Nano Solutions

Essential Eight requirements matrix

What each Essential Eight strategy requires at Maturity Levels One, Two and Three: timeframes, scanning intervals and controls introduced at higher levels. Sourced line by line from the November 2023 maturity model.

Last checked against cyber.gov.au on . Current model: Essential Eight Maturity Model (November 2023).

On this page 10 sections
  1. How to read a maturity level
  2. 1. Patch applications
  3. 2. Patch operating systems
  4. 3. Multi-factor authentication
  5. 4. Restrict administrative privileges
  6. 5. Application control
  7. 6. Restrict Microsoft Office macros
  8. 7. User application hardening
  9. 8. Regular backups
  10. Evidence assessors evaluate

Essential Eight at a glance

Eight strategies, three maturity levels

Requirements are cumulative: Level Three means everything in Levels One and Two as well. Overall maturity is the lowest strategy, so one weak row caps the whole board. Every cell links to that requirement on the matrix.

What each of the eight mitigation strategies requires at each maturity level.
Mitigation strategy ML1 Maturity Level One ML2 Maturity Level Two ML3 Maturity Level Three
Patch applications Patch applications, Maturity Level One: Patch online services — critical, or a working exploit exists (ISM-1876) Patch applications, Maturity Level Two: Patch all other applications Patch applications, Maturity Level Three: Patch office suites, browsers, email clients, PDF and security products — critical or exploited
Patch operating systems Patch operating systems, Maturity Level One: Patch internet-facing OS — critical or exploited / otherwise Patch operating systems, Maturity Level Two: Carries Maturity Level One No new requirements Patch operating systems, Maturity Level Three: Patch drivers and firmware — critical or exploited / otherwise
Multi-factor authentication Multi-factor authentication, Maturity Level One: MFA for users of your own and third-party online services handling your sensitive data (ISM-1504, ISM-1679) Multi-factor authentication, Maturity Level Two: MFA for privileged and unprivileged users of systems Multi-factor authentication, Maturity Level Three: MFA for users of data repositories
Restrict administrative privileges Restrict administrative privileges, Maturity Level One: Privileged access requests validated when first requested (ISM-1507) Restrict administrative privileges, Maturity Level Two: Administrative activities via jump servers; privileged environments not virtualised within unprivileged ones Restrict administrative privileges, Maturity Level Three: Secure Admin Workstations and just-in-time administration
Application control Application control, Maturity Level One: Implemented on workstations (ISM-0843) Application control, Maturity Level Two: Implemented on internet-facing servers Application control, Maturity Level Three: Implemented on non-internet-facing servers
Restrict Microsoft Office macros Restrict Microsoft Office macros, Maturity Level One: Macros disabled for users without a demonstrated business requirement (ISM-1671) Restrict Microsoft Office macros, Maturity Level Two: Macros blocked from making Win32 API calls Restrict Microsoft Office macros, Maturity Level Three: Only macros from a sandboxed environment, a Trusted Location, or signed by a trusted publisher may execute
User application hardening User application hardening, Maturity Level One: Browsers do not process Java or web advertisements from the internet; Internet Explorer 11 disabled or removed; browser security settings unchangeable by users User application hardening, Maturity Level Two: Browsers, Office suites and PDF software hardened using ASD and vendor guidance, most restrictive taking precedence User application hardening, Maturity Level Three: .NET Framework 3.5 (including 2.0 and 3.0) and Windows PowerShell 2.0 disabled or removed; PowerShell in Constrained Language Mode
Regular backups Regular backups, Maturity Level One: Performed and retained in accordance with business criticality and business continuity requirements (ISM-1511) Regular backups, Maturity Level Two: Privileged accounts (excluding backup administrators) cannot access other users' backups, or modify or delete backups Regular backups, Maturity Level Three: Unprivileged and privileged accounts cannot access their own backups
New requirements start here Carries the level below Score yourself with the self-assessment, or look a term up in the glossary.

