The Essential Eight is not a certificate. It is a set of controls that either work in your environment or they do not.
The Essential Eight is the Australian Signals Directorate’s baseline set of cyber mitigation strategies for protecting internet-connected IT environments.
For many Australian organisations, it now appears in cyber insurance questionnaires, procurement processes, governance conversations and customer security reviews.
The useful question is not whether the organisation can claim alignment. It is whether the controls are implemented consistently enough to reduce real operating risk, and whether the evidence would stand up when someone asks for it.
Three questions that come up before the framework conversation properly starts.
A specific set of eight controls, chosen by the ASD because they address the most common methods used to compromise Australian organisations.
The Essential Eight is not a general security checklist. It is a specific set of eight controls chosen by the Australian Signals Directorate because, when properly implemented, they address the most common methods used by adversaries to compromise Australian organisations.
The ASD groups the eight strategies into three categories: prevent malware delivery and execution, limit the extent of incidents, and recover data and system availability. Each strategy has its own maturity model, assessed separately.
An organisation can be ML2 on patching and ML0 on application control. Overall maturity is determined by the lowest score across all eight strategies, which is why gap remediation must be systematic, not selective.
Four converging forces have made the Essential Eight practically unavoidable for most Australian organisations with operational complexity.
The Essential Eight was always a sensible baseline. What has changed is the structural pressure behind it.
Australian cyber insurers increasingly want evidence of controls rather than self-attestation. Essential Eight alignment, particularly around MFA, patching, privileged access and backup recovery, is becoming a practical underwriting baseline. Organisations that cannot demonstrate a defensible posture face coverage gaps or premium increases.
Government and enterprise procurement increasingly use Essential Eight alignment as part of supplier due diligence, especially where data handling, operational resilience or public sector supply chains are involved. The requirement is cascading into the private sector through procurement conditions and supply chain questionnaires.
The cost of a breach is no longer limited to technical recovery. Regulatory scrutiny, contractual exposure, customer impact and reputational damage all increase when an organisation cannot demonstrate a defensible security baseline. Recent high-profile incidents have made this commercial reality harder to ignore at board level.
Serious cyber incidents remain among the most disruptive events facing Australian organisations. The Essential Eight materially reduces common pathways into them, but only when the controls are genuinely enforced and maintained, not simply listed in a policy document.
The ASD reported a cybercrime report every six minutes in FY2024-25. Cyber extortion remains the most disruptive category. Edge device exploitation increased 34% year on year. The threat environment has not been theoretical for some time.
The gap between knowing the Essential Eight matters and achieving consistent maturity across all eight strategies remains significant. Most organisations are stronger on some controls than others, which is exactly why selective uplift does not produce a defensible outcome.
ASD describes the Essential Eight as a minimum set of preventative measures and notes that additional strategies and controls may be required depending on the environment.
For most private organisations, the Essential Eight is not automatically mandatory. But it can become effectively required.
For most private organisations, the Essential Eight is not automatically mandatory. But it can become effectively required through government policy, regulator expectation, contractual obligation, procurement condition, cyber insurance underwriting, customer security requirements or board and governance standards.
ASD states there is no general requirement for organisations to have their Essential Eight implementation certified by an independent party, but Essential Eight implementations may need to be assessed if required by government directive, policy, regulation or contract.
The practical question is therefore not only whether it is mandatory. The better question is who is asking for your maturity position, and what evidence will they expect.
Maturity is about how consistently controls are implemented and how resistant they are to adversary tradecraft.
The Essential Eight maturity model defines four maturity levels: Level 0 through Level 3. ASD states that, except for Level 0, the levels are based on mitigating increasing levels of attacker tradecraft and targeting.
The Essential Eight should not be treated as eight independent scores that can be averaged. ASD advises organisations to achieve the same maturity level across all eight mitigation strategies before moving to a higher level.
Seven strong controls do not compensate for one exposed pathway.
