The ASD Essential Eight is Australia's baseline set of eight mitigation strategies, published by the Australian Signals Directorate and the Australian Cyber Security Centre, designed to make it significantly harder for attackers to compromise your systems. For Australian organisations in 2026 it has become the default yardstick for cyber resilience, referenced by regulators, insurers, boards and customers alike.
This guide explains what each of the eight strategies does, how the maturity levels from ML0 to ML3 work, who has to comply, and the practical steps involved in assessing and uplifting your posture. By the end you will understand what the framework asks of you and how to prove you are meeting it.
What the Essential Eight Is and Why It Exists
The Australian Signals Directorate maintains a longer catalogue of mitigation strategies, but the Essential Eight are the eight it considers the most effective baseline for most organisations. They were chosen because they counter the techniques adversaries use most often, from initial access through to maintaining a foothold and recovering after an incident.
The model is deliberately prioritised. Rather than presenting a sprawling checklist, it focuses effort on a small number of high-impact controls that, when implemented well together, dramatically reduce the likelihood and impact of a successful attack. This is why it has been adopted so widely as a shared language for cyber maturity across Australia.
The Eight Mitigation Strategies
The Essential Eight group into three goals: preventing malware from running, limiting the extent of any incident, and recovering data. Each strategy is meaningful on its own, but the real strength comes from implementing all eight in concert.
- Application control: Only approved applications are allowed to execute, which stops malicious or unapproved programs from running in the first place.
- Patch applications: Vulnerable applications, especially internet-facing ones, are updated quickly to close weaknesses before attackers can use them.
- Configure Microsoft Office macro settings: Macros are disabled or tightly restricted, because malicious macros remain a common delivery method for malware.
- User application hardening: Risky features in browsers and common applications, such as legacy scripting and unnecessary plugins, are disabled to shrink the attack surface.
- Restrict administrative privileges: Admin access is limited to those who genuinely need it, reducing the damage an attacker can do if they compromise an account.
- Patch operating systems: Operating systems are kept current and unsupported versions are removed, closing weaknesses at the platform level.
- Multi-factor authentication: Strong MFA is applied to important systems and remote access, making stolen passwords far less useful to an attacker.
- Regular backups: Important data is backed up, retained and tested for restoration, so the organisation can recover after ransomware or destructive attacks.
Together, the first four make it harder for malicious code to run, the next three limit how far an intruder can spread, and the last ensures you can recover when prevention fails.
Understanding Maturity Levels ML0 to ML3
The Essential Eight is measured against four maturity levels. Each level reflects the sophistication of the adversary it is designed to counter, and every strategy is assessed independently, so an organisation can be at different levels for different strategies.
| Maturity level | Adversary it counters | Typical posture |
|---|---|---|
| ML0 | Not applicable | Significant weaknesses in the overall posture that leave the organisation exposed. |
| ML1 | Opportunistic attackers using widely available techniques | Baseline hygiene that defeats common, untargeted attacks. |
| ML2 | Attackers investing more time and using modest tradecraft | Stronger controls that resist more capable, deliberate adversaries. |
| ML3 | Adaptive, well-resourced attackers | Robust, tightly managed controls that counter targeted campaigns. |
Choosing a target level is a risk decision. A small business might aim for ML1 across the board, while an agency handling sensitive information or a critical infrastructure operator may target ML2 or ML3. The important point is that maturity is not a single score but a profile across all eight strategies.
Who Must Comply
Compliance obligations vary depending on the type of organisation.
- Commonwealth non-corporate entities are mandated to implement the Essential Eight under the Protective Security Policy Framework, making it a requirement rather than a recommendation.
- State and territory agencies frequently adopt it through their own policies, sometimes with mandated target levels.
- Regulated sectors such as financial services and healthcare use it alongside obligations like APRA CPS 234, because it maps neatly to expectations around control effectiveness.
- Private organisations adopt it voluntarily because customers, insurers and boards increasingly expect a recognised baseline.
Even where it is not mandated, the Essential Eight has become a de facto standard. Demonstrating a credible maturity level is now a common requirement in tenders, cyber insurance applications and supply chain assurance.
How to Assess and Uplift Your Maturity
Improving your Essential Eight posture follows a clear cycle: understand where you are, decide where you need to be, close the gaps and prove the result.
- Assess honestly: Measure each strategy against your target level using the ACSC assessment guidance, reviewing configuration and gathering evidence. A structured maturity assessment gives you an accurate starting point.
- Prioritise the gaps: Focus first on the strategies that reduce the most risk for your environment, rather than trying to fix everything at once.
