The Australian Signals Directorate's (ASD) Essential Eight is Australia's most widely referenced cybersecurity framework for businesses. But many business owners encounter it without a clear understanding of what the four maturity levels actually mean, and more importantly — which level they should be aiming for.
This guide demystifies the maturity model in plain English, explains what each level protects against, and gives you a clear recommendation for where most Australian SMBs should target their efforts.
What Is the Essential Eight?
The Essential Eight is a set of eight mitigation strategies developed by the Australian Signals Directorate (ASD), the government agency responsible for Australia's cybersecurity. The strategies were designed to protect organisations against the most common cyberattack techniques observed against Australian systems.
The eight strategies are:
- Application control — prevent unapproved software from running
- Patch applications — update software vulnerabilities promptly
- Configure Microsoft Office macro settings — block macros from internet-sourced files
- User application hardening — disable features commonly used in attacks (Flash, Java, ads)
- Restrict administrative privileges — limit who has admin access and when
- Patch operating systems — keep OS updated, remove unsupported versions
- Multi-factor authentication (MFA) — require additional verification for privileged and remote access
- Regular backups — maintain and test backups of important data
What Are the Essential Eight Maturity Levels?
The Essential Eight is assessed across four maturity levels — 0, 1, 2, and 3. Each level builds on the previous one. Here is what each level means:
Maturity Level 0 — Not Protected
Controls are absent or so incomplete that the organisation provides no effective protection against common attacks. Most cybersecurity incidents targeting SMBs succeed against ML0 environments because basic defences are not in place.
Maturity Level 1 — Basic Protection
Controls protect against adversaries using widely available, commodity attack tools. Think script kiddies and automated scanning tools. ML1 requires each of the eight strategies to be partially implemented. For example, MFA must be required for remote access, and backups of important data must exist. ML1 is a meaningful step forward but leaves gaps that more targeted attackers can exploit.
Maturity Level 2 — Recommended for Most Australian SMBs
Controls protect against adversaries who invest more time and use more sophisticated techniques. ML2 requires each strategy to be more comprehensively implemented. MFA must cover all users accessing internet-facing services (not just remote access). Backups must be stored offline or in immutable form. OS patching must occur within 48 hours of a critical patch release. For the vast majority of Queensland and Australian SMBs, ML2 is the right target — it provides a robust defence against the threats that most commonly result in data breaches and ransomware incidents.
Maturity Level 3 — Critical Infrastructure & High-Risk Organisations
Controls protect against the most sophisticated and persistent threat actors, including nation-state adversaries. ML3 requires the most stringent implementation of each control — for example, privileged access workstations, just-in-time admin access, and hardware-based MFA only. ML3 is generally appropriate for government agencies, critical infrastructure operators, and organisations with extremely sensitive data. Most private sector SMBs do not need ML3.
Maturity Level Comparison: What Each Level Requires
| Control | ML1 | ML2 | ML3 |
|---|---|---|---|
| MFA | Remote access only | All internet-facing services & privileged accounts | All users, phishing-resistant only |
| Patching (OS) | Within 1 month (critical) | Within 48 hours (critical) | Within 48 hours (all patches) |
| Backups | Important data, tested occasionally | Offline/immutable, tested quarterly | As ML2, plus tested & verified monthly |
| Admin privileges | Limited to required users | Privileged accounts for admin tasks only | Just-in-time, PAWs required |
| Application control | Partial coverage | All desktops and servers | All systems including drivers |
What Level Should Your Business Target?
For most Australian SMBs — including professional services firms, accounting practices, healthcare providers, and construction businesses in SEQ — Maturity Level 2 is the right target. Here is why:
- ML2 protects against the threat actors who are most likely to target your business — financially motivated criminal groups using proven, repeatable attack methods
- ML2 is achievable for most SMBs within 6–12 months with the right MSP partner
- ML2 satisfies most cyber insurance requirements, which are becoming a standard part of renewal questions
- ML2 demonstrates a level of due diligence that is increasingly expected by large enterprise clients in contracts and supply chain questionnaires
- ML2 provides a meaningful defence against ransomware — the most financially damaging threat to Australian SMBs
How to Achieve Essential Eight ML2
Getting to ML2 is not a one-day project, but it is achievable. The typical roadmap for an SMB looks like this:
- Assessment — conduct an Essential Eight gap assessment against your current environment to understand your current maturity level and identify the most critical gaps
- MFA first — deploy MFA across Microsoft 365, email, and any internet-facing systems; this is the fastest high-impact win
- Backup hardening — move to immutable or offline backup storage and establish a quarterly test schedule
- Patch management — implement automated patching with a defined 48-hour SLA for critical patches
- Admin privilege reduction — audit and reduce admin accounts; ensure admin accounts are not used for day-to-day tasks
- Application hardening — disable macros, outdated browser plugins, and unnecessary application features
- Application control — implement allowlisting for known-good software across desktops
- Ongoing monitoring and review — maintain and verify controls quarterly
Essential Eight Compliance Support — Gold Coast and Brisbane
Xen Technologies provides Essential Eight gap assessments and implementation support for businesses in Gold Coast, Brisbane, and across South East Queensland. We assess your current maturity level, provide a prioritised remediation roadmap, and implement controls through our managed IT and cybersecurity services. Contact us at (07) 5619 6555 or visit our compliance services page.
Frequently Asked Questions
What are the Essential Eight maturity levels?
The Essential Eight has four maturity levels: ML0 (no effective protection), ML1 (basic protection against commodity attacks), ML2 (protection against more targeted attackers — recommended for most Australian SMBs), and ML3 (protection against the most sophisticated threat actors, typically required for government and critical infrastructure).
What Essential Eight maturity level should a small business aim for?
Maturity Level 2 is the appropriate target for most Australian small and medium businesses. It provides robust protection against the financially motivated criminal groups that most commonly target SMBs, satisfies cyber insurance requirements, and is achievable within 6–12 months with the right managed IT partner.
Is the Essential Eight mandatory for Australian businesses?
The Essential Eight is mandatory only for non-corporate Commonwealth entities (Australian Government departments and agencies). For private sector businesses, it is strongly recommended — and increasingly expected by cyber insurers, enterprise procurement teams, and government supply chain contracts. It is not yet legislated for most private sector organisations, though this is expected to change as Australia's cyber regulatory environment evolves.
How long does it take to achieve Essential Eight Maturity Level 2?
For most SMBs, achieving ML2 takes between 3 and 12 months depending on the current state of IT infrastructure, the number of endpoints, and the complexity of the software environment. Quick wins — such as enforcing MFA and establishing immutable backups — can be achieved in days to weeks. More complex controls like application control typically take longer to implement without disrupting operations.