Nano Solutions

The Essential Eight, explained

The Essential Eight is ASD's baseline set of eight cyber security mitigation strategies for internet-connected corporate IT. This hub explains what each strategy requires, who must implement it, and what ASD has announced about the proposed Essentials series.

Last checked against cyber.gov.au on . Current model: Essential Eight Maturity Model (November 2023).

On this page 8 sections
  1. What the Essential Eight is
  2. The eight strategies
  3. The four maturity levels
  4. Is there Essential Eight certification?
  5. Who must implement it
  6. What changed in the last update
  7. The proposed Essentials series
  8. Where to go next

Essential Eight at a glance

Eight strategies, three maturity levels

Requirements are cumulative: Level Three means everything in Levels One and Two as well. Overall maturity is the lowest strategy, so one weak row caps the whole board. Every cell links to that requirement on the matrix.

What each of the eight mitigation strategies requires at each maturity level.
Mitigation strategy ML1 Maturity Level One ML2 Maturity Level Two ML3 Maturity Level Three
Patch applications Patch applications, Maturity Level One: Patch online services — critical, or a working exploit exists (ISM-1876) Patch applications, Maturity Level Two: Patch all other applications Patch applications, Maturity Level Three: Patch office suites, browsers, email clients, PDF and security products — critical or exploited
Patch operating systems Patch operating systems, Maturity Level One: Patch internet-facing OS — critical or exploited / otherwise Patch operating systems, Maturity Level Two: Carries Maturity Level One No new requirements Patch operating systems, Maturity Level Three: Patch drivers and firmware — critical or exploited / otherwise
Multi-factor authentication Multi-factor authentication, Maturity Level One: MFA for users of your own and third-party online services handling your sensitive data (ISM-1504, ISM-1679) Multi-factor authentication, Maturity Level Two: MFA for privileged and unprivileged users of systems Multi-factor authentication, Maturity Level Three: MFA for users of data repositories
Restrict administrative privileges Restrict administrative privileges, Maturity Level One: Privileged access requests validated when first requested (ISM-1507) Restrict administrative privileges, Maturity Level Two: Administrative activities via jump servers; privileged environments not virtualised within unprivileged ones Restrict administrative privileges, Maturity Level Three: Secure Admin Workstations and just-in-time administration
Application control Application control, Maturity Level One: Implemented on workstations (ISM-0843) Application control, Maturity Level Two: Implemented on internet-facing servers Application control, Maturity Level Three: Implemented on non-internet-facing servers
Restrict Microsoft Office macros Restrict Microsoft Office macros, Maturity Level One: Macros disabled for users without a demonstrated business requirement (ISM-1671) Restrict Microsoft Office macros, Maturity Level Two: Macros blocked from making Win32 API calls Restrict Microsoft Office macros, Maturity Level Three: Only macros from a sandboxed environment, a Trusted Location, or signed by a trusted publisher may execute
User application hardening User application hardening, Maturity Level One: Browsers do not process Java or web advertisements from the internet; Internet Explorer 11 disabled or removed; browser security settings unchangeable by users User application hardening, Maturity Level Two: Browsers, Office suites and PDF software hardened using ASD and vendor guidance, most restrictive taking precedence User application hardening, Maturity Level Three: .NET Framework 3.5 (including 2.0 and 3.0) and Windows PowerShell 2.0 disabled or removed; PowerShell in Constrained Language Mode
Regular backups Regular backups, Maturity Level One: Performed and retained in accordance with business criticality and business continuity requirements (ISM-1511) Regular backups, Maturity Level Two: Privileged accounts (excluding backup administrators) cannot access other users' backups, or modify or delete backups Regular backups, Maturity Level Three: Unprivileged and privileged accounts cannot access their own backups
New requirements start here Carries the level below Score yourself with the self-assessment, or look a term up in the glossary.

What the Essential Eight is

The Essential Eight is a set of eight baseline mitigation strategies published by the Australian Signals Directorate (ASD) through the Australian Cyber Security Centre. It is drawn from a longer list of 37 Strategies to Mitigate Cyber Security Incidents. The eight are the ones ASD rates "essential".

ASD presents the strategies as a baseline, not a guarantee:

While no set of mitigation strategies are guaranteed to protect against all cyber threats, organisations are recommended to implement eight essential mitigation strategies from the Strategies to mitigate cyber security incidents as a baseline.

