About this Framework
Maturity Level Three of the ASD Essential Eight Maturity Model focuses on adversaries who are more adaptive and much less reliant on public tools and techniques. They exploit weaknesses in a target's cyber security posture, such as older software or inadequate logging and monitoring, and focus on evading detection and solidifying their access once inside. This is the most demanding level: phishing-resistant multi-factor authentication, just-in-time administration and Credential Guard, application control across workstations and all servers with a vulnerable driver blocklist, Microsoft Office macros restricted to sandboxed, Trusted Location or trusted-publisher-signed execution, removal of legacy runtimes such as PowerShell 2.0 and .NET Framework 3.5, and event logs protected from unauthorised modification and deletion.
Key Control Domains
Who Needs This?
- Organisations handling highly sensitive or nationally significant data
- Critical infrastructure operators facing targeted threats
- Defence and national security supply chain participants
- Organisations that have experienced a targeted intrusion
- Entities required to demonstrate the highest Essential Eight maturity
Compliance Benefits
- Resists adaptive adversaries using bespoke tooling
- Phishing-resistant authentication across privileged and data access
- Tamper-evident logging that survives an intruder with access
- Legacy attack surface removed rather than merely configured
- Highest recognised level of Essential Eight assurance
Official Reference
Assessment Details
Share this Assessment
Share this permanent link with your team, clients or auditors.
https://grcopilot.app/frameworks/acsc-essential-eight-maturity-level-3