Essential Eight requirements matrix
What each Essential Eight strategy requires at Maturity Levels One, Two and Three: timeframes, scanning intervals and controls introduced at higher levels. Sourced line by line from the November 2023 maturity model.
Last checked against cyber.gov.au on . Current model: Essential Eight Maturity Model (November 2023).
On this page 10 sections
Essential Eight at a glance
Eight strategies, three maturity levels
Requirements are cumulative: Level Three means everything in Levels One and Two as well. Overall maturity is the lowest strategy, so one weak row caps the whole board. Every cell links to that requirement on the matrix.
This is the reference table behind the Essential Eight guide. Every requirement below is drawn from the Essential Eight Maturity Model (November 2023), which is the current release. There has been no revision since 27 November 2023.
Requirements are cumulative: Maturity Level Two includes everything at Level One unless a row supersedes it. A dash means the requirement does not exist at that level. Information Security Manual (ISM) control identifiers come from ASD's own Essential Eight to ISM mapping of October 2024.
Every row has a stable anchor, so you can link to a single requirement rather than to the page.
How to read a maturity level
Before the tables, three rules that change what the numbers mean.
A level is all-or-nothing within a strategy
From the Assessment Process Guide:
If one of the controls specified for a mitigation strategy is assessed as 'ineffective', the system owner cannot claim to have met the requirements for that maturity level.
There is no partial credit and no averaging inside a strategy.
Your overall level is your weakest strategy
If maturity differs between strategies, the organisation's overall maturity is the level of its least mature strategy. Seven strategies at Level Two and one at Level Zero is an organisation at Level Zero.
Declining a whole strategy scores Level Zero
ASD addresses risk acceptance directly:
Note, system owners that seek to use risk acceptance without compensating controls, or risk transference (e.g. by sourcing cyber insurance), as justification for not implementing an entire mitigation strategy, such as application control or multi-factor authentication, will be considered to have not protected themselves against a specific class of cyber threat and will subsequently be assessed as Maturity Level Zero for both that mitigation strategy and their overall Essential Eight implementation.
Compensating controls are permitted, but the bar is that they "provide an equivalent level of protection" to the specific requirement being compensated for. Exceptions must be documented, approved, and should not run beyond one year.
1. Patch applications
| Requirement | ML1 | ML2 | ML3 |
|---|---|---|---|
| Automated asset discovery (ISM-1807) | At least fortnightly | Fortnightly | Fortnightly |
| Vulnerability scanning — online services (ISM-1698) | At least daily | Daily | Daily |
| Scanning — office suites, browsers and extensions, email clients, PDF software, security products (ISM-1699) | At least weekly | Weekly | Weekly |
| Scanning — all other applications | — | At least fortnightly | Fortnightly |
| Patch online services — critical, or a working exploit exists (ISM-1876) | 48 hours | 48 hours | 48 hours |
| Patch online services — otherwise (ISM-1690) | Two weeks | Two weeks | Two weeks |
| Patch office suites, browsers, email clients, PDF and security products — critical or exploited | Two weeks | Two weeks | 48 hours |
| Patch office suites, browsers, email clients, PDF and security products — otherwise (ISM-1691) | Two weeks | Two weeks | Two weeks |
| Patch all other applications | — | One month | One month |
| Remove unsupported online services (ISM-1905) and unsupported productivity software including Adobe Flash Player (ISM-1704) | Required | Required | Required |
| Remove all other unsupported applications | — | — | Required |
What counts as "critical". ASD's guidance is that vendors assess a vulnerability as critical where, for example, "it facilitates authentication bypasses that grant privileged access or facilitates remote code execution without user interaction". Where a vendor gives no rating, ASD suggests considering the Common Vulnerability Scoring System (CVSS) score and the US Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities Catalog.
How the 48-hour requirement is triggered. For vulnerabilities rated critical by the vendor, the model measures 48 hours from the release of a patch, update or other vendor mitigation. When a working exploit is the trigger, ASD's FAQ says the requirement relates to "the announcement of a working exploit or that exploitation is already occurring, whichever occurs first".
Full detail: patch applications.