ASD says the guidance draws on its experience responding to cyber security incidents, conducting vulnerability assessments and performing penetration testing across Australian government organisations.

The eight strategies

In ASD's own order and wording, from Essential Eight explained:

  1. Patch applications
  2. Patch operating systems
  3. Multi-factor authentication
  4. Restrict administrative privileges
  5. Application control
  6. Restrict Microsoft Office macros
  7. User application hardening
  8. Regular backups

Why the names and order differ

ASD uses two different orders and two different names across current documents.

The maturity model, above, lists application control fifth and calls strategy six "restrict Microsoft Office macros". The 2017 Strategies to Mitigate Cyber Security Incidents (still live, still cited in Commonwealth policy) lists application control first and calls the same strategy "configure Microsoft Office macro settings".

Both remain current ASD wording. When comparing documents, check which order and naming convention each one uses.

The eight also group into three of ASD's four outcome categories: prevent malware delivery and execution, limit the extent of cyber security incidents, and recover data and system availability. No "detect and respond" strategy is among the eight. The November 2023 model instead introduced centralised event logging as a cross-cutting requirement at Maturity Level Two.

The four maturity levels

Maturity is measured per strategy, on a scale of Zero to Three. Each level above Zero is defined by the level of adversary tradecraft it mitigates, not by the adversary's identity.

Level What it mitigates Who it typically suits
Zero Nothing. It signifies weaknesses in the organisation's overall cyber security posture. Not a target; it indicates significant control gaps.
One Adversaries using commodity tradecraft that is widely available: publicly available exploits against unpatched services, or credentials that were stolen, reused, brute forced or guessed. Looking for any victim rather than a specific one. Small to medium enterprises.
Two Adversaries with a modest step-up in capability, willing to invest more time in a target and in the effectiveness of their tools — including actively phishing credentials and circumventing weak multi-factor authentication. Large enterprises.
Three Adversaries who are adaptive and much less reliant on public tools, making swift use of exploits, socially engineering users into helping bypass controls, and stealing authentication tokens to circumvent even strong MFA. Critical infrastructure and high-threat environments.

Two rules determine how maturity is assessed:

Implement across all eight before going up. ASD says organisations should reach the same maturity level across all eight strategies before moving higher. The Assessment Process Guide adds that an organisation that has never demonstrated Maturity Level One should not begin an assessment against Level Two.

Your overall level is your least mature strategy. If one strategy sits at Level One and the other seven at Level Two, the organisation is at Level One. Within a strategy, every requirement must be met: if a single control is assessed ineffective, that maturity level cannot be claimed.

Risk acceptance without compensating controls does not preserve a maturity level. ASD states that declining an entire strategy on the basis of risk acceptance or risk transference results in Maturity Level Zero for that strategy and for the overall implementation.

Organisations may exceed a level's requirements. ASD says they "should not be penalised for implementing more robust security measures than specified for the given maturity level". For example, an organisation may adopt security keys even where the level would also accept one-time-password tokens.

The requirements matrix sets out every requirement at every level.

Is there Essential Eight certification?

No. Independent assessments are available commercially, but ASD does not offer Essential Eight certification.

ASD's maturity model says it in one sentence:

Finally, there is no requirement for organisations to have their Essential Eight implementation certified by an independent party.

ASD does not certify Essential Eight implementations, endorse or register Essential Eight assessors, or publish a list of approved products. Its maturity model FAQ answers "does ASD provide a list of approved products for implementing the Essential Eight?" with "No."

ASD designed an Essential Eight Assessment Course, delivered in partnership with TAFEcyber. Graduates are told that they "must not state or imply that they are endorsed by ASD or ACSC to conduct Essential Eight assessments."

An independent assessment may still be required by a government directive, regulator or contract. That is an assessment obligation, not ASD certification or endorsement of the assessor. The same distinction applies to IRAP; see why "IRAP certified" does not exist.

