AuditXYZ

Compliance Framework

Essential Eight Maturity Model (Essential Eight)

The Essential Eight is Australia's prioritized cybersecurity mitigation strategies from ASD. Learn how to implement these eight controls across four maturity levels.

$10,000–$100,0002–12 months2023
Issuing BodyAustralian Signals Directorate (ASD)
First Published2017-02-01
Latest Version2023
Typical Cost$10,000–$100,000
Typical Timeline2–12 months
Audit RequiredNo
Audit FrequencySelf-assessment recommended annually. Australian government entities report maturity levels to the ASD. Third-party assessment available but not mandatory for all organizations.
Geographyaustralia

Essential Eight: Australian Cybersecurity Maturity Model

The Essential Eight is a set of prioritized mitigation strategies published by the Australian Signals Directorate (ASD) to help organizations protect against cybersecurity incidents. Based on ASD's experience responding to real-world incidents, these eight strategies address the most common attack vectors targeting Australian organizations.

What the Essential Eight Covers

The eight mitigation strategies are:

  1. Application control — Only approved applications can execute, preventing malware and unauthorized software
  2. Patch applications — Security patches for applications applied within prescribed timeframes
  3. Configure Microsoft Office macro settings — Block macros from the internet, only allow vetted macros
  4. User application hardening — Configure web browsers and other applications to block ads, Java, Flash, and unneeded features
  5. Restrict administrative privileges — Limit admin access to those who need it, regularly revalidate
  6. Patch operating systems — Security patches for operating systems applied within prescribed timeframes
  7. Multi-factor authentication — MFA for all users accessing important data and internet-facing services
  8. Regular backups — Perform and test backups of important data, software, and configuration settings

Maturity Model

Each strategy is assessed across four maturity levels:

  • Maturity Level Zero — Weaknesses exist that could be exploited
  • Maturity Level One — Partly aligned with the intent of the strategy
  • Maturity Level Two — Mostly aligned, providing greater protection
  • Maturity Level Three — Fully aligned, providing the highest level of protection

Australian government entities are expected to achieve Maturity Level Two as a baseline, with critical systems targeting Level Three.

Who Needs the Essential Eight

The Essential Eight is mandatory for Australian federal government entities under the Protective Security Policy Framework (PSPF). State and territory governments have adopted similar requirements. Beyond government, organizations in critical infrastructure, finance, healthcare, and education increasingly use the Essential Eight as their cybersecurity baseline.

The framework's strength lies in its simplicity and practicality. Eight clearly defined strategies with measurable maturity levels make it accessible even to organizations with limited cybersecurity expertise.

Implementation Strategy

  1. Baseline assessment — Determine current maturity level for each of the eight strategies
  2. Set target — Choose a target maturity level appropriate for your risk profile
  3. Prioritize gaps — Focus on the strategies where you have the largest gap between current and target
  4. Implement incrementally — Achieve Maturity Level One across all eight before advancing individual strategies
  5. Test and verify — Use ASD's assessment guidance to validate your maturity level claims
  6. Report and iterate — Document maturity levels and continuously improve

The Essential Eight works well as a complement to broader frameworks like ISO 27001 or NIST CSF, providing tactical, measurable cybersecurity controls within a strategic governance structure.

The Eight Mitigation Strategies Explained in Detail

1. Application control prevents unauthorized software from executing on workstations, servers, and other endpoints. At Maturity Level One, this means maintaining a list of approved applications. At Maturity Level Three, it means only digitally signed applications from approved publishers can execute, blocking all unsigned code.

2. Patch applications addresses the reality that application vulnerabilities are among the most exploited attack vectors. Maturity Level One requires patching within 30 days; Maturity Level Two within 14 days; Maturity Level Three within 48 hours for vulnerabilities rated critical or high severity. Unsupported applications must be removed or appropriately mitigated.

3. Configure Microsoft Office macro settings — Macros embedded in Office documents are a primary delivery mechanism for malware. The standard requires disabling macros from the internet by default and only allowing macros from trusted locations or digitally signed from trusted publishers. At Maturity Level Three, only privileged users in secured environments may run macros.

4. User application hardening focuses on web browsers and other user-facing applications that regularly process untrusted content. Requirements include disabling web advertisement processing, blocking Java from the web, enabling HTTPS-only mode, and preventing users from installing browser extensions not approved by an administrator.

5. Restrict administrative privileges addresses privilege escalation attacks. Users must not be granted administrative privileges by default. Privileged accounts must not be used for web browsing or email. At Maturity Level Three, privileged access workstations (PAWs) are required for administrative activities, completely isolated from standard user environments.

6. Patch operating systems mirrors application patching requirements for the OS layer. Critical and high-severity OS vulnerabilities must be patched within specified timeframes. Unsupported operating systems that cannot receive security patches are not acceptable — they require replacement or isolation.

7. Multi-factor authentication — MFA must be enabled for all users authenticating to internet-facing services, remote access infrastructure, and privileged accounts. At Maturity Level Three, phishing-resistant MFA (hardware tokens, passkeys) is required for all privileged access, not just internet-facing services.

8. Regular backups — Critical data, software, and configuration settings must be backed up and tested. Backups must be inaccessible to unprivileged accounts (protecting against ransomware). At Maturity Level Three, offline or immutable backups are required for critical systems, and restoration is tested at least quarterly.

The Maturity Level Framework in Practice

Moving up the maturity levels is not linear across all eight strategies simultaneously. The ASD recommends a specific progression:

Approach 1 — Achieve Maturity Level One across all eight before advancing any strategy. This establishes a consistent security baseline. Organizations that advance one strategy to Level Three while others remain at Level Zero create an unbalanced posture that attackers can route around.

