Back to Blog
Cybersecurity April 2026 · 7 min read

Essential Eight Maturity Levels Explained: What Level Should Your Business Target?

The Australian Signals Directorate's (ASD) Essential Eight is Australia's most widely referenced cybersecurity framework for businesses. But many business owners encounter it without a clear understanding of what the four maturity levels actually mean, and more importantly — which level they should be aiming for.

This guide demystifies the maturity model in plain English, explains what each level protects against, and gives you a clear recommendation for where most Australian SMBs should target their efforts.

What Is the Essential Eight?

The Essential Eight is a set of eight mitigation strategies developed by the Australian Signals Directorate (ASD), the government agency responsible for Australia's cybersecurity. The strategies were designed to protect organisations against the most common cyberattack techniques observed against Australian systems.

The eight strategies are:

  1. Application control — prevent unapproved software from running
  2. Patch applications — update software vulnerabilities promptly
  3. Configure Microsoft Office macro settings — block macros from internet-sourced files
  4. User application hardening — disable features commonly used in attacks (Flash, Java, ads)
  5. Restrict administrative privileges — limit who has admin access and when
  6. Patch operating systems — keep OS updated, remove unsupported versions
  7. Multi-factor authentication (MFA) — require additional verification for privileged and remote access
  8. Regular backups — maintain and test backups of important data

What Are the Essential Eight Maturity Levels?

The Essential Eight is assessed across four maturity levels — 0, 1, 2, and 3. Each level builds on the previous one. Here is what each level means:

ML0

Maturity Level 0 — Not Protected

Controls are absent or so incomplete that the organisation provides no effective protection against common attacks. Most cybersecurity incidents targeting SMBs succeed against ML0 environments because basic defences are not in place.

ML1

Maturity Level 1 — Basic Protection

Controls protect against adversaries using widely available, commodity attack tools. Think script kiddies and automated scanning tools. ML1 requires each of the eight strategies to be partially implemented. For example, MFA must be required for remote access, and backups of important data must exist. ML1 is a meaningful step forward but leaves gaps that more targeted attackers can exploit.

ML2

Maturity Level 2 — Recommended for Most Australian SMBs

Controls protect against adversaries who invest more time and use more sophisticated techniques. ML2 requires each strategy to be more comprehensively implemented. MFA must cover all users accessing internet-facing services (not just remote access). Backups must be stored offline or in immutable form. OS patching must occur within 48 hours of a critical patch release. For the vast majority of Queensland and Australian SMBs, ML2 is the right target — it provides a robust defence against the threats that most commonly result in data breaches and ransomware incidents.

ML3

Maturity Level 3 — Critical Infrastructure & High-Risk Organisations

Controls protect against the most sophisticated and persistent threat actors, including nation-state adversaries. ML3 requires the most stringent implementation of each control — for example, privileged access workstations, just-in-time admin access, and hardware-based MFA only. ML3 is generally appropriate for government agencies, critical infrastructure operators, and organisations with extremely sensitive data. Most private sector SMBs do not need ML3.

Maturity Level Comparison: What Each Level Requires

Control ML1 ML2 ML3
MFA Remote access only All internet-facing services & privileged accounts All users, phishing-resistant only
Patching (OS) Within 1 month (critical) Within 48 hours (critical) Within 48 hours (all patches)
Backups Important data, tested occasionally Offline/immutable, tested quarterly As ML2, plus tested & verified monthly
Admin privileges Limited to required users Privileged accounts for admin tasks only Just-in-time, PAWs required
Application control Partial coverage All desktops and servers All systems including drivers

What Level Should Your Business Target?

For most Australian SMBs — including professional services firms, accounting practices, healthcare providers, and construction businesses in SEQ — Maturity Level 2 is the right target. Here is why:

How to Achieve Essential Eight ML2

Getting to ML2 is not a one-day project, but it is achievable. The typical roadmap for an SMB looks like this:

  1. Assessment — conduct an Essential Eight gap assessment against your current environment to understand your current maturity level and identify the most critical gaps
  2. MFA first — deploy MFA across Microsoft 365, email, and any internet-facing systems; this is the fastest high-impact win
  3. Backup hardening — move to immutable or offline backup storage and establish a quarterly test schedule
  4. Patch management — implement automated patching with a defined 48-hour SLA for critical patches
  5. Admin privilege reduction — audit and reduce admin accounts; ensure admin accounts are not used for day-to-day tasks
  6. Application hardening — disable macros, outdated browser plugins, and unnecessary application features
  7. Application control — implement allowlisting for known-good software across desktops
  8. Ongoing monitoring and review — maintain and verify controls quarterly

Essential Eight Compliance Support — Gold Coast and Brisbane

Xen Technologies provides Essential Eight gap assessments and implementation support for businesses in Gold Coast, Brisbane, and across South East Queensland. We assess your current maturity level, provide a prioritised remediation roadmap, and implement controls through our managed IT and cybersecurity services. Contact us at (07) 5619 6555 or visit our compliance services page.

Frequently Asked Questions

What are the Essential Eight maturity levels?

The Essential Eight has four maturity levels: ML0 (no effective protection), ML1 (basic protection against commodity attacks), ML2 (protection against more targeted attackers — recommended for most Australian SMBs), and ML3 (protection against the most sophisticated threat actors, typically required for government and critical infrastructure).

What Essential Eight maturity level should a small business aim for?

Maturity Level 2 is the appropriate target for most Australian small and medium businesses. It provides robust protection against the financially motivated criminal groups that most commonly target SMBs, satisfies cyber insurance requirements, and is achievable within 6–12 months with the right managed IT partner.

Is the Essential Eight mandatory for Australian businesses?

The Essential Eight is mandatory only for non-corporate Commonwealth entities (Australian Government departments and agencies). For private sector businesses, it is strongly recommended — and increasingly expected by cyber insurers, enterprise procurement teams, and government supply chain contracts. It is not yet legislated for most private sector organisations, though this is expected to change as Australia's cyber regulatory environment evolves.

How long does it take to achieve Essential Eight Maturity Level 2?

For most SMBs, achieving ML2 takes between 3 and 12 months depending on the current state of IT infrastructure, the number of endpoints, and the complexity of the software environment. Quick wins — such as enforcing MFA and establishing immutable backups — can be achieved in days to weeks. More complex controls like application control typically take longer to implement without disrupting operations.

Category: Cybersecurity Published: April 2026 Read time: 7 minutes Author: Xen IT Team

Find out your Essential Eight maturity level today.

Xen Technologies provides Essential Eight gap assessments for Queensland businesses. Understand where you stand, what the risks are, and get a clear roadmap to achieve Maturity Level 2.

Book a Free Assessment