This is the reference table behind the Essential Eight guide. Every requirement below is drawn from the Essential Eight Maturity Model (November 2023), which is the current release. There has been no revision since 27 November 2023.

Requirements are cumulative: Maturity Level Two includes everything at Level One unless a row supersedes it. A dash means the requirement does not exist at that level. Information Security Manual (ISM) control identifiers come from ASD's own Essential Eight to ISM mapping of October 2024.

Every row has a stable anchor, so you can link to a single requirement rather than to the page.

How to read a maturity level

Before the tables, three rules that change what the numbers mean.

A level is all-or-nothing within a strategy

From the Assessment Process Guide:

If one of the controls specified for a mitigation strategy is assessed as 'ineffective', the system owner cannot claim to have met the requirements for that maturity level.

There is no partial credit and no averaging inside a strategy.

If maturity differs between strategies, the organisation's overall maturity is the level of its least mature strategy. Seven strategies at Level Two and one at Level Zero is an organisation at Level Zero.

Declining a whole strategy scores Level Zero

ASD addresses risk acceptance directly:

Note, system owners that seek to use risk acceptance without compensating controls, or risk transference (e.g. by sourcing cyber insurance), as justification for not implementing an entire mitigation strategy, such as application control or multi-factor authentication, will be considered to have not protected themselves against a specific class of cyber threat and will subsequently be assessed as Maturity Level Zero for both that mitigation strategy and their overall Essential Eight implementation.

Compensating controls are permitted, but the bar is that they "provide an equivalent level of protection" to the specific requirement being compensated for. Exceptions must be documented, approved, and should not run beyond one year.

1. Patch applications

RequirementML1ML2ML3
Automated asset discovery (ISM-1807)At least fortnightlyFortnightlyFortnightly
Vulnerability scanning — online services (ISM-1698)At least dailyDailyDaily
Scanning — office suites, browsers and extensions, email clients, PDF software, security products (ISM-1699)At least weeklyWeeklyWeekly
Scanning — all other applicationsAt least fortnightlyFortnightly
Patch online services — critical, or a working exploit exists (ISM-1876)48 hours48 hours48 hours
Patch online services — otherwise (ISM-1690)Two weeksTwo weeksTwo weeks
Patch office suites, browsers, email clients, PDF and security products — critical or exploitedTwo weeksTwo weeks48 hours
Patch office suites, browsers, email clients, PDF and security products — otherwise (ISM-1691)Two weeksTwo weeksTwo weeks
Patch all other applicationsOne monthOne month
Remove unsupported online services (ISM-1905) and unsupported productivity software including Adobe Flash Player (ISM-1704)RequiredRequiredRequired
Remove all other unsupported applicationsRequired

What counts as "critical". ASD's guidance is that vendors assess a vulnerability as critical where, for example, "it facilitates authentication bypasses that grant privileged access or facilitates remote code execution without user interaction". Where a vendor gives no rating, ASD suggests considering the Common Vulnerability Scoring System (CVSS) score and the US Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities Catalog.

How the 48-hour requirement is triggered. For vulnerabilities rated critical by the vendor, the model measures 48 hours from the release of a patch, update or other vendor mitigation. When a working exploit is the trigger, ASD's FAQ says the requirement relates to "the announcement of a working exploit or that exploitation is already occurring, whichever occurs first".

Full detail: patch applications.