Approach 2 — Prioritize by threat context. Organizations under active targeted threat (government agencies, critical infrastructure operators) should prioritize the strategies most relevant to their threat profile — typically patching, administrative privilege restriction, and MFA.

For Australian government entities, the PSPF requires achieving Maturity Level Two as an organization-wide baseline, with critical systems targeting Level Three.

Who Needs the Essential Eight and Why

Australian government entities are required to implement the Essential Eight under the Protective Security Policy Framework. The ASD conducts maturity assessments of non-corporate Commonwealth entities and publishes aggregate findings in its annual cyber security report. Being called out for low maturity levels in this report has reputational consequences.

Critical infrastructure operators under the Security of Critical Infrastructure Act 2018 (SOCI Act) face sector-specific risk management obligations that the Essential Eight helps satisfy. Regulated entities in energy, water, communications, banking, and transport are expected to demonstrate Essential Eight alignment.

Organizations pursuing IRAP assessment need to demonstrate Essential Eight maturity as part of the ISM control evidence. Most IRAP assessors expect Maturity Level 2 as a baseline before beginning the formal assessment process.

Smaller organizations seeking a practical starting point find the Essential Eight more accessible than ISO 27001 as a first compliance target. The eight-strategy structure is easier to communicate to non-technical leadership than a 93-control framework.

Assessment and Reporting

Self-assessment using the ASD's Assessment Guidance and the Essential Eight Maturity Model documentation is the most common approach. Organizations score each of the eight strategies at their current maturity level and identify gaps.

Third-party assessment provides independent validation of self-reported maturity levels. Independent assessments are not mandatory for most organizations but are increasingly expected for government contractors and critical infrastructure operators seeking to demonstrate credible compliance.

ASD voluntary reporting — Non-corporate Commonwealth entities report their Essential Eight maturity levels to the ASD annually. This data informs ASD's annual cyber security posture reports and sector-wide insights.

Costs and Timeline

ComponentLow EstimateHigh Estimate
Maturity Level One assessment$5,000$15,000
Maturity Level One implementation$10,000$40,000
Maturity Level Two uplift$15,000$60,000
Maturity Level Three (critical systems)$25,000$100,000
Third-party assessment$10,000$40,000
Total (to Maturity Level Two)$40,000$115,000

Timeline: 2 to 12 months. Achieving Level One across all eight strategies in 2 to 4 months is realistic for organizations with modern IT environments. Level Two typically requires 6 to 12 months.

Essential Eight vs. IRAPIRAP assessments use the ISM, which encompasses the Essential Eight plus many additional controls. Essential Eight Maturity Level 2 is a prerequisite expectation before engaging an IRAP assessor for most government ICT assessments.

Essential Eight vs. CIS Controls — About 55% overlap. Both are prioritized control frameworks derived from threat data. CIS Controls (18 controls, 153 safeguards) are more comprehensive and internationally applicable; Essential Eight is more narrowly focused and specific to Australian threat context. The patching and administrative privilege strategies in Essential Eight directly mirror CIS Controls 2 and 5.

Essential Eight vs. ISO 27001 — About 35% overlap. ISO 27001 is a management system framework covering governance, risk management, and 93 controls. Essential Eight addresses 8 specific technical mitigation strategies. Most organizations pursuing ISO 27001 will implement Essential Eight controls as part of their Annex A technological controls.

Essential Eight vs. Cyber EssentialsCyber Essentials is the UK's analogous baseline framework — five technical control themes covering similar territory. Both frameworks cover patching, access control, and malware protection with comparable intent.

How Automation Helps

The Essential Eight's measurable, technology-specific requirements are well-suited to automation. Patch compliance monitoring, application control logging, MFA verification, and backup status tracking are all available as continuous automated checks rather than periodic manual assessments.

LowerPlane supports Essential Eight maturity tracking as part of its 50-plus framework library, integrating with endpoint management, patch management, and identity tools to provide real-time maturity level visibility. At $4,000/year entry pricing with a free tier, it provides continuous Essential Eight monitoring accessible to organizations at any maturity stage. AuditXYZ rates it 9.4/10. Compare at Best Compliance Automation Platforms.

Frequently Asked Questions

Is the Essential Eight mandatory for private Australian companies? Not directly, for most private companies. It is mandatory for non-corporate Commonwealth entities under the PSPF. However, critical infrastructure operators under the SOCI Act face risk management obligations that the Essential Eight satisfies. Many private companies adopt it voluntarily as a recognized security baseline.

How does the ASD update the Essential Eight? The ASD updates the Essential Eight maturity model periodically as threats evolve. The most recent update in 2023 increased the stringency of patch management timelines, clarified macro settings for Microsoft 365, and raised the MFA requirements to address phishing-resistant authentication at higher maturity levels. Monitor the ASD website for updates.

What is the difference between the Essential Eight and the ISM? The Essential Eight is eight prioritized mitigation strategies derived from the ISM and presented as a focused starting point. The ISM is a comprehensive controls document covering hundreds of controls across all security domains. Think of the Essential Eight as an accessible subset of ISM controls that delivers the highest return on security investment against the most common attack techniques.

Can we achieve Maturity Level Three across all eight strategies? Yes, but few organizations need or can justify this investment. Level Three is most appropriate for systems handling highly sensitive information, critical infrastructure, or targets of advanced persistent threats. Most organizations in the private sector target Level Two across all eight strategies as a balanced risk posture.

Request a Essential Eight consultation

Step 1 of 520%

Which framework do you need?

Framework Mappings

Overlap with other frameworks

CIS ControlsMedium55%
NIST CSFLow45%
ISO 27001Low35%

Get matched with a Essential Eight auditor in 24 hours

Free, no-obligation — just tell us your email and we'll do the rest.

By submitting, you agree to our privacy policy.

Recommended Tools