Maturity Level 1 means all eight of ASD’s mitigation strategies are implemented to a baseline that counters adversaries using widely available tradecraft. All eight — your overall maturity is the lowest level you achieve across the set, so seven strong strategies and one missing leaves you below Maturity Level 1.
The Essential Eight is published by the Australian Signals Directorate (ASD) through the Australian Cyber Security Centre (ACSC) at cyber.gov.au. It’s eight mitigation strategies, each assessed at Maturity Levels 0 to 3. Maturity Level 1 is the first rung that counts for anything: in ASD’s terms, it’s designed to counter adversaries using widely available tradecraft — commodity tools, known exploits, opportunistic targeting.
Two things define the level. First, it covers all eight strategies at once — there’s no partial credit. Second, each strategy has to be genuinely implemented and demonstrable, not written into a policy document. An assessor asks to see the control working, not the intention.
Here’s what Maturity Level 1 expects of each strategy, kept at the level ASD’s model actually operates at.
| Mitigation strategy | What Maturity Level 1 expects | What the evidence looks like |
|---|---|---|
| Application control | Unapproved executables are blocked from running on workstations — a technical control, not an acceptable-use policy | The ruleset itself, plus a test showing an unapproved binary failing to run |
| Patch applications | Vulnerability scanning is in place and application patches are applied within defined timeframes, fastest for internet-facing services | Scan output and patch records that line up against the timeframes |
| Configure Microsoft Office macro settings | Macros disabled for users without a demonstrated business need; macros in files from the internet blocked; users can’t change the settings | The policy configuration and the list of users with an approved macro need |
| User application hardening | Browsers and common applications configured to cut attack surface, with settings users can’t switch back off | The hardening configuration, deployed and enforced fleet-wide |
| Restrict administrative privileges | Requests for privileged access are validated; privileged accounts are separate from everyday accounts and aren’t used for email and web browsing | A privileged-account register and the validation records behind each grant |
| Patch operating systems | Scanning and OS patching within defined timeframes; operating systems out of vendor support are replaced | Scan output, patch records, and no unsupported OS in the fleet |
| Multi-factor authentication | MFA on remote access and internet-facing services, including third-party services holding your data | Coverage records showing who authenticates with what, service by service |
| Regular backups | Important data, software and settings backed up on a schedule set by business criticality, with restoration tested | The backup schedule and a dated, successful restore test |
Read the table honestly and one pattern stands out: half of Maturity Level 1 is operational, not project work. Patching, backups, privilege reviews and MFA coverage aren’t things you implement once — they’re things you run weekly, and the evidence trail is the running. Continuous vulnerability scanning and patch tracking alone carries two of the eight strategies.
There’s no single central provider for Essential Eight assessment. In practice it’s a mix: self-assessment against ASD’s published assessment process guide, IRAP assessors where formal independent assurance is required, and private consultancies and MSPs for everything in between. Which one you need depends on who’s asking — a tender clause, a customer questionnaire, or your own board.
Whoever assesses, the method is the same: controls get tested, not asserted. “We patch monthly” isn’t a finding; a scan result showing nothing outside the timeframe is. Build the evidence trail as you implement and assessment becomes a formality. Build the controls without the trail and you’ll do the work twice.
One more mechanic worth knowing before you claim anything: the maturity level you report is the lowest level across the eight strategies. That single rule shapes every sensible uplift plan — you bring the weakest strategy up before polishing the strongest one.
Treating Maturity Level 1 as “basic hygiene we’ve probably already got.” Most organisations that assume this pass five or six strategies and fail on application control and administrative privileges — the two that need deliberate engineering rather than good habits. Because the overall level is set by the weakest strategy, those two failures put the whole organisation at Maturity Level 0, which is exactly what goes on the tender response. The fix isn’t heroic. It’s finding the two or three weak strategies early and sequencing them first, instead of discovering them in an assessment you’d told a customer you’d pass.
Tools hand you a to-do list. We do the list — and run the security behind it. For Maturity Level 1 that means the ongoing half of the model — vulnerability management, patch visibility, MFA coverage, backup verification — runs on our platform with the evidence accumulating as a by-product. The engineering half (application control, privilege restructuring, hardening) gets scoped and done, not listed. Commercials are scoped to the engagement; a readiness call gives you the gap and the sequence.
Is Essential Eight Maturity Level 1 mandatory?
Not by law for most private organisations. Non-corporate Commonwealth entities are mandated to reach Maturity Level 2 under the Protective Security Policy Framework, and suppliers pick up requirements through contract and tender clauses — see Essential Eight for government suppliers.
Can we self-assess Maturity Level 1?
Yes. ASD publishes an Essential Eight assessment process guide on cyber.gov.au. Where a customer or tender wants independent assurance, that comes from an IRAP assessor or a private consultancy — there’s no single central provider.
We've done seven of the eight strategies. Are we Maturity Level 1?
No. Your overall maturity is the lowest level achieved across the eight strategies. Seven strategies at Maturity Level 1 and one at Maturity Level 0 makes you Maturity Level 0 overall.
How long does it take to reach Maturity Level 1?
It depends entirely on the gap. Patching and MFA are often partway there already; application control is usually the longest pole because it needs an inventory of what’s allowed to run before anything can be blocked. A readiness call scopes the actual distance.
Is Maturity Level 1 enough?
ASD’s framing: Maturity Level 1 counters adversaries using widely available tradecraft — opportunistic attacks, not someone targeting you specifically. If a contract, regulator or your own threat picture points higher, look at Maturity Level 2.