All insights
Cyber & risk6 min read

Essential Eight maturity levels explained: a practical guide for Australian businesses

What each Essential Eight maturity level actually requires, how assessment works, what it costs, and how Australian businesses can reach Maturity Level Two without stalling.

By FORTE/CYBERx AdvisoryReviewed by FORTE/CYBERx Advisory21 September 2026

What the Essential Eight is — and is not

The Essential Eight is the Australian Signals Directorate's baseline set of eight mitigation strategies, chosen because they prevent the majority of commodity attacks: ransomware operators, credential theft and opportunistic exploitation. The eight are application control, patching applications, Microsoft Office macro restrictions, user application hardening, restricting administrative privileges, patching operating systems, multi-factor authentication, and regular backups.

It is not a certification, a framework, or a management system. There is no ISO-style audit cycle built in. It is a prescriptive technical list with three maturity levels, each describing how consistently and broadly the controls are applied. That distinction matters commercially: enterprise and government buyers increasingly ask for a maturity level, and the answer they want is evidence of consistent application, not a policy document.

The ACSC also publishes a maturity model alongside the strategies. Maturity Level Zero means the controls are absent or ad hoc. The three real levels escalate the coverage, the sophistication of the adversary they resist, and the operational discipline required to hold them.

Maturity Level One: resisting commodity attacks

Level One targets attackers using publicly available tools and known exploits — the automated end of the threat landscape. At this level, the eight controls exist but the tolerances are loose: application control on workstations only, monthly patching, macros restricted for internet-sourced files, MFA for remote access and important data stores.

Level One stops drive-by attacks and mass ransomware campaigns reasonably well. It does not stop a human adversary who picks your organisation out specifically, because the gaps — unmanaged servers, slow patching of exploited vulnerabilities, admin accounts shared between people — are exactly what a targeted attacker looks for.

For a small business with no regulatory driver and limited data holdings, Level One held genuinely and consistently is a rational starting point. The qualifier matters: Level One claimed on the basis of a good laptop fleet, while the file server and the legacy line-of-business application are excluded, is not Level One.

Maturity Level Two: the defensible target for most businesses

Level Two targets attackers willing to invest some effort: phishing that bypasses basic filtering, exploitation of recent vulnerabilities, and credential theft against privileged users. The tolerances tighten materially. Patches for exploited vulnerabilities must be applied within 48 hours for applications and two weeks generally. Application control extends to servers. Administrative privileges are restricted to those who need them, are validated regularly, and cannot be used for email or web browsing. MFA covers sensitive data, privileged access and third-party access.

This is the level most Australian mid-market businesses should target, and it is the level that answers most procurement and cyber-insurance questions credibly. It is also where the honest work sits: the difference between Level One and Level Two is mostly operational cadence — patch windows, access reviews, tested backups — not new technology purchases.

The control that stalls most Level Two programmes is application control, because allow-listing breaks legacy software and requires a change process the business has never run. The second is privileged access hygiene, because it forces an uncomfortable conversation about who actually needs admin rights. Plan for both early.

Maturity Level Three: targeted, capable adversaries

Level Three assumes an adversary willing to develop custom tooling and spend time inside your environment. Tolerances tighten again: patching within 48 hours extends across the board, application control is enforced with execution rules and logging, workstation administration is brokered through jump hosts, and backups are segregated from the network with restore testing on a schedule.

Level Three is the right target for critical infrastructure operators, organisations handling sensitive government data, and businesses whose compromise would have consequences beyond their own walls. For everyone else, the honest question is whether the incremental cost of Level Three would be better spent on detection and response capability, because prevention alone at any maturity level eventually fails.

How assessment actually works

The ACSC publishes the Essential Eight Maturity Model and an assessment process guide. Assessment is evidence-based: for each strategy, an assessor samples systems and checks whether the control operates as the model describes. The maturity level achieved is the lowest level where all eight strategies are met — a business at Level Three for seven controls and Level One for patching is a Level One business.

That "lowest common denominator" rule is why self-assessment usually overstates maturity. It is natural to assess against the well-managed part of the estate — the modern laptops under the endpoint platform — and quietly exclude the warehouse PCs, the development server, and the application nobody owns. An assessor will not make that exclusion, and neither will an insurer after a claim.

A defensible internal assessment needs a complete asset inventory, configuration evidence (not policy statements) for each strategy, and records showing the control operating over time. Screenshots of a settings page prove a point in time; patch compliance reports over three months prove a cadence.

Apply this to your organisation

Want this assessed against your environment?

Send us the specifics and a senior advisor will respond within one business day.

Native secure submission. Your details are never sold or shared.

What it costs and how long it takes

The honest answer is that most of the cost is operational change, not licensing. MFA, patching and macro restrictions are largely configuration of tools Australian businesses already own, particularly in a Microsoft 365 environment. Application control (via AppLocker or Windows Defender Application Control) is included in existing Windows licensing. The real spend is the internal or advisory effort to inventory the estate, remediate exceptions, and run the change process without breaking the business.

A focused programme moving a mid-size business from ad hoc to a verified Level Two typically runs three to six months, with the first month spent on inventory and gap analysis and the remainder on sequenced remediation. The constraint is rarely technology; it is the backlog of legacy applications, unowned systems and informal administrative access that accumulates over years.

We do not publish fixed prices for this work because the driver is the state of the existing environment, and any number quoted before an inventory is a guess. A short assessment conversation gets you a defensible range and a sequenced plan.

How the Essential Eight fits with ISO 27001, CPS 234 and insurance

The Essential Eight and ISO 27001 answer different questions. The Essential Eight is a prescriptive technical baseline; ISO 27001 is a risk management system that decides which controls your risks justify. They work well together: many Australian organisations use the Essential Eight as the default technical mitigation set inside an ISO 27001 risk treatment plan, which gives both prescriptive coverage and a governance wrapper auditors and boards recognise.

For APRA-regulated entities, CPS 234 requires information security capability commensurate with threats — the Essential Eight is the most commonly referenced baseline for demonstrating that capability, and APRA has publicly encouraged regulated entities to assess against it. It is not the compliance answer on its own, but it is the floor.

Cyber insurers increasingly ask Essential Eight-style questions at renewal: MFA coverage, backup segregation, patch cadence. Answering those questions with a documented maturity level and evidence is materially easier than reconstructing your posture from memory in a questionnaire.

A sensible first 30 days

Week one — build the asset inventory: every device, server, cloud tenancy and application that touches business data. You cannot assess or remediate what is not on the list.

Week two — assess the eight strategies against the inventory using the ACSC maturity model, recording evidence gaps as findings with owners. Be honest about the unmanaged parts of the estate; they are the maturity level.

Week three — fix the fast, high-value items: MFA coverage for remote access and privileged accounts, macro restrictions for internet-sourced files, and the patching of currently exploited vulnerabilities.

Week four — sequence the hard work: application control pilot on a friendly device group, privileged access review, and a backup restore test that actually restores something. Then set the recurring cadence, because maturity is held by cadence, not by projects.

Sources and further reading

This article provides general information and decision support. It is not legal advice, audit assurance, certification advice or a guarantee of outcome.

Related reading

Start a useful conversation

Talk to a senior advisor

Tell us the decision, constraint or opportunity. A senior operator responds within one business day.

Native secure submission. No embedded HubSpot branding.