Essential Eight
Essential Eight maturity levels, explained
The Australian Cyber Security Centre’s model is eight mitigation strategies at three levels. Here is what each level demands and how to pick the right target.
Certifyi compliance team · Updated September 2026
Short answer. The Essential Eight is a set of eight mitigation strategies from the Australian Cyber Security Centre: application control, patch applications, configure Microsoft Office macro settings, user application hardening, restrict administrative privileges, patch operating systems, multi-factor authentication, and regular backups. Each is assessed at Maturity Level 0 to 3, where Level 1 defends against opportunistic adversaries using commodity tools, Level 2 against adversaries willing to invest more time, and Level 3 against adaptive adversaries. Organisations are expected to reach the same level across all eight before moving up.
The eight strategies
- Application control: only approved executables, scripts, installers and drivers run on workstations and servers.
- Patch applications: internet-facing services patched within 48 hours for exploited vulnerabilities; others within two weeks or a month depending on level.
- Configure Microsoft Office macro settings: macros blocked for users without a business need; only trusted, scanned macros run.
- User application hardening: browsers do not process Java or ads; Office and PDF readers hardened; PowerShell logging.
- Restrict administrative privileges: requests validated, privileged accounts separated from internet and email, just-in-time administration at higher levels.
- Patch operating systems: same timelines as applications; unsupported systems replaced.
- Multi-factor authentication: for users of internet-facing services, remote access and privileged actions; phishing-resistant at Level 3.
- Regular backups: backups of important data, software and settings, tested restores, protected from modification and deletion.
How the levels differ
| Strategy | Level 1 | Level 2 | Level 3 |
|---|---|---|---|
| MFA | Users of internet-facing services; something-you-have plus something-you-know | Adds privileged users and important data repositories; phishing-resistant for internet-facing | Phishing-resistant MFA everywhere; MFA events logged and analysed |
| Admin privileges | Requests validated; privileged accounts cannot access internet or email | Admin activities via jump servers; credentials managed; events logged | Just-in-time administration; secure admin workstations; logging centralised and monitored |
| Patching | 48 hours for exploited internet-facing vulnerabilities; two weeks otherwise | Same, plus scanning at least weekly/fortnightly by asset class | Same, plus daily scanning of internet-facing services; unsupported software removed |
| Backups | Regular, tested, retained per continuity needs | Adds restriction of privileged access to backups | Adds immutability: backups cannot be modified or deleted during retention |
Choosing a target level
Level 1 is a reasonable floor for any Australian business; Level 2 is the common target for organisations handling customer data or selling to government; Level 3 is expected of entities facing sophisticated adversaries, including critical infrastructure. Non-corporate Commonwealth entities are required to implement Level 2. The model is explicit that you should not cherry-pick: reach Level 1 across all eight before pursuing Level 2 on any.
Assessing and evidencing
The ACSC assessment process expects evidence at the technical level: configuration exports, policy objects, patch reports, MFA logs, backup restore tests. Most of it can be collected automatically from identity providers, endpoint management, cloud accounts and backup systems. In Certifyi the Essential Eight sits alongside ISO 27001 and SOC 2 on one control library, so a patching or MFA control is evidenced once and reported at the maturity level you target.
Essential Eight, answered
Is the Essential Eight mandatory?
For non-corporate Commonwealth entities, Maturity Level 2 is mandated under the Protective Security Policy Framework. For private companies it is guidance, but increasingly required by government buyers and insurers.
How is it assessed?
Either by self-assessment or by an independent assessor, typically an IRAP assessor for government work. Assessment follows the ACSC Essential Eight Assessment Process Guide.
Does the Essential Eight replace ISO 27001?
No. It is a technical baseline for Windows-centric environments. ISO 27001 adds governance, risk management and the broader control set. Many Australian companies hold both.
How often does the model change?
The ACSC updates the Maturity Model periodically, most recently strengthening MFA, logging and patching expectations. Reassess when the model changes.
Get audit-ready in 8 to 12 weeks
Certifyi pairs the platform with a named compliance lead who implements with your team, priced on scope and due at audit sign-off.