Home / Cybersecurity / Essential Eight
Essential Eight · ASD framework

The Essential Eight is not a certificate. It is a set of controls that either work in your environment or they do not.

The Essential Eight is the Australian Signals Directorate’s baseline set of cyber mitigation strategies for protecting internet-connected IT environments.

For many Australian organisations, it now appears in cyber insurance questionnaires, procurement processes, governance conversations and customer security reviews.

The useful question is not whether the organisation can claim alignment. It is whether the controls are implemented consistently enough to reduce real operating risk, and whether the evidence would stand up when someone asks for it.

The framework in 90 seconds

Three questions that come up before the framework conversation properly starts.

Q
Who needs to comply with the Essential Eight?
Australian Commonwealth non-corporate entities are required under governance requirements to implement the Essential Eight to at least ML2. For private sector organisations, it is not universally legislated, but is increasingly embedded in government procurement, cyber insurance questionnaires and enterprise supplier due diligence.
Q
What is the difference between Essential Eight and ISO 27001?
The Essential Eight is a set of eight specific technical controls designed to reduce the most common attack vectors in Australian environments. ISO 27001 is a broader information security management system standard. They are complementary. Many organisations implement Essential Eight controls as part of an ISO 27001 implementation. Essential Eight does not require an ISMS structure. ISO 27001 does not prescribe specific technical controls the way Essential Eight does. The full comparison is on Essential Eight vs ISO 27001.
Q
What does Maturity Level 2 actually require?
At ML2, controls must be consistently enforced and harder to bypass. Critical patches inside 48 hours for internet-facing systems. Application control covering additional execution paths. Admin privilege restrictions enforced consistently. Backups tested for successful restoration, not just confirmed running.
The eight controls

A specific set of eight controls, chosen by the ASD because they address the most common methods used to compromise Australian organisations.

The Essential Eight is not a general security checklist. It is a specific set of eight controls chosen by the Australian Signals Directorate because, when properly implemented, they address the most common methods used by adversaries to compromise Australian organisations.

The ASD groups the eight strategies into three categories: prevent malware delivery and execution, limit the extent of incidents, and recover data and system availability. Each strategy has its own maturity model, assessed separately.

Application Control
Prevent execution of unapproved or malicious programs. One of the most technically demanding controls to implement correctly in diverse environments.
Patch Applications
Apply security patches to applications within defined timeframes. At ML2, critical patches must be applied within 48 hours of release for internet-facing services.
Configure Microsoft Office Macro Settings
Restrict execution of Microsoft Office macros to signed macros from trusted sources. Directly addresses one of the most common initial access vectors.
User Application Hardening
Configure web browsers and other applications to reduce attack surface. Includes disabling web advertisements, Java and Flash where not required.
Restrict Administrative Privileges
Limit administrative accounts to only those who require them. Privileged accounts should not be used for web browsing or email. One of the highest-impact controls when properly enforced.
Patch Operating Systems
Apply security patches to operating systems within defined timeframes. At ML2, critical OS patches must be applied within 48 hours for internet-facing systems.
Multi-Factor Authentication
Require MFA for remote access, privileged accounts and access to important data and systems. MFA requirements tighten materially through the maturity model, with stronger and harder-to-bypass methods required at higher maturity. One of the most frequently misrepresented controls in assessments.
Regular Backups
Maintain complete, restorable backups of important data, software and configuration settings. At ML2, backups must be tested for restoration. Untested backups are not compliant backups.
Each strategy is assessed independently

An organisation can be ML2 on patching and ML0 on application control. Overall maturity is determined by the lowest score across all eight strategies, which is why gap remediation must be systematic, not selective.

Pressure points

Four converging forces have made the Essential Eight practically unavoidable for most Australian organisations with operational complexity.

The Essential Eight was always a sensible baseline. What has changed is the structural pressure behind it.

Cyber insurance underwriting

Australian cyber insurers increasingly want evidence of controls rather than self-attestation. Essential Eight alignment, particularly around MFA, patching, privileged access and backup recovery, is becoming a practical underwriting baseline. Organisations that cannot demonstrate a defensible posture face coverage gaps or premium increases.

Government and procurement requirements

Government and enterprise procurement increasingly use Essential Eight alignment as part of supplier due diligence, especially where data handling, operational resilience or public sector supply chains are involved. The requirement is cascading into the private sector through procurement conditions and supply chain questionnaires.

Board and governance scrutiny

The cost of a breach is no longer limited to technical recovery. Regulatory scrutiny, contractual exposure, customer impact and reputational damage all increase when an organisation cannot demonstrate a defensible security baseline. Recent high-profile incidents have made this commercial reality harder to ignore at board level.