Many organisations assume maturity can be averaged or that strength in five or six controls offsets weakness in two or three. It cannot. If one strategy remains at ML0 or ML1, the overall posture remains constrained regardless of strength elsewhere.
This is why an organisation can invest significantly in MFA, endpoint protection and patching, and still fail to present a defensible Essential Eight outcome if application control or backup restoration testing remains weak. The lowest score determines the overall maturity, not the mean score.
Remediation must be coordinated across all eight strategies simultaneously, not addressed one control at a time. An organisation that closes one major gap while allowing drift in other strategies may find its overall maturity unchanged at reassessment. The assessment should produce a roadmap that sequences all eight strategies together, not a single-control action list.
ML2 is where the Essential Eight moves from theoretical compliance to actual security improvement.
At ML1, many controls can be technically present but trivially bypassed. ML2 changes the operating environment in ways that matter against the threats organisations actually face.
For most Australian organisations outside the highest-risk categories, ML2 represents a defensible, insurably demonstrable and operationally sustainable target. ML3 requires significantly more operational maturity and ongoing discipline, and is typically justified by specific threat intelligence rather than general risk appetite.
ML2 is usually the point at which the organisation has to move from informal IT habits to enforced operational discipline. That is why it is both the most valuable and the most difficult maturity level for many organisations to sustain.
The Essential Eight is often described as if it were a certification. That is misleading.
ASD is clear that there is no general requirement for organisations to have their implementation certified by an independent party. However, an organisation may still need to have its implementation assessed if a directive, policy, regulator or contract requires it.
The distinction matters. A certification suggests a pass/fail badge. A maturity assessment examines how consistently controls are implemented and what evidence supports the maturity position.
The question is not “do we have a certificate.” The question is “can we demonstrate the maturity of our controls in a way that stands up to scrutiny from an insurer, auditor or government customer.”
Evidence of control implementation in the live environment, not policy documents describing intended controls. Technical evidence collected by tooling, not interview responses or self-assessment questionnaires alone. Assessment methodology aligned to the ASD Essential Eight Assessment Process Guide, which specifies evidence types for each strategy and maturity level. A clear maturity outcome per strategy that reflects the actual state of the environment, not the best-case interpretation of partial evidence.
Assessors trained on the ASD methodology are better positioned to produce assessments aligned to the official process guide. The ASD offers an Essential Eight Assessment Course through TAFEcyber that covers the methodology and evidence requirements in depth.
A proper maturity view examines whether the controls are implemented, scoped, evidenced and operating across the environment.
Each dimension below is part of a defensible position.
Scope
Which users, devices, servers, applications, cloud services and systems are included in the maturity view. Poor scope definition is one of the fastest ways to make a maturity claim unreliable.
The scope statement names device classes, user populations, identity boundaries and cloud services, not just “the corporate environment.”
Coverage
Whether each of the eight mitigation strategies is applied consistently across the intended scope. Coverage gaps often appear in remote users, privileged accounts, legacy systems, unmanaged devices and specialist applications.
The view reports coverage per strategy with population counts and exception flags, not a single overall percentage.
Exceptions
Where controls are not applied, why the exception exists, what compensating controls are in place and who approved the exception. ASD notes that exceptions should be documented, approved, monitored and reviewed.
An exception register exists, names an approver, sets a review date and lists the compensating control.
Evidence
Whether the organisation can show configuration, policy, logs, reports, restore tests, patch status, MFA coverage, privileged access review and other supporting artefacts. Evidence should come from the environment, not from policy statements describing intent.
Every maturity claim cites a specific artefact: a config export, a log query, a restore test report, a privileged access review record.
Operating cadence
Whether controls are reviewed and maintained, or whether they were only configured once. Essential Eight maturity changes as users, devices, applications, vendors, cloud services and business requirements change.
Each control has a named owner, a defined review cadence and evidence of the most recent review.