2. Patch operating systems
| Requirement | ML1 | ML2 | ML3 |
|---|---|---|---|
| Scanning — internet-facing servers and network devices (ISM-1701) | At least daily | Daily | Daily |
| Scanning — workstations, non-internet-facing servers and network devices (ISM-1702) | At least fortnightly | Fortnightly | Fortnightly |
| Scanning — drivers and firmware | — | — | Fortnightly |
| Patch internet-facing OS — critical or exploited / otherwise | 48 hours / two weeks | 48 hours / two weeks | 48 hours / two weeks |
| Patch workstation and non-internet-facing OS — critical or exploited | One month | One month | 48 hours |
| Patch workstation and non-internet-facing OS — otherwise | One month | One month | One month |
| Patch drivers and firmware — critical or exploited / otherwise | — | — | 48 hours / one month |
| Only the latest or previous release of operating systems is used | — | — | Required |
| Replace unsupported operating systems | Required | Required | Required |
Note the direction of travel. The November 2023 update relaxed the workstation and non-internet-facing timeframe from two weeks to one month. The associated scanning moved from weekly to fortnightly. ASD called this a counter-balance to the tightening elsewhere. Guides claiming this got stricter are quoting the pre-2023 model.
Full detail: patch operating systems.
3. Multi-factor authentication
| Requirement | ML1 | ML2 | ML3 |
|---|---|---|---|
| MFA for users of your own and third-party online services handling your sensitive data (ISM-1504, ISM-1679) | Required | Required | Required |
| MFA for customers of your online customer services handling sensitive customer data (ISM-1681) | Required | Required | Required |
| Factors: something users have and something they know, or something they have unlocked by something they know or are (ISM-1401) | Required | Required | Required |
| MFA for privileged and unprivileged users of systems | — | Required | Required |
| Phishing-resistant MFA for users of online services and of systems | — | Required | Required |
| Phishing-resistant MFA for customers | — | A phishing-resistant option is provided | Is phishing-resistant |
| MFA for users of data repositories | — | — | Required |
| Successful and unsuccessful MFA events centrally logged and protected from modification or deletion | — | Required | Required |
| Log analysis — internet-facing servers / all servers and workstations | — | Internet-facing | All |
| Incidents reported to the chief information security officer (CISO) and to ASD; incident response plan enacted | — | Required | Required |
What does not count as a factor. ASD is specific: security questions are not a recognised memorised secret; "Trusted Signals" cannot be a primary factor; and biometrics can only be a secondary factor unlocking something you have. Also, "remember this computer" fails the definition outright, because the token verifies the browser rather than the user. And multi-step authentication is not a substitute for multi-factor.
Phishing-resistant means smart cards, security keys, Windows Hello for Business or passkeys, not SMS or voice calls. ASD prefers FIDO2 Level 2 certification over Level 1.
Full detail: multi-factor authentication.
4. Restrict administrative privileges
| Requirement | ML1 | ML2 | ML3 |
|---|---|---|---|
| Privileged access requests validated when first requested (ISM-1507) | Required | Required | Required |
| Privileged access to systems, applications and data repositories disabled after 12 months unless revalidated; access to systems and applications also disabled after 45 days of inactivity | — | Required | Required |
| Dedicated privileged accounts, used solely for privileged duties (ISM-0445) | Required | Required | Required |
| Privileged accounts prevented from internet, email and web services — excluding those explicitly authorised to access online services (ISM-1175, ISM-1883) | Required | Required | Required |
| Separate privileged and unprivileged operating environments; unprivileged accounts cannot log on to privileged environments; privileged accounts other than local administrator accounts cannot log on to unprivileged environments (ISM-1380, ISM-1688, ISM-1689) | Required | Required | Required |
| Administrative activities via jump servers; privileged environments not virtualised within unprivileged ones | — | Required | Required |
| Break glass, local administrator and service account credentials long, unique, unpredictable and managed (≥30 characters) | — | Required | Required |
| Secure Admin Workstations and just-in-time administration | — | — | Required |
| Credential Guard, Remote Credential Guard, LSA protection and memory integrity enabled | — | — | Required |
| Privileged access and account/security-group management events centrally logged | — | Required | Required |
| Logs protected; relevant logs analysed; incidents reported to the CISO and ASD; incident response plan enacted | — | Internet-facing server logs | All server and workstation logs |
Online-service administration is an explicit exception. The internet restriction excludes accounts authorised to access online services. ASD's Assessment Process Guide gives privileged accounts used to manage cloud services as an example. The authorisation must be explicit and access limited to what the account needs.