Incident resilience

Serious cyber incidents remain among the most disruptive events facing Australian organisations. The Essential Eight materially reduces common pathways into them, but only when the controls are genuinely enforced and maintained, not simply listed in a policy document.

Threat environment context

The ASD reported a cybercrime report every six minutes in FY2024-25. Cyber extortion remains the most disruptive category. Edge device exploitation increased 34% year on year. The threat environment has not been theoretical for some time.

Maturity gap context

The gap between knowing the Essential Eight matters and achieving consistent maturity across all eight strategies remains significant. Most organisations are stronger on some controls than others, which is exactly why selective uplift does not produce a defensible outcome.

ASD describes the Essential Eight as a minimum set of preventative measures and notes that additional strategies and controls may be required depending on the environment.

The compliance question

For most private organisations, the Essential Eight is not automatically mandatory. But it can become effectively required.

For most private organisations, the Essential Eight is not automatically mandatory. But it can become effectively required through government policy, regulator expectation, contractual obligation, procurement condition, cyber insurance underwriting, customer security requirements or board and governance standards.

ASD states there is no general requirement for organisations to have their Essential Eight implementation certified by an independent party, but Essential Eight implementations may need to be assessed if required by government directive, policy, regulation or contract.

The practical question is therefore not only whether it is mandatory. The better question is who is asking for your maturity position, and what evidence will they expect.

01
Commonwealth non-corporate entities
Required under governance requirements to implement the Essential Eight to at least ML2. This applies to all non-corporate Commonwealth entities and has been the formal minimum since 2022.
02
Defence Industry Security Program members
Essential Eight alignment is directly tied to Defence Industry Security Program membership and the procurement conditions associated with it.
03
Critical infrastructure operators
The Security of Critical Infrastructure Act applies to organisations in designated critical infrastructure sectors and increases the importance of demonstrable cyber risk management, operational resilience and incident readiness.
04
Private sector suppliers to government
Not mandated by legislation as a universal rule, but increasingly embedded in procurement contracts and supply chain due diligence as a condition of engagement. Government and enterprise buyers are pushing the requirement through their supplier questionnaires.
05
Cyber insurance
Not mandated, but underwriters are increasingly requiring evidence of specific Essential Eight controls at renewal. Organisations that cannot demonstrate a defensible posture face coverage gaps or increased premiums.
Maturity levels

Maturity is about how consistently controls are implemented and how resistant they are to adversary tradecraft.

The Essential Eight maturity model defines four maturity levels: Level 0 through Level 3. ASD states that, except for Level 0, the levels are based on mitigating increasing levels of attacker tradecraft and targeting.

ML0
Controls missing or ineffective
Controls are missing, incomplete or not operating effectively enough to meet Level 1. This often means the organisation has significant gaps in implementation, coverage or evidence.
ML1
Controls present, inconsistently enforced
The organisation has taken steps to mitigate common cyber threats, but controls may still be limited in coverage, consistency or resistance to more targeted activity. Addresses adversaries using publicly available exploits and common tools.
ML2Practical benchmark
Controls consistently enforced and harder to bypass
Controls are implemented more consistently and are designed to mitigate more deliberate attacker behaviour, including adversaries who can phish users, target credentials and work around weak implementations. For many organisations, Level 2 becomes the practical benchmark because it demonstrates a stronger and more repeatable control position. It is also the level most often discussed in insurance, procurement, governance and due diligence conversations.
ML3
Controls designed to resist sophisticated adversaries
Controls are implemented to resist more advanced tradecraft and more targeted activity. This level is more demanding and may be appropriate for higher-risk environments, larger exposure profiles or organisations with stronger assurance requirements.

The Essential Eight should not be treated as eight independent scores that can be averaged. ASD advises organisations to achieve the same maturity level across all eight mitigation strategies before moving to a higher level.

The most common mistake

Seven strong controls do not compensate for one exposed pathway.

Many organisations assume maturity can be averaged or that strength in five or six controls offsets weakness in two or three. It cannot. If one strategy remains at ML0 or ML1, the overall posture remains constrained regardless of strength elsewhere.

This is why an organisation can invest significantly in MFA, endpoint protection and patching, and still fail to present a defensible Essential Eight outcome if application control or backup restoration testing remains weak. The lowest score determines the overall maturity, not the mean score.

Remediation must be coordinated across all eight strategies simultaneously, not addressed one control at a time. An organisation that closes one major gap while allowing drift in other strategies may find its overall maturity unchanged at reassessment. The assessment should produce a roadmap that sequences all eight strategies together, not a single-control action list.

