The Essential Eight, explained
The Essential Eight is ASD's baseline set of eight cyber security mitigation strategies for internet-connected corporate IT. This hub explains what each strategy requires, who must implement it, and what ASD has announced about the proposed Essentials series.
Last checked against cyber.gov.au on . Current model: Essential Eight Maturity Model (November 2023).
On this page 8 sections
Essential Eight at a glance
Eight strategies, three maturity levels
Requirements are cumulative: Level Three means everything in Levels One and Two as well. Overall maturity is the lowest strategy, so one weak row caps the whole board. Every cell links to that requirement on the matrix.
What the Essential Eight is
The Essential Eight is a set of eight baseline mitigation strategies published by the Australian Signals Directorate (ASD) through the Australian Cyber Security Centre. It is drawn from a longer list of 37 Strategies to Mitigate Cyber Security Incidents. The eight are the ones ASD rates "essential".
ASD presents the strategies as a baseline, not a guarantee:
While no set of mitigation strategies are guaranteed to protect against all cyber threats, organisations are recommended to implement eight essential mitigation strategies from the Strategies to mitigate cyber security incidents as a baseline.
ASD says the guidance draws on its experience responding to cyber security incidents, conducting vulnerability assessments and performing penetration testing across Australian government organisations.
The eight strategies
In ASD's own order and wording, from Essential Eight explained:
- Patch applications
- Patch operating systems
- Multi-factor authentication
- Restrict administrative privileges
- Application control
- Restrict Microsoft Office macros
- User application hardening
- Regular backups
Why the names and order differ
ASD uses two different orders and two different names across current documents.
The maturity model, above, lists application control fifth and calls strategy six "restrict Microsoft Office macros". The 2017 Strategies to Mitigate Cyber Security Incidents (still live, still cited in Commonwealth policy) lists application control first and calls the same strategy "configure Microsoft Office macro settings".
Both remain current ASD wording. When comparing documents, check which order and naming convention each one uses.
The eight also group into three of ASD's four outcome categories: prevent malware delivery and execution, limit the extent of cyber security incidents, and recover data and system availability. No "detect and respond" strategy is among the eight. The November 2023 model instead introduced centralised event logging as a cross-cutting requirement at Maturity Level Two.
The four maturity levels
Maturity is measured per strategy, on a scale of Zero to Three. Each level above Zero is defined by the level of adversary tradecraft it mitigates, not by the adversary's identity.
| Level | What it mitigates | Who it typically suits |
|---|---|---|
| Zero | Nothing. It signifies weaknesses in the organisation's overall cyber security posture. | Not a target; it indicates significant control gaps. |
| One | Adversaries using commodity tradecraft that is widely available: publicly available exploits against unpatched services, or credentials that were stolen, reused, brute forced or guessed. Looking for any victim rather than a specific one. | Small to medium enterprises. |
| Two | Adversaries with a modest step-up in capability, willing to invest more time in a target and in the effectiveness of their tools — including actively phishing credentials and circumventing weak multi-factor authentication. | Large enterprises. |
| Three | Adversaries who are adaptive and much less reliant on public tools, making swift use of exploits, socially engineering users into helping bypass controls, and stealing authentication tokens to circumvent even strong MFA. | Critical infrastructure and high-threat environments. |
Two rules determine how maturity is assessed:
Implement across all eight before going up. ASD says organisations should reach the same maturity level across all eight strategies before moving higher. The Assessment Process Guide adds that an organisation that has never demonstrated Maturity Level One should not begin an assessment against Level Two.
Your overall level is your least mature strategy. If one strategy sits at Level One and the other seven at Level Two, the organisation is at Level One. Within a strategy, every requirement must be met: if a single control is assessed ineffective, that maturity level cannot be claimed.
Risk acceptance without compensating controls does not preserve a maturity level. ASD states that declining an entire strategy on the basis of risk acceptance or risk transference results in Maturity Level Zero for that strategy and for the overall implementation.
Organisations may exceed a level's requirements. ASD says they "should not be penalised for implementing more robust security measures than specified for the given maturity level". For example, an organisation may adopt security keys even where the level would also accept one-time-password tokens.
The requirements matrix sets out every requirement at every level.
Is there Essential Eight certification?
No. Independent assessments are available commercially, but ASD does not offer Essential Eight certification.
ASD's maturity model says it in one sentence:
Finally, there is no requirement for organisations to have their Essential Eight implementation certified by an independent party.
ASD does not certify Essential Eight implementations, endorse or register Essential Eight assessors, or publish a list of approved products. Its maturity model FAQ answers "does ASD provide a list of approved products for implementing the Essential Eight?" with "No."
ASD designed an Essential Eight Assessment Course, delivered in partnership with TAFEcyber. Graduates are told that they "must not state or imply that they are endorsed by ASD or ACSC to conduct Essential Eight assessments."
An independent assessment may still be required by a government directive, regulator or contract. That is an assessment obligation, not ASD certification or endorsement of the assessor. The same distinction applies to IRAP; see why "IRAP certified" does not exist.
