What Is the Essential Eight? A Plain-English Guide for Australian Executives
The Essential Eight is the Australian Signals Directorate's set of eight baseline cyber security controls, measured from Maturity Level Zero to Three. It is mandatory for federal agencies and a common benchmark for everyone else.
Written and reviewed by The Technology Office · Independent technology advisory
Key takeaways
- The Essential Eight is ASD's set of eight baseline cyber security controls, measured from Maturity Level Zero to Three.
- It is mandatory for non-corporate Commonwealth entities and a common benchmark in contracts, supply chains, and cyber insurance for everyone else.
- Overall maturity is set by the weakest strategy, so reach one level across all eight before aiming higher.
- As at September 2026, the November 2023 maturity model remains current while ASD develops a broader Essentials series.
The short answer
The Essential Eight is a set of eight baseline cyber security mitigation strategies published by the Australian Signals Directorate (ASD). Its maturity model measures how well each strategy is implemented, from Maturity Level Zero to Maturity Level Three. It is mandatory for non-corporate Commonwealth entities and is widely used as a benchmark by private organisations, their customers, and cyber insurers.
What are the eight strategies?
| Strategy | What it does, in plain English |
|---|---|
| Application control | Only approved software can run, so unapproved and malicious programs are blocked |
| Patch applications | Security updates for applications are applied promptly; unsupported applications are removed |
| Configure Microsoft Office macro settings | Macros from the internet and other untrusted sources are blocked |
| User application hardening | Risky features in browsers, office tools, and PDF readers are turned off |
| Restrict administrative privileges | Admin access is limited, controlled, and used only for admin tasks |
| Patch operating systems | Operating systems are kept updated and unsupported versions are replaced |
| Multi-factor authentication | Signing in requires more than a password, especially for remote and privileged access |
| Regular backups | Important data is backed up, the backups are protected, and restores are tested |
ASD groups the strategies by purpose. The first four help prevent malicious code being delivered and run. Restricting admin privileges, patching operating systems, and multi-factor authentication limit how far an incident can spread. Regular backups support recovery.
What are the maturity levels?
- Maturity Level Zero: weaknesses in the organisation's overall cyber security posture.
- Maturity Level One: protects against opportunistic attackers using widely available tools and techniques.
- Maturity Level Two: protects against attackers willing to invest more time and use more effective tools.
- Maturity Level Three: protects against more adaptive attackers who target specific organisations and are less reliant on publicly available tools.
An organisation's maturity is only as strong as its weakest strategy. ASD recommends reaching the same level across all eight before moving to a higher level.
Is the Essential Eight mandatory?
It is mandatory for non-corporate Commonwealth entities under the Australian Government's Protective Security Policy Framework. For most private businesses and not-for-profits it is not a legal requirement. In practice, it is increasingly referenced in government and enterprise contracts, supply-chain security requirements, and cyber insurance questionnaires. Boards also use it as a shared language for cyber risk.
Which maturity level should your business target?
ASD's guidance is to choose a target level suited to your environment, considering how attractive you are to attackers and the consequences of an incident. As a practical starting point:
- if you are not yet at Level One across all eight strategies, get there first, because it addresses the most common attacks
- many mid-sized organisations then target Level Two, particularly if they hold sensitive personal or financial information or supply government or larger enterprises
- Level Three is usually reserved for high-risk environments or specific critical systems
A genuine Level One across all eight is worth more than a Level Two claim with gaps.
Has the Essential Eight changed recently?
ASD updates the maturity model periodically as attacker techniques change. The most recent substantive update was published in November 2023 and strengthened requirements in areas including multi-factor authentication. In mid-2026 ASD consulted on evolving the Essential Eight into a broader Essentials series. At the time of writing, September 2026, no replacement had been published, so the current maturity model remains the benchmark and work towards it carries forward.
How do you assess Essential Eight maturity?
- Define the scope. Decide which systems, users, and environments are included. Gaps in scope are a common source of false confidence.
- Gather evidence, not just policies. Maturity depends on controls that are implemented and working, such as actual patching timeframes and successful restore tests, not documents that say they should happen.
- Assess each strategy against the target level. The lowest-scoring strategy sets overall maturity.
- Document exceptions. ASD allows justified exceptions, but they should be approved, kept to a minimum, backed by compensating controls, and reviewed regularly.
- Build a prioritised uplift plan. Sequence the fixes by risk and effort, with owners and dates.
- Reassess regularly. Controls drift as systems, suppliers, and staff change.
What should executives and boards ask?
- What is our current maturity for each of the eight strategies, and what is our target?
- Is the assessment based on evidence or self-attestation?
- Which systems are out of scope, and why?
- What exceptions exist, who approved them, and what compensating controls are in place?
- When did we last successfully restore from backup?
- Which accounts are protected by phishing-resistant multi-factor authentication?
- What is the plan, budget, and timeline to reach our target level?
What does the Essential Eight not cover?
The Essential Eight is a minimum baseline, not a complete security program. It does not replace incident response planning, staff awareness, supplier security, monitoring, or data protection. Organisations handling personal information also need to meet their Privacy Act obligations, including the Notifiable Data Breaches scheme where it applies.
Where to get help
If your organisation lacks a security lead, independent cybersecurity governance support can set the target level, commission the assessment, and hold your IT provider to account for the uplift. In Microsoft environments, a Microsoft 365 security review covers many of the controls that underpin Essential Eight maturity. For board reporting, see the board technology risk review.
Frequently asked questions
What are the Essential Eight?
Application control, patching applications, configuring Microsoft Office macro settings, user application hardening, restricting administrative privileges, patching operating systems, multi-factor authentication, and regular backups.
Is the Essential Eight mandatory for private businesses?
No. It is mandatory for non-corporate Commonwealth entities, but voluntary for most private businesses and not-for-profits. Customers, government contracts, and cyber insurers increasingly ask about it.
What maturity level should a small or mid-sized business target?
Reach Maturity Level One across all eight strategies first. Many mid-sized organisations then target Level Two, especially if they hold sensitive information or supply government or larger enterprises.
How is Essential Eight maturity measured?
Each strategy is assessed against the requirements for each maturity level. Overall maturity is set by the weakest strategy, so implemented, evidenced controls across all eight matter.
Is the Essential Eight being replaced?
ASD consulted in mid-2026 on evolving it into a broader Essentials series. As at September 2026 no replacement had been published, so the current maturity model still applies and existing work carries forward.
Sources and further reading
- Essential Eight maturity model — Australian Signals Directorate (cyber.gov.au)
Mentioned services
These service and regional NSW pages expand on the topics covered in this article.
Need help applying this?
Bring in senior technology leadership without the full-time overhead.
The Technology Office works with Sydney and regional NSW businesses on embedded CIO support, Head of IT leadership, governance, vendor management, cost optimisation, crisis stabilisation, and no-cost technology reviews as a lighter first step.