Essential 8 maturity levels, explained
The Essential 8 is the Australian Signals Directorate’s baseline of eight mitigation strategies for hardening against cyber attacks. The part that trips most teams up isn’t the eight strategies - it’s the maturity model bolted on top: ML0 to ML3. This guide explains what those levels actually mean, how each strategy is assessed against them, and how to work out - and prove - where you sit.
The eight strategies, quickly
The Essential 8 groups into three goals:
Prevent attacks
- Application control - only approved software can run.
- Patch applications - close known holes in apps and drivers fast.
- Configure Microsoft Office macro settings - block macros from the internet.
- User application hardening - lock down browsers, PDF readers and the like.
Limit the extent of attacks
- Restrict administrative privileges - fewer admins, tightly controlled.
- Patch operating systems - keep the OS current on a defined timeline.
- Multi-factor authentication - MFA on the accounts that matter.
Recover data and system availability
- Regular backups - tested, isolated, and actually restorable.
Each of the eight is assessed on its own. Your overall Essential 8 maturity is only as high as your weakest strategy - a common surprise for teams who assume strong MFA lifts the whole score.
The maturity model: ML0 to ML3
The ASD maturity levels describe how completely you’ve implemented each strategy, framed against the kind of adversary each level is meant to stop.
- Maturity Level 0 (ML0) - Not aligned. There are weaknesses in the strategy that a determined attacker could exploit. This is the honest starting point for most organisations on at least one strategy.
- Maturity Level 1 (ML1) - Partly aligned. Mitigates attackers using widely available, commodity tooling - the opportunistic end of the spectrum.
- Maturity Level 2 (ML2) - Mostly aligned. Mitigates attackers willing to invest more time and effort, and to work harder to evade detection.
- Maturity Level 3 (ML3) - Fully aligned. Mitigates adaptive attackers who are focused on a specific target and prepared to bypass the weaker controls.
The model is designed to be implemented as a package at each level, rather than cherry-picking the easy strategies. The ASD recommends most organisations target ML1 as a minimum, and step up to ML2 or ML3 based on the sensitivity of the data and the threat they realistically face.
How a strategy gets assessed
For each of the eight, an assessor checks specific, testable requirements at the level you’re claiming. Take patch applications at ML1 versus ML3: ML1 asks for patching of internet-facing services within two weeks (or 48 hours if an exploit exists); ML3 tightens the windows, widens the scope to all applications, and expects vulnerability scanning to confirm it. The strategy is the same; the rigour and evidence required climb with each level.
That’s why “we do MFA” isn’t a maturity level. The question is always: to what standard, across which systems, and can you show it?
Working out where you sit
The practical steps are the same whichever tool you use:
- Assess each strategy independently against the ML1, ML2 and ML3 requirements - not as a single overall guess.
- Take the lowest as your headline maturity, and record the per-strategy detail underneath.
- Attach evidence to each requirement - a config export, a patch report, a backup-restore test - so the score is defensible, not asserted.
- Track the gap to target so the next prioritised step is always obvious.
Done in spreadsheets, this is where Essential 8 programmes stall: eight strategies × three levels × a growing pile of evidence, re-tallied by hand every board cycle. Software built around the maturity model does the cross-referencing and keeps the score live - which is exactly what Cybereen’s maturity assessments are for.
Essential 8 and your other frameworks
If you also run ISO 27001, NIST CSF or an APRA obligation, most of the evidence overlaps. MFA satisfies an Essential 8 strategy, an ISO 27001 Annex A control and a NIST CSF outcome at once. Mapping those controls so one piece of evidence counts everywhere is the difference between doing the work once and doing it three times - the core idea behind multi-standard mapping.
The Essential 8 rewards discipline over heroics: pick a target level, get every strategy there, and keep the evidence current. The model makes the next step obvious - the hard part is just keeping score honestly.
Want to see your level? Explore Cybereen’s Essential 8 support or book a walkthrough.
See your frameworks - and their overlap - on one platform.
Book a walkthrough →