2. Patch operating systems

RequirementML1ML2ML3
Scanning — internet-facing servers and network devices (ISM-1701)At least dailyDailyDaily
Scanning — workstations, non-internet-facing servers and network devices (ISM-1702)At least fortnightlyFortnightlyFortnightly
Scanning — drivers and firmwareFortnightly
Patch internet-facing OS — critical or exploited / otherwise48 hours / two weeks48 hours / two weeks48 hours / two weeks
Patch workstation and non-internet-facing OS — critical or exploitedOne monthOne month48 hours
Patch workstation and non-internet-facing OS — otherwiseOne monthOne monthOne month
Patch drivers and firmware — critical or exploited / otherwise48 hours / one month
Only the latest or previous release of operating systems is usedRequired
Replace unsupported operating systemsRequiredRequiredRequired

Note the direction of travel. The November 2023 update relaxed the workstation and non-internet-facing timeframe from two weeks to one month. The associated scanning moved from weekly to fortnightly. ASD called this a counter-balance to the tightening elsewhere. Guides claiming this got stricter are quoting the pre-2023 model.

Full detail: patch operating systems.

3. Multi-factor authentication

RequirementML1ML2ML3
MFA for users of your own and third-party online services handling your sensitive data (ISM-1504, ISM-1679)RequiredRequiredRequired
MFA for customers of your online customer services handling sensitive customer data (ISM-1681)RequiredRequiredRequired
Factors: something users have and something they know, or something they have unlocked by something they know or are (ISM-1401)RequiredRequiredRequired
MFA for privileged and unprivileged users of systemsRequiredRequired
Phishing-resistant MFA for users of online services and of systemsRequiredRequired
Phishing-resistant MFA for customersA phishing-resistant option is providedIs phishing-resistant
MFA for users of data repositoriesRequired
Successful and unsuccessful MFA events centrally logged and protected from modification or deletionRequiredRequired
Log analysis — internet-facing servers / all servers and workstationsInternet-facingAll
Incidents reported to the chief information security officer (CISO) and to ASD; incident response plan enactedRequiredRequired

What does not count as a factor. ASD is specific: security questions are not a recognised memorised secret; "Trusted Signals" cannot be a primary factor; and biometrics can only be a secondary factor unlocking something you have. Also, "remember this computer" fails the definition outright, because the token verifies the browser rather than the user. And multi-step authentication is not a substitute for multi-factor.

Phishing-resistant means smart cards, security keys, Windows Hello for Business or passkeys, not SMS or voice calls. ASD prefers FIDO2 Level 2 certification over Level 1.

Full detail: multi-factor authentication.

4. Restrict administrative privileges

RequirementML1ML2ML3
Privileged access requests validated when first requested (ISM-1507)RequiredRequiredRequired
Privileged access to systems, applications and data repositories disabled after 12 months unless revalidated; access to systems and applications also disabled after 45 days of inactivityRequiredRequired
Dedicated privileged accounts, used solely for privileged duties (ISM-0445)RequiredRequiredRequired
Privileged accounts prevented from internet, email and web services — excluding those explicitly authorised to access online services (ISM-1175, ISM-1883)RequiredRequiredRequired
Separate privileged and unprivileged operating environments; unprivileged accounts cannot log on to privileged environments; privileged accounts other than local administrator accounts cannot log on to unprivileged environments (ISM-1380, ISM-1688, ISM-1689)RequiredRequiredRequired
Administrative activities via jump servers; privileged environments not virtualised within unprivileged onesRequiredRequired
Break glass, local administrator and service account credentials long, unique, unpredictable and managed (≥30 characters)RequiredRequired
Secure Admin Workstations and just-in-time administrationRequired
Credential Guard, Remote Credential Guard, LSA protection and memory integrity enabledRequired
Privileged access and account/security-group management events centrally loggedRequiredRequired
Logs protected; relevant logs analysed; incidents reported to the CISO and ASD; incident response plan enactedInternet-facing server logsAll server and workstation logs

Online-service administration is an explicit exception. The internet restriction excludes accounts authorised to access online services. ASD's Assessment Process Guide gives privileged accounts used to manage cloud services as an example. The authorisation must be explicit and access limited to what the account needs.

Full detail: restrict administrative privileges.