Full detail: restrict administrative privileges.
5. Application control
| Requirement | ML1 | ML2 | ML3 |
|---|---|---|---|
| Implemented on workstations (ISM-0843) | Required | Required | Required |
| Implemented on internet-facing servers | — | Required | Required |
| Implemented on non-internet-facing servers | — | — | Required |
| Applied to user profiles and temp folders used by the OS, browsers and email clients (ISM-1870) / all other locations | User profiles and temp folders | All locations | All locations |
| Restricts executables, software libraries, scripts, installers, compiled HTML, HTML applications and control panel applets to an approved set (ISM-1657) | Required | Required | Required |
| Restricts execution of drivers | — | — | Required |
| Microsoft's recommended application blocklist / vulnerable driver blocklist | — | Application blocklist | Both |
| Rulesets validated annually or more frequently | — | Required | Required |
| Allowed and blocked execution events centrally logged | — | Required | Required |
| Logs protected; relevant logs analysed; incidents reported to the CISO and ASD; incident response plan enacted | — | Internet-facing server logs | All server and workstation logs |
What application control is not. ASD says none of the following satisfies the strategy:
- providing a portal for installing approved applications
- using web or email content filtering to stop downloads
- checking an application's reputation with a cloud service before execution
- using a next-generation firewall to identify traffic by application
Full detail: application control.
6. Restrict Microsoft Office macros
| Requirement | ML1 | ML2 | ML3 |
|---|---|---|---|
| Macros disabled for users without a demonstrated business requirement (ISM-1671) | Required | Required | Required |
| Macros in files originating from the internet are blocked (ISM-1488) | Required | Required | Required |
| Macro antivirus scanning enabled (ISM-1672) | Required | Required | Required |
| Macro security settings cannot be changed by users (ISM-1489) | Required | Required | Required |
| Macros blocked from making Win32 API calls | — | Required | Required |
| Only macros from a sandboxed environment, a Trusted Location, or signed by a trusted publisher may execute | — | — | Required |
| V3 signatures enforced; macros signed by untrusted publishers cannot be enabled via the Message Bar or Backstage View | — | — | Required |
| Macros checked for malicious code before signing or placement in Trusted Locations; publisher list validated annually | — | — | Required |
| Removed in the November 2023 update | |||
A removal, not an addition. ASD deleted the macro execution event logging requirement in the November 2023 update. It cited a lack of native support in Microsoft Windows, and "advice from incident responders and threat hunters that such events provide limited benefit". Any guide still listing it is quoting a superseded model.
Full detail: restrict Microsoft Office macros.
7. User application hardening
| Requirement | ML1 | ML2 | ML3 |
|---|---|---|---|
| Browsers do not process Java or web advertisements from the internet; Internet Explorer 11 disabled or removed; browser security settings unchangeable by users | Required | Required | Required |
| Browsers, Office suites and PDF software hardened using ASD and vendor guidance, most restrictive taking precedence | — | Required | Required |
| Office blocked from creating child processes, creating executable content, injecting code into other processes, and activating OLE packages | — | Required | Required |
| PDF software blocked from creating child processes; PDF and Office security settings unchangeable by users | — | Required | Required |
| PowerShell module logging, script block logging and transcription, plus command line process creation events, centrally logged | — | Required | Required |
| Logs protected; relevant logs analysed; incidents reported to the CISO and ASD; incident response plan enacted | — | Internet-facing server logs | All server and workstation logs |
| .NET Framework 3.5 (including 2.0 and 3.0) and Windows PowerShell 2.0 disabled or removed; PowerShell in Constrained Language Mode | — | — | Required |
Java is not JavaScript. ASD answers this directly: blocking web browsers from processing Java from the internet does not include JavaScript. This strategy also applies to servers, not only workstations.
Full detail: user application hardening.