The practical target

ML2 is where the Essential Eight moves from theoretical compliance to actual security improvement.

At ML1, many controls can be technically present but trivially bypassed. ML2 changes the operating environment in ways that matter against the threats organisations actually face.

For most Australian organisations outside the highest-risk categories, ML2 represents a defensible, insurably demonstrable and operationally sustainable target. ML3 requires significantly more operational maturity and ongoing discipline, and is typically justified by specific threat intelligence rather than general risk appetite.

ML2 is usually the point at which the organisation has to move from informal IT habits to enforced operational discipline. That is why it is both the most valuable and the most difficult maturity level for many organisations to sustain.

MFA requirements tighten materially at ML2
MFA must be implemented across a broader set of systems and must be stronger and harder to bypass than basic MFA deployments. For privileged access, phishing-resistant methods are increasingly important as organisations move to higher maturity. SMS OTP does not satisfy these requirements for privileged users.
Critical patches within 48 hours for internet-facing systems
ML1 allows 30 days for high-severity patches. ML2 requires 48 hours for internet-facing services and two weeks for others. This requires a defined, automated patch management capability, not ad-hoc maintenance.
Application control must cover a broader scope
At ML2, application control extends to cover user profiles, temp directories and other locations commonly used by attackers as execution points. This is harder to implement without disrupting legitimate workflows.
Backups must be tested and proven restorable
Untested backups do not satisfy ML2. Restoration testing must be evidenced. The backup must be complete enough to restore operations within defined recovery time objectives.
Controls operate consistently and are harder to bypass
At ML2, the assessment standard moves from “is the control present” to “does the control actually work consistently under realistic conditions.”
Controls resist adaptive, sophisticated attack
ML2 is designed against adversaries who can phish users, target credentials and adapt to weak control implementations, not just opportunistic adversaries using publicly available tools.
A common market misunderstanding

The Essential Eight is often described as if it were a certification. That is misleading.

ASD is clear that there is no general requirement for organisations to have their implementation certified by an independent party. However, an organisation may still need to have its implementation assessed if a directive, policy, regulator or contract requires it.

The distinction matters. A certification suggests a pass/fail badge. A maturity assessment examines how consistently controls are implemented and what evidence supports the maturity position.

The question is not “do we have a certificate.” The question is “can we demonstrate the maturity of our controls in a way that stands up to scrutiny from an insurer, auditor or government customer.”

What is actually required to demonstrate maturity

Evidence of control implementation in the live environment, not policy documents describing intended controls. Technical evidence collected by tooling, not interview responses or self-assessment questionnaires alone. Assessment methodology aligned to the ASD Essential Eight Assessment Process Guide, which specifies evidence types for each strategy and maturity level. A clear maturity outcome per strategy that reflects the actual state of the environment, not the best-case interpretation of partial evidence.

Assessors trained on the ASD methodology are better positioned to produce assessments aligned to the official process guide. The ASD offers an Essential Eight Assessment Course through TAFEcyber that covers the methodology and evidence requirements in depth.

The six dimensions of a defensible position

A proper maturity view examines whether the controls are implemented, scoped, evidenced and operating across the environment.

Each dimension below is part of a defensible position.

Scope

Which users, devices, servers, applications, cloud services and systems are included in the maturity view. Poor scope definition is one of the fastest ways to make a maturity claim unreliable.

What good looks like

The scope statement names device classes, user populations, identity boundaries and cloud services, not just “the corporate environment.”

Coverage

Whether each of the eight mitigation strategies is applied consistently across the intended scope. Coverage gaps often appear in remote users, privileged accounts, legacy systems, unmanaged devices and specialist applications.

What good looks like

The view reports coverage per strategy with population counts and exception flags, not a single overall percentage.

Exceptions

Where controls are not applied, why the exception exists, what compensating controls are in place and who approved the exception. ASD notes that exceptions should be documented, approved, monitored and reviewed.

What good looks like

An exception register exists, names an approver, sets a review date and lists the compensating control.

Evidence

Whether the organisation can show configuration, policy, logs, reports, restore tests, patch status, MFA coverage, privileged access review and other supporting artefacts. Evidence should come from the environment, not from policy statements describing intent.

What good looks like

Every maturity claim cites a specific artefact: a config export, a log query, a restore test report, a privileged access review record.

Operating cadence

Whether controls are reviewed and maintained, or whether they were only configured once. Essential Eight maturity changes as users, devices, applications, vendors, cloud services and business requirements change.