5. Application control

RequirementML1ML2ML3
Implemented on workstations (ISM-0843)RequiredRequiredRequired
Implemented on internet-facing serversRequiredRequired
Implemented on non-internet-facing serversRequired
Applied to user profiles and temp folders used by the OS, browsers and email clients (ISM-1870) / all other locationsUser profiles and temp foldersAll locationsAll locations
Restricts executables, software libraries, scripts, installers, compiled HTML, HTML applications and control panel applets to an approved set (ISM-1657)RequiredRequiredRequired
Restricts execution of driversRequired
Microsoft's recommended application blocklist / vulnerable driver blocklistApplication blocklistBoth
Rulesets validated annually or more frequentlyRequiredRequired
Allowed and blocked execution events centrally loggedRequiredRequired
Logs protected; relevant logs analysed; incidents reported to the CISO and ASD; incident response plan enactedInternet-facing server logsAll server and workstation logs

What application control is not. ASD says none of the following satisfies the strategy:

  • providing a portal for installing approved applications
  • using web or email content filtering to stop downloads
  • checking an application's reputation with a cloud service before execution
  • using a next-generation firewall to identify traffic by application

Full detail: application control.

6. Restrict Microsoft Office macros

RequirementML1ML2ML3
Macros disabled for users without a demonstrated business requirement (ISM-1671)RequiredRequiredRequired
Macros in files originating from the internet are blocked (ISM-1488)RequiredRequiredRequired
Macro antivirus scanning enabled (ISM-1672)RequiredRequiredRequired
Macro security settings cannot be changed by users (ISM-1489)RequiredRequiredRequired
Macros blocked from making Win32 API callsRequiredRequired
Only macros from a sandboxed environment, a Trusted Location, or signed by a trusted publisher may executeRequired
V3 signatures enforced; macros signed by untrusted publishers cannot be enabled via the Message Bar or Backstage ViewRequired
Macros checked for malicious code before signing or placement in Trusted Locations; publisher list validated annuallyRequired
Macro execution event loggingRemoved in the November 2023 update

A removal, not an addition. ASD deleted the macro execution event logging requirement in the November 2023 update. It cited a lack of native support in Microsoft Windows, and "advice from incident responders and threat hunters that such events provide limited benefit". Any guide still listing it is quoting a superseded model.

Full detail: restrict Microsoft Office macros.

7. User application hardening

RequirementML1ML2ML3
Browsers do not process Java or web advertisements from the internet; Internet Explorer 11 disabled or removed; browser security settings unchangeable by usersRequiredRequiredRequired
Browsers, Office suites and PDF software hardened using ASD and vendor guidance, most restrictive taking precedenceRequiredRequired
Office blocked from creating child processes, creating executable content, injecting code into other processes, and activating OLE packagesRequiredRequired
PDF software blocked from creating child processes; PDF and Office security settings unchangeable by usersRequiredRequired
PowerShell module logging, script block logging and transcription, plus command line process creation events, centrally loggedRequiredRequired
Logs protected; relevant logs analysed; incidents reported to the CISO and ASD; incident response plan enactedInternet-facing server logsAll server and workstation logs
.NET Framework 3.5 (including 2.0 and 3.0) and Windows PowerShell 2.0 disabled or removed; PowerShell in Constrained Language ModeRequired

Java is not JavaScript. ASD answers this directly: blocking web browsers from processing Java from the internet does not include JavaScript. This strategy also applies to servers, not only workstations.

Full detail: user application hardening.

8. Regular backups

RequirementML1ML2ML3
Performed and retained in accordance with business criticality and business continuity requirements (ISM-1511)RequiredRequiredRequired
Synchronised to enable restoration to a common point in time (ISM-1810); retained securely and resiliently (ISM-1811)RequiredRequiredRequired
Restoration tested as part of disaster recovery exercises (ISM-1515)RequiredRequiredRequired
Unprivileged accounts cannot access other users' backups (ISM-1812) or modify or delete any backup (ISM-1814)RequiredRequiredRequired
Privileged accounts (excluding backup administrators) cannot access other users' backups, or modify or delete backupsRequiredRequired
Unprivileged and privileged accounts cannot access their own backupsRequired
Backup administrator accounts cannot modify or delete backups during the retention periodRequired

There is no retention number here. Not three months, not thirty days. The "at least three months" figure comes from the separate 2017 Strategies to Mitigate Cyber Security Incidents, which also describes backups as "stored disconnected". The current maturity model instead uses a business-criticality and continuity test.

