Maturity Level 2 counters adversaries with modestly more capability — attackers willing to invest time in a specific target. Across all eight strategies that means tighter patch timeframes, broader MFA coverage, stricter privilege management and a heavier evidence load. There’s no fixed price: cost depends on your gap and environment, so an honest uplift is scoped, not quoted.
ASD’s maturity model, published at cyber.gov.au, frames each level around an adversary. Maturity Level 1 counters adversaries using widely available tradecraft. Maturity Level 2 counters adversaries with modestly more capability — attackers who invest more time in a target and more care in their tooling. Same eight strategies, harder test.
That framing tells you what the uplift actually is. Against an opportunist, “patched within the month” is often enough. Against someone watching your organisation specifically, the window between a vulnerability being published and you closing it is the attack surface. Maturity Level 2 tightens the clocks and widens the coverage.
| Mitigation strategy | What changes at Maturity Level 2 |
|---|---|
| Application control | Coverage broadens beyond the Maturity Level 1 baseline; rulesets are maintained and reviewed, and blocked executions leave a record |
| Patch applications | Tighter timeframes across a wider set of applications, with more frequent scanning to prove it |
| Configure Microsoft Office macro settings | Fewer users permitted macros, tighter limits on what approved macros can do, and events you can point to when one is blocked |
| User application hardening | Hardening extends across more applications, aligned to published hardening guidance rather than defaults |
| Restrict administrative privileges | Privileged access is re-validated on a schedule, unused access is removed, and privileged activity becomes visible |
| Patch operating systems | Tighter OS patch timeframes with more frequent scanning, fastest for internet-facing systems |
| Multi-factor authentication | MFA extends to more users and systems — including privileged users — and weaker second factors stop being acceptable as maturity rises |
| Regular backups | Access to backups is restricted so an attacker with a foothold can’t reach them, and restoration testing gets more rigorous |
We’ve kept that table at the level of posture deliberately. The control-by-control detail lives in ASD’s model and shifts with each update — read the current version at cyber.gov.au before you commit a plan to it. What doesn’t shift is the shape: tighter timeframes, broader coverage, better records, and event visibility feeding toward the centralised logging the model expects as maturity climbs.
We won’t put a number on this page, because there isn’t one — and the ranges you’ll find elsewhere collapse the moment they meet a real environment. What we can do is name the drivers, because they’re consistent.
The gap. An organisation already sitting at a solid Maturity Level 1 is tightening screws. An organisation that assumed it was at Maturity Level 1 and wasn’t is running two uplifts. The assessment that measures this costs a fraction of what guessing wrong does.
Fleet diversity and legacy. Tighter patch timeframes are cheap on a standardised, cloud-managed fleet and expensive across mixed hardware, unmanaged devices and that one application that breaks when you patch its host. Legacy is the single most reliable cost multiplier in Essential Eight work.
The operational load. Maturity Level 2 is a pace, not a milestone. Someone has to run the faster patch cycle, the privilege re-validation, the MFA enrolment edge cases, the backup access reviews — every month, with records. Whether that’s headcount or a provider, it’s the cost line most budgets miss.
Evidence and assessment. The level has to be demonstrable. Assessment itself is a mix of self-assessment, IRAP assessors and private consultancies — there’s no single central provider — and the evidence trail that makes any of them fast has to be built into the operation, not reconstructed before the visit.
Reading Maturity Level 2 as “Maturity Level 1, plus a bit.” The strategies don’t change, so the uplift looks incremental on paper — and then the operating model turns out to be the real project. Maturity Level 1 can survive on good quarterly habits. Maturity Level 2 runs on a clock: patch windows measured against scan results, privilege grants that expire unless re-validated, MFA coverage that has to hold every time someone new starts. Organisations that budget for the configuration change and not for the ongoing cadence reach the level once, drift out of it within months, and find out in front of an assessor.
The cadence is the product. Our platform runs the recurring load Maturity Level 2 creates — continuous vulnerability scanning and patch tracking, MFA and privilege coverage visibility, backup checks — with the evidence trail generated as the work happens, not assembled before an assessment. Commercials are scoped to the engagement, because the honest cost of Maturity Level 2 is your gap and your environment — which is exactly what a readiness call measures.
How much does Maturity Level 2 cost?
There’s no honest fixed figure. Cost is driven by the size of your gap, the diversity of your fleet, how much legacy sits in it, and the ongoing operational load the level demands. Anyone quoting a number before assessing your environment is guessing — an uplift is scoped, then priced.
Who is required to reach Maturity Level 2?
Non-corporate Commonwealth entities are mandated to reach it under the Protective Security Policy Framework. Suppliers to government increasingly meet the same bar through contract and tender clauses — the mandate applies to the entities; suppliers inherit it commercially.
What's the single biggest jump from Maturity Level 1 to 2?
Timeframes and proof. The controls are mostly the same eight strategies — what changes is how fast you have to act, how far coverage extends, and how much evidence you need that it all happened on schedule.
Do we need to buy new tools to reach Maturity Level 2?
Often not. Much of the uplift is configuring and operating what you already own — tighter patch cycles, broader MFA enrolment, privilege reviews. Where tooling gaps do exist, a gap assessment finds them before you spend anything.
Can we skip Maturity Level 1 and go straight to 2?
ASD’s guidance is to bring all eight strategies to the same maturity level before pushing any of them higher. Going ‘straight to Maturity Level 2’ really means doing both levels in one program — legitimate, but plan and cost it that way.