What is ASD Essential Eight Maturity Model compliance?

The Essential Eight Maturity Model is the Australian Signals Directorate's (ASD) four-level scale for measuring how well an organization has implemented its eight baseline cyber mitigation strategies across internet-connected IT networks.

Banner thumbnail
On this page  
  • Introduction
  • Applicability and scope
  • Compliance levels and requirements
  • The eight mitigation strategies
  • Maturity Level Zero
  • Maturity Level One
  • Maturity Level Two
  • Maturity Level Three
  • Challenges of implementing the Essential Eight Maturity Model
  • Benefits of implementing the Essential Eight Maturity Model
  • Best practices
  • Conclusion
 

Introduction

If you run internet-connected IT anywhere in Australia, you have almost certainly been asked what Essential Eight maturity level you are at. The Essential Eight is ASD's baseline set of eight mitigation strategies, drawn from its wider Strategies to Mitigate Cyber Security Incidents. The Essential Eight Maturity Model is the companion document that answers the harder question: not whether you have those eight controls in place, but how well you have implemented them. It gives you four defined levels and tells you what each one has to look like, strategy by strategy.

ASD first published the model in June 2017 and has updated it regularly since, drawing on what it sees through cyberthreat intelligence, incident response, penetration testing, and its work helping organizations implement the Essential Eight. The version most teams work to today came out of a substantial 2021 revision, which reinstated Maturity Level Zero and asked organizations to reach a level across all eight strategies before climbing to a higher one, and a November 2023 update that hardened the controls and pulled several requirements down from Level Three into Level Two. In fact, that 2023 change is why some teams watched their rating slip without altering a thing.

Applicability and scope

You are working to the Essential Eight by obligation if you are a non-corporate Commonwealth entity, where the Protective Security Policy Framework (PSPF) Policy 14 (previously Policy 10) has required implementation to Maturity Level Two since July 1, 2022, or if you hold Defence Industry Security Program (DISP) membership, where Level Two is also the mandated baseline. Several state and territory frameworks reference it as well. If you are a private business, no legislation names it directly, but your cyber insurer, your government tender, or your customer's third-party risk questionnaire very likely will.

It is worth knowing what the model was not built for, too. ASD designed the Essential Eight to protect internet-connected IT networks, and notes that while the principles can be applied to enterprise mobility and operational technology, it was not designed for those environments and other mitigation strategies may suit them better.

Compliance levels and requirements

You will work through four levels, and only three of them are targets. What separates this model from most control frameworks is what those levels are pegged to. They are not pegged to your headcount, your budget, or how many boxes you have ticked. Each level is defined by the tradecraft and targeting it is built to mitigate, and ASD is explicit that you should think about the level of tradecraft you want to stop rather than which particular actors you imagine facing. One more rule shapes everything downstream: You are assessed strategy by strategy, and your overall maturity level is equal to your least-mature strategy.

The eight mitigation strategies

Before the levels can mean anything, you need the eight controls they apply to. ASD groups them by the job each one does. Four work to stop an attack landing on your systems at all, three limit how far an attacker travels once inside, and one exists so you can come back afterwards. You are rated against all eight, and there is no partial credit for the ones you have done well. That is deliberate, because the eight are designed to cover different attack paths and to compensate for each other's blind spots.

Maturity Level Zero

Level Zero is not a rating you aim for. It exists to capture instances where the requirements of Maturity Level One are not met, and because your overall rating follows your weakest strategy, a single gap in a single strategy puts your whole environment here. ASD reinstated it in 2021 for a practical reason: without a maturity level to represent that state, the data point was simply lost to assessors. Before you assume your organization sits comfortably above it, the Commonwealth's own numbers are worth a look.

Maturity Level One

Level One is built for the attacker who has no particular interest in you. They are looking for any victim rather than a specific one, seeking common weaknesses across many targets rather than investing heavily in access to yours, and using ordinary social engineering to get there. They leverage publicly available exploits, credentials leaked on the dark web, and whatever is reachable. None of these tactics require patience or skill, which is why Level One is mostly about closing doors that should never have been open. It is the lowest target level and still not a soft option, because you have to satisfy every requirement across all eight strategies to claim it.

Maturity Level Two

At Level Two, you are defending against someone who has decided you are worth some effort. ASD describes this as a modest step-up in capability, with actors willing to invest more time in you as a target and, more importantly, in the effectiveness of their tools. They will phish your people for credentials and walk straight through weaker MFA, and even start choosing targets inside your organization, favoring accounts that carry privilege. The controls answer by widening coverage, shortening clocks, and requiring you to log everything that happens in your IT environment. This is the level most Australian obligations point at, and the gap from Level One is larger than it first looks.

Maturity Level Three

Level Three assumes an adversary who is adaptive, focused on you specifically, and deliberately avoiding the tools everyone already detects. They are willing and able to invest effort into understanding your organization and the policy and technical controls you have implemented, and they exploit weaknesses to gain initial access, evade detection, and solidify their presence. Getting past strong MFA by stealing session tokens sits at this level. The controls respond by tightening timeframes further, stripping out the legacy components attackers reach for, and putting centralized monitoring beyond an intruder's reach. ASD is candid about the ceiling: Level Three will not stop actors willing and able to invest enough time, money, and effort, which is why the remaining Strategies to Mitigate Cyber Security Incidents and the Information Security Manual still matter.

Challenges of implementing the Essential Eight Maturity Model

Climbing the maturity levels is demanding in ways that are not obvious at the outset, and much of the difficulty comes from how the model is scored rather than from any individual control.

