Essential Eight

Essential Eight maturity levels, explained

The Australian Cyber Security Centre’s model is eight mitigation strategies at three levels. Here is what each level demands and how to pick the right target.
Certifyi compliance team · Updated September 2026
Short answer. The Essential Eight is a set of eight mitigation strategies from the Australian Cyber Security Centre: application control, patch applications, configure Microsoft Office macro settings, user application hardening, restrict administrative privileges, patch operating systems, multi-factor authentication, and regular backups. Each is assessed at Maturity Level 0 to 3, where Level 1 defends against opportunistic adversaries using commodity tools, Level 2 against adversaries willing to invest more time, and Level 3 against adaptive adversaries. Organisations are expected to reach the same level across all eight before moving up.

The eight strategies

How the levels differ

StrategyLevel 1Level 2Level 3
MFAUsers of internet-facing services; something-you-have plus something-you-knowAdds privileged users and important data repositories; phishing-resistant for internet-facingPhishing-resistant MFA everywhere; MFA events logged and analysed
Admin privilegesRequests validated; privileged accounts cannot access internet or emailAdmin activities via jump servers; credentials managed; events loggedJust-in-time administration; secure admin workstations; logging centralised and monitored
Patching48 hours for exploited internet-facing vulnerabilities; two weeks otherwiseSame, plus scanning at least weekly/fortnightly by asset classSame, plus daily scanning of internet-facing services; unsupported software removed
BackupsRegular, tested, retained per continuity needsAdds restriction of privileged access to backupsAdds immutability: backups cannot be modified or deleted during retention

Choosing a target level

Level 1 is a reasonable floor for any Australian business; Level 2 is the common target for organisations handling customer data or selling to government; Level 3 is expected of entities facing sophisticated adversaries, including critical infrastructure. Non-corporate Commonwealth entities are required to implement Level 2. The model is explicit that you should not cherry-pick: reach Level 1 across all eight before pursuing Level 2 on any.

Assessing and evidencing

The ACSC assessment process expects evidence at the technical level: configuration exports, policy objects, patch reports, MFA logs, backup restore tests. Most of it can be collected automatically from identity providers, endpoint management, cloud accounts and backup systems. In Certifyi the Essential Eight sits alongside ISO 27001 and SOC 2 on one control library, so a patching or MFA control is evidenced once and reported at the maturity level you target.

Essential Eight, answered

For non-corporate Commonwealth entities, Maturity Level 2 is mandated under the Protective Security Policy Framework. For private companies it is guidance, but increasingly required by government buyers and insurers.

Either by self-assessment or by an independent assessor, typically an IRAP assessor for government work. Assessment follows the ACSC Essential Eight Assessment Process Guide.

No. It is a technical baseline for Windows-centric environments. ISO 27001 adds governance, risk management and the broader control set. Many Australian companies hold both.

The ACSC updates the Maturity Model periodically, most recently strengthening MFA, logging and patching expectations. Reassess when the model changes.

Get audit-ready in 8 to 12 weeks

Certifyi pairs the platform with a named compliance lead who implements with your team, priced on scope and due at audit sign-off.
Scroll to Top