Menu
Contact us →
Cybereen / Resources / Essential 8
Essential 8

Essential 8 maturity levels, explained

By Cybereen · 11 July 2026

The Essential 8 is the Australian Signals Directorate’s baseline of eight mitigation strategies for hardening against cyber attacks. The part that trips most teams up isn’t the eight strategies - it’s the maturity model bolted on top: ML0 to ML3. This guide explains what those levels actually mean, how each strategy is assessed against them, and how to work out - and prove - where you sit.

The eight strategies, quickly

The Essential 8 groups into three goals:

Prevent attacks

  • Application control - only approved software can run.
  • Patch applications - close known holes in apps and drivers fast.
  • Configure Microsoft Office macro settings - block macros from the internet.
  • User application hardening - lock down browsers, PDF readers and the like.

Limit the extent of attacks

  • Restrict administrative privileges - fewer admins, tightly controlled.
  • Patch operating systems - keep the OS current on a defined timeline.
  • Multi-factor authentication - MFA on the accounts that matter.

Recover data and system availability

  • Regular backups - tested, isolated, and actually restorable.

Each of the eight is assessed on its own. Your overall Essential 8 maturity is only as high as your weakest strategy - a common surprise for teams who assume strong MFA lifts the whole score.

The maturity model: ML0 to ML3

The ASD maturity levels describe how completely you’ve implemented each strategy, framed against the kind of adversary each level is meant to stop.

  • Maturity Level 0 (ML0) - Not aligned. There are weaknesses in the strategy that a determined attacker could exploit. This is the honest starting point for most organisations on at least one strategy.
  • Maturity Level 1 (ML1) - Partly aligned. Mitigates attackers using widely available, commodity tooling - the opportunistic end of the spectrum.
  • Maturity Level 2 (ML2) - Mostly aligned. Mitigates attackers willing to invest more time and effort, and to work harder to evade detection.
  • Maturity Level 3 (ML3) - Fully aligned. Mitigates adaptive attackers who are focused on a specific target and prepared to bypass the weaker controls.

The model is designed to be implemented as a package at each level, rather than cherry-picking the easy strategies. The ASD recommends most organisations target ML1 as a minimum, and step up to ML2 or ML3 based on the sensitivity of the data and the threat they realistically face.

How a strategy gets assessed

For each of the eight, an assessor checks specific, testable requirements at the level you’re claiming. Take patch applications at ML1 versus ML3: ML1 asks for patching of internet-facing services within two weeks (or 48 hours if an exploit exists); ML3 tightens the windows, widens the scope to all applications, and expects vulnerability scanning to confirm it. The strategy is the same; the rigour and evidence required climb with each level.

That’s why “we do MFA” isn’t a maturity level. The question is always: to what standard, across which systems, and can you show it?

Working out where you sit

The practical steps are the same whichever tool you use:

  1. Assess each strategy independently against the ML1, ML2 and ML3 requirements - not as a single overall guess.
  2. Take the lowest as your headline maturity, and record the per-strategy detail underneath.
  3. Attach evidence to each requirement - a config export, a patch report, a backup-restore test - so the score is defensible, not asserted.
  4. Track the gap to target so the next prioritised step is always obvious.

Done in spreadsheets, this is where Essential 8 programmes stall: eight strategies × three levels × a growing pile of evidence, re-tallied by hand every board cycle. Software built around the maturity model does the cross-referencing and keeps the score live - which is exactly what Cybereen’s maturity assessments are for.

Essential 8 and your other frameworks

If you also run ISO 27001, NIST CSF or an APRA obligation, most of the evidence overlaps. MFA satisfies an Essential 8 strategy, an ISO 27001 Annex A control and a NIST CSF outcome at once. Mapping those controls so one piece of evidence counts everywhere is the difference between doing the work once and doing it three times - the core idea behind multi-standard mapping.

The Essential 8 rewards discipline over heroics: pick a target level, get every strategy there, and keep the evidence current. The model makes the next step obvious - the hard part is just keeping score honestly.

Want to see your level? Explore Cybereen’s Essential 8 support or book a walkthrough.

See your frameworks - and their overlap - on one platform.

Book a walkthrough →