Skip to content
arrow_back
search
E8-AH-ML3.1 bolt ASD Essential Eight

.NET Framework 3.5, 3.0, 2.0 is disabled or removed

Ensure older versions of .NET Framework (3.5, 3.0, 2.0) are turned off or uninstalled.

record_voice_over

Plain language

This control is about making sure that older versions of the .NET Framework, which is a kind of software that helps programs run on Windows computers, are either turned off or completely removed. These older versions can be unsafe because they might have security holes that hackers can exploit to break into or mess up your computer systems.

Framework

ASD Essential Eight

Control effect

Proactive

E8 mitigation strategy

Application hardening

Classifications

N/A

Official last update

N/A

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML3

Official control statement

.NET Framework 3.5 (includes .NET 2.0 and 3.0) is disabled or removed.
bolt ASD Essential Eight E8-AH-ML3.1
priority_high

Why it matters

Without disabling or removing .NET Framework 3.5/3.0/2.0, systems remain exposed to legacy vulnerabilities that attackers can exploit.

settings

Operational notes

Regularly audit endpoints to ensure .NET Framework 3.5/3.0/2.0 stays disabled/removed, and block re-enablement or reinstall via policy.

Mapping detail

Mapping

Direction

Controls