Who must implement it
| Who | Obligation | Instrument |
|---|---|---|
| Non-corporate Commonwealth entities | All eight to Maturity Level Two | Protective Security Policy Framework (PSPF), in force since 1 July 2022; now Policy 14 of PSPF Release 2026 |
| Corporate Commonwealth entities, Commonwealth companies | Better practice, not mandatory | PSPF applicability |
| Defence Industry Security Program (DISP) members | Full Essential Eight at Maturity Level Two | Defence Industry Security Program; "top four" assessments ended 15 November 2025 |
| Critical infrastructure covered by the Security of Critical Infrastructure (SOCI) Act | One of five frameworks — the Essential Eight at Maturity Level One is one option, alongside ISO 27001, NIST CSF, C2M2 and AESCSF | CIRMP Rules 2023. A 2026 amendment raises nine asset classes to Level Two equivalents |
| WA government entities | Maturity Level One minimum, continuing to Level Two where appropriate | WA Government Cyber Security Policy 2024 |
| NSW government | Maturity Level One | NSW Cyber Security Policy |
| Everyone else | Recommended | — |
Two recurring claims about these obligations need clarification.
There is no "PSPF Direction 002-2023". The register of Protective Security Directions contains no direction with that identifier. The obligation for non-corporate Commonwealth entities instead comes from an amendment to PSPF Policy 10, effective 1 July 2022. The same obligation now appears in Policy 14 of the current PSPF Release.
The Australian Prudential Regulation Authority's CPS 234 does not reference the Essential Eight. It is outcomes-based: it requires controls commensurate with the threat and leaves the choice of framework to the entity. The Essential Eight also does not appear in:
- APRA CPG 234, the practice guide to CPS 234
- APRA CPS 230 and CPG 230, on operational risk
- The Cyber Security Act 2024
WA sets Maturity Level One, not the Commonwealth's Level Two, and its scope reaches the five WA universities and all Government Trading Enterprises, while local government is only encouraged. WA also mandates the ACSC "Further Five" on top of the Essential Eight.
Commonwealth implementation
Only 22% of Commonwealth entities reached overall Maturity Level Two in 2024–25, according to The Commonwealth Cyber Security Posture. That is up from 15% the year before but below the 25% recorded in 2023. The November 2023 update raised the assessment standard between those reporting periods. Multi-factor authentication had the lowest strategy result, with 34% at Level Two or higher.
Commonwealth adoption
Entities at Maturity Level Two or above, 2024–25
Non-corporate Commonwealth entities self-assessing at Maturity Level Two or above, by strategy. The median is 49%. Multi-factor authentication is the least adopted of the eight, not the most.
| Mitigation strategy | Entities at Maturity Level Two or above |
|---|---|
| Restrict Microsoft Office macros | 81% was 68% (2023–24) |
| Regular backups | 67% was 70% (2022–23) |
| Patch operating systems | 62% was 51% (2023–24) |
| User application hardening | 49% was 37% (2023–24) |
| Application control | 48% was 36% (2023–24) |
| Restrict administrative privileges | 46% was 31% (2023–24) |
| Multi-factor authentication | 34% was 23% (2023–24) |
| Patch applications | Not recorded in our sources |
Audit findings show a similar implementation gap. The Australian National Audit Office (ANAO) has found entities "relied on documenting policies and procedures to achieve compliance" rather than implementing the strategies, and that entities overstated their maturity in reporting.
The WA Auditor General audited ten entities. Five had not achieved Level One in any control. None achieved it in all. And seven of the ten overstated their self-assessed maturity.
Those findings support testing controls rather than relying on survey responses. ASD ranks evidence in four tiers, with "a policy or verbal statement of intent" at the bottom.
What changed in the last update
The current model is the November 2023 release. The previous release dates from November 2022, so older guidance may contain superseded timeframes and requirements.
| Requirement | Before | November 2023 |
|---|---|---|
| Patching online services, where a vulnerability is critical or has a working exploit | No 48-hour tier | 48 hours — and at every maturity level, including Level One |
| Patching office suites, browsers and extensions, email clients, PDF software and security products | Within one month | Within two weeks |
| Vulnerability scanning for that same software | At least fortnightly | At least weekly |
| Patching workstations, non-internet-facing servers and network devices | Within two weeks | Within one month — relaxed, not tightened |
| Phishing-resistant multi-factor authentication | Required at a higher level | Required from Maturity Level Two |
| Which authentication factors count at Level One | Unspecified | Specified — biometrics, security questions and "Trusted Signals" are not valid |
| Centralised event logging | Per-strategy only | Required at Maturity Level Two as a cross-cutting measure |
| Microsoft Office macro execution logging | Required | Removed |
Three changes deserve emphasis.
One requirement got easier. Operating system patching for workstations and non-internet-facing servers moved from two weeks to one month. ASD describes this as a counter-balance to tighter patching timeframes for higher-risk scenarios. Guidance describing the update as uniformly stricter does not reflect the changes document.
One requirement disappeared. Macro execution-event logging was removed because Windows lacks native support for it and incident responders advised ASD that the events provided limited benefit. A checklist that still requires it uses a pre-November 2023 model.
The MFA standard changed the reported result. Moving phishing-resistant MFA to Level Two raised the technical standard. ASD says the previous model had led to weaker implementations using biometrics, security questions or Trusted Signals. The proportion of Commonwealth entities at Level Two or above fell from 54% to 23%, then recovered to 34% by 2024–25.
ASD also aligned the model with Information Security Manual (ISM) control language and published machine-readable mappings for compliance tooling. That alignment supports the proposed move to a broader, ISM-grounded Essentials series.
The requirements matrix carries the current numbers in full.
The proposed Essentials series
On 15 June 2026 ASD announced a consultation on evolving the Essential Eight into a broader, ISM-grounded Essentials series, beginning with a chapter called Essentials for enterprise IT. Consultation closed on 12 July 2026.
ASD describes the proposal as an "evolution" and has published no retirement date. The claim that the Essential Eight will be retired by 2028 comes from a media interview, not an ASD publication.
We track the difference, with sources, on the Essentials transition page.
Where to go next
- Requirements matrix — every strategy at every maturity level, with the current timeframes.
- Glossary and sources — 53 sourced terms explained in plain language, plus the primary ASD documents used by this hub and the separate instruments that establish compliance obligations. Start here when a document uses unfamiliar terminology.
- Essentials transition tracker — what ASD has and has not said.
- Knowledge quiz — ten random questions drawn from a bank of forty, with an immediate explanation after every answer.
- Self-assessment — score yourself against the published requirements.
- If you build software — why the Essential Eight says nothing about the software you ship, and what does.
Sources
- ASD — Essential Eight
- ASD — Essential Eight explained — Last updated 27 November 2023
- ASD — Essential Eight maturity model — Last updated 27 November 2023
- ASD — Consultation on evolution of Essential Eight — 15 June 2026
- Home Affairs — PSPF policy amendment, information security
Common questions
Is there such a thing as Essential Eight certification?
No. ASD does not require independent certification, endorse or register Essential Eight assessors, or publish a list of approved products. Graduates of its Assessment Course must not claim ASD or ACSC endorsement. A directive, regulator or contract may still require an independent assessment, but that is an assessment obligation rather than an ASD certification.
What is the difference between the current Essential Eight and the previous version?
November 2023 is the current release. It introduced 48-hour patching for critical or exploited vulnerabilities in online services. It also reduced the common application patching window to two weeks while relaxing workstation and non-internet-facing operating system patching to one month. Other changes include phishing-resistant MFA and centralised logging from Level Two, specified MFA factors at Level One, and the removal of macro execution-event logging.
Is the Essentials series the same as a new version of the Essential Eight?
No. A new Essential Eight version would revise the maturity model. The Essentials series is a proposed broader framework grounded in the Information Security Manual (ISM). Its first chapter would evolve the Essential Eight into Essentials for enterprise IT. Consultation ran from 15 June to 12 July 2026. ASD has published neither a draft nor a retirement date.
Has the Essential Eight been updated recently?
No. The current release is the Essential Eight Maturity Model of November 2023, last updated 27 November 2023 and unchanged since. Some satellite documents have moved — the FAQ, the Assessment Process Guide and the ISM mapping were all revised in October 2024 — but the model itself has not. ASD's own reporting confirms there were no updates to the maturity model in 2024–25.
Is the Essential Eight mandatory?
It depends. Non-corporate Commonwealth entities and Defence Industry Security Program members must reach Maturity Level Two. Covered critical infrastructure entities may use the Essential Eight as one of five frameworks under the Security of Critical Infrastructure (SOCI) rules. Western Australian and New South Wales government entities must reach at least Level One. It is otherwise generally recommended, although contracts can make it an obligation.
Which maturity level should we target?
Choose a level based on how attractive the organisation is to adversaries and the likely consequences of compromise. ASD suggests Level One for small to medium enterprises, Level Two for large enterprises, and Level Three for critical infrastructure providers and organisations in high-threat environments. It also warns that Level Three cannot stop every sufficiently determined adversary.
Does the Essential Eight cover cloud, mobile or operational technology?
Not by design. ASD designed the Essential Eight for internet-connected information technology networks. Its principles can be applied to enterprise mobility and operational technology, but ASD says the framework "was not designed for such purposes". The proposed Essentials series is intended to cover a broader range of environments.
Read next
-
Essential Eight requirements matrix
What each Essential Eight strategy requires at Maturity Levels One, Two and Three: timeframes, scanning intervals and controls introduced at higher levels. Sourced line by line from the November 2023 maturity model.
-
Essential Eight self-assessment
Twenty-four questions, three per mitigation strategy, one for each maturity level. Scored the way ASD scores: cumulative within a strategy, and capped at your weakest strategy overall.
-
Essential Eight glossary
A sourced guide to terms used in ASD's Essential Eight publications and in the separate instruments that make the framework mandatory for some organisations.
Essential Eight
Need this assessed rather than explained?
We assess your maturity across all eight strategies, show you where you actually stand, and do the remediation. We are not an ASD-endorsed assessor — nobody is, because no such endorsement exists.