ComplianceEssential Eight
Essential Eight

The Essential Eight: Scope and Applicability

The Short Answer

The Essential Eight is a set of eight technical mitigation strategies published by the ACSC, part of the Australian Signals Directorate, and measured at Maturity Levels 0–3. Non-corporate Commonwealth entities must reach Maturity Level 2 under the PSPF. Every other organisation picks the requirement up contractually, through tenders and supplier clauses that pass the obligation down.

What the Essential Eight is

The Essential Eight is a list of eight technical mitigation strategies published by the Australian Cyber Security Centre (ACSC), part of the Australian Signals Directorate (ASD). It is a prioritised technical baseline with a model that measures how well each strategy has been implemented. It is not a management standard and carries no certification scheme.

Mitigation strategy What it means in practice
Application control Only approved executables, scripts and installers run on your systems
Patch applications Security patches for applications applied within defined timeframes
Configure Microsoft Office macro settings Macros blocked or restricted to vetted, justified use
User application hardening Browsers and productivity apps stripped of the risky features attackers rely on
Restrict administrative privileges Admin rights limited, validated and separated from everyday accounts
Patch operating systems OS security patches applied within defined timeframes
Multi-factor authentication MFA on remote access, privileged actions and important data repositories
Regular backups Backups taken, retained and tested

The authoritative source is cyber.gov.au, where the ASD publishes the maturity model and an Essential Eight assessment process guide. Where a document in front of you uses different wording from the ASD’s, the ASD’s is the version your assessor will use.

Maturity Levels 0 to 3

Each of the eight strategies is assessed at a maturity level. The levels are defined against the sophistication of the adversary they are meant to frustrate, not against the effort spent implementing them.

Level Broadly, what it means
Maturity Level 0 Weaknesses in your posture — the strategy is not meaningfully in place
Maturity Level 1 Protects against adversaries using widely available tools and techniques
Maturity Level 2 Holds up against adversaries willing to invest more time and effort in a target
Maturity Level 3 Counters more adaptive adversaries who are far less reliant on public tooling

Your overall maturity is the lowest level achieved across all eight strategies. Seven strategies at Maturity Level 2 with backups at Maturity Level 1 produces an overall rating of Maturity Level 1. The per-level pages break down what Maturity Level 1, Maturity Level 2 and Maturity Level 3 each require.

Who is mandated, and who inherits it contractually

The legal mandate is narrow. Non-corporate Commonwealth entities — federal departments and agencies under the PGPA Act — must reach Maturity Level 2 under the Protective Security Policy Framework (PSPF). No other organisation is bound by law.

The contractual reach is much wider. Government buyers pass their obligations down through contracts, so suppliers and tenderers inherit Essential Eight requirements without being named in the PSPF. A tender clause naming a required maturity level, with a submission deadline attached, is the most common route by which a private company encounters the framework. The supplier guide and the tender page cover that path.

Assessment has no central provider. In practice it is a mix of self-assessment against the ACSC’s assessment process guide, private consultancies and MSPs, and ASD-endorsed IRAP assessors where formal independent assurance is required, particularly for OFFICIAL and PROTECTED environments. The clause determines which of these you need, and what it asks you to evidence.

Every guide in this section

There is no Essential Eight certificate

The framework produces a maturity level claim and, where required, an independent assessment of that claim. Budget spent searching for a certification body is spent on something that does not exist.

The consequence for how you prepare: what an assessor examines is the evidence behind each of the eight strategies — patch records, MFA coverage, application control logs, backup test results. A folder of policies does not substitute for it. Evidence is the deliverable of Essential Eight work.

How Secure60 handles this

Most of the eight strategies are ongoing operations rather than projects. Patching applications and operating systems never finishes, restricted admin privileges hold only while someone keeps reviewing them, and backups count only once they are tested. We implement the eight to the maturity level your tender or agency requires, then run the recurring strategies: vulnerability management covers both patching strategies end to end, and the evidence for all eight stays current rather than being rebuilt before each assessment. Where ISO 27001 is also in scope, we run both from the same platform so the work is done once.

Frequently Asked Questions

Is the Essential Eight mandatory?

Only for non-corporate Commonwealth entities — federal departments and agencies — which must reach Maturity Level 2 under the Protective Security Policy Framework. Every other organisation acquires the requirement by contract: tenders and supplier agreements that require a stated maturity level.

Is there an Essential Eight certificate?

No. There is no certification scheme and no central certifier. You self-assess against the ASD’s maturity model, or engage an independent assessor — an IRAP assessor where formal assurance is required — and the outcome is a maturity level claim rather than a certificate.

What maturity level should we aim for?

The level named in the clause or tender in front of you. Federal entities are held to Maturity Level 2, and supplier requirements often mirror the buyer’s own obligation. Where nothing is named, Maturity Level 1 is the sensible floor to build from.

Who can assess our Essential Eight maturity?

There is no single provider. Assessment is a mix of self-assessment using the ACSC’s published assessment process guide, private consultancies and MSPs, and ASD-endorsed IRAP assessors where independent assurance is required — particularly for OFFICIAL and PROTECTED environments.

Essential Eight or ISO 27001 — which one do we need?

Whichever your buyer names. Government work names the Essential Eight; commercial and international customers ask for ISO 27001. The two overlap in the underlying work, and the comparison page works through the decision.

Identify the Required Maturity Level

A readiness call reviews the clause in scope, assesses current position against it, and sets out what closing the gap requires.

30 days, every feature switched on. No credit card.