Who must implement it

Who Obligation Instrument
Non-corporate Commonwealth entities All eight to Maturity Level Two Protective Security Policy Framework (PSPF), in force since 1 July 2022; now Policy 14 of PSPF Release 2026
Corporate Commonwealth entities, Commonwealth companies Better practice, not mandatory PSPF applicability
Defence Industry Security Program (DISP) members Full Essential Eight at Maturity Level Two Defence Industry Security Program; "top four" assessments ended 15 November 2025
Critical infrastructure covered by the Security of Critical Infrastructure (SOCI) Act One of five frameworks — the Essential Eight at Maturity Level One is one option, alongside ISO 27001, NIST CSF, C2M2 and AESCSF CIRMP Rules 2023. A 2026 amendment raises nine asset classes to Level Two equivalents
WA government entities Maturity Level One minimum, continuing to Level Two where appropriate WA Government Cyber Security Policy 2024
NSW government Maturity Level One NSW Cyber Security Policy
Everyone else Recommended

Two recurring claims about these obligations need clarification.

There is no "PSPF Direction 002-2023". The register of Protective Security Directions contains no direction with that identifier. The obligation for non-corporate Commonwealth entities instead comes from an amendment to PSPF Policy 10, effective 1 July 2022. The same obligation now appears in Policy 14 of the current PSPF Release.

The Australian Prudential Regulation Authority's CPS 234 does not reference the Essential Eight. It is outcomes-based: it requires controls commensurate with the threat and leaves the choice of framework to the entity. The Essential Eight also does not appear in:

WA sets Maturity Level One, not the Commonwealth's Level Two, and its scope reaches the five WA universities and all Government Trading Enterprises, while local government is only encouraged. WA also mandates the ACSC "Further Five" on top of the Essential Eight.

Commonwealth implementation

Only 22% of Commonwealth entities reached overall Maturity Level Two in 2024–25, according to The Commonwealth Cyber Security Posture. That is up from 15% the year before but below the 25% recorded in 2023. The November 2023 update raised the assessment standard between those reporting periods. Multi-factor authentication had the lowest strategy result, with 34% at Level Two or higher.

Commonwealth adoption

Entities at Maturity Level Two or above, 2024–25

Non-corporate Commonwealth entities self-assessing at Maturity Level Two or above, by strategy. The median is 49%. Multi-factor authentication is the least adopted of the eight, not the most.

Percentage of Commonwealth entities at Maturity Level Two or above for each Essential Eight mitigation strategy, 2024–25.
Mitigation strategy Entities at Maturity Level Two or above
Restrict Microsoft Office macros 81%
Regular backups 67%
Patch operating systems 62%
User application hardening 49%
Application control 48%
Restrict administrative privileges 46%
Multi-factor authentication 34%
Patch applications Not recorded in our sources
Previous year Source: ASD, The Commonwealth Cyber Security Posture in 2025. Each figure is cited on the strategy page it belongs to.

Audit findings show a similar implementation gap. The Australian National Audit Office (ANAO) has found entities "relied on documenting policies and procedures to achieve compliance" rather than implementing the strategies, and that entities overstated their maturity in reporting.

The WA Auditor General audited ten entities. Five had not achieved Level One in any control. None achieved it in all. And seven of the ten overstated their self-assessed maturity.

Those findings support testing controls rather than relying on survey responses. ASD ranks evidence in four tiers, with "a policy or verbal statement of intent" at the bottom.

What changed in the last update

The current model is the November 2023 release. The previous release dates from November 2022, so older guidance may contain superseded timeframes and requirements.

Requirement Before November 2023
Patching online services, where a vulnerability is critical or has a working exploit No 48-hour tier 48 hours — and at every maturity level, including Level One
Patching office suites, browsers and extensions, email clients, PDF software and security products Within one month Within two weeks
Vulnerability scanning for that same software At least fortnightly At least weekly
Patching workstations, non-internet-facing servers and network devices Within two weeks Within one monthrelaxed, not tightened
Phishing-resistant multi-factor authentication Required at a higher level Required from Maturity Level Two
Which authentication factors count at Level One Unspecified Specified — biometrics, security questions and "Trusted Signals" are not valid
Centralised event logging Per-strategy only Required at Maturity Level Two as a cross-cutting measure
Microsoft Office macro execution logging Required Removed

Three changes deserve emphasis.

One requirement got easier. Operating system patching for workstations and non-internet-facing servers moved from two weeks to one month. ASD describes this as a counter-balance to tighter patching timeframes for higher-risk scenarios. Guidance describing the update as uniformly stricter does not reflect the changes document.

One requirement disappeared. Macro execution-event logging was removed because Windows lacks native support for it and incident responders advised ASD that the events provided limited benefit. A checklist that still requires it uses a pre-November 2023 model.

