Essential Eight maturity levels, explained
The Essential Eight is the Australian Signals Directorate’s baseline of eight mitigation strategies for hardening against cyber attacks. The part that trips most teams up isn’t the eight strategies — it’s the maturity model bolted on top: ML0 to ML3. This guide explains what those levels actually mean, how each strategy is assessed against them, and how to work out — and prove — where you sit.
The eight strategies, quickly
The Essential Eight groups into three goals:
Prevent attacks
- Application control — only approved software can run.
- Patch applications — close known holes in apps and drivers fast.
- Configure Microsoft Office macro settings — block macros from the internet.
- User application hardening — lock down browsers, PDF readers and the like.
Limit the extent of attacks
- Restrict administrative privileges — fewer admins, tightly controlled.
- Patch operating systems — keep the OS current on a defined timeline.
- Multi-factor authentication — MFA on the accounts that matter.
Recover data and system availability
- Regular backups — tested, isolated, and actually restorable.
Each of the eight is assessed on its own. Your overall Essential Eight maturity is only as high as your weakest strategy — a common surprise for teams who assume strong MFA lifts the whole score.
The maturity model: ML0 to ML3
The ASD maturity levels describe how completely you’ve implemented each strategy, framed against the kind of adversary each level is meant to stop.
- Maturity Level 0 (ML0) — Not aligned. There are weaknesses in the strategy that a determined attacker could exploit. This is the honest starting point for most organisations on at least one strategy.
- Maturity Level 1 (ML1) — Partly aligned. Mitigates attackers using widely available, commodity tooling — the opportunistic end of the spectrum.
- Maturity Level 2 (ML2) — Mostly aligned. Mitigates attackers willing to invest more time and effort, and to work harder to evade detection.
- Maturity Level 3 (ML3) — Fully aligned. Mitigates adaptive attackers who are focused on a specific target and prepared to bypass the weaker controls.
The model is designed to be implemented as a package at each level, rather than cherry-picking the easy strategies. The ASD recommends most organisations target ML1 as a minimum, and step up to ML2 or ML3 based on the sensitivity of the data and the threat they realistically face.
How a strategy gets assessed
For each of the eight, an assessor checks specific, testable requirements at the level you’re claiming. Take patch applications at ML1 versus ML3: ML1 asks for patching of internet-facing services within two weeks (or 48 hours if an exploit exists); ML3 tightens the windows, widens the scope to all applications, and expects vulnerability scanning to confirm it. The strategy is the same; the rigour and evidence required climb with each level.
That’s why “we do MFA” isn’t a maturity level. The question is always: to what standard, across which systems, and can you show it?
Working out where you sit
The practical steps are the same whichever tool you use:
- Assess each strategy independently against the ML1, ML2 and ML3 requirements — not as a single overall guess.
- Take the lowest as your headline maturity, and record the per-strategy detail underneath.
- Attach evidence to each requirement — a config export, a patch report, a backup-restore test — so the score is defensible, not asserted.
- Track the gap to target so the next prioritised step is always obvious.
Done in spreadsheets, this is where Essential Eight programmes stall: eight strategies × three levels × a growing pile of evidence, re-tallied by hand every board cycle. Software built around the maturity model does the cross-referencing and keeps the score live — which is exactly what Cybereen’s maturity assessments are for.
Essential Eight and your other frameworks
If you also run ISO 27001, NIST CSF or an APRA obligation, most of the evidence overlaps. MFA satisfies an Essential Eight strategy, an ISO 27001 Annex A control and a NIST CSF outcome at once. Mapping those controls so one piece of evidence counts everywhere is the difference between doing the work once and doing it three times — the core idea behind multi-standard mapping.
The Essential Eight rewards discipline over heroics: pick a target level, get every strategy there, and keep the evidence current. The model makes the next step obvious — the hard part is just keeping score honestly.
Want to see your level? Explore Cybereen’s Essential Eight support or book a walkthrough.
See your frameworks — and their overlap — on one platform.
Book a walkthrough →