8. Regular backups
| Requirement | ML1 | ML2 | ML3 |
|---|---|---|---|
| Performed and retained in accordance with business criticality and business continuity requirements (ISM-1511) | Required | Required | Required |
| Synchronised to enable restoration to a common point in time (ISM-1810); retained securely and resiliently (ISM-1811) | Required | Required | Required |
| Restoration tested as part of disaster recovery exercises (ISM-1515) | Required | Required | Required |
| Unprivileged accounts cannot access other users' backups (ISM-1812) or modify or delete any backup (ISM-1814) | Required | Required | Required |
| Privileged accounts (excluding backup administrators) cannot access other users' backups, or modify or delete backups | — | Required | Required |
| Unprivileged and privileged accounts cannot access their own backups | — | — | Required |
| Backup administrator accounts cannot modify or delete backups during the retention period | — | — | Required |
There is no retention number here. Not three months, not thirty days. The "at least three months" figure comes from the separate 2017 Strategies to Mitigate Cyber Security Incidents, which also describes backups as "stored disconnected". The current maturity model instead uses a business-criticality and continuity test.
Full detail: regular backups.
Evidence assessors evaluate
The requirements above are what must be true. The Assessment Process Guide governs how that gets tested, and it ranks evidence in four tiers:
| Tier | What it is |
|---|---|
| Excellent | Testing a control with a simulated activity designed to confirm it is in place and effective |
| Good | Reviewing the configuration of a system through the system's own interface |
| Fair | Reviewing a copy of a system's configuration — reports or screenshots |
| Poor | A policy, or a verbal statement of intent |
ASD is direct about the implication: "Conducting assessments using interviews, reports and screenshots will always be inferior to conducting assessments using scripts and tools."
Each control is then given one of seven outcomes: not assessed, effective, alternate control, ineffective, no visibility, not implemented, or not applicable.
Audit findings show the difference between documenting a control and demonstrating that it works. The ANAO found entities that "relied on documenting policies and procedures to achieve compliance" rather than implementing the strategies. The WA Auditor General found seven of ten audited entities had overstated their own maturity.
You can score yourself against these requirements, but the result is only as strong as the evidence used. ASD ranks tool-based testing above interviews, reports and statements of intent.
Sources
- ASD — Essential Eight maturity model — Last updated 27 November 2023
- ASD — Essential Eight maturity model changes — 27 November 2023
- ASD — Essential Eight maturity model FAQ — Last updated 28 October 2024
- ASD — Essential Eight assessment process guide — Last updated 2 October 2024
- ASD — Essential Eight maturity model and ISM mapping — October 2024
Common questions
How quickly do we have to patch under the Essential Eight?
It depends on the asset and vulnerability. Online services must be patched within 48 hours when a vulnerability is critical or a working exploit exists, and within two weeks otherwise, from Level One. Office suites, browsers, email clients, PDF software and security products have two weeks, tightening to 48 hours for critical or exploited vulnerabilities at Level Three. Other applications enter scope at Level Two with one month. Workstation and non-internet-facing operating systems have one month, tightening to 48 hours for critical or exploited vulnerabilities at Level Three.
Did the November 2023 update make everything stricter?
No. Patching for internet-facing and higher-risk scenarios was tightened, including the 48-hour rule and a move from one month to two weeks for common productivity software. Operating system patching for workstations, non-internet-facing servers and non-internet-facing network devices was relaxed from two weeks to one month, with scanning moved from weekly to fortnightly. The update also removed macro execution-event logging.
How long do we have to keep backups?
The maturity model sets no numeric retention period. Backups must be performed and retained "in accordance with business criticality and business continuity requirements". The commonly cited "at least three months" comes from the separate 2017 Strategies to Mitigate Cyber Security Incidents publication; it is not the current maturity-level requirement.
Is twelve-month log retention an Essential Eight requirement?
No. Retaining event logs in a searchable manner for at least 12 months is ISM control ISM-1989, which is tagged "Essential 8: N/A" in the Information Security Manual. The Essential Eight requires centralised collection, protection and analysis of event logs from Maturity Level Two, but sets no retention period.
Read next
-
Essential Eight to Essentials: a transition tracker
ASD has announced an evolution of the Essential Eight into a new Essentials series, starting with Essentials for enterprise IT. This page tracks what ASD has published against what has only been reported. The difference is being lost, and it changes what you should do.
-
Application control
Application control restricts execution to an organisation-approved set. ASD treats it as one of the most effective controls for preventing malicious code from running.
-
Multi-factor authentication
MFA was the lowest-performing Essential Eight strategy across Commonwealth entities in 2024–25. ASD is specific about which factors and implementations count.
Essential Eight
Need this assessed rather than explained?
We assess your maturity across all eight strategies, show you where you actually stand, and do the remediation. We are not an ASD-endorsed assessor — nobody is, because no such endorsement exists.