Maturity Level 2 counters adversaries with modestly more capability — attackers willing to invest time in a specific target. Across all eight strategies that means tighter patch timeframes, broader MFA coverage, stricter privilege management and a heavier evidence load. Cost depends on your gap and your environment, so an uplift is scoped rather than quoted.
ASD’s maturity model, published at cyber.gov.au, frames each level around an adversary. Maturity Level 1 counters adversaries using widely available tradecraft. Maturity Level 2 counters adversaries with modestly more capability — attackers who invest more time in a target and more care in their tooling. The eight strategies are unchanged; the test applied to them is harder.
That framing defines the uplift. Against an opportunist, patching within the month is often sufficient. Against an adversary working on your organisation specifically, the window between a vulnerability being published and closed is the attack surface. Maturity Level 2 tightens the clocks and widens the coverage.
| Mitigation strategy | What changes at Maturity Level 2 |
|---|---|
| Application control | Coverage broadens beyond the Maturity Level 1 baseline; rulesets are maintained and reviewed, and blocked executions leave a record |
| Patch applications | Tighter timeframes across a wider set of applications, with more frequent scanning to evidence it |
| Configure Microsoft Office macro settings | Fewer users permitted macros, tighter limits on what approved macros can do, and recorded events when one is blocked |
| User application hardening | Hardening extends across more applications, aligned to published hardening guidance rather than defaults |
| Restrict administrative privileges | Privileged access is re-validated on a schedule, unused access is removed, and privileged activity becomes visible |
| Patch operating systems | Tighter OS patch timeframes with more frequent scanning, fastest for internet-facing systems |
| Multi-factor authentication | MFA extends to more users and systems, including privileged users, and weaker second factors cease to be acceptable as maturity rises |
| Regular backups | Access to backups is restricted so an attacker with a foothold cannot reach them, and restoration testing becomes more rigorous |
The table stays at the level of posture deliberately. Control-by-control detail lives in ASD’s model and shifts with each update, so the current version at cyber.gov.au governs any plan committed to it. The consistent elements are tighter timeframes, broader coverage, better records, and event visibility feeding toward the centralised logging the model expects as maturity climbs.
Published ranges for Maturity Level 2 uplift lose accuracy as soon as they meet a specific environment. The drivers, however, are consistent.
The gap. An organisation already at a solid Maturity Level 1 is tightening existing controls. An organisation that assumed Maturity Level 1 and did not have it is running two uplifts. The assessment that measures this costs a fraction of the cost of an incorrect assumption.
Fleet diversity and legacy. Tighter patch timeframes are inexpensive on a standardised, cloud-managed fleet and expensive across mixed hardware, unmanaged devices and applications that break when their host is patched. Legacy is the most reliable cost multiplier in Essential Eight work.
The operational load. Maturity Level 2 sets a pace rather than a milestone. The faster patch cycle, the privilege re-validation, the MFA enrolment edge cases and the backup access reviews recur monthly, with records. Whether that load is met by headcount or a provider, it is the cost line most budgets omit.
Evidence and assessment. The level has to be demonstrable. Assessment is a mix of self-assessment, IRAP assessors and private consultancies, with no single central provider, and the evidence trail that makes any of them fast has to be built into the operation rather than reconstructed before the visit.
The strategies do not change between levels, so the uplift reads as incremental on paper while the operating model turns out to be the substantive project. Maturity Level 1 can survive on good quarterly habits. Maturity Level 2 runs on a clock: patch windows measured against scan results, privilege grants that expire unless re-validated, MFA coverage that has to hold every time someone new starts.
Organisations that budget for the configuration change and not the ongoing cadence reach the level once, drift out of it within months, and discover the drift in front of an assessor.
The cadence is the product. Our platform runs the recurring load Maturity Level 2 creates — continuous vulnerability scanning and patch tracking, MFA and privilege coverage visibility, backup checks — with the evidence trail generated as the work happens rather than assembled before an assessment. Commercials are scoped to the engagement, because the cost of Maturity Level 2 is set by your gap and your environment, which is what a readiness call measures.
How much does Maturity Level 2 cost?
There is no fixed figure. Cost is driven by the size of your gap, the diversity of your fleet, how much legacy sits in it, and the ongoing operational load the level demands. A price quoted before the environment is assessed is an estimate without inputs. An uplift is scoped, then priced.
Who is required to reach Maturity Level 2?
Non-corporate Commonwealth entities are mandated to reach it under the Protective Security Policy Framework. Suppliers to government increasingly meet the same bar through contract and tender clauses — the mandate applies to the entities, and suppliers inherit it commercially.
What's the biggest jump from Maturity Level 1 to 2?
Timeframes and proof. The controls remain the same eight strategies. What changes is how fast you have to act, how far coverage extends, and how much evidence you need that it happened on schedule.
Do we need to buy new tools to reach Maturity Level 2?
Often not. Much of the uplift is configuring and operating what you already own — tighter patch cycles, broader MFA enrolment, privilege reviews. Where tooling gaps exist, a gap assessment identifies them before anything is purchased.
Can we skip Maturity Level 1 and go straight to 2?
ASD’s guidance is to bring all eight strategies to the same maturity level before pushing any of them higher. Going straight to Maturity Level 2 means delivering both levels in one program, which is legitimate provided it is planned and costed that way.