resistant multi-factor authentication, just-in-time administration and Credential Guard, application control across workstations and all servers with a vulnerable driver blocklist, Microsoft Office macros restricted to sandboxed, Trusted Location or trusted-publisher-signed execution, removal of legacy runtimes such as PowerShell 2.0 and .NET Framework 3.5, and event logs protected from unauthorised modification and deletion.

Key Control Domains

Patch Applications
Patch Operating Systems
Multi-Factor Authentication
Restrict Administrative Privileges
Application Control
Restrict Microsoft Office Macros
User Application Hardening
Regular Backups

Who Needs This?

  • Organisations handling highly sensitive or nationally significant data
  • Critical infrastructure operators facing targeted threats
  • Defence and national security supply chain participants
  • Organisations that have experienced a targeted intrusion
  • Entities required to demonstrate the highest Essential Eight maturity

Compliance Benefits

  • Resists adaptive adversaries using bespoke tooling
  • Phishing-resistant authentication across privileged and data access
  • Tamper-evident logging that survives an intruder with access
  • Legacy attack surface removed rather than merely configured
  • Highest recognised level of Essential Eight assurance

Official Reference

ACSC Essential Eight Maturity Model
https://www.cyber.gov.au

Assessment Details

Issuer / AuthorityAustralian Signals Directorate (ASD) / Australian Cyber Security Centre (ACSC)
FrameworkACSC Essential Eight - Maturity Level 3
Controls8
Questions149
StatusActive
Assessment Start05 Aug 2026

Share this Assessment

Share this permanent link with your team, clients or auditors.

https://grcopilot.app/frameworks/acsc-essential-eight-maturity-level-3

Sign in to begin this assessment

Create a free GRC Copilot account to access this and 50+ other security and compliance frameworks.