The Essential Eight is a set of eight technical mitigation strategies published by the ACSC, part of the Australian Signals Directorate, and measured at Maturity Levels 0–3. Non-corporate Commonwealth entities must reach Maturity Level 2 under the PSPF. Everyone else gets pulled in contractually — through tenders and supplier clauses that pass the obligation down.
The Essential Eight is a list of eight technical mitigation strategies published by the Australian Cyber Security Centre (ACSC), part of the Australian Signals Directorate (ASD). It isn’t a management standard and it isn’t a certification scheme. It’s a prioritised technical baseline: the eight things the ASD wants done, in a model that measures how well you’ve done them.
| Mitigation strategy | What it means in practice |
|---|---|
| Application control | Only approved executables, scripts and installers run on your systems |
| Patch applications | Security patches for applications applied within defined timeframes |
| Configure Microsoft Office macro settings | Macros blocked or restricted to vetted, justified use |
| User application hardening | Browsers and productivity apps stripped of risky features attackers rely on |
| Restrict administrative privileges | Admin rights limited, validated and separated from everyday accounts |
| Patch operating systems | OS security patches applied within defined timeframes |
| Multi-factor authentication | MFA on remote access, privileged actions and important data repositories |
| Regular backups | Backups taken, retained and — the part that gets skipped — tested |
The authoritative source is cyber.gov.au, where the ASD publishes the maturity model and an Essential Eight assessment process guide. If a document in front of you uses different wording than the ASD’s, treat the ASD’s as the one your assessor will use.
Each of the eight strategies is assessed at a maturity level, and the levels are defined against the sophistication of the attacker they’re meant to frustrate — not against effort spent.
| Level | Broadly, what it means |
|---|---|
| Maturity Level 0 | Weaknesses in your posture — the strategy isn’t meaningfully in place |
| Maturity Level 1 | Protects against adversaries using widely available tools and techniques |
| Maturity Level 2 | Holds up against adversaries willing to invest more time and effort in a target |
| Maturity Level 3 | Counters more adaptive adversaries who are far less reliant on public tooling |
Your overall maturity is the lowest level across all eight strategies. Seven strategies at Maturity Level 2 and backups at Maturity Level 1 makes you a Maturity Level 1 organisation — a detail that surprises a lot of teams at assessment time. The per-level pages break down exactly what Maturity Level 1, Maturity Level 2 and Maturity Level 3 each require.
The hard mandate is narrow. Non-corporate Commonwealth entities — federal departments and agencies under the PGPA Act — must reach Maturity Level 2 under the Protective Security Policy Framework (PSPF). That’s it for legal obligation.
The soft mandate is much wider, and it’s probably why you’re reading this. Government buyers pass their obligations down through contracts, so suppliers and tenderers inherit Essential Eight requirements without ever being named in the PSPF. “The tender says Essential Eight compliance and closes in six weeks” is the most common way a private company meets this framework. If that’s you, start with the supplier guide or the tender page.
Assessment has no central provider. In practice it’s a mix: self-assessment against the ACSC’s assessment process guide, private consultancies and MSPs, and IRAP assessors — ASD-endorsed — where formal independent assurance is required, especially for OFFICIAL and PROTECTED environments. Which one you need depends on what the clause asks you to evidence, so read it before you buy an assessment.
Shopping for an “Essential Eight certificate”. There isn’t one, and a surprising amount of budget gets spent looking for it.
What actually exists is a maturity claim and, where required, independent assessment of that claim. The practical consequence: the document that matters isn’t a certificate on the wall, it’s the evidence behind each of the eight strategies — patch records, MFA coverage, application control logs, backup test results — sitting ready for whoever assesses you. Teams that chase the certificate build a folder of policies; teams that understand the model build evidence. Assessors ask for the second one.
Most of the eight aren’t projects — they’re operations. Patching applications and operating systems never finishes, restricted admin privileges only hold if someone keeps reviewing them, and backups only count if they’re tested. We implement the eight to the maturity level your tender or agency requires, then run the ongoing ones: vulnerability management covers both patching strategies end to end, and the evidence for all eight stays current instead of being rebuilt in a panic before each assessment. If ISO 27001 is also on your horizon, we run both from the same platform so the work isn’t done twice.
Is the Essential Eight mandatory?
Only for non-corporate Commonwealth entities — federal departments and agencies — which must reach Maturity Level 2 under the Protective Security Policy Framework. For everyone else it arrives by contract: tenders and supplier agreements that require a stated maturity level.
Is there an Essential Eight certificate?
No. There’s no certification scheme and no central certifier. You self-assess against the ASD’s maturity model, or engage an independent assessor — an IRAP assessor where formal assurance is required — and the outcome is a maturity level claim, not a certificate.
What maturity level should we aim for?
The level named in the clause or tender in front of you. Federal entities are held to Maturity Level 2, and supplier requirements often mirror the buyer’s own obligation. If nothing is named, Maturity Level 1 is the sensible floor to build from.
Who can assess our Essential Eight maturity?
There’s no single provider. Assessment is a mix of self-assessment using the ACSC’s published assessment process guide, private consultancies and MSPs, and ASD-endorsed IRAP assessors where independent assurance is required — especially for OFFICIAL and PROTECTED environments.
Essential Eight or ISO 27001 — which one do we need?
Whichever your buyer names. Government work names the Essential Eight; commercial and international customers ask for ISO 27001. The two overlap in the underlying work, and the comparison page works through the decision properly.