  • Your weakest strategy sets your score

You can be excellent at meeting seven of the eight controls and still be rated at the level of the eighth. Most organizations find this out the hard way, usually on application control or macro settings. It means uplift budget has to be spread across the laggards rather than spent where your team already has momentum and enthusiasm.

  • Patching clocks that assume automation

Two weeks for internet-facing services, and 48 hours where an exploit exists or the vendor rates the flaw critical, is not achievable by hand at any real scale. You need dependable asset discovery first, because you can't meet a deadline to patch something you do not know you own, and most teams find the inventory is the actual project.

  • Application control on a live estate

Allowlisting is the control that trips up assessments most often, because deciding what is allowed to execute means genuinely understanding every piece of software the business depends on. Level Two extends that to internet-facing servers, and keeping the ruleset accurate as software changes is continuous work rather than a one-off exercise.

  • Legacy systems and technical debt

ASD accepts that legacy environments and technical debt can prevent full implementation and expects you to handle that through risk management rather than pretend the gap is absent. What it does not accept is skipping an entire strategy you could technically implement, so your exceptions need to be documented, justified, and actually exceptional.

  • Holding the level once you have earned it

An assessment is a snapshot, not a standing credential. Environments drift, new systems arrive unmapped, and a rating earned last financial year can quietly lapse. Assessors increasingly want evidence over assertion, so you need scan records, log extracts, and restoration test results that show the control worked, not a policy saying it should.

Benefits of implementing the Essential Eight Maturity Model

The work pays back well beyond the assessment result, and some of the return lands outside the security team entirely.

A number your board can actually use

Most frameworks hand you a pass or a long list of findings. This one gives you a single figure between zero and three, on a scale your executives can follow and track across reporting periods. That turns uplift funding into a much more straightforward conversation than any heat map has ever managed.

Access to government and defense work

Level Two is the baseline for DISP membership and the standing requirement for non-corporate Commonwealth entities, so it operates as a gate on a large slice of Australian contract work. If you supply into that market, or intend to, your maturity level is a commercial asset rather than a technical detail.

Better conversations with insurers

Cyber underwriters have shifted from asking whether you have controls to asking how deeply they are implemented. A documented maturity level, backed by evidence you can produce on request, gives you something concrete for a renewal submission and tends to shape the terms you are offered.

Controls that count more than once

The Essential Eight sits within ASD's Information Security Manual and overlaps substantially with what ISO 27001, the PSPF, and Security of Critical Infrastructure Act (SOCI) obligations already ask of you. Work done for maturity uplift is rarely wasted in another audit cycle, as long as you keep the evidence in a form you can hand across.

Real reduction in the attacks you actually see

These eight strategies were selected because ASD watches what works against Australian organizations through its incident response and threat intelligence functions. Patching quickly, restricting privilege, enforcing MFA, and holding tested backups address the initial access and escalation paths behind most incidents, so the risk reduction is not theoretical.

Best practices

If you want more than a rating out of this, a few habits separate organizations that hold their maturity from those that rediscover the same gaps at every assessment.

Choosing and planning your target level

  • Set your target level from the tradecraft you realistically expect to face and how attractive your data makes you, rather than from your headcount or what a competitor claims.
  • Build a reliable asset inventory before anything else, because every patching, hardening, and application control requirement depends on knowing what you run and where.
  • Sequence uplift across all eight strategies together instead of perfecting the ones your team finds interesting, since your rating will follow the laggard regardless.
  • Plan separately for reaching the level and for holding it; the two need different resourcing and different owners.

Implementing and evidencing the controls

  • Automate patch deployment and vulnerability scanning early, because the Level One and Level Two timeframes are not survivable manually once you pass a few dozen endpoints.
  • Turn on centralized logging before Level Two forces you to, since logs are what convert a maturity claim into something an assessor can independently verify.
  • Test backup restoration on a fixed schedule and keep the results, because restoring is the requirement and holding backups is only half of it.
  • Document every exception alongside the risk decision behind it, and review those decisions on a set cycle rather than when somebody finally asks.

Assessing and keeping the level

  • Follow ASD's Essential Eight assessment process guide so your self-assessment lines up with what an external assessor will actually test.
  • Reassess after significant environment changes rather than only once a year, because newly introduced systems are where maturity most often slips.
  • Track maturity per strategy over time so you can spot the one trending downward before it pulls your overall rating with it.
  • Keep an eye on ASD's Essentials series work and map your existing controls against it, since the underlying controls are expected to carry over.

Conclusion

he Essential Eight Maturity Model earns its standing because it refuses to grade you on effort. Your rating is set by your weakest strategy and measured against an adversary profile rather than a checklist, which is uncomfortable in precisely the way it should be. If you are a Commonwealth entity or a defense supplier, Level Two is not a matter of choice. If you sit anywhere else in the Australian economy, the pressure arrives through your insurer, your customers, and your tender responses instead, and the answer you give when someone asks for your maturity level is increasingly a commercial one.

It is worth knowing that ASD and the Australian Cyber Security Centre (ACSC) have said the Essential Eight will be retired within roughly two years and replaced by a new Essentials series, described as prioritized, threat-informed mitigations rather than a static compliance ladder, with organizations already invested in the Essential Eight told their work will not be made redundant. That is not a reason to pause. The model remains current, the obligations referencing it are unchanged, and the controls are expected to carry across. Treat maturity as a capability you maintain rather than a project you finish, and the transition becomes a relabeling exercise instead of a restart.