What good looks like

Each control has a named owner, a defined review cadence and evidence of the most recent review.

Sequencing

Which gaps should be addressed first because other controls depend on them. Privileged access, device management, identity hygiene and application inventory often affect multiple strategies. If those foundations are weak, individual control uplift can become fragmented.

What good looks like

The remediation roadmap is sequenced by dependency, not by score. Foundational controls move first.

Common failure patterns

The patterns that produce low maturity outcomes, failed insurance assessments and ongoing vulnerability are predictable.

Most organisations that have done an assessment have done one that missed at least one of these.

01
MFA enabled but not at the maturity level required
Having MFA enabled is not the same as having MFA that meets the maturity requirements. MFA requirements tighten through the maturity levels, and the type of MFA matters significantly at ML2 and above. Standard push notification MFA does not satisfy the stronger requirements for privileged access at higher maturity. The gap is widespread and frequently undetected until an assessment reveals it.
02
Measuring patch intent rather than patch state
A patch management policy is not patch management. The assessment must verify the actual patch state across endpoints and servers, including systems that are rarely online, endpoints in remote offices and legacy systems that may be excluded from standard patching routines.
03
Application control on managed devices only
Application control configured on standard corporate laptops does not address BYOD, unmanaged devices accessing corporate systems, or server-class systems where attackers commonly move laterally after initial compromise.
04
Counting licensed backups as tested backups
A backup tool that is running and generating jobs does not satisfy Essential Eight requirements unless the backup has been tested for successful restoration. Organisations that have not tested recovery within the past year face a material gap at ML2.
05
Admin privilege sprawl after remediation
Restricting administrative privileges at a point in time does not produce a sustainable posture. Without ongoing controls that prevent privilege accumulation over time, environments revert. The assessment must look at the current state, not the intended state from the last remediation project.
06
Assessing one strategy at a time
Because overall maturity is the lowest score across all eight strategies, organisations that focus remediation on their weakest control while neglecting incremental gaps in others remain at a lower overall maturity than their effort suggests. Remediation must be coordinated across all eight strategies simultaneously.
How uplift actually works

For many organisations, the biggest improvement comes from making existing controls consistent, measurable and reviewed.

Essential Eight uplift should be sequenced around the environment, not around a checklist alone.

01
Confirm scope, which systems, identities, applications and devices are in.
02
Identify current maturity across all eight strategies.
03
Find the weakest strategies and the controls that drive overall maturity.
04
Validate evidence in the live environment, not from policy intent.
05
Reduce exceptions and confirm compensating controls where they remain.
06
Prioritise high-risk gaps based on exposure, obligation and feasibility.
07
Implement changes in a sequence the business can absorb operationally.
08
Re-check evidence after uplift, not only at the next assessment cycle.

Essential Eight maturity is not only a project. It becomes part of the operating discipline around identity, endpoint, patching, applications, backup and administration. The organisations that sustain ML2 are usually the ones that built the discipline into operations, not the ones that scheduled a remediation sprint.

Where the Essential Eight conversation usually ends, and where the next one starts

The hard part is not reaching ML2 once. The hard part is maintaining it when users, systems and threat conditions change.

Most organisations that engage with the Essential Eight reach a point where the assessment is complete and the gaps are documented. The harder question is whether the operational discipline exists to close them and sustain the posture once it is reached.

For many Australian organisations, ML2 is achievable without significant additional tooling spend. The controls required are implementable within a well-configured Microsoft 365 environment with a properly managed endpoint fleet and a disciplined identity hygiene program. The investment is in engineering time, operational discipline and ongoing maintenance, not technology procurement.

The organisations that fail to sustain ML2 after achieving it are usually not lacking tools. They are lacking the operational discipline to enforce MFA type requirements as user populations change, to patch within 48-hour windows when a critical vulnerability is released, and to test backup restoration on a defined schedule.

This is where the Essential Eight conversation usually leads into a different conversation. Establishing the maturity position is the assessment. Holding and improving it continuously is the operating discipline above it. For Australian organisations, Inlight IT delivers that operating discipline as part of Managed Cyber Security, the service designed to provide the deeper security operating layer above the managed IT baseline. The Essential Eight Assessment establishes where the organisation stands. Managed Cyber Security is one way that maturity can be operated continuously when the organisation does not have that discipline internally.

The two services work together. Some organisations engage the assessment alone and execute the remediation with their internal team. Others engage the assessment first and then move into MCS to operate the maturity continuously. The right scope depends on what the organisation can sustain operationally after the assessment is complete.

The Inlight IT view

The Inlight IT view on Essential Eight.