- Uplift deliberately: Implement changes in a planned way, testing that they work without breaking business processes.
- Validate the controls: Use technical testing to confirm controls behave as intended. This is where penetration testing and vulnerability assessments add real value, proving that MFA, application control and privilege restrictions actually hold up under attack.
- Maintain and review: Reassess regularly, because maturity can slip as systems change and new weaknesses emerge.
A frequent mistake is treating the Essential Eight as a one-off project. It is a program, not a milestone. Controls that were mature last year can drift as software is added, exceptions accumulate and staff change.
Common Pitfalls to Avoid
Many organisations invest effort in the Essential Eight yet still fall short at assessment time. The reasons are usually the same, and they are avoidable once you know what to watch for.
- Overstating maturity: Self-assessments often assume a control is fully implemented when exceptions or gaps mean it is not. Honest, evidence-based assessment protects you from a false sense of security.
- Focusing on the easy strategies: Multi-factor authentication and backups often progress quickly, while application control and privilege restriction lag because they are harder. A balanced maturity profile matters more than a few strong strategies.
- Ignoring the whole environment: Applying controls to some systems but not others leaves exploitable gaps. Maturity is only meaningful when applied consistently across the environment in scope.
- Forgetting to test recovery: Backups that have never been restored are a liability. Regular restoration testing is what turns a backup strategy into genuine resilience.
- Letting exceptions pile up: Temporary exceptions have a habit of becoming permanent. Reviewing and retiring them keeps your real maturity aligned with your stated maturity.
Avoiding these pitfalls is often the difference between an organisation that looks compliant on paper and one that is genuinely resilient when tested.
Where the Essential Eight Fits in a Broader Strategy
The Essential Eight is a powerful baseline, but it is not the whole picture. It is focused primarily on internet-connected Windows environments and does not, by itself, cover cloud configuration, application security, identity governance across every platform, or supply chain risk. The strongest programs treat it as a foundation, wrapped in broader risk management, monitoring and independent assurance.
If you want to understand your current maturity and build a practical uplift plan, our team of expert operators can help you assess each strategy, validate your controls and prioritise the work that matters most. Explore our maturity level assessments and penetration testing services, or get in touch to talk it through. You can also reach StrikeCyber on 1300 654 898.
Frequently asked questions
What is the ASD Essential Eight?
The ASD Essential Eight is a set of eight mitigation strategies published by the Australian Signals Directorate and the Australian Cyber Security Centre. It is a prioritised baseline designed to make it much harder for adversaries to compromise systems. The strategies cover application control, patching, macro settings, application hardening, admin privileges, operating system patching, multi-factor authentication and backups, and together they form Australia's most widely referenced security baseline.
Who has to comply with the Essential Eight?
Commonwealth non-corporate entities are mandated to implement the Essential Eight under the Protective Security Policy Framework. Beyond that, the model is voluntary but very widely adopted. State and territory agencies, universities, healthcare providers, financial services firms and many private organisations use it as their security benchmark, often because customers, insurers or boards expect a recognised baseline that maps clearly to real attack techniques.
What are the Essential Eight maturity levels?
There are four maturity levels, from ML0 to ML3. ML0 signals weaknesses in an organisation's overall posture. ML1 targets adversaries using widely available, opportunistic techniques. ML2 addresses attackers who invest more time and use modest tradecraft. ML3 counters adaptive, well-resourced adversaries. Organisations choose a target level based on the threats they face, and each strategy is assessed independently against that level.
Is the Essential Eight enough on its own?
The Essential Eight is a strong baseline, but it is not a complete security program. It focuses on preventing and limiting cyber incidents on internet-connected Windows environments, and it does not cover every risk such as cloud misconfiguration, application security, physical security or supply chain assurance. Treat it as a foundation to build on, supported by broader risk management, monitoring and regular independent testing.
How do we assess our Essential Eight maturity?
Assessment involves measuring each of the eight strategies against the requirements of your target maturity level, using the ACSC assessment guidance. This includes reviewing configuration, testing controls in practice and gathering evidence. Many organisations combine a formal maturity assessment with technical validation such as penetration testing, so they can show not only that controls are configured but that they genuinely resist attack.
How often should the Essential Eight be reviewed?
The Essential Eight should be reviewed regularly because environments and threats change constantly. A common rhythm is a formal maturity assessment at least annually, supported by continuous patching and monitoring, and a fresh review after any significant change such as a migration, a merger or a major new system. Regular review keeps evidence current for auditors and ensures maturity does not quietly slip over time.
