ComplianceEssential EightMaturity Level 1
Essential Eight · Maturity Level 1

Essential Eight Maturity Level 1 Control Requirements

The Short Answer

Maturity Level 1 means all eight of ASD’s mitigation strategies are implemented to a baseline that counters adversaries using widely available tradecraft. Overall maturity is the lowest level achieved across the set, so seven strong strategies and one missing leaves an organisation below Maturity Level 1.

What Maturity Level 1 requires

The Essential Eight is published by the Australian Signals Directorate (ASD) through the Australian Cyber Security Centre (ACSC) at cyber.gov.au. It comprises eight mitigation strategies, each assessed at Maturity Levels 0 to 3. In ASD’s terms, Maturity Level 1 is designed to counter adversaries using widely available tradecraft — commodity tools, known exploits, opportunistic targeting.

Two properties define the level. It covers all eight strategies at once, with no partial credit. And each strategy has to be implemented and demonstrable rather than documented, because an assessor examines the control in operation.

The table below sets out what Maturity Level 1 expects of each strategy, at the level ASD’s model operates at.

Mitigation strategy What Maturity Level 1 expects What the evidence looks like
Application control Unapproved executables are blocked from running on workstations, as a technical control rather than an acceptable-use policy The ruleset itself, plus a test showing an unapproved binary failing to run
Patch applications Vulnerability scanning is in place and application patches are applied within defined timeframes, fastest for internet-facing services Scan output and patch records that line up against the timeframes
Configure Microsoft Office macro settings Macros disabled for users without a demonstrated business need; macros in files from the internet blocked; users unable to change the settings The policy configuration and the list of users with an approved macro need
User application hardening Browsers and common applications configured to reduce attack surface, with settings users cannot switch back off The hardening configuration, deployed and enforced fleet-wide
Restrict administrative privileges Requests for privileged access are validated; privileged accounts are separate from everyday accounts and are not used for email and web browsing A privileged-account register and the validation records behind each grant
Patch operating systems Scanning and OS patching within defined timeframes; operating systems out of vendor support are replaced Scan output, patch records, and no unsupported OS in the fleet
Multi-factor authentication MFA on remote access and internet-facing services, including third-party services holding your data Coverage records showing who authenticates with what, service by service
Regular backups Important data, software and settings backed up on a schedule set by business criticality, with restoration tested The backup schedule and a dated, successful restore test

Half of Maturity Level 1 is recurring operational work rather than project work. Patching, backups, privilege reviews and MFA coverage are run weekly, and the running is what produces the evidence trail. Continuous vulnerability scanning and patch tracking alone carries two of the eight strategies.

How Maturity Level 1 is assessed

There is no single central provider for Essential Eight assessment. In practice it is a mix of self-assessment against ASD’s published assessment process guide, IRAP assessors where formal independent assurance is required, and private consultancies and MSPs in between. Which one applies depends on who is asking — a tender clause, a customer questionnaire, or your own board.

The method is the same in each case: controls are tested rather than asserted. A statement that patching happens monthly carries no weight; a scan result showing nothing outside the timeframe does. Evidence built during implementation makes assessment a formality, and controls built without it require the work to be repeated.

One mechanic shapes every uplift plan: the maturity level you report is the lowest level across the eight strategies. The weakest strategy comes up before the strongest one is polished.

Maturity Level 1 is not baseline hygiene

Most organisations that assume they already meet it pass five or six strategies and fail on application control and administrative privileges — the two that require deliberate engineering rather than good habits. Because the overall level is set by the weakest strategy, those two failures produce an organisational rating of Maturity Level 0, which is the figure that goes into the tender response.

The remedy is sequencing. Identify the two or three weak strategies at the start of the program and address them first, rather than discovering them during an assessment you have already told a customer you would pass.

How Secure60 handles this

Secure60 runs the uplift and operates the controls behind it. For Maturity Level 1 the recurring half of the model — vulnerability management, patch visibility, MFA coverage, backup verification — runs on our platform, with the evidence accumulating as a by-product. The engineering half (application control, privilege restructuring, hardening) is scoped and delivered. Commercials are scoped to the engagement; a readiness call gives you the gap and the sequence.

Frequently Asked Questions

Is Essential Eight Maturity Level 1 mandatory?

Not by law for most private organisations. Non-corporate Commonwealth entities are mandated to reach Maturity Level 2 under the Protective Security Policy Framework, and suppliers acquire requirements through contract and tender clauses — see Essential Eight for government suppliers.

Can we self-assess Maturity Level 1?

Yes. ASD publishes an Essential Eight assessment process guide on cyber.gov.au. Where a customer or tender requires independent assurance, that comes from an IRAP assessor or a private consultancy — there is no single central provider.

We've done seven of the eight strategies. Are we Maturity Level 1?

No. Overall maturity is the lowest level achieved across the eight strategies. Seven strategies at Maturity Level 1 and one at Maturity Level 0 produces an overall rating of Maturity Level 0.

How long does it take to reach Maturity Level 1?

It depends on the gap. Patching and MFA are often partway there already; application control usually takes longest, because it requires an inventory of what is allowed to run before anything can be blocked. A readiness call scopes the distance.

Is Maturity Level 1 enough?

In ASD’s framing, Maturity Level 1 counters adversaries using widely available tradecraft — opportunistic attacks rather than targeted ones. Where a contract, regulator or your own threat picture points higher, see Maturity Level 2.

Establish Current Maturity Level Against ASD Criteria

A readiness call maps the environment against all eight strategies and identifies which are holding the organisation below Maturity Level 1.

30 days, every feature switched on. No credit card.