Most of the work involved in sustaining ML2 is engineering work that happens after the assessment: keeping MFA type requirements aligned with the maturity standard as user populations change, holding patching to a 48-hour cadence on internet-facing systems, testing backup restoration on a defined schedule, reviewing privileged access on a defined cadence and re-checking evidence between assessment cycles rather than only at the next assessment.

That work has to happen continuously. It cannot be delivered by an assessment alone, no matter how good the assessment is. The assessment establishes where the maturity stands. The operating discipline holds it.

The Essential Eight is not a list to tick off. It is a control set that either works in the environment or does not. The difference between an organisation that reaches ML2 once and one that maintains it is operational discipline, not tooling.

Inlight IT does the assessment work the same way regardless of whether the organisation goes on to engage Managed Cyber Security to operate the maturity continuously or executes the remediation roadmap with their internal team. The assessment has to stand on its own. What happens after the assessment is a separate decision, and the page that covers the formal assessment scoping is Essential Eight Assessment.

Frequently asked

Questions Australian organisations ask when researching Essential Eight implementation.

Who needs to comply with the Essential Eight?
Australian Commonwealth non-corporate entities are required under governance requirements to implement the Essential Eight to at least ML2. For private sector organisations, it is not universally legislated, but it is increasingly embedded in government procurement, cyber insurance questionnaires and enterprise supplier due diligence. The practical question is who is asking for the maturity position and what evidence they will accept.
What are the requirements for Essential Eight Maturity Level 2?
At ML2, controls must be consistently enforced and harder to bypass. Critical patches inside 48 hours for internet-facing systems. Application control covering additional execution paths. Admin privilege restrictions enforced consistently. Backups tested for successful restoration, not just confirmed running. MFA requirements tighten materially, with stronger and harder-to-bypass methods required for privileged access.
Is the Essential Eight a certification?
No. The Essential Eight is a maturity model, not a certification scheme. There is no universal certificate issued by the ASD that proves maturity. What matters is whether the organisation can demonstrate, with technical evidence, that the controls are operating effectively in the live environment. The framework itself does not produce a certificate the way ISO 27001 certification does.
What is the difference between the Essential Eight and ISO 27001?
The Essential Eight is a prescriptive technical framework that measures whether specific security controls are working. ISO 27001 is a broader information security management system standard that certifies the organisation has a documented, risk-based governance framework for managing information security risk. They are not alternatives, they measure different things. Detailed comparison: Essential Eight vs ISO 27001.
What is the difference between Essential Eight and NIST?
NIST publishes multiple frameworks (CSF, 800-53, 800-171) with different scopes. The NIST Cybersecurity Framework is a high-level outcome-based framework that organisations adapt to their own context. The Essential Eight is a prescriptive set of eight specific controls assessed at three maturity levels, with Australian-specific threat intelligence behind the control choices. NIST is broader and more flexible; Essential Eight is more specific and more directly testable.
What is the difference between Essential Eight and SMB1001?
SMB1001 is an Australian small business cybersecurity standard designed for organisations that may not have the scale to implement the full Essential Eight. It introduces simpler tier-based maturity (Bronze, Silver, Gold, Platinum) and is intended as an entry point for small businesses building toward stronger cyber maturity. Essential Eight is the deeper, more technically specific framework. Organisations operating in or supplying to government, regulated sectors, or enterprise procurement typically need Essential Eight maturity rather than SMB1001 alignment.
How do you get Essential Eight certified?
You don’t. There is no Essential Eight certification. What organisations can obtain is a maturity assessment that produces a defensible maturity position, a gap analysis and a remediation roadmap. The maturity position is what insurers, customers and procurement teams ask for, not a certificate. The formal scoping of that assessment is on Essential Eight Assessment.
Is MFA mandatory under the Essential Eight?
MFA is one of the eight strategies and is required at all maturity levels. The type of MFA matters at higher maturity levels: SMS OTP does not satisfy ML2 requirements for privileged accounts, where phishing-resistant methods (FIDO2, certificate-based authentication) are increasingly required. The MFA strategy tightens materially through the maturity model.
How is Essential Eight maturity maintained over time?
Through operational discipline that operates after the assessment: enforcing MFA type requirements as user populations change, patching within defined windows when critical vulnerabilities are released, testing backup restoration on schedule and reviewing privileged access regularly. For organisations using Inlight IT, that ongoing discipline is delivered as part of Managed Cyber Security.
Practical next step

Understand where Essential Eight maturity actually stands.

Know whether the evidence behind it would actually hold up.

Discuss Essential Eight maturity