Sequencing
Which gaps should be addressed first because other controls depend on them. Privileged access, device management, identity hygiene and application inventory often affect multiple strategies. If those foundations are weak, individual control uplift can become fragmented.
The remediation roadmap is sequenced by dependency, not by score. Foundational controls move first.
The patterns that produce low maturity outcomes, failed insurance assessments and ongoing vulnerability are predictable.
Most organisations that have done an assessment have done one that missed at least one of these.
For many organisations, the biggest improvement comes from making existing controls consistent, measurable and reviewed.
Essential Eight uplift should be sequenced around the environment, not around a checklist alone.
Essential Eight maturity is not only a project. It becomes part of the operating discipline around identity, endpoint, patching, applications, backup and administration. The organisations that sustain ML2 are usually the ones that built the discipline into operations, not the ones that scheduled a remediation sprint.
The hard part is not reaching ML2 once. The hard part is maintaining it when users, systems and threat conditions change.
Most organisations that engage with the Essential Eight reach a point where the assessment is complete and the gaps are documented. The harder question is whether the operational discipline exists to close them and sustain the posture once it is reached.
For many Australian organisations, ML2 is achievable without significant additional tooling spend. The controls required are implementable within a well-configured Microsoft 365 environment with a properly managed endpoint fleet and a disciplined identity hygiene program. The investment is in engineering time, operational discipline and ongoing maintenance, not technology procurement.
The organisations that fail to sustain ML2 after achieving it are usually not lacking tools. They are lacking the operational discipline to enforce MFA type requirements as user populations change, to patch within 48-hour windows when a critical vulnerability is released, and to test backup restoration on a defined schedule.
This is where the Essential Eight conversation usually leads into a different conversation. Establishing the maturity position is the assessment. Holding and improving it continuously is the operating discipline above it. For Australian organisations, Inlight IT delivers that operating discipline as part of Managed Cyber Security, the service designed to provide the deeper security operating layer above the managed IT baseline. The Essential Eight Assessment establishes where the organisation stands. Managed Cyber Security is one way that maturity can be operated continuously when the organisation does not have that discipline internally.
The two services work together. Some organisations engage the assessment alone and execute the remediation with their internal team. Others engage the assessment first and then move into MCS to operate the maturity continuously. The right scope depends on what the organisation can sustain operationally after the assessment is complete.
The Inlight IT view on Essential Eight.
Most of the work involved in sustaining ML2 is engineering work that happens after the assessment: keeping MFA type requirements aligned with the maturity standard as user populations change, holding patching to a 48-hour cadence on internet-facing systems, testing backup restoration on a defined schedule, reviewing privileged access on a defined cadence and re-checking evidence between assessment cycles rather than only at the next assessment.
That work has to happen continuously. It cannot be delivered by an assessment alone, no matter how good the assessment is. The assessment establishes where the maturity stands. The operating discipline holds it.
The Essential Eight is not a list to tick off. It is a control set that either works in the environment or does not. The difference between an organisation that reaches ML2 once and one that maintains it is operational discipline, not tooling.
Inlight IT does the assessment work the same way regardless of whether the organisation goes on to engage Managed Cyber Security to operate the maturity continuously or executes the remediation roadmap with their internal team. The assessment has to stand on its own. What happens after the assessment is a separate decision, and the page that covers the formal assessment scoping is Essential Eight Assessment.
Questions Australian organisations ask when researching Essential Eight implementation.
Who needs to comply with the Essential Eight?
What are the requirements for Essential Eight Maturity Level 2?
Is the Essential Eight a certification?
What is the difference between the Essential Eight and ISO 27001?
What is the difference between Essential Eight and NIST?
What is the difference between Essential Eight and SMB1001?
How do you get Essential Eight certified?
Is MFA mandatory under the Essential Eight?
How is Essential Eight maturity maintained over time?
Understand where Essential Eight maturity actually stands.
Know whether the evidence behind it would actually hold up.
Discuss Essential Eight maturity