The MFA standard changed the reported result. Moving phishing-resistant MFA to Level Two raised the technical standard. ASD says the previous model had led to weaker implementations using biometrics, security questions or Trusted Signals. The proportion of Commonwealth entities at Level Two or above fell from 54% to 23%, then recovered to 34% by 2024–25.

ASD also aligned the model with Information Security Manual (ISM) control language and published machine-readable mappings for compliance tooling. That alignment supports the proposed move to a broader, ISM-grounded Essentials series.

The requirements matrix carries the current numbers in full.

The proposed Essentials series

On 15 June 2026 ASD announced a consultation on evolving the Essential Eight into a broader, ISM-grounded Essentials series, beginning with a chapter called Essentials for enterprise IT. Consultation closed on 12 July 2026.

ASD describes the proposal as an "evolution" and has published no retirement date. The claim that the Essential Eight will be retired by 2028 comes from a media interview, not an ASD publication.

We track the difference, with sources, on the Essentials transition page.

Where to go next

Sources

All ASD source documents →

Common questions

Is there such a thing as Essential Eight certification?

No. ASD does not require independent certification, endorse or register Essential Eight assessors, or publish a list of approved products. Graduates of its Assessment Course must not claim ASD or ACSC endorsement. A directive, regulator or contract may still require an independent assessment, but that is an assessment obligation rather than an ASD certification.

What is the difference between the current Essential Eight and the previous version?

November 2023 is the current release. It introduced 48-hour patching for critical or exploited vulnerabilities in online services. It also reduced the common application patching window to two weeks while relaxing workstation and non-internet-facing operating system patching to one month. Other changes include phishing-resistant MFA and centralised logging from Level Two, specified MFA factors at Level One, and the removal of macro execution-event logging.

Is the Essentials series the same as a new version of the Essential Eight?

No. A new Essential Eight version would revise the maturity model. The Essentials series is a proposed broader framework grounded in the Information Security Manual (ISM). Its first chapter would evolve the Essential Eight into Essentials for enterprise IT. Consultation ran from 15 June to 12 July 2026. ASD has published neither a draft nor a retirement date.

Has the Essential Eight been updated recently?

No. The current release is the Essential Eight Maturity Model of November 2023, last updated 27 November 2023 and unchanged since. Some satellite documents have moved — the FAQ, the Assessment Process Guide and the ISM mapping were all revised in October 2024 — but the model itself has not. ASD's own reporting confirms there were no updates to the maturity model in 2024–25.

Is the Essential Eight mandatory?

It depends. Non-corporate Commonwealth entities and Defence Industry Security Program members must reach Maturity Level Two. Covered critical infrastructure entities may use the Essential Eight as one of five frameworks under the Security of Critical Infrastructure (SOCI) rules. Western Australian and New South Wales government entities must reach at least Level One. It is otherwise generally recommended, although contracts can make it an obligation.

Which maturity level should we target?

Choose a level based on how attractive the organisation is to adversaries and the likely consequences of compromise. ASD suggests Level One for small to medium enterprises, Level Two for large enterprises, and Level Three for critical infrastructure providers and organisations in high-threat environments. It also warns that Level Three cannot stop every sufficiently determined adversary.

Does the Essential Eight cover cloud, mobile or operational technology?

Not by design. ASD designed the Essential Eight for internet-connected information technology networks. Its principles can be applied to enterprise mobility and operational technology, but ASD says the framework "was not designed for such purposes". The proposed Essentials series is intended to cover a broader range of environments.

  • Essential Eight requirements matrix

    What each Essential Eight strategy requires at Maturity Levels One, Two and Three: timeframes, scanning intervals and controls introduced at higher levels. Sourced line by line from the November 2023 maturity model.

  • Essential Eight self-assessment

    Twenty-four questions, three per mitigation strategy, one for each maturity level. Scored the way ASD scores: cumulative within a strategy, and capped at your weakest strategy overall.

  • Essential Eight glossary

    A sourced guide to terms used in ASD's Essential Eight publications and in the separate instruments that make the framework mandatory for some organisations.

Essential Eight

Need this assessed rather than explained?

We assess your maturity across all eight strategies, show you where you actually stand, and do the remediation. We are not an ASD-endorsed assessor — nobody is, because no such endorsement exists.