Full detail: regular backups.

Evidence assessors evaluate

The requirements above are what must be true. The Assessment Process Guide governs how that gets tested, and it ranks evidence in four tiers:

Tier What it is
Excellent Testing a control with a simulated activity designed to confirm it is in place and effective
Good Reviewing the configuration of a system through the system's own interface
Fair Reviewing a copy of a system's configuration — reports or screenshots
Poor A policy, or a verbal statement of intent

ASD is direct about the implication: "Conducting assessments using interviews, reports and screenshots will always be inferior to conducting assessments using scripts and tools."

Each control is then given one of seven outcomes: not assessed, effective, alternate control, ineffective, no visibility, not implemented, or not applicable.

Audit findings show the difference between documenting a control and demonstrating that it works. The ANAO found entities that "relied on documenting policies and procedures to achieve compliance" rather than implementing the strategies. The WA Auditor General found seven of ten audited entities had overstated their own maturity.

You can score yourself against these requirements, but the result is only as strong as the evidence used. ASD ranks tool-based testing above interviews, reports and statements of intent.

Sources

All ASD source documents →

Common questions

How quickly do we have to patch under the Essential Eight?

It depends on the asset and vulnerability. Online services must be patched within 48 hours when a vulnerability is critical or a working exploit exists, and within two weeks otherwise, from Level One. Office suites, browsers, email clients, PDF software and security products have two weeks, tightening to 48 hours for critical or exploited vulnerabilities at Level Three. Other applications enter scope at Level Two with one month. Workstation and non-internet-facing operating systems have one month, tightening to 48 hours for critical or exploited vulnerabilities at Level Three.

Did the November 2023 update make everything stricter?

No. Patching for internet-facing and higher-risk scenarios was tightened, including the 48-hour rule and a move from one month to two weeks for common productivity software. Operating system patching for workstations, non-internet-facing servers and non-internet-facing network devices was relaxed from two weeks to one month, with scanning moved from weekly to fortnightly. The update also removed macro execution-event logging.

How long do we have to keep backups?

The maturity model sets no numeric retention period. Backups must be performed and retained "in accordance with business criticality and business continuity requirements". The commonly cited "at least three months" comes from the separate 2017 Strategies to Mitigate Cyber Security Incidents publication; it is not the current maturity-level requirement.

Is twelve-month log retention an Essential Eight requirement?

No. Retaining event logs in a searchable manner for at least 12 months is ISM control ISM-1989, which is tagged "Essential 8: N/A" in the Information Security Manual. The Essential Eight requires centralised collection, protection and analysis of event logs from Maturity Level Two, but sets no retention period.

  • Essential Eight to Essentials: a transition tracker

    ASD has announced an evolution of the Essential Eight into a new Essentials series, starting with Essentials for enterprise IT. This page tracks what ASD has published against what has only been reported. The difference is being lost, and it changes what you should do.

  • Application control

    Application control restricts execution to an organisation-approved set. ASD treats it as one of the most effective controls for preventing malicious code from running.

  • Multi-factor authentication

    MFA was the lowest-performing Essential Eight strategy across Commonwealth entities in 2024–25. ASD is specific about which factors and implementations count.

Essential Eight

Need this assessed rather than explained?

We assess your maturity across all eight strategies, show you where you actually stand, and do the remediation. We are not an ASD-endorsed assessor — nobody is